1//===-- Verifier.cpp - Implement the Module Verifier -----------------------==//
2//
3// Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
4// See https://llvm.org/LICENSE.txt for license information.
5// SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
6//
7//===----------------------------------------------------------------------===//
8//
9// This file defines the function verifier interface, that can be used for some
10// basic correctness checking of input to the system.
11//
12// Note that this does not provide full `Java style' security and verifications,
13// instead it just tries to ensure that code is well-formed.
14//
15// * Both of a binary operator's parameters are of the same type
16// * Verify that the indices of mem access instructions match other operands
17// * Verify that arithmetic and other things are only performed on first-class
18// types. Verify that shifts & logicals only happen on integrals f.e.
19// * All of the constants in a switch statement are of the correct type
20// * The code is in valid SSA form
21// * It should be illegal to put a label into any other type (like a structure)
22// or to return one. [except constant arrays!]
23// * Only phi nodes can be self referential: 'add i32 %0, %0 ; <int>:0' is bad
24// * PHI nodes must have an entry for each predecessor, with no extras.
25// * PHI nodes must be the first thing in a basic block, all grouped together
26// * All basic blocks should only end with terminator insts, not contain them
27// * The entry node to a function must not have predecessors
28// * All Instructions must be embedded into a basic block
29// * Functions cannot take a void-typed parameter
30// * Verify that a function's argument list agrees with it's declared type.
31// * It is illegal to specify a name for a void value.
32// * It is illegal to have a internal global value with no initializer
33// * It is illegal to have a ret instruction that returns a value that does not
34// agree with the function return value type.
35// * Function call argument types match the function prototype
36// * A landing pad is defined by a landingpad instruction, and can be jumped to
37// only by the unwind edge of an invoke instruction.
38// * A landingpad instruction must be the first non-PHI instruction in the
39// block.
40// * Landingpad instructions must be in a function with a personality function.
41// * Convergence control intrinsics are introduced in ConvergentOperations.rst.
42// The applied restrictions are too numerous to list here.
43// * The convergence entry intrinsic and the loop heart must be the first
44// non-PHI instruction in their respective block. This does not conflict with
45// the landing pads, since these two kinds cannot occur in the same block.
46// * All other things that are tested by asserts spread about the code...
47//
48//===----------------------------------------------------------------------===//
49
50#include "llvm/IR/Verifier.h"
51#include "VerifierInternal.h"
52#include "llvm/ADT/APFloat.h"
53#include "llvm/ADT/APInt.h"
54#include "llvm/ADT/ArrayRef.h"
55#include "llvm/ADT/DenseMap.h"
56#include "llvm/ADT/MapVector.h"
57#include "llvm/ADT/STLExtras.h"
58#include "llvm/ADT/SmallPtrSet.h"
59#include "llvm/ADT/SmallVector.h"
60#include "llvm/ADT/StringExtras.h"
61#include "llvm/ADT/StringRef.h"
62#include "llvm/ADT/Twine.h"
63#include "llvm/BinaryFormat/Dwarf.h"
64#include "llvm/IR/Argument.h"
65#include "llvm/IR/AttributeMask.h"
66#include "llvm/IR/Attributes.h"
67#include "llvm/IR/AutoUpgrade.h"
68#include "llvm/IR/BasicBlock.h"
69#include "llvm/IR/BundleAttributes.h"
70#include "llvm/IR/CFG.h"
71#include "llvm/IR/CallingConv.h"
72#include "llvm/IR/Comdat.h"
73#include "llvm/IR/Constant.h"
74#include "llvm/IR/ConstantRange.h"
75#include "llvm/IR/ConstantRangeList.h"
76#include "llvm/IR/Constants.h"
77#include "llvm/IR/ConvergenceVerifier.h"
78#include "llvm/IR/DataLayout.h"
79#include "llvm/IR/DebugInfo.h"
80#include "llvm/IR/DebugInfoMetadata.h"
81#include "llvm/IR/DebugLoc.h"
82#include "llvm/IR/DerivedTypes.h"
83#include "llvm/IR/Dominators.h"
84#include "llvm/IR/EHPersonalities.h"
85#include "llvm/IR/FPEnv.h"
86#include "llvm/IR/Function.h"
87#include "llvm/IR/GCStrategy.h"
88#include "llvm/IR/GetElementPtrTypeIterator.h"
89#include "llvm/IR/GlobalAlias.h"
90#include "llvm/IR/GlobalValue.h"
91#include "llvm/IR/GlobalVariable.h"
92#include "llvm/IR/InlineAsm.h"
93#include "llvm/IR/InstVisitor.h"
94#include "llvm/IR/InstrTypes.h"
95#include "llvm/IR/Instruction.h"
96#include "llvm/IR/Instructions.h"
97#include "llvm/IR/IntrinsicInst.h"
98#include "llvm/IR/Intrinsics.h"
99#include "llvm/IR/IntrinsicsAArch64.h"
100#include "llvm/IR/IntrinsicsARM.h"
101#include "llvm/IR/IntrinsicsNVPTX.h"
102#include "llvm/IR/IntrinsicsRISCV.h"
103#include "llvm/IR/IntrinsicsWebAssembly.h"
104#include "llvm/IR/LLVMContext.h"
105#include "llvm/IR/MemoryModelRelaxationAnnotations.h"
106#include "llvm/IR/Metadata.h"
107#include "llvm/IR/Module.h"
108#include "llvm/IR/ModuleSlotTracker.h"
109#include "llvm/IR/PassManager.h"
110#include "llvm/IR/ProfDataUtils.h"
111#include "llvm/IR/Statepoint.h"
112#include "llvm/IR/Type.h"
113#include "llvm/IR/Use.h"
114#include "llvm/IR/User.h"
115#include "llvm/IR/VFABIDemangler.h"
116#include "llvm/IR/Value.h"
117#include "llvm/InitializePasses.h"
118#include "llvm/Pass.h"
119#include "llvm/ProfileData/InstrProf.h"
120#include "llvm/Support/AtomicOrdering.h"
121#include "llvm/Support/Casting.h"
122#include "llvm/Support/CodeGen.h"
123#include "llvm/Support/CommandLine.h"
124#include "llvm/Support/ErrorHandling.h"
125#include "llvm/Support/FormatVariadic.h"
126#include "llvm/Support/MathExtras.h"
127#include "llvm/Support/ModRef.h"
128#include "llvm/Support/TimeProfiler.h"
129#include "llvm/Support/raw_ostream.h"
130#include "llvm/TargetParser/RISCVTargetParser.h"
131#include "llvm/TargetParser/Triple.h"
132#include "llvm/Transforms/Coroutines/CoroInstr.h"
133#include <algorithm>
134#include <cassert>
135#include <cstdint>
136#include <limits>
137#include <memory>
138#include <optional>
139#include <queue>
140#include <string>
141#include <utility>
142
143using namespace llvm;
144
145static cl::opt<bool> VerifyNoAliasScopeDomination(
146 "verify-noalias-scope-decl-dom", cl::Hidden, cl::init(Val: false),
147 cl::desc("Ensure that llvm.experimental.noalias.scope.decl for identical "
148 "scopes are not dominating"));
149
150namespace {
151
152class Verifier : public InstVisitor<Verifier>, VerifierSupport {
153 friend class InstVisitor<Verifier>;
154 DominatorTree DT;
155
156 /// When verifying a basic block, keep track of all of the
157 /// instructions we have seen so far.
158 ///
159 /// This allows us to do efficient dominance checks for the case when an
160 /// instruction has an operand that is an instruction in the same block.
161 SmallPtrSet<Instruction *, 16> InstsInThisBlock;
162
163 /// Keep track of the metadata nodes that have been checked already.
164 SmallPtrSet<const Metadata *, 32> MDNodes;
165
166 /// Keep track which DISubprogram is attached to which function.
167 DenseMap<const DISubprogram *, const Function *> DISubprogramAttachments;
168
169 /// For each visited DIScope, whether walking its scope chain reaches a
170 /// repeated node.
171 DenseMap<const Metadata *, bool> DIScopeChainReachesCycle;
172
173 /// Track all DICompileUnits visited.
174 SmallPtrSet<const Metadata *, 2> CUVisited;
175
176 /// The result type for a landingpad.
177 Type *LandingPadResultTy;
178
179 /// Whether we've seen a call to @llvm.localescape in this function
180 /// already.
181 bool SawFrameEscape;
182
183 /// Whether the current function has a DISubprogram attached to it.
184 bool HasDebugInfo = false;
185
186 /// Stores the count of how many objects were passed to llvm.localescape for a
187 /// given function and the largest index passed to llvm.localrecover.
188 DenseMap<Function *, std::pair<unsigned, unsigned>> FrameEscapeInfo;
189
190 // Maps catchswitches and cleanuppads that unwind to siblings to the
191 // terminators that indicate the unwind, used to detect cycles therein.
192 MapVector<Instruction *, Instruction *> SiblingFuncletInfo;
193
194 /// Cache which blocks are in which funclet, if an EH funclet personality is
195 /// in use. Otherwise empty.
196 DenseMap<BasicBlock *, ColorVector> BlockEHFuncletColors;
197
198 /// Cache of constants visited in search of ConstantExprs.
199 SmallPtrSet<const Constant *, 32> ConstantExprVisited;
200
201 /// Cache of declarations of the llvm.experimental.deoptimize.<ty> intrinsic.
202 SmallVector<const Function *, 4> DeoptimizeDeclarations;
203
204 /// Cache of attribute lists verified.
205 SmallPtrSet<const void *, 32> AttributeListsVisited;
206
207 // Verify that this GlobalValue is only used in this module.
208 // This map is used to avoid visiting uses twice. We can arrive at a user
209 // twice, if they have multiple operands. In particular for very large
210 // constant expressions, we can arrive at a particular user many times.
211 SmallPtrSet<const Value *, 32> GlobalValueVisited;
212
213 // Keeps track of duplicate function argument debug info.
214 SmallVector<const DILocalVariable *, 16> DebugFnArgs;
215
216 TBAAVerifier TBAAVerifyHelper;
217 ConvergenceVerifier ConvergenceVerifyHelper;
218
219 SmallVector<IntrinsicInst *, 4> NoAliasScopeDecls;
220
221 void checkAtomicMemAccessSize(Type *Ty, const Instruction *I);
222
223public:
224 explicit Verifier(raw_ostream *OS, bool ShouldTreatBrokenDebugInfoAsError,
225 const Module &M)
226 : VerifierSupport(OS, M), LandingPadResultTy(nullptr),
227 SawFrameEscape(false), TBAAVerifyHelper(this) {
228 TreatBrokenDebugInfoAsError = ShouldTreatBrokenDebugInfoAsError;
229 }
230
231 bool hasBrokenDebugInfo() const { return BrokenDebugInfo; }
232
233 bool verify(const Function &F) {
234 llvm::TimeTraceScope timeScope("Verifier");
235 assert(F.getParent() == &M &&
236 "An instance of this class only works with a specific module!");
237
238 // First ensure the function is well-enough formed to compute dominance
239 // information, and directly compute a dominance tree. We don't rely on the
240 // pass manager to provide this as it isolates us from a potentially
241 // out-of-date dominator tree and makes it significantly more complex to run
242 // this code outside of a pass manager.
243
244 // First check that every basic block has a terminator, otherwise we can't
245 // even inspect the CFG.
246 for (const BasicBlock &BB : F) {
247 if (!BB.empty() && BB.back().isTerminator())
248 continue;
249
250 if (OS) {
251 *OS << "Basic Block in function '" << F.getName()
252 << "' does not have terminator!\n";
253 BB.printAsOperand(O&: *OS, PrintType: true, MST);
254 *OS << "\n";
255 }
256 return false;
257 }
258
259 // FIXME: It's really gross that we have to cast away constness here.
260 if (!F.empty())
261 DT.recalculate(Func&: const_cast<Function &>(F));
262
263 auto FailureCB = [this](const Twine &Message) {
264 this->CheckFailed(Message);
265 };
266 ConvergenceVerifyHelper.initialize(OS, FailureCB, F);
267
268 Broken = false;
269 // FIXME: We strip const here because the inst visitor strips const.
270 visit(F&: const_cast<Function &>(F));
271 verifySiblingFuncletUnwinds();
272
273 if (ConvergenceVerifyHelper.sawTokens())
274 ConvergenceVerifyHelper.verify(DT);
275
276 InstsInThisBlock.clear();
277 DebugFnArgs.clear();
278 DIScopeChainReachesCycle.clear();
279 LandingPadResultTy = nullptr;
280 SawFrameEscape = false;
281 SiblingFuncletInfo.clear();
282 verifyNoAliasScopeDecl();
283 NoAliasScopeDecls.clear();
284
285 return !Broken;
286 }
287
288 /// Verify the module that this instance of \c Verifier was initialized with.
289 bool verify() {
290 Broken = false;
291
292 // Collect all declarations of the llvm.experimental.deoptimize intrinsic.
293 for (const Function &F : M)
294 if (F.getIntrinsicID() == Intrinsic::experimental_deoptimize)
295 DeoptimizeDeclarations.push_back(Elt: &F);
296
297 // Now that we've visited every function, verify that we never asked to
298 // recover a frame index that wasn't escaped.
299 verifyFrameRecoverIndices();
300 for (const GlobalVariable &GV : M.globals())
301 visitGlobalVariable(GV);
302
303 for (const GlobalAlias &GA : M.aliases())
304 visitGlobalAlias(GA);
305
306 for (const GlobalIFunc &GI : M.ifuncs())
307 visitGlobalIFunc(GI);
308
309 for (const NamedMDNode &NMD : M.named_metadata())
310 visitNamedMDNode(NMD);
311
312 for (const StringMapEntry<Comdat> &SMEC : M.getComdatSymbolTable())
313 visitComdat(C: SMEC.getValue());
314
315 visitModuleFlags();
316 visitModuleIdents();
317 visitModuleCommandLines();
318 visitModuleErrnoTBAA();
319
320 verifyCompileUnits();
321
322 verifyDeoptimizeCallingConvs();
323 DISubprogramAttachments.clear();
324 DIScopeChainReachesCycle.clear();
325 return !Broken;
326 }
327
328private:
329 /// Whether a metadata node is allowed to be, or contain, a DILocation.
330 enum class AreDebugLocsAllowed { No, Yes };
331
332 /// Metadata that should be treated as a range, with slightly different
333 /// requirements.
334 enum class RangeLikeMetadataKind {
335 Range, // MD_range
336 AbsoluteSymbol, // MD_absolute_symbol
337 NoaliasAddrspace // MD_noalias_addrspace
338 };
339
340 // Verification methods...
341 void visitGlobalValue(const GlobalValue &GV);
342 void visitGlobalVariable(const GlobalVariable &GV);
343 void visitGlobalAlias(const GlobalAlias &GA);
344 void visitGlobalIFunc(const GlobalIFunc &GI);
345 void visitAliaseeSubExpr(const GlobalAlias &A, const Constant &C);
346 void visitAliaseeSubExpr(SmallPtrSetImpl<const GlobalAlias *> &Visited,
347 const GlobalAlias &A, const Constant &C);
348 void visitNamedMDNode(const NamedMDNode &NMD);
349 void visitMDNode(const MDNode &MD, AreDebugLocsAllowed AllowLocs);
350 void visitMetadataAsValue(const MetadataAsValue &MD, Function *F);
351 void visitValueAsMetadata(const ValueAsMetadata &MD, Function *F);
352 void visitDIArgList(const DIArgList &AL, Function *F);
353 void visitComdat(const Comdat &C);
354 void visitModuleIdents();
355 void visitModuleCommandLines();
356 void visitModuleErrnoTBAA();
357 void visitModuleFlags();
358 void visitModuleFlag(const MDNode *Op,
359 DenseMap<const MDString *, const MDNode *> &SeenIDs,
360 SmallVectorImpl<const MDNode *> &Requirements);
361 void visitModuleFlagCGProfileEntry(const MDOperand &MDO);
362 void visitFunction(const Function &F);
363 void visitBasicBlock(BasicBlock &BB);
364 void verifyRangeLikeMetadata(const Value &V, const MDNode *Range, Type *Ty,
365 RangeLikeMetadataKind Kind);
366 void visitRangeMetadata(Instruction &I, MDNode *Range, Type *Ty);
367 void visitNoFPClassMetadata(Instruction &I, MDNode *Range, Type *Ty);
368 void visitNoaliasAddrspaceMetadata(Instruction &I, MDNode *Range, Type *Ty);
369 void visitDereferenceableMetadata(Instruction &I, MDNode *MD);
370 void visitNoFreeObjMetadata(Instruction &I, MDNode *MD);
371 void visitProfMetadata(Instruction &I, MDNode *MD);
372 void visitCallStackMetadata(MDNode *MD);
373 void visitMemProfMetadata(Instruction &I, MDNode *MD);
374 void visitCallsiteMetadata(Instruction &I, MDNode *MD);
375 void visitCalleeTypeMetadata(Instruction &I, MDNode *MD);
376 void visitDIAssignIDMetadata(Instruction &I, MDNode *MD);
377 void visitMMRAMetadata(Instruction &I, MDNode *MD);
378 void visitAnnotationMetadata(MDNode *Annotation);
379 void visitAliasScopeMetadata(const MDNode *MD);
380 void visitAliasScopeListMetadata(const MDNode *MD);
381 void visitAccessGroupMetadata(const MDNode *MD);
382 void visitCapturesMetadata(Instruction &I, const MDNode *Captures);
383 void visitAllocTokenMetadata(Instruction &I, MDNode *MD);
384 void visitInlineHistoryMetadata(Instruction &I, MDNode *MD);
385 void visitMemCacheHintMetadata(Instruction &I, MDNode *MD);
386
387#define HANDLE_SPECIALIZED_MDNODE_LEAF(CLASS) void visit##CLASS(const CLASS &N);
388#include "llvm/IR/Metadata.def"
389 void visitDIType(const DIType &N);
390 void visitDIScope(const DIScope &N);
391 void visitDIScopeChain(const DIScope &N);
392 bool hasDIScopeCycle(const Metadata *S);
393 DISubprogram *getSubprogram(Metadata *LocalScope);
394 void visitDIVariable(const DIVariable &N);
395 void visitDILexicalBlockBase(const DILexicalBlockBase &N);
396 void visitDITemplateParameter(const DITemplateParameter &N);
397
398 void visitTemplateParams(const MDNode &N, const Metadata &RawParams);
399
400 void visit(DbgLabelRecord &DLR);
401 void visit(DbgVariableRecord &DVR);
402 // InstVisitor overrides...
403 using InstVisitor<Verifier>::visit;
404 void visitDbgRecords(Instruction &I);
405 void visit(Instruction &I);
406
407 void visitTruncInst(TruncInst &I);
408 void visitZExtInst(ZExtInst &I);
409 void visitSExtInst(SExtInst &I);
410 void visitFPTruncInst(FPTruncInst &I);
411 void visitFPExtInst(FPExtInst &I);
412 void visitFPToUIInst(FPToUIInst &I);
413 void visitFPToSIInst(FPToSIInst &I);
414 void visitUIToFPInst(UIToFPInst &I);
415 void visitSIToFPInst(SIToFPInst &I);
416 void visitIntToPtrInst(IntToPtrInst &I);
417 void checkPtrToAddr(Type *SrcTy, Type *DestTy, const Value &V);
418 void visitPtrToAddrInst(PtrToAddrInst &I);
419 void visitPtrToIntInst(PtrToIntInst &I);
420 void visitBitCastInst(BitCastInst &I);
421 void visitAddrSpaceCastInst(AddrSpaceCastInst &I);
422 void visitPHINode(PHINode &PN);
423 void visitCallBase(CallBase &Call);
424 void visitUnaryOperator(UnaryOperator &U);
425 void visitBinaryOperator(BinaryOperator &B);
426 void visitICmpInst(ICmpInst &IC);
427 void visitFCmpInst(FCmpInst &FC);
428 void visitExtractElementInst(ExtractElementInst &EI);
429 void visitInsertElementInst(InsertElementInst &EI);
430 void visitShuffleVectorInst(ShuffleVectorInst &EI);
431 void visitBitInsertInst(BitInsertInst &BII);
432 void visitBitExtractInst(BitExtractInst &BEI);
433 void visitVAArgInst(VAArgInst &VAA) { visitInstruction(I&: VAA); }
434 void visitCallInst(CallInst &CI);
435 void visitInvokeInst(InvokeInst &II);
436 void visitGetElementPtrInst(GetElementPtrInst &GEP);
437 void visitLoadInst(LoadInst &LI);
438 void visitStoreInst(StoreInst &SI);
439 void verifyDominatesUse(Instruction &I, unsigned i);
440 void visitInstruction(Instruction &I);
441 void visitTerminator(Instruction &I);
442 void visitCondBrInst(CondBrInst &BI);
443 void visitReturnInst(ReturnInst &RI);
444 void visitSwitchInst(SwitchInst &SI);
445 void visitIndirectBrInst(IndirectBrInst &BI);
446 void visitCallBrInst(CallBrInst &CBI);
447 void visitSelectInst(SelectInst &SI);
448 void visitUserOp1(Instruction &I);
449 void visitUserOp2(Instruction &I) { visitUserOp1(I); }
450 void visitIntrinsicCall(Intrinsic::ID ID, CallBase &Call);
451 void visitConstrainedFPIntrinsic(ConstrainedFPIntrinsic &FPI);
452 void visitVPIntrinsic(VPIntrinsic &VPI);
453 void visitDbgLabelIntrinsic(StringRef Kind, DbgLabelInst &DLI);
454 void visitAtomicCmpXchgInst(AtomicCmpXchgInst &CXI);
455 void visitAtomicRMWInst(AtomicRMWInst &RMWI);
456 void visitFenceInst(FenceInst &FI);
457 void visitAllocaInst(AllocaInst &AI);
458 void visitExtractValueInst(ExtractValueInst &EVI);
459 void visitInsertValueInst(InsertValueInst &IVI);
460 void visitEHPadPredecessors(Instruction &I);
461 void visitLandingPadInst(LandingPadInst &LPI);
462 void visitResumeInst(ResumeInst &RI);
463 void visitCatchPadInst(CatchPadInst &CPI);
464 void visitCatchReturnInst(CatchReturnInst &CatchReturn);
465 void visitCleanupPadInst(CleanupPadInst &CPI);
466 void visitFuncletPadInst(FuncletPadInst &FPI);
467 void visitCatchSwitchInst(CatchSwitchInst &CatchSwitch);
468 void visitCleanupReturnInst(CleanupReturnInst &CRI);
469
470 void verifySwiftErrorCall(CallBase &Call, const Value *SwiftErrorVal);
471 void verifySwiftErrorValue(const Value *SwiftErrorVal);
472 void verifyTailCCMustTailAttrs(const AttrBuilder &Attrs, StringRef Context);
473 void verifyMustTailCall(CallInst &CI);
474 bool verifyAttributeCount(AttributeList Attrs, unsigned Params);
475 void verifyAttributeTypes(AttributeSet Attrs, const Value *V);
476 void verifyParameterAttrs(AttributeSet Attrs, Type *Ty, const Value *V);
477 void checkUnsignedBaseTenFuncAttr(AttributeList Attrs, StringRef Attr,
478 const Value *V);
479 void verifyFunctionAttrs(FunctionType *FT, AttributeList Attrs,
480 const Value *V, bool IsIntrinsic, bool IsInlineAsm);
481 void verifyFunctionMetadata(ArrayRef<std::pair<unsigned, MDNode *>> MDs);
482 void verifyUnknownProfileMetadata(MDNode *MD);
483 void visitConstantExprsRecursively(const Constant *EntryC);
484 void visitConstantExpr(const ConstantExpr *CE);
485 void visitConstantPtrAuth(const ConstantPtrAuth *CPA);
486 void verifyInlineAsmCall(const CallBase &Call);
487 void verifyStatepoint(const CallBase &Call);
488 void verifyFrameRecoverIndices();
489 void verifySiblingFuncletUnwinds();
490
491 void verifyFragmentExpression(const DbgVariableRecord &I);
492 template <typename ValueOrMetadata>
493 void verifyFragmentExpression(const DIVariable &V,
494 DIExpression::FragmentInfo Fragment,
495 ValueOrMetadata *Desc);
496 void verifyFnArgs(const DbgVariableRecord &DVR);
497 void verifyNotEntryValue(const DbgVariableRecord &I);
498
499 /// Module-level debug info verification...
500 void verifyCompileUnits();
501
502 /// Module-level verification that all @llvm.experimental.deoptimize
503 /// declarations share the same calling convention.
504 void verifyDeoptimizeCallingConvs();
505
506 void verifyAttachedCallBundle(const CallBase &Call,
507 const OperandBundleUse &BU);
508
509 /// Verify the llvm.experimental.noalias.scope.decl declarations
510 void verifyNoAliasScopeDecl();
511};
512
513} // end anonymous namespace
514
515/// We know that cond should be true, if not print an error message.
516#define Check(C, ...) \
517 do { \
518 if (!(C)) { \
519 CheckFailed(__VA_ARGS__); \
520 return; \
521 } \
522 } while (false)
523
524/// We know that a debug info condition should be true, if not print
525/// an error message.
526#define CheckDI(C, ...) \
527 do { \
528 if (!(C)) { \
529 DebugInfoCheckFailed(__VA_ARGS__); \
530 return; \
531 } \
532 } while (false)
533
534void Verifier::visitDbgRecords(Instruction &I) {
535 if (!I.getDbgMarker())
536 return;
537 CheckDI(I.getDbgMarker()->MarkedInstr == &I,
538 "Instruction has invalid DebugMarker", &I);
539 CheckDI(!isa<PHINode>(&I) || !I.hasDbgRecords(),
540 "PHI Node must not have any attached DbgRecords", &I);
541 for (DbgRecord &DR : I.getDbgRecordRange()) {
542 CheckDI(DR.getMarker() == I.getDbgMarker(),
543 "DbgRecord had invalid DebugMarker", &I, &DR);
544 if (auto *Loc =
545 dyn_cast_or_null<DILocation>(Val: DR.getDebugLoc().getAsMDNode()))
546 visitMDNode(MD: *Loc, AllowLocs: AreDebugLocsAllowed::Yes);
547 if (auto *DVR = dyn_cast<DbgVariableRecord>(Val: &DR)) {
548 visit(DVR&: *DVR);
549 // These have to appear after `visit` for consistency with existing
550 // intrinsic behaviour.
551 verifyFragmentExpression(I: *DVR);
552 verifyNotEntryValue(I: *DVR);
553 } else if (auto *DLR = dyn_cast<DbgLabelRecord>(Val: &DR)) {
554 visit(DLR&: *DLR);
555 }
556 }
557}
558
559void Verifier::visit(Instruction &I) {
560 visitDbgRecords(I);
561 for (unsigned i = 0, e = I.getNumOperands(); i != e; ++i)
562 Check(I.getOperand(i) != nullptr, "Operand is null", &I);
563 InstVisitor<Verifier>::visit(I);
564}
565
566// Helper to iterate over indirect users. By returning false, the callback can ask to stop traversing further.
567static void forEachUser(const Value *User,
568 SmallPtrSet<const Value *, 32> &Visited,
569 llvm::function_ref<bool(const Value *)> Callback) {
570 if (!Visited.insert(Ptr: User).second)
571 return;
572
573 SmallVector<const Value *> WorkList(User->materialized_users());
574 while (!WorkList.empty()) {
575 const Value *Cur = WorkList.pop_back_val();
576 if (!Visited.insert(Ptr: Cur).second)
577 continue;
578 if (Callback(Cur))
579 append_range(C&: WorkList, R: Cur->materialized_users());
580 }
581}
582
583void Verifier::visitGlobalValue(const GlobalValue &GV) {
584 Check(!GV.isDeclaration() || GV.hasValidDeclarationLinkage(),
585 "Global is external, but doesn't have external or weak linkage!", &GV);
586
587 if (const auto *GO = dyn_cast<GlobalObject>(Val: &GV)) {
588 if (const MDNode *Associated =
589 GO->getMetadata(KindID: LLVMContext::MD_associated)) {
590 Check(Associated->getNumOperands() == 1,
591 "associated metadata must have one operand", &GV, Associated);
592 const Metadata *Op = Associated->getOperand(I: 0).get();
593 Check(Op, "associated metadata must have a global value", GO, Associated);
594
595 const auto *VM = dyn_cast_or_null<ValueAsMetadata>(Val: Op);
596 Check(VM, "associated metadata must be ValueAsMetadata", GO, Associated);
597 if (VM) {
598 Check(isa<PointerType>(VM->getValue()->getType()),
599 "associated value must be pointer typed", GV, Associated);
600
601 const Value *Stripped = VM->getValue()->stripPointerCastsAndAliases();
602 Check(isa<GlobalObject>(Stripped) || isa<Constant>(Stripped),
603 "associated metadata must point to a GlobalObject", GO, Stripped);
604 Check(Stripped != GO,
605 "global values should not associate to themselves", GO,
606 Associated);
607 }
608 }
609
610 // FIXME: Why is getMetadata on GlobalValue protected?
611 if (const MDNode *AbsoluteSymbol =
612 GO->getMetadata(KindID: LLVMContext::MD_absolute_symbol)) {
613 verifyRangeLikeMetadata(V: *GO, Range: AbsoluteSymbol,
614 Ty: DL.getIntPtrType(GO->getType()),
615 Kind: RangeLikeMetadataKind::AbsoluteSymbol);
616 }
617
618 if (GO->hasMetadata(KindID: LLVMContext::MD_implicit_ref)) {
619 Check(!GO->isDeclaration(),
620 "ref metadata must not be placed on a declaration", GO);
621
622 SmallVector<MDNode *> MDs;
623 GO->getMetadata(KindID: LLVMContext::MD_implicit_ref, MDs);
624 for (const MDNode *MD : MDs) {
625 Check(MD->getNumOperands() == 1, "ref metadata must have one operand",
626 &GV, MD);
627 const Metadata *Op = MD->getOperand(I: 0).get();
628 const auto *VM = dyn_cast_or_null<ValueAsMetadata>(Val: Op);
629 Check(VM, "ref metadata must be ValueAsMetadata", GO, MD);
630 if (VM) {
631 Check(isa<PointerType>(VM->getValue()->getType()),
632 "ref value must be pointer typed", GV, MD);
633
634 const Value *Stripped = VM->getValue()->stripPointerCastsAndAliases();
635 Check(isa<GlobalObject>(Stripped) || isa<Constant>(Stripped),
636 "ref metadata must point to a GlobalObject", GO, Stripped);
637 Check(Stripped != GO, "values should not reference themselves", GO,
638 MD);
639 }
640 }
641 }
642
643 if (auto *Props = GO->getMetadata(KindID: LLVMContext::MD_elf_section_properties)) {
644 Check(Props->getNumOperands() == 2,
645 "elf_section_properties metadata must have two operands", GO,
646 Props);
647 if (Props->getNumOperands() == 2) {
648 auto *Type = dyn_cast<ConstantAsMetadata>(Val: Props->getOperand(I: 0));
649 Check(Type, "type field must be ConstantAsMetadata", GO, Props);
650 auto *TypeInt = dyn_cast<ConstantInt>(Val: Type->getValue());
651 Check(TypeInt, "type field must be ConstantInt", GO, Props);
652
653 auto *Entsize = dyn_cast<ConstantAsMetadata>(Val: Props->getOperand(I: 1));
654 Check(Entsize, "entsize field must be ConstantAsMetadata", GO, Props);
655 auto *EntsizeInt = dyn_cast<ConstantInt>(Val: Entsize->getValue());
656 Check(EntsizeInt, "entsize field must be ConstantInt", GO, Props);
657 }
658 }
659 }
660
661 Check(!GV.hasAppendingLinkage() || isa<GlobalVariable>(GV),
662 "Only global variables can have appending linkage!", &GV);
663
664 if (GV.hasAppendingLinkage()) {
665 const auto *GVar = dyn_cast<GlobalVariable>(Val: &GV);
666 Check(GVar && GVar->getValueType()->isArrayTy(),
667 "Only global arrays can have appending linkage!", GVar);
668 }
669
670 if (GV.isDeclarationForLinker())
671 Check(!GV.hasComdat(), "Declaration may not be in a Comdat!", &GV);
672
673 if (GV.hasDLLExportStorageClass()) {
674 Check(!GV.hasHiddenVisibility(),
675 "dllexport GlobalValue must have default or protected visibility",
676 &GV);
677 }
678 if (GV.hasDLLImportStorageClass()) {
679 Check(GV.hasDefaultVisibility(),
680 "dllimport GlobalValue must have default visibility", &GV);
681 Check(!GV.isDSOLocal(), "GlobalValue with DLLImport Storage is dso_local!",
682 &GV);
683
684 Check((GV.isDeclaration() &&
685 (GV.hasExternalLinkage() || GV.hasExternalWeakLinkage())) ||
686 GV.hasAvailableExternallyLinkage(),
687 "Global is marked as dllimport, but not external", &GV);
688 }
689
690 if (GV.isImplicitDSOLocal())
691 Check(GV.isDSOLocal(),
692 "GlobalValue with local linkage or non-default "
693 "visibility must be dso_local!",
694 &GV);
695
696 forEachUser(User: &GV, Visited&: GlobalValueVisited, Callback: [&](const Value *V) -> bool {
697 if (const auto *I = dyn_cast<Instruction>(Val: V)) {
698 if (!I->getParent() || !I->getParent()->getParent())
699 CheckFailed(Message: "Global is referenced by parentless instruction!", V1: &GV, Vs: &M,
700 Vs: I);
701 else if (I->getParent()->getParent()->getParent() != &M)
702 CheckFailed(Message: "Global is referenced in a different module!", V1: &GV, Vs: &M, Vs: I,
703 Vs: I->getParent()->getParent(),
704 Vs: I->getParent()->getParent()->getParent());
705 return false;
706 } else if (const auto *F = dyn_cast<Function>(Val: V)) {
707 if (F->getParent() != &M)
708 CheckFailed(Message: "Global is used by function in a different module", V1: &GV, Vs: &M,
709 Vs: F, Vs: F->getParent());
710 return false;
711 }
712 return true;
713 });
714}
715
716void Verifier::visitGlobalVariable(const GlobalVariable &GV) {
717 // Target-specific global variable checks. Done first because this function
718 // returns early for a global without an initializer.
719 verifyAMDGPUGlobalVariable(VS&: *this, GV);
720
721 Type *GVType = GV.getValueType();
722
723 if (MaybeAlign A = GV.getAlign()) {
724 Check(A->value() <= Value::MaximumAlignment,
725 "huge alignment values are unsupported", &GV);
726 }
727
728 if (GV.hasInitializer()) {
729 Check(GV.getInitializer()->getType() == GVType,
730 "Global variable initializer type does not match global "
731 "variable type!",
732 &GV);
733 Check(GV.getInitializer()->getType()->isSized(),
734 "Global variable initializer must be sized", &GV);
735 visitConstantExprsRecursively(EntryC: GV.getInitializer());
736 // If the global has common linkage, it must have a zero initializer and
737 // cannot be constant.
738 if (GV.hasCommonLinkage()) {
739 Check(GV.getInitializer()->isNullValue(),
740 "'common' global must have a zero initializer!", &GV);
741 Check(!GV.isConstant(), "'common' global may not be marked constant!",
742 &GV);
743 Check(!GV.hasComdat(), "'common' global may not be in a Comdat!", &GV);
744 }
745 }
746
747 if (GV.hasName() && (GV.getName() == "llvm.global_ctors" ||
748 GV.getName() == "llvm.global_dtors")) {
749 Check(!GV.hasInitializer() || GV.hasAppendingLinkage(),
750 "invalid linkage for intrinsic global variable", &GV);
751 Check(GV.materialized_use_empty(),
752 "invalid uses of intrinsic global variable", &GV);
753
754 // Don't worry about emitting an error for it not being an array,
755 // visitGlobalValue will complain on appending non-array.
756 if (const auto *ATy = dyn_cast<ArrayType>(Val: GVType)) {
757 const auto *STy = dyn_cast<StructType>(Val: ATy->getElementType());
758 PointerType *FuncPtrTy =
759 PointerType::get(C&: Context, AddressSpace: DL.getProgramAddressSpace());
760 Check(STy && (STy->getNumElements() == 2 || STy->getNumElements() == 3) &&
761 STy->getTypeAtIndex(0u)->isIntegerTy(32) &&
762 STy->getTypeAtIndex(1) == FuncPtrTy,
763 "wrong type for intrinsic global variable", &GV);
764 Check(STy->getNumElements() == 3,
765 "the third field of the element type is mandatory, "
766 "specify ptr null to migrate from the obsoleted 2-field form");
767 Type *ETy = STy->getTypeAtIndex(N: 2);
768 Check(ETy->isPointerTy(), "wrong type for intrinsic global variable",
769 &GV);
770 }
771
772 auto *Init = GV.hasInitializer()
773 ? dyn_cast<ConstantArray>(Val: GV.getInitializer())
774 : nullptr;
775 if (Init) {
776 for (const Use &U : Init->operands()) {
777 auto *Structor = dyn_cast<ConstantStruct>(Val: U);
778 if (!Structor || Structor->getNumOperands() != 3)
779 continue;
780 Check(!isa<ConstantPtrAuth>(Structor->getOperand(1)),
781 "signing of ctors/dtors should be requested via module flags");
782 }
783 }
784 }
785
786 if (GV.hasName() && (GV.getName() == "llvm.used" ||
787 GV.getName() == "llvm.compiler.used")) {
788 Check(!GV.hasInitializer() || GV.hasAppendingLinkage(),
789 "invalid linkage for intrinsic global variable", &GV);
790 Check(GV.materialized_use_empty(),
791 "invalid uses of intrinsic global variable", &GV);
792
793 if (const auto *ATy = dyn_cast<ArrayType>(Val: GVType)) {
794 const auto *PTy = dyn_cast<PointerType>(Val: ATy->getElementType());
795 Check(PTy, "wrong type for intrinsic global variable", &GV);
796 if (GV.hasInitializer()) {
797 const Constant *Init = GV.getInitializer();
798 const auto *InitArray = dyn_cast<ConstantArray>(Val: Init);
799 Check(InitArray, "wrong initializer for intrinsic global variable",
800 Init);
801 for (Value *Op : InitArray->operands()) {
802 Value *V = Op->stripPointerCasts();
803 Check(isa<GlobalVariable>(V) || isa<Function>(V) ||
804 isa<GlobalAlias>(V),
805 Twine("invalid ") + GV.getName() + " member", V);
806 Check(V->hasName(),
807 Twine("members of ") + GV.getName() + " must be named", V);
808 }
809 }
810 }
811 }
812
813 // Visit any debug info attachments.
814 SmallVector<MDNode *, 1> MDs;
815 GV.getMetadata(KindID: LLVMContext::MD_dbg, MDs);
816 for (MDNode *MD : MDs) {
817 if (auto *GVE = dyn_cast<DIGlobalVariableExpression>(Val: MD))
818 visitDIGlobalVariableExpression(N: *GVE);
819 else
820 CheckDI(false, "!dbg attachment of global variable must be a "
821 "DIGlobalVariableExpression");
822 }
823
824 // Scalable vectors cannot be global variables, since we don't know
825 // the runtime size.
826 Check(!GVType->isScalableTy(), "Globals cannot contain scalable types", &GV);
827
828 // Check if it is or contains a target extension type that disallows being
829 // used as a global.
830 Check(!GVType->containsNonGlobalTargetExtType(),
831 "Global @" + GV.getName() + " has illegal target extension type",
832 GVType);
833
834 // Check that the the address space can hold all bits of the type, recognized
835 // by an access in the address space being able to reach all bytes of the
836 // type.
837 Check(!GVType->isSized() ||
838 isUIntN(DL.getAddressSizeInBits(GV.getAddressSpace()),
839 GV.getGlobalSize(DL)),
840 "Global variable is too large to fit into the address space", &GV,
841 GVType);
842
843 if (!GV.hasInitializer()) {
844 visitGlobalValue(GV);
845 return;
846 }
847
848 // Walk any aggregate initializers looking for bitcasts between address spaces
849 visitConstantExprsRecursively(EntryC: GV.getInitializer());
850
851 visitGlobalValue(GV);
852}
853
854void Verifier::visitAliaseeSubExpr(const GlobalAlias &GA, const Constant &C) {
855 SmallPtrSet<const GlobalAlias*, 4> Visited;
856 Visited.insert(Ptr: &GA);
857 visitAliaseeSubExpr(Visited, A: GA, C);
858}
859
860void Verifier::visitAliaseeSubExpr(SmallPtrSetImpl<const GlobalAlias*> &Visited,
861 const GlobalAlias &GA, const Constant &C) {
862 if (GA.hasAvailableExternallyLinkage()) {
863 Check(isa<GlobalValue>(C) &&
864 cast<GlobalValue>(C).hasAvailableExternallyLinkage(),
865 "available_externally alias must point to available_externally "
866 "global value",
867 &GA);
868 }
869 if (const auto *GV = dyn_cast<GlobalValue>(Val: &C)) {
870 if (!GA.hasAvailableExternallyLinkage()) {
871 Check(!GV->isDeclarationForLinker(), "Alias must point to a definition",
872 &GA);
873 }
874
875 if (const auto *GA2 = dyn_cast<GlobalAlias>(Val: GV)) {
876 Check(Visited.insert(GA2).second, "Aliases cannot form a cycle", &GA);
877
878 Check(!GA2->isInterposable(),
879 "Alias cannot point to an interposable alias", &GA);
880 } else {
881 // Only continue verifying subexpressions of GlobalAliases.
882 // Do not recurse into global initializers.
883 return;
884 }
885 }
886
887 if (const auto *CE = dyn_cast<ConstantExpr>(Val: &C))
888 visitConstantExprsRecursively(EntryC: CE);
889
890 for (const Use &U : C.operands()) {
891 Value *V = &*U;
892 if (const auto *GA2 = dyn_cast<GlobalAlias>(Val: V))
893 visitAliaseeSubExpr(Visited, GA, C: *GA2->getAliasee());
894 else if (const auto *C2 = dyn_cast<Constant>(Val: V))
895 visitAliaseeSubExpr(Visited, GA, C: *C2);
896 }
897}
898
899void Verifier::visitGlobalAlias(const GlobalAlias &GA) {
900 Check(GlobalAlias::isValidLinkage(GA.getLinkage()),
901 "Alias should have private, internal, linkonce, weak, linkonce_odr, "
902 "weak_odr, external, or available_externally linkage!",
903 &GA);
904 const Constant *Aliasee = GA.getAliasee();
905 Check(Aliasee, "Aliasee cannot be NULL!", &GA);
906 Check(GA.getType() == Aliasee->getType(),
907 "Alias and aliasee types should match!", &GA);
908
909 Check(isa<GlobalValue>(Aliasee) || isa<ConstantExpr>(Aliasee),
910 "Aliasee should be either GlobalValue or ConstantExpr", &GA);
911
912 visitAliaseeSubExpr(GA, C: *Aliasee);
913
914 visitGlobalValue(GV: GA);
915}
916
917void Verifier::visitGlobalIFunc(const GlobalIFunc &GI) {
918 visitGlobalValue(GV: GI);
919
920 SmallVector<std::pair<unsigned, MDNode *>, 4> MDs;
921 GI.getAllMetadata(MDs);
922 for (const auto &I : MDs) {
923 CheckDI(I.first != LLVMContext::MD_dbg,
924 "an ifunc may not have a !dbg attachment", &GI);
925 Check(I.first != LLVMContext::MD_prof,
926 "an ifunc may not have a !prof attachment", &GI);
927 visitMDNode(MD: *I.second, AllowLocs: AreDebugLocsAllowed::No);
928 }
929
930 Check(GlobalIFunc::isValidLinkage(GI.getLinkage()),
931 "IFunc should have private, internal, linkonce, weak, linkonce_odr, "
932 "weak_odr, or external linkage!",
933 &GI);
934 // Pierce through ConstantExprs and GlobalAliases and check that the resolver
935 // is a Function definition.
936 const Function *Resolver = GI.getResolverFunction();
937 Check(Resolver, "IFunc must have a Function resolver", &GI);
938 Check(!Resolver->isDeclarationForLinker(),
939 "IFunc resolver must be a definition", &GI);
940
941 // Check that the immediate resolver operand (prior to any bitcasts) has the
942 // correct type.
943 const Type *ResolverTy = GI.getResolver()->getType();
944
945 Check(isa<PointerType>(Resolver->getFunctionType()->getReturnType()),
946 "IFunc resolver must return a pointer", &GI);
947
948 Check(ResolverTy == PointerType::get(Context, GI.getAddressSpace()),
949 "IFunc resolver has incorrect type", &GI);
950}
951
952void Verifier::visitNamedMDNode(const NamedMDNode &NMD) {
953 // There used to be various other llvm.dbg.* nodes, but we don't support
954 // upgrading them and we want to reserve the namespace for future uses.
955 if (NMD.getName().starts_with(Prefix: "llvm.dbg."))
956 CheckDI(NMD.getName() == "llvm.dbg.cu",
957 "unrecognized named metadata node in the llvm.dbg namespace", &NMD);
958 for (const MDNode *MD : NMD.operands()) {
959 if (NMD.getName() == "llvm.dbg.cu")
960 CheckDI(MD && isa<DICompileUnit>(MD), "invalid compile unit", &NMD, MD);
961
962 if (!MD)
963 continue;
964
965 visitMDNode(MD: *MD, AllowLocs: AreDebugLocsAllowed::Yes);
966 }
967}
968
969/// Parent scope operand of \p S, or null if \p S has no parent (a \c DIFile,
970/// \c DICompileUnit, or non-scope). Mirrors \c DIScope::getScope() without
971/// asserting on unexpected metadata kinds.
972static const Metadata *getRawDIScopeParent(const Metadata *S) {
973 if (!S)
974 return nullptr;
975 if (auto *T = dyn_cast<DIType>(Val: S))
976 return T->getRawScope();
977 if (auto *SP = dyn_cast<DISubprogram>(Val: S))
978 return SP->getRawScope();
979 if (auto *LB = dyn_cast<DILexicalBlockBase>(Val: S))
980 return LB->getRawScope();
981 if (auto *NS = dyn_cast<DINamespace>(Val: S))
982 return NS->getRawScope();
983 if (auto *CB = dyn_cast<DICommonBlock>(Val: S))
984 return CB->getRawScope();
985 if (auto *M = dyn_cast<DIModule>(Val: S))
986 return M->getRawScope();
987 return nullptr;
988}
989
990/// True if following the scope operand from \p S repeats a node.
991bool Verifier::hasDIScopeCycle(const Metadata *S) {
992 SmallPtrSet<const Metadata *, 8> Seen;
993 auto CacheSeen = [&](bool HasCycle) {
994 for (const Metadata *M : Seen)
995 DIScopeChainReachesCycle[M] = HasCycle;
996 return HasCycle;
997 };
998
999 while (auto *Scope = dyn_cast_or_null<DIScope>(Val: S)) {
1000 auto It = DIScopeChainReachesCycle.find(Val: Scope);
1001 bool IsInCache = It != DIScopeChainReachesCycle.end();
1002 if (IsInCache)
1003 return CacheSeen(It->second);
1004 bool AlreadySeen = !Seen.insert(Ptr: Scope).second;
1005 if (AlreadySeen) // New cycle detected
1006 return CacheSeen(true);
1007 // No new cycle detected
1008 S = getRawDIScopeParent(S: Scope);
1009 }
1010
1011 // Finished walking node chain without detecting any cycles
1012 return CacheSeen(false);
1013}
1014
1015void Verifier::visitDIScopeChain(const DIScope &N) {
1016 CheckDI(!hasDIScopeCycle(&N), "DIScope scope chain must not contain a cycle",
1017 &N);
1018}
1019
1020void Verifier::visitMDNode(const MDNode &BaseMD,
1021 AreDebugLocsAllowed AllowLocs) {
1022 // Only visit each node once. Metadata can be mutually recursive, so this
1023 // avoids infinite recursion here, as well as being an optimization.
1024 if (!MDNodes.insert(Ptr: &BaseMD).second)
1025 return;
1026
1027 std::queue<const MDNode *> Worklist;
1028 Worklist.push(x: &BaseMD);
1029
1030 while (!Worklist.empty()) {
1031 const MDNode *CurrentMD = Worklist.front();
1032 Worklist.pop();
1033 Check(&CurrentMD->getContext() == &Context,
1034 "MDNode context does not match Module context!", CurrentMD);
1035
1036 switch (CurrentMD->getMetadataID()) {
1037 default:
1038 llvm_unreachable("Invalid MDNode subclass");
1039 case Metadata::MDTupleKind:
1040 break;
1041#define HANDLE_SPECIALIZED_MDNODE_LEAF(CLASS) \
1042 case Metadata::CLASS##Kind: \
1043 visit##CLASS(cast<CLASS>(*CurrentMD)); \
1044 break;
1045#include "llvm/IR/Metadata.def"
1046 }
1047
1048 // A scope chain must terminate.
1049 if (const auto *S = dyn_cast<DIScope>(Val: CurrentMD))
1050 visitDIScopeChain(N: *S);
1051
1052 for (const Metadata *Op : CurrentMD->operands()) {
1053 if (!Op)
1054 continue;
1055 Check(!isa<LocalAsMetadata>(Op), "Invalid operand for global metadata!",
1056 CurrentMD, Op);
1057 CheckDI(!isa<DILocation>(Op) || AllowLocs == AreDebugLocsAllowed::Yes,
1058 "DILocation not allowed within this metadata node", CurrentMD,
1059 Op);
1060 if (auto *N = dyn_cast<MDNode>(Val: Op)) {
1061 if (MDNodes.insert(Ptr: N).second)
1062 Worklist.push(x: N);
1063 continue;
1064 }
1065 if (auto *V = dyn_cast<ValueAsMetadata>(Val: Op)) {
1066 visitValueAsMetadata(MD: *V, F: nullptr);
1067 continue;
1068 }
1069 }
1070
1071 // FIXME: The nested llvm.loop.* property tags (llvm.loop.align,
1072 // llvm.loop.estimated_trip_count, the boolean enable/disable tags below)
1073 // are only meaningful as operands of an llvm.loop node. Neither llvm.loop's
1074 // structure nor the requirement that these tags appear only within it is
1075 // validated here; the checks below fire on any matching tuple regardless of
1076 // where it appears.
1077
1078 // Check llvm.loop.estimated_trip_count.
1079 if (CurrentMD->getNumOperands() > 0 &&
1080 CurrentMD->getOperand(I: 0).equalsStr(Str: LLVMLoopEstimatedTripCount)) {
1081 Check(CurrentMD->getNumOperands() == 2, "Expected two operands",
1082 CurrentMD);
1083 auto *Count =
1084 dyn_cast_or_null<ConstantAsMetadata>(Val: CurrentMD->getOperand(I: 1));
1085 Check(Count && Count->getType()->isIntegerTy() &&
1086 cast<IntegerType>(Count->getType())->getBitWidth() <= 32,
1087 "Expected second operand to be an integer constant of type i32 or "
1088 "smaller",
1089 CurrentMD);
1090 }
1091
1092 // Check llvm.loop.align.
1093 if (CurrentMD->getNumOperands() > 0 &&
1094 CurrentMD->getOperand(I: 0).equalsStr(Str: "llvm.loop.align")) {
1095 Check(CurrentMD->getNumOperands() == 2, "Expected two operands",
1096 CurrentMD);
1097 auto *AlignMD =
1098 mdconst::dyn_extract_or_null<ConstantInt>(MD: CurrentMD->getOperand(I: 1));
1099 Check(AlignMD && AlignMD->getType()->isIntegerTy(32),
1100 "Expected the alignment to be an integer constant of type i32",
1101 CurrentMD);
1102 if (AlignMD) {
1103 uint64_t Align = AlignMD->getValue().getZExtValue();
1104 Check(isPowerOf2_64(Align),
1105 "Expected the alignment to be a power of two", CurrentMD);
1106 Check(Align <= Value::MaximumAlignment,
1107 "Alignment is larger than the implementation defined limit",
1108 CurrentMD);
1109 }
1110 }
1111
1112 // Enforce the single-operand form of the loop enable/disable pairs.
1113 if (CurrentMD->getNumOperands() > 0 &&
1114 any_of(Range: OldBooleanLoopTags, P: [CurrentMD](const BooleanLoopTags &Tags) {
1115 return CurrentMD->getOperand(I: 0).equalsStr(Str: Tags.Enable) ||
1116 CurrentMD->getOperand(I: 0).equalsStr(Str: Tags.Disable);
1117 }))
1118 Check(CurrentMD->getNumOperands() == 1,
1119 "Expecting only the metadata name", CurrentMD);
1120
1121 // Check these last, so we diagnose problems in operands first.
1122 Check(!CurrentMD->isTemporary(), "Expected no forward declarations!",
1123 CurrentMD);
1124 Check(CurrentMD->isResolved(), "All nodes should be resolved!", CurrentMD);
1125 }
1126}
1127
1128void Verifier::visitValueAsMetadata(const ValueAsMetadata &MD, Function *F) {
1129 Check(MD.getValue(), "Expected valid value", &MD);
1130 Check(!MD.getValue()->getType()->isMetadataTy(),
1131 "Unexpected metadata round-trip through values", &MD, MD.getValue());
1132
1133 auto *L = dyn_cast<LocalAsMetadata>(Val: &MD);
1134 if (!L)
1135 return;
1136
1137 Check(F, "function-local metadata used outside a function", L);
1138
1139 // If this was an instruction, bb, or argument, verify that it is in the
1140 // function that we expect.
1141 Function *ActualF = nullptr;
1142 if (auto *I = dyn_cast<Instruction>(Val: L->getValue())) {
1143 Check(I->getParent(), "function-local metadata not in basic block", L, I);
1144 ActualF = I->getParent()->getParent();
1145 } else if (auto *BB = dyn_cast<BasicBlock>(Val: L->getValue())) {
1146 ActualF = BB->getParent();
1147 } else if (auto *A = dyn_cast<Argument>(Val: L->getValue())) {
1148 ActualF = A->getParent();
1149 }
1150 assert(ActualF && "Unimplemented function local metadata case!");
1151
1152 Check(ActualF == F, "function-local metadata used in wrong function", L);
1153}
1154
1155void Verifier::visitDIArgList(const DIArgList &AL, Function *F) {
1156 for (const ValueAsMetadata *VAM : AL.getArgs())
1157 visitValueAsMetadata(MD: *VAM, F);
1158}
1159
1160void Verifier::visitMetadataAsValue(const MetadataAsValue &MDV, Function *F) {
1161 Metadata *MD = MDV.getMetadata();
1162 if (auto *N = dyn_cast<MDNode>(Val: MD)) {
1163 visitMDNode(BaseMD: *N, AllowLocs: AreDebugLocsAllowed::No);
1164 return;
1165 }
1166
1167 // Only visit each node once. Metadata can be mutually recursive, so this
1168 // avoids infinite recursion here, as well as being an optimization.
1169 if (!MDNodes.insert(Ptr: MD).second)
1170 return;
1171
1172 if (auto *V = dyn_cast<ValueAsMetadata>(Val: MD))
1173 visitValueAsMetadata(MD: *V, F);
1174
1175 if (auto *AL = dyn_cast<DIArgList>(Val: MD))
1176 visitDIArgList(AL: *AL, F);
1177}
1178
1179static bool isType(const Metadata *MD) { return !MD || isa<DIType>(Val: MD); }
1180static bool isScope(const Metadata *MD) { return !MD || isa<DIScope>(Val: MD); }
1181static bool isDINode(const Metadata *MD) { return !MD || isa<DINode>(Val: MD); }
1182static bool isMDTuple(const Metadata *MD) { return !MD || isa<MDTuple>(Val: MD); }
1183
1184void Verifier::visitDILocation(const DILocation &N) {
1185 CheckDI(N.getRawScope() && isa<DILocalScope>(N.getRawScope()),
1186 "location requires a valid scope", &N, N.getRawScope());
1187 if (auto *IA = N.getRawInlinedAt())
1188 CheckDI(isa<DILocation>(IA), "inlined-at should be a location", &N, IA);
1189 if (auto *SP = dyn_cast<DISubprogram>(Val: N.getRawScope()))
1190 CheckDI(SP->isDefinition(), "scope points into the type hierarchy", &N);
1191 if (auto *L = N.getRawIRLayers())
1192 CheckDI(isa<DILayerLocList>(L), "irlayers must be a DILayerLocList", &N, L);
1193}
1194
1195void Verifier::visitDILayerLoc(const DILayerLoc &N) {
1196 CheckDI(isa_and_nonnull<MDString>(N.getRawKind()),
1197 "layer kind must be a non-null MDString", &N, N.getRawKind());
1198 CheckDI(isa_and_nonnull<DIFile>(N.getRawFile()),
1199 "layer file must be a non-null DIFile", &N, N.getRawFile());
1200}
1201
1202void Verifier::visitDILayerLocList(const DILayerLocList &N) {
1203 CheckDI(N.getNumLayers() > 0, "DILayerLocList must be non-empty", &N);
1204 for (const MDOperand &Op : N.layers())
1205 CheckDI(isa_and_nonnull<DILayerLoc>(Op.get()),
1206 "DILayerLocList entry must be a DILayerLoc", &N, Op.get());
1207}
1208
1209void Verifier::visitGenericDINode(const GenericDINode &N) {
1210 CheckDI(N.getTag(), "invalid tag", &N);
1211}
1212
1213void Verifier::visitDIScope(const DIScope &N) {
1214 if (auto *F = N.getRawFile())
1215 CheckDI(isa<DIFile>(F), "invalid file", &N, F);
1216}
1217
1218void Verifier::visitDIType(const DIType &N) {
1219 CheckDI(isScope(N.getRawScope()), "invalid scope", &N, N.getRawScope());
1220 visitDIScope(N);
1221 CheckDI(N.getRawFile() || N.getLine() == 0, "line specified with no file", &N,
1222 N.getLine());
1223}
1224
1225void Verifier::visitDISubrangeType(const DISubrangeType &N) {
1226 visitDIType(N);
1227
1228 CheckDI(N.getTag() == dwarf::DW_TAG_subrange_type, "invalid tag", &N);
1229 auto *BaseType = N.getRawBaseType();
1230 CheckDI(!BaseType || isType(BaseType), "BaseType must be a type");
1231 auto *LBound = N.getRawLowerBound();
1232 CheckDI(!LBound || isa<ConstantAsMetadata>(LBound) ||
1233 isa<DIVariable>(LBound) || isa<DIExpression>(LBound) ||
1234 isa<DIDerivedType>(LBound),
1235 "LowerBound must be signed constant or DIVariable or DIExpression or "
1236 "DIDerivedType",
1237 &N);
1238 auto *UBound = N.getRawUpperBound();
1239 CheckDI(!UBound || isa<ConstantAsMetadata>(UBound) ||
1240 isa<DIVariable>(UBound) || isa<DIExpression>(UBound) ||
1241 isa<DIDerivedType>(UBound),
1242 "UpperBound must be signed constant or DIVariable or DIExpression or "
1243 "DIDerivedType",
1244 &N);
1245 auto *Stride = N.getRawStride();
1246 CheckDI(!Stride || isa<ConstantAsMetadata>(Stride) ||
1247 isa<DIVariable>(Stride) || isa<DIExpression>(Stride),
1248 "Stride must be signed constant or DIVariable or DIExpression", &N);
1249 auto *Bias = N.getRawBias();
1250 CheckDI(!Bias || isa<ConstantAsMetadata>(Bias) || isa<DIVariable>(Bias) ||
1251 isa<DIExpression>(Bias),
1252 "Bias must be signed constant or DIVariable or DIExpression", &N);
1253 // Subrange types currently only support constant size.
1254 auto *Size = N.getRawSizeInBits();
1255 CheckDI(!Size || isa<ConstantAsMetadata>(Size),
1256 "SizeInBits must be a constant");
1257}
1258
1259void Verifier::visitDISubrange(const DISubrange &N) {
1260 CheckDI(N.getTag() == dwarf::DW_TAG_subrange_type, "invalid tag", &N);
1261 CheckDI(!N.getRawCountNode() || !N.getRawUpperBound(),
1262 "Subrange can have any one of count or upperBound", &N);
1263 auto *CBound = N.getRawCountNode();
1264 CheckDI(!CBound || isa<ConstantAsMetadata>(CBound) ||
1265 isa<DIVariable>(CBound) || isa<DIExpression>(CBound),
1266 "Count must be signed constant or DIVariable or DIExpression", &N);
1267 auto Count = N.getCount();
1268 CheckDI(!Count || !isa<ConstantInt *>(Count) ||
1269 cast<ConstantInt *>(Count)->getSExtValue() >= -1,
1270 "invalid subrange count", &N);
1271 auto *LBound = N.getRawLowerBound();
1272 CheckDI(!LBound || isa<ConstantAsMetadata>(LBound) ||
1273 isa<DIVariable>(LBound) || isa<DIExpression>(LBound),
1274 "LowerBound must be signed constant or DIVariable or DIExpression",
1275 &N);
1276 auto *UBound = N.getRawUpperBound();
1277 CheckDI(!UBound || isa<ConstantAsMetadata>(UBound) ||
1278 isa<DIVariable>(UBound) || isa<DIExpression>(UBound),
1279 "UpperBound must be signed constant or DIVariable or DIExpression",
1280 &N);
1281 auto *Stride = N.getRawStride();
1282 CheckDI(!Stride || isa<ConstantAsMetadata>(Stride) ||
1283 isa<DIVariable>(Stride) || isa<DIExpression>(Stride),
1284 "Stride must be signed constant or DIVariable or DIExpression", &N);
1285}
1286
1287void Verifier::visitDIGenericSubrange(const DIGenericSubrange &N) {
1288 CheckDI(N.getTag() == dwarf::DW_TAG_generic_subrange, "invalid tag", &N);
1289 CheckDI(!N.getRawCountNode() || !N.getRawUpperBound(),
1290 "GenericSubrange can have any one of count or upperBound", &N);
1291 auto *CBound = N.getRawCountNode();
1292 CheckDI(!CBound || isa<DIVariable>(CBound) || isa<DIExpression>(CBound),
1293 "Count must be signed constant or DIVariable or DIExpression", &N);
1294 auto *LBound = N.getRawLowerBound();
1295 CheckDI(LBound, "GenericSubrange must contain lowerBound", &N);
1296 CheckDI(isa<DIVariable>(LBound) || isa<DIExpression>(LBound),
1297 "LowerBound must be signed constant or DIVariable or DIExpression",
1298 &N);
1299 auto *UBound = N.getRawUpperBound();
1300 CheckDI(!UBound || isa<DIVariable>(UBound) || isa<DIExpression>(UBound),
1301 "UpperBound must be signed constant or DIVariable or DIExpression",
1302 &N);
1303 auto *Stride = N.getRawStride();
1304 CheckDI(Stride, "GenericSubrange must contain stride", &N);
1305 CheckDI(isa<DIVariable>(Stride) || isa<DIExpression>(Stride),
1306 "Stride must be signed constant or DIVariable or DIExpression", &N);
1307}
1308
1309void Verifier::visitDIEnumerator(const DIEnumerator &N) {
1310 CheckDI(N.getTag() == dwarf::DW_TAG_enumerator, "invalid tag", &N);
1311}
1312
1313void Verifier::visitDIBasicType(const DIBasicType &N) {
1314 visitDIType(N);
1315
1316 CheckDI(N.getTag() == dwarf::DW_TAG_base_type ||
1317 N.getTag() == dwarf::DW_TAG_unspecified_type ||
1318 N.getTag() == dwarf::DW_TAG_string_type,
1319 "invalid tag", &N);
1320 // Basic types currently only support constant size.
1321 auto *Size = N.getRawSizeInBits();
1322 CheckDI(!Size || isa<ConstantAsMetadata>(Size),
1323 "SizeInBits must be a constant");
1324}
1325
1326void Verifier::visitDIFixedPointType(const DIFixedPointType &N) {
1327 visitDIBasicType(N);
1328
1329 CheckDI(N.getTag() == dwarf::DW_TAG_base_type, "invalid tag", &N);
1330 CheckDI(N.getEncoding() == dwarf::DW_ATE_signed_fixed ||
1331 N.getEncoding() == dwarf::DW_ATE_unsigned_fixed,
1332 "invalid encoding", &N);
1333 CheckDI(N.getKind() == DIFixedPointType::FixedPointBinary ||
1334 N.getKind() == DIFixedPointType::FixedPointDecimal ||
1335 N.getKind() == DIFixedPointType::FixedPointRational,
1336 "invalid kind", &N);
1337 CheckDI(N.getKind() != DIFixedPointType::FixedPointRational ||
1338 N.getFactorRaw() == 0,
1339 "factor should be 0 for rationals", &N);
1340 CheckDI(N.getKind() == DIFixedPointType::FixedPointRational ||
1341 (N.getNumeratorRaw() == 0 && N.getDenominatorRaw() == 0),
1342 "numerator and denominator should be 0 for non-rationals", &N);
1343}
1344
1345void Verifier::visitDIStringType(const DIStringType &N) {
1346 visitDIType(N);
1347
1348 CheckDI(N.getTag() == dwarf::DW_TAG_string_type, "invalid tag", &N);
1349 CheckDI(!(N.isBigEndian() && N.isLittleEndian()), "has conflicting flags",
1350 &N);
1351 if (N.getRawCharType())
1352 CheckDI(isa<DIType>(N.getRawCharType()), "invalid character type", &N,
1353 N.getRawCharType());
1354}
1355
1356void Verifier::visitDIDerivedType(const DIDerivedType &N) {
1357 // Common type checks.
1358 visitDIType(N);
1359
1360 CheckDI(N.getTag() == dwarf::DW_TAG_typedef ||
1361 N.getTag() == dwarf::DW_TAG_pointer_type ||
1362 N.getTag() == dwarf::DW_TAG_ptr_to_member_type ||
1363 N.getTag() == dwarf::DW_TAG_reference_type ||
1364 N.getTag() == dwarf::DW_TAG_rvalue_reference_type ||
1365 N.getTag() == dwarf::DW_TAG_const_type ||
1366 N.getTag() == dwarf::DW_TAG_immutable_type ||
1367 N.getTag() == dwarf::DW_TAG_volatile_type ||
1368 N.getTag() == dwarf::DW_TAG_restrict_type ||
1369 N.getTag() == dwarf::DW_TAG_atomic_type ||
1370 N.getTag() == dwarf::DW_TAG_LLVM_ptrauth_type ||
1371 N.getTag() == dwarf::DW_TAG_member ||
1372 (N.getTag() == dwarf::DW_TAG_variable && N.isStaticMember()) ||
1373 N.getTag() == dwarf::DW_TAG_inheritance ||
1374 N.getTag() == dwarf::DW_TAG_friend ||
1375 N.getTag() == dwarf::DW_TAG_set_type ||
1376 N.getTag() == dwarf::DW_TAG_template_alias,
1377 "invalid tag", &N);
1378 if (N.getTag() == dwarf::DW_TAG_ptr_to_member_type) {
1379 CheckDI(isType(N.getRawExtraData()), "invalid pointer to member type", &N,
1380 N.getRawExtraData());
1381 } else if (N.getTag() == dwarf::DW_TAG_template_alias) {
1382 CheckDI(isMDTuple(N.getRawExtraData()), "invalid template parameters", &N,
1383 N.getRawExtraData());
1384 } else if (N.getTag() == dwarf::DW_TAG_inheritance ||
1385 N.getTag() == dwarf::DW_TAG_member ||
1386 N.getTag() == dwarf::DW_TAG_variable) {
1387 auto *ExtraData = N.getRawExtraData();
1388 auto IsValidExtraData = [&]() {
1389 if (ExtraData == nullptr)
1390 return true;
1391 if (isa<ConstantAsMetadata>(Val: ExtraData) || isa<MDString>(Val: ExtraData) ||
1392 isa<DIObjCProperty>(Val: ExtraData))
1393 return true;
1394 if (auto *Tuple = dyn_cast<MDTuple>(Val: ExtraData)) {
1395 if (Tuple->getNumOperands() != 1)
1396 return false;
1397 return isa_and_nonnull<ConstantAsMetadata>(Val: Tuple->getOperand(I: 0).get());
1398 }
1399 return false;
1400 };
1401 CheckDI(IsValidExtraData(),
1402 "extraData must be ConstantAsMetadata, MDString, DIObjCProperty, "
1403 "or MDTuple with single ConstantAsMetadata operand",
1404 &N, ExtraData);
1405 }
1406
1407 if (N.getTag() == dwarf::DW_TAG_set_type) {
1408 if (auto *T = N.getRawBaseType()) {
1409 auto *Enum = dyn_cast_or_null<DICompositeType>(Val: T);
1410 auto *Subrange = dyn_cast_or_null<DISubrangeType>(Val: T);
1411 auto *Basic = dyn_cast_or_null<DIBasicType>(Val: T);
1412 CheckDI(
1413 (Enum && Enum->getTag() == dwarf::DW_TAG_enumeration_type) ||
1414 (Subrange && Subrange->getTag() == dwarf::DW_TAG_subrange_type) ||
1415 (Basic && (Basic->getEncoding() == dwarf::DW_ATE_unsigned ||
1416 Basic->getEncoding() == dwarf::DW_ATE_signed ||
1417 Basic->getEncoding() == dwarf::DW_ATE_unsigned_char ||
1418 Basic->getEncoding() == dwarf::DW_ATE_signed_char ||
1419 Basic->getEncoding() == dwarf::DW_ATE_boolean)),
1420 "invalid set base type", &N, T);
1421 }
1422 }
1423
1424 CheckDI(isType(N.getRawBaseType()), "invalid base type", &N,
1425 N.getRawBaseType());
1426
1427 if (N.getDWARFAddressSpace()) {
1428 CheckDI(N.getTag() == dwarf::DW_TAG_pointer_type ||
1429 N.getTag() == dwarf::DW_TAG_reference_type ||
1430 N.getTag() == dwarf::DW_TAG_rvalue_reference_type,
1431 "DWARF address space only applies to pointer or reference types",
1432 &N);
1433 }
1434
1435 auto *Size = N.getRawSizeInBits();
1436 CheckDI(!Size || isa<ConstantAsMetadata>(Size) || isa<DIVariable>(Size) ||
1437 isa<DIExpression>(Size),
1438 "SizeInBits must be a constant or DIVariable or DIExpression");
1439}
1440
1441/// Detect mutually exclusive flags.
1442static bool hasConflictingReferenceFlags(unsigned Flags) {
1443 return ((Flags & DINode::FlagLValueReference) &&
1444 (Flags & DINode::FlagRValueReference)) ||
1445 ((Flags & DINode::FlagTypePassByValue) &&
1446 (Flags & DINode::FlagTypePassByReference));
1447}
1448
1449void Verifier::visitTemplateParams(const MDNode &N, const Metadata &RawParams) {
1450 auto *Params = dyn_cast<MDTuple>(Val: &RawParams);
1451 CheckDI(Params, "invalid template params", &N, &RawParams);
1452 for (Metadata *Op : Params->operands()) {
1453 CheckDI(Op && isa<DITemplateParameter>(Op), "invalid template parameter",
1454 &N, Params, Op);
1455 }
1456}
1457
1458void Verifier::visitDICompositeType(const DICompositeType &N) {
1459 // Common type checks.
1460 visitDIType(N);
1461
1462 CheckDI(N.getTag() == dwarf::DW_TAG_array_type ||
1463 N.getTag() == dwarf::DW_TAG_structure_type ||
1464 N.getTag() == dwarf::DW_TAG_union_type ||
1465 N.getTag() == dwarf::DW_TAG_enumeration_type ||
1466 N.getTag() == dwarf::DW_TAG_class_type ||
1467 N.getTag() == dwarf::DW_TAG_variant_part ||
1468 N.getTag() == dwarf::DW_TAG_variant ||
1469 N.getTag() == dwarf::DW_TAG_namelist,
1470 "invalid tag", &N);
1471
1472 CheckDI(isType(N.getRawBaseType()), "invalid base type", &N,
1473 N.getRawBaseType());
1474
1475 CheckDI(!N.getRawElements() || isa<MDTuple>(N.getRawElements()),
1476 "invalid composite elements", &N, N.getRawElements());
1477 CheckDI(isType(N.getRawVTableHolder()), "invalid vtable holder", &N,
1478 N.getRawVTableHolder());
1479 CheckDI(!hasConflictingReferenceFlags(N.getFlags()),
1480 "invalid reference flags", &N);
1481 unsigned DIBlockByRefStruct = 1 << 4;
1482 CheckDI((N.getFlags() & DIBlockByRefStruct) == 0,
1483 "DIBlockByRefStruct on DICompositeType is no longer supported", &N);
1484 CheckDI(llvm::all_of(N.getElements(), [](const DINode *N) { return N; }),
1485 "DISubprogram contains null entry in `elements` field", &N);
1486
1487 if (N.isVector()) {
1488 const DINodeArray Elements = N.getElements();
1489 CheckDI(Elements.size() == 1 &&
1490 Elements[0]->getTag() == dwarf::DW_TAG_subrange_type,
1491 "invalid vector, expected one element of type subrange", &N);
1492 }
1493
1494 if (auto *Params = N.getRawTemplateParams())
1495 visitTemplateParams(N, RawParams: *Params);
1496
1497 if (auto *D = N.getRawDiscriminator()) {
1498 CheckDI(isa<DIDerivedType>(D) && N.getTag() == dwarf::DW_TAG_variant_part,
1499 "discriminator can only appear on variant part");
1500 }
1501
1502 if (N.getRawDataLocation()) {
1503 CheckDI(N.getTag() == dwarf::DW_TAG_array_type,
1504 "dataLocation can only appear in array type");
1505 }
1506
1507 if (N.getRawAssociated()) {
1508 CheckDI(N.getTag() == dwarf::DW_TAG_array_type,
1509 "associated can only appear in array type");
1510 }
1511
1512 if (N.getRawAllocated()) {
1513 CheckDI(N.getTag() == dwarf::DW_TAG_array_type,
1514 "allocated can only appear in array type");
1515 }
1516
1517 if (N.getRawRank()) {
1518 CheckDI(N.getTag() == dwarf::DW_TAG_array_type,
1519 "rank can only appear in array type");
1520 }
1521
1522 if (N.getTag() == dwarf::DW_TAG_array_type) {
1523 CheckDI(N.getRawBaseType(), "array types must have a base type", &N);
1524 }
1525
1526 auto *Size = N.getRawSizeInBits();
1527 CheckDI(!Size || isa<ConstantAsMetadata>(Size) || isa<DIVariable>(Size) ||
1528 isa<DIExpression>(Size),
1529 "SizeInBits must be a constant or DIVariable or DIExpression");
1530}
1531
1532void Verifier::visitDISubroutineType(const DISubroutineType &N) {
1533 visitDIType(N);
1534 CheckDI(N.getTag() == dwarf::DW_TAG_subroutine_type, "invalid tag", &N);
1535 if (auto *Types = N.getRawTypeArray()) {
1536 CheckDI(isa<MDTuple>(Types), "invalid composite elements", &N, Types);
1537 for (Metadata *Ty : N.getTypeArray()->operands()) {
1538 CheckDI(isType(Ty), "invalid subroutine type ref", &N, Types, Ty);
1539 }
1540 }
1541 CheckDI(!hasConflictingReferenceFlags(N.getFlags()),
1542 "invalid reference flags", &N);
1543}
1544
1545void Verifier::visitDIFile(const DIFile &N) {
1546 CheckDI(N.getTag() == dwarf::DW_TAG_file_type, "invalid tag", &N);
1547 std::optional<DIFile::ChecksumInfo<StringRef>> Checksum = N.getChecksum();
1548 if (Checksum) {
1549 CheckDI(Checksum->Kind <= DIFile::ChecksumKind::CSK_Last,
1550 "invalid checksum kind", &N);
1551 size_t Size;
1552 switch (Checksum->Kind) {
1553 case DIFile::CSK_MD5:
1554 Size = 32;
1555 break;
1556 case DIFile::CSK_SHA1:
1557 Size = 40;
1558 break;
1559 case DIFile::CSK_SHA256:
1560 Size = 64;
1561 break;
1562 }
1563 CheckDI(Checksum->Value.size() == Size, "invalid checksum length", &N);
1564 CheckDI(Checksum->Value.find_if_not(llvm::isHexDigit) == StringRef::npos,
1565 "invalid checksum", &N);
1566 }
1567}
1568
1569void Verifier::visitDICompileUnit(const DICompileUnit &N) {
1570 CheckDI(N.isDistinct(), "compile units must be distinct", &N);
1571 CheckDI(N.getTag() == dwarf::DW_TAG_compile_unit, "invalid tag", &N);
1572
1573 // Don't bother verifying the compilation directory or producer string
1574 // as those could be empty.
1575 CheckDI(N.getRawFile() && isa<DIFile>(N.getRawFile()), "invalid file", &N,
1576 N.getRawFile());
1577 CheckDI(!N.getFile()->getFilename().empty(), "invalid filename", &N,
1578 N.getFile());
1579
1580 CheckDI((N.getEmissionKind() <= DICompileUnit::LastEmissionKind),
1581 "invalid emission kind", &N);
1582
1583 CheckDI(N.getSourceLanguage().getDialect() <= dwarf::DW_LLVM_LANG_DIALECT_max,
1584 "invalid language dialect", &N);
1585
1586 if (auto *Array = N.getRawEnumTypes()) {
1587 CheckDI(isa<MDTuple>(Array), "invalid enum list", &N, Array);
1588 for (Metadata *Op : N.getEnumTypes()->operands()) {
1589 auto *Enum = dyn_cast_or_null<DICompositeType>(Val: Op);
1590 CheckDI(Enum && Enum->getTag() == dwarf::DW_TAG_enumeration_type,
1591 "invalid enum type", &N, N.getEnumTypes(), Op);
1592 CheckDI(!Enum->getScope() || !isa<DILocalScope>(Enum->getScope()),
1593 "function-local enum in a DICompileUnit's enum list", &N,
1594 N.getEnumTypes(), Op);
1595 }
1596 }
1597 if (auto *Array = N.getRawRetainedTypes()) {
1598 CheckDI(isa<MDTuple>(Array), "invalid retained type list", &N, Array);
1599 for (Metadata *Op : N.getRetainedTypes()->operands()) {
1600 CheckDI(
1601 Op && (isa<DIType>(Op) || (isa<DISubprogram>(Op) &&
1602 !cast<DISubprogram>(Op)->isDefinition())),
1603 "invalid retained type", &N, Op);
1604 }
1605 }
1606 if (auto *Array = N.getRawGlobalVariables()) {
1607 CheckDI(isa<MDTuple>(Array), "invalid global variable list", &N, Array);
1608 for (Metadata *Op : N.getGlobalVariables()->operands()) {
1609 auto *GVE = dyn_cast_or_null<DIGlobalVariableExpression>(Val: Op);
1610 CheckDI(GVE, "invalid global variable ref", &N, Op);
1611 CheckDI(!isa_and_nonnull<DILocalScope>(GVE->getVariable()->getScope()),
1612 "function-local variables are not allowed in a DICompileUnit's "
1613 "global variables list",
1614 &N, Op);
1615 }
1616 }
1617 if (auto *Array = N.getRawImportedEntities()) {
1618 CheckDI(isa<MDTuple>(Array), "invalid imported entity list", &N, Array);
1619 for (Metadata *Op : N.getImportedEntities()->operands()) {
1620 auto *IE = dyn_cast_or_null<DIImportedEntity>(Val: Op);
1621 CheckDI(IE, "invalid imported entity ref", &N, Op);
1622 CheckDI(!isa_and_nonnull<DILocalScope>(IE->getScope()),
1623 "function-local imports are not allowed in a DICompileUnit's "
1624 "imported entities list",
1625 &N, Op);
1626 }
1627 }
1628 if (auto *Array = N.getRawMacros()) {
1629 CheckDI(isa<MDTuple>(Array), "invalid macro list", &N, Array);
1630 for (Metadata *Op : N.getMacros()->operands()) {
1631 CheckDI(Op && isa<DIMacroNode>(Op), "invalid macro ref", &N, Op);
1632 }
1633 }
1634 CUVisited.insert(Ptr: &N);
1635}
1636
1637void Verifier::visitDISubprogram(const DISubprogram &N) {
1638 CheckDI(N.getTag() == dwarf::DW_TAG_subprogram, "invalid tag", &N);
1639 CheckDI(isScope(N.getRawScope()), "invalid scope", &N, N.getRawScope());
1640 if (auto *F = N.getRawFile())
1641 CheckDI(isa<DIFile>(F), "invalid file", &N, F);
1642 else
1643 CheckDI(N.getLine() == 0, "line specified with no file", &N, N.getLine());
1644 auto *T = N.getRawType();
1645 CheckDI(T, "DISubprogram requires a non-null type", &N);
1646 CheckDI(isa<DISubroutineType>(T), "invalid subroutine type", &N, T);
1647 CheckDI(isType(N.getRawContainingType()), "invalid containing type", &N,
1648 N.getRawContainingType());
1649 if (auto *Params = N.getRawTemplateParams())
1650 visitTemplateParams(N, RawParams: *Params);
1651 if (auto *S = N.getRawDeclaration())
1652 CheckDI(isa<DISubprogram>(S) && !cast<DISubprogram>(S)->isDefinition(),
1653 "invalid subprogram declaration", &N, S);
1654 if (auto *RawNode = N.getRawRetainedNodes()) {
1655 auto *Node = dyn_cast<MDTuple>(Val: RawNode);
1656 CheckDI(Node, "invalid retained nodes list", &N, RawNode);
1657
1658 DenseMap<unsigned, DILocalVariable *> Args;
1659 for (Metadata *Op : Node->operands()) {
1660 CheckDI(Op, "nullptr in retained nodes", &N, Node);
1661
1662 auto True = [](const Metadata *) { return true; };
1663 auto False = [](const Metadata *) { return false; };
1664 bool IsTypeCorrect = DISubprogram::visitRetainedNode<bool>(
1665 N: Op, FuncLV&: True, FuncLabel&: True, FuncIE&: True, FuncType&: True, FuncGVE&: True, FuncUnknown&: False);
1666 CheckDI(IsTypeCorrect,
1667 "invalid retained nodes, expected DILocalVariable, DILabel, "
1668 "DIImportedEntity, DIType or DIGlobalVariableExpression",
1669 &N, Node, Op);
1670
1671 auto *RetainedNode = cast<MDNode>(Val: Op);
1672 auto *RetainedNodeScope = dyn_cast_or_null<DILocalScope>(
1673 Val: DISubprogram::getRawRetainedNodeScope(N: RetainedNode));
1674 CheckDI(RetainedNodeScope,
1675 "invalid retained nodes, retained node is not local", &N, Node,
1676 RetainedNode);
1677
1678 DISubprogram *RetainedNodeSP = getSubprogram(LocalScope: RetainedNodeScope);
1679 DICompileUnit *RetainedNodeUnit =
1680 RetainedNodeSP ? RetainedNodeSP->getUnit() : nullptr;
1681 CheckDI(
1682 RetainedNodeSP == &N,
1683 "invalid retained nodes, retained node does not belong to subprogram",
1684 &N, Node, RetainedNode, RetainedNodeScope, RetainedNodeSP,
1685 RetainedNodeUnit);
1686
1687 auto *DV = dyn_cast<DILocalVariable>(Val: RetainedNode);
1688 if (!DV)
1689 continue;
1690 if (unsigned ArgNum = DV->getArg()) {
1691 auto [ArgI, Inserted] = Args.insert(KV: {ArgNum, DV});
1692 CheckDI(Inserted || DV == ArgI->second,
1693 "invalid retained nodes, more than one local variable with the "
1694 "same argument index",
1695 &N, N.getUnit(), Node, RetainedNode, Args[ArgNum]);
1696 }
1697 }
1698 }
1699 CheckDI(!hasConflictingReferenceFlags(N.getFlags()),
1700 "invalid reference flags", &N);
1701
1702 auto *Unit = N.getRawUnit();
1703 if (N.isDefinition()) {
1704 // Subprogram definitions (not part of the type hierarchy).
1705 CheckDI(N.isDistinct(), "subprogram definitions must be distinct", &N);
1706 CheckDI(Unit, "subprogram definitions must have a compile unit", &N);
1707 CheckDI(isa<DICompileUnit>(Unit), "invalid unit type", &N, Unit);
1708 // There's no good way to cross the CU boundary to insert a nested
1709 // DISubprogram definition in one CU into a type defined in another CU.
1710 auto *CT = dyn_cast_or_null<DICompositeType>(Val: N.getRawScope());
1711 if (CT && CT->getRawIdentifier() &&
1712 M.getContext().isODRUniquingDebugTypes())
1713 CheckDI(N.getDeclaration(),
1714 "definition subprograms cannot be nested within DICompositeType "
1715 "when enabling ODR",
1716 &N);
1717 } else {
1718 // Subprogram declarations (part of the type hierarchy).
1719 CheckDI(!Unit, "subprogram declarations must not have a compile unit", &N);
1720 CheckDI(!N.getRawDeclaration(),
1721 "subprogram declaration must not have a declaration field");
1722 }
1723
1724 if (auto *RawThrownTypes = N.getRawThrownTypes()) {
1725 auto *ThrownTypes = dyn_cast<MDTuple>(Val: RawThrownTypes);
1726 CheckDI(ThrownTypes, "invalid thrown types list", &N, RawThrownTypes);
1727 for (Metadata *Op : ThrownTypes->operands())
1728 CheckDI(Op && isa<DIType>(Op), "invalid thrown type", &N, ThrownTypes,
1729 Op);
1730 }
1731
1732 if (N.areAllCallsDescribed())
1733 CheckDI(N.isDefinition(),
1734 "DIFlagAllCallsDescribed must be attached to a definition");
1735}
1736
1737void Verifier::visitDILexicalBlockBase(const DILexicalBlockBase &N) {
1738 CheckDI(N.getTag() == dwarf::DW_TAG_lexical_block, "invalid tag", &N);
1739 CheckDI(N.getRawScope() && isa<DILocalScope>(N.getRawScope()),
1740 "invalid local scope", &N, N.getRawScope());
1741 if (auto *SP = dyn_cast<DISubprogram>(Val: N.getRawScope()))
1742 CheckDI(SP->isDefinition(), "scope points into the type hierarchy", &N);
1743}
1744
1745void Verifier::visitDILexicalBlock(const DILexicalBlock &N) {
1746 visitDILexicalBlockBase(N);
1747
1748 CheckDI(N.getLine() || !N.getColumn(),
1749 "cannot have column info without line info", &N);
1750}
1751
1752void Verifier::visitDILexicalBlockFile(const DILexicalBlockFile &N) {
1753 visitDILexicalBlockBase(N);
1754}
1755
1756void Verifier::visitDICommonBlock(const DICommonBlock &N) {
1757 CheckDI(N.getTag() == dwarf::DW_TAG_common_block, "invalid tag", &N);
1758 if (auto *S = N.getRawScope())
1759 CheckDI(isa<DIScope>(S), "invalid scope ref", &N, S);
1760 if (auto *S = N.getRawDecl())
1761 CheckDI(isa<DIGlobalVariable>(S), "invalid declaration", &N, S);
1762}
1763
1764void Verifier::visitDINamespace(const DINamespace &N) {
1765 CheckDI(N.getTag() == dwarf::DW_TAG_namespace, "invalid tag", &N);
1766 if (auto *S = N.getRawScope())
1767 CheckDI(isa<DIScope>(S), "invalid scope ref", &N, S);
1768}
1769
1770void Verifier::visitDIMacro(const DIMacro &N) {
1771 CheckDI(N.getMacinfoType() == dwarf::DW_MACINFO_define ||
1772 N.getMacinfoType() == dwarf::DW_MACINFO_undef,
1773 "invalid macinfo type", &N);
1774 CheckDI(!N.getName().empty(), "anonymous macro", &N);
1775 if (!N.getValue().empty()) {
1776 assert(N.getValue().data()[0] != ' ' && "Macro value has a space prefix");
1777 }
1778}
1779
1780void Verifier::visitDIMacroFile(const DIMacroFile &N) {
1781 CheckDI(N.getMacinfoType() == dwarf::DW_MACINFO_start_file,
1782 "invalid macinfo type", &N);
1783 if (auto *F = N.getRawFile())
1784 CheckDI(isa<DIFile>(F), "invalid file", &N, F);
1785
1786 if (auto *Array = N.getRawElements()) {
1787 CheckDI(isa<MDTuple>(Array), "invalid macro list", &N, Array);
1788 for (Metadata *Op : N.getElements()->operands()) {
1789 CheckDI(Op && isa<DIMacroNode>(Op), "invalid macro ref", &N, Op);
1790 }
1791 }
1792}
1793
1794void Verifier::visitDIModule(const DIModule &N) {
1795 CheckDI(N.getTag() == dwarf::DW_TAG_module, "invalid tag", &N);
1796 CheckDI(!N.getName().empty(), "anonymous module", &N);
1797}
1798
1799void Verifier::visitDITemplateParameter(const DITemplateParameter &N) {
1800 CheckDI(isType(N.getRawType()), "invalid type ref", &N, N.getRawType());
1801}
1802
1803void Verifier::visitDITemplateTypeParameter(const DITemplateTypeParameter &N) {
1804 visitDITemplateParameter(N);
1805
1806 CheckDI(N.getTag() == dwarf::DW_TAG_template_type_parameter, "invalid tag",
1807 &N);
1808}
1809
1810void Verifier::visitDITemplateValueParameter(
1811 const DITemplateValueParameter &N) {
1812 visitDITemplateParameter(N);
1813
1814 CheckDI(N.getTag() == dwarf::DW_TAG_template_value_parameter ||
1815 N.getTag() == dwarf::DW_TAG_GNU_template_template_param ||
1816 N.getTag() == dwarf::DW_TAG_GNU_template_parameter_pack,
1817 "invalid tag", &N);
1818}
1819
1820void Verifier::visitDIVariable(const DIVariable &N) {
1821 if (auto *S = N.getRawScope())
1822 CheckDI(isa<DIScope>(S), "invalid scope", &N, S);
1823 if (auto *F = N.getRawFile())
1824 CheckDI(isa<DIFile>(F), "invalid file", &N, F);
1825}
1826
1827void Verifier::visitDIGlobalVariable(const DIGlobalVariable &N) {
1828 // Checks common to all variables.
1829 visitDIVariable(N);
1830
1831 CheckDI(N.getTag() == dwarf::DW_TAG_variable, "invalid tag", &N);
1832 CheckDI(isType(N.getRawType()), "invalid type ref", &N, N.getRawType());
1833 // Check only if the global variable is not an extern
1834 if (N.isDefinition())
1835 CheckDI(N.getType(), "missing global variable type", &N);
1836 if (auto *Member = N.getRawStaticDataMemberDeclaration()) {
1837 CheckDI(isa<DIDerivedType>(Member),
1838 "invalid static data member declaration", &N, Member);
1839 }
1840}
1841
1842void Verifier::visitDILocalVariable(const DILocalVariable &N) {
1843 // Checks common to all variables.
1844 visitDIVariable(N);
1845
1846 CheckDI(isType(N.getRawType()), "invalid type ref", &N, N.getRawType());
1847 CheckDI(N.getTag() == dwarf::DW_TAG_variable, "invalid tag", &N);
1848 CheckDI(N.getRawScope() && isa<DILocalScope>(N.getRawScope()),
1849 "local variable requires a valid scope", &N, N.getRawScope());
1850 if (auto Ty = N.getType())
1851 CheckDI(!isa<DISubroutineType>(Ty), "invalid type", &N, N.getType());
1852}
1853
1854void Verifier::visitDIAssignID(const DIAssignID &N) {
1855 CheckDI(!N.getNumOperands(), "DIAssignID has no arguments", &N);
1856 CheckDI(N.isDistinct(), "DIAssignID must be distinct", &N);
1857}
1858
1859void Verifier::visitDILabel(const DILabel &N) {
1860 if (auto *S = N.getRawScope())
1861 CheckDI(isa<DIScope>(S), "invalid scope", &N, S);
1862 if (auto *F = N.getRawFile())
1863 CheckDI(isa<DIFile>(F), "invalid file", &N, F);
1864
1865 CheckDI(N.getTag() == dwarf::DW_TAG_label, "invalid tag", &N);
1866 CheckDI(N.getRawScope() && isa<DILocalScope>(N.getRawScope()),
1867 "label requires a valid scope", &N, N.getRawScope());
1868}
1869
1870void Verifier::visitDIExpression(const DIExpression &N) {
1871 CheckDI(N.isValid(), "invalid expression", &N);
1872}
1873
1874void Verifier::visitDIGlobalVariableExpression(
1875 const DIGlobalVariableExpression &GVE) {
1876 CheckDI(GVE.getVariable(), "missing variable");
1877 if (auto *Var = GVE.getVariable())
1878 visitDIGlobalVariable(N: *Var);
1879 if (auto *Expr = GVE.getExpression()) {
1880 visitDIExpression(N: *Expr);
1881 if (auto Fragment = Expr->getFragmentInfo())
1882 verifyFragmentExpression(V: *GVE.getVariable(), Fragment: *Fragment, Desc: &GVE);
1883 }
1884}
1885
1886void Verifier::visitDIObjCProperty(const DIObjCProperty &N) {
1887 CheckDI(N.getTag() == dwarf::DW_TAG_APPLE_property, "invalid tag", &N);
1888 if (auto *T = N.getRawType())
1889 CheckDI(isType(T), "invalid type ref", &N, T);
1890 if (auto *F = N.getRawFile())
1891 CheckDI(isa<DIFile>(F), "invalid file", &N, F);
1892}
1893
1894void Verifier::visitDIProperty(const DIProperty &N) {
1895 CheckDI(N.getTag() == dwarf::DW_TAG_property, "invalid tag", &N);
1896 if (auto *T = N.getRawType())
1897 CheckDI(isType(T), "invalid type ref", &N, T);
1898 if (auto *F = N.getRawFile())
1899 CheckDI(isa<DIFile>(F), "invalid file", &N, F);
1900 // DWARF allows a property getter to forward to a subprogram, variable, or
1901 // constant too, but the backend only knows how to forward to a member.
1902 if (DINode *BackingStorage = N.getBackingStorage()) {
1903 auto *DT = dyn_cast<DIDerivedType>(Val: BackingStorage);
1904 CheckDI(DT && DT->getTag() == dwarf::DW_TAG_member,
1905 "property backing storage must be a member", &N, BackingStorage);
1906 }
1907}
1908
1909void Verifier::visitDIImportedEntity(const DIImportedEntity &N) {
1910 CheckDI(N.getTag() == dwarf::DW_TAG_imported_module ||
1911 N.getTag() == dwarf::DW_TAG_imported_declaration,
1912 "invalid tag", &N);
1913 if (auto *S = N.getRawScope())
1914 CheckDI(isa<DIScope>(S), "invalid scope for imported entity", &N, S);
1915 CheckDI(isDINode(N.getRawEntity()), "invalid imported entity", &N,
1916 N.getRawEntity());
1917}
1918
1919void Verifier::visitComdat(const Comdat &C) {
1920 // In COFF the Module is invalid if the GlobalValue has private linkage.
1921 // Entities with private linkage don't have entries in the symbol table.
1922 if (TT.isOSBinFormatCOFF())
1923 if (const GlobalValue *GV = M.getNamedValue(Name: C.getName()))
1924 Check(!GV->hasPrivateLinkage(), "comdat global value has private linkage",
1925 GV);
1926}
1927
1928void Verifier::visitModuleIdents() {
1929 const NamedMDNode *Idents = M.getNamedMetadata(Name: "llvm.ident");
1930 if (!Idents)
1931 return;
1932
1933 // llvm.ident takes a list of metadata entry. Each entry has only one string.
1934 // Scan each llvm.ident entry and make sure that this requirement is met.
1935 for (const MDNode *N : Idents->operands()) {
1936 Check(N->getNumOperands() == 1,
1937 "incorrect number of operands in llvm.ident metadata", N);
1938 Check(dyn_cast_or_null<MDString>(N->getOperand(0)),
1939 ("invalid value for llvm.ident metadata entry operand"
1940 "(the operand should be a string)"),
1941 N->getOperand(0));
1942 }
1943}
1944
1945void Verifier::visitModuleCommandLines() {
1946 const NamedMDNode *CommandLines = M.getNamedMetadata(Name: "llvm.commandline");
1947 if (!CommandLines)
1948 return;
1949
1950 // llvm.commandline takes a list of metadata entry. Each entry has only one
1951 // string. Scan each llvm.commandline entry and make sure that this
1952 // requirement is met.
1953 for (const MDNode *N : CommandLines->operands()) {
1954 Check(N->getNumOperands() == 1,
1955 "incorrect number of operands in llvm.commandline metadata", N);
1956 Check(dyn_cast_or_null<MDString>(N->getOperand(0)),
1957 ("invalid value for llvm.commandline metadata entry operand"
1958 "(the operand should be a string)"),
1959 N->getOperand(0));
1960 }
1961}
1962
1963void Verifier::visitModuleErrnoTBAA() {
1964 const NamedMDNode *ErrnoTBAA = M.getNamedMetadata(Name: "llvm.errno.tbaa");
1965 if (!ErrnoTBAA)
1966 return;
1967
1968 Check(ErrnoTBAA->getNumOperands() >= 1,
1969 "llvm.errno.tbaa must have at least one operand", ErrnoTBAA);
1970
1971 for (const MDNode *N : ErrnoTBAA->operands())
1972 TBAAVerifyHelper.visitTBAAMetadata(I: nullptr, MD: N);
1973}
1974
1975void Verifier::visitModuleFlags() {
1976 const NamedMDNode *Flags = M.getModuleFlagsMetadata();
1977 if (!Flags) return;
1978
1979 // Scan each flag, and track the flags and requirements.
1980 DenseMap<const MDString*, const MDNode*> SeenIDs;
1981 SmallVector<const MDNode*, 16> Requirements;
1982
1983 // Either both aarch64-elf-pauthabi-* flags should be set or none at all.
1984 std::optional<uint64_t> PAuthABIPlatform;
1985 std::optional<uint64_t> PAuthABIVersion;
1986 // Signing of init/fini pointers: address diversity implies basic signing.
1987 uint64_t HasPtrauthInitFini = 0;
1988 uint64_t HasPtrauthInitFiniAddr = 0;
1989
1990 for (const MDNode *MDN : Flags->operands()) {
1991 visitModuleFlag(Op: MDN, SeenIDs, Requirements);
1992 if (MDN->getNumOperands() != 3)
1993 continue;
1994
1995 if (const auto *FlagName = dyn_cast_or_null<MDString>(Val: MDN->getOperand(I: 1))) {
1996 auto GetFlagNamed = [&](StringRef Name) -> std::optional<uint64_t> {
1997 if (FlagName->getString() != Name)
1998 return std::nullopt;
1999 if (const auto *FlagValue =
2000 mdconst::dyn_extract_or_null<ConstantInt>(MD: MDN->getOperand(I: 2)))
2001 return FlagValue->getZExtValue();
2002
2003 CheckFailed(Message: Name + ": module flag expects integer value");
2004 return std::nullopt;
2005 };
2006
2007 if (auto Value = GetFlagNamed("aarch64-elf-pauthabi-platform"))
2008 PAuthABIPlatform = *Value;
2009 else if (auto Value = GetFlagNamed("aarch64-elf-pauthabi-version"))
2010 PAuthABIVersion = *Value;
2011 else if (auto Value = GetFlagNamed("ptrauth-init-fini"))
2012 HasPtrauthInitFini = *Value;
2013 else if (auto Value =
2014 GetFlagNamed("ptrauth-init-fini-address-discrimination"))
2015 HasPtrauthInitFiniAddr = *Value;
2016 }
2017 }
2018
2019 Check(llvm::is_contained({0u, 1u}, HasPtrauthInitFini),
2020 "ptrauth-init-fini must be 0 or 1");
2021 Check(llvm::is_contained({0u, 1u}, HasPtrauthInitFiniAddr),
2022 "ptrauth-init-fini-address-discrimination must be 0 or 1, if set");
2023 if (HasPtrauthInitFiniAddr)
2024 Check(HasPtrauthInitFini, "ptrauth-init-fini-address-discrimination module "
2025 "flag requires ptrauth-init-fini");
2026
2027 if (PAuthABIPlatform.has_value() != PAuthABIVersion.has_value())
2028 CheckFailed(Message: "either both or no 'aarch64-elf-pauthabi-platform' and "
2029 "'aarch64-elf-pauthabi-version' module flags must be present");
2030
2031 // Validate that the requirements in the module are valid.
2032 for (const MDNode *Requirement : Requirements) {
2033 const MDString *Flag = cast<MDString>(Val: Requirement->getOperand(I: 0));
2034 const Metadata *ReqValue = Requirement->getOperand(I: 1);
2035
2036 const MDNode *Op = SeenIDs.lookup(Val: Flag);
2037 if (!Op) {
2038 CheckFailed(Message: "invalid requirement on flag, flag is not present in module",
2039 V1: Flag);
2040 continue;
2041 }
2042
2043 if (Op->getOperand(I: 2) != ReqValue) {
2044 CheckFailed(Message: ("invalid requirement on flag, "
2045 "flag does not have the required value"),
2046 V1: Flag);
2047 continue;
2048 }
2049 }
2050}
2051
2052void
2053Verifier::visitModuleFlag(const MDNode *Op,
2054 DenseMap<const MDString *, const MDNode *> &SeenIDs,
2055 SmallVectorImpl<const MDNode *> &Requirements) {
2056 // Each module flag should have three arguments, the merge behavior (a
2057 // constant int), the flag ID (an MDString), and the value.
2058 Check(Op->getNumOperands() == 3,
2059 "incorrect number of operands in module flag", Op);
2060 Module::ModFlagBehavior MFB;
2061 if (!Module::isValidModFlagBehavior(MD: Op->getOperand(I: 0), MFB)) {
2062 Check(mdconst::dyn_extract_or_null<ConstantInt>(Op->getOperand(0)),
2063 "invalid behavior operand in module flag (expected constant integer)",
2064 Op->getOperand(0));
2065 Check(false,
2066 "invalid behavior operand in module flag (unexpected constant)",
2067 Op->getOperand(0));
2068 }
2069 MDString *ID = dyn_cast_or_null<MDString>(Val: Op->getOperand(I: 1));
2070 Check(ID, "invalid ID operand in module flag (expected metadata string)",
2071 Op->getOperand(1));
2072
2073 // Check the values for behaviors with additional requirements.
2074 switch (MFB) {
2075 case Module::Error:
2076 case Module::Warning:
2077 case Module::Override:
2078 // These behavior types accept any value.
2079 break;
2080
2081 case Module::Min: {
2082 auto *V = mdconst::dyn_extract_or_null<ConstantInt>(MD: Op->getOperand(I: 2));
2083 Check(V && V->getValue().isNonNegative(),
2084 "invalid value for 'min' module flag (expected constant non-negative "
2085 "integer)",
2086 Op->getOperand(2));
2087 break;
2088 }
2089
2090 case Module::Max: {
2091 Check(mdconst::dyn_extract_or_null<ConstantInt>(Op->getOperand(2)),
2092 "invalid value for 'max' module flag (expected constant integer)",
2093 Op->getOperand(2));
2094 break;
2095 }
2096
2097 case Module::Require: {
2098 // The value should itself be an MDNode with two operands, a flag ID (an
2099 // MDString), and a value.
2100 auto *Value = dyn_cast<MDNode>(Val: Op->getOperand(I: 2));
2101 Check(Value && Value->getNumOperands() == 2,
2102 "invalid value for 'require' module flag (expected metadata pair)",
2103 Op->getOperand(2));
2104 Check(isa<MDString>(Value->getOperand(0)),
2105 ("invalid value for 'require' module flag "
2106 "(first value operand should be a string)"),
2107 Value->getOperand(0));
2108
2109 // Append it to the list of requirements, to check once all module flags are
2110 // scanned.
2111 Requirements.push_back(Elt: Value);
2112 break;
2113 }
2114
2115 case Module::Append:
2116 case Module::AppendUnique: {
2117 // These behavior types require the operand be an MDNode.
2118 Check(isa<MDNode>(Op->getOperand(2)),
2119 "invalid value for 'append'-type module flag "
2120 "(expected a metadata node)",
2121 Op->getOperand(2));
2122 break;
2123 }
2124 }
2125
2126 // Unless this is a "requires" flag, check the ID is unique.
2127 if (MFB != Module::Require) {
2128 bool Inserted = SeenIDs.insert(KV: std::make_pair(x&: ID, y&: Op)).second;
2129 Check(Inserted,
2130 "module flag identifiers must be unique (or of 'require' type)", ID);
2131 }
2132
2133 StringRef Name = ID->getString();
2134 if (Name == "wchar_size") {
2135 ConstantInt *Value
2136 = mdconst::dyn_extract_or_null<ConstantInt>(MD: Op->getOperand(I: 2));
2137 Check(Value, "wchar_size metadata requires constant integer argument");
2138 return;
2139 }
2140
2141 if (Name == "long-double-type") {
2142 Check(MFB == Module::Error,
2143 "long-double-type module flag must use 'error' merge behavior", Op);
2144 const MDString *Value = dyn_cast_or_null<MDString>(Val: Op->getOperand(I: 2));
2145 Check(Value, "long-double-type metadata requires a string argument");
2146 if (Value)
2147 Check(parseLongDoubleFormat(Value->getString()).has_value(),
2148 "invalid long-double-type metadata value", Op);
2149 return;
2150 }
2151
2152 if (Name == "float-abi") {
2153 Check(MFB == Module::Error,
2154 "float-abi module flag must use 'error' merge behavior", Op);
2155 const MDString *Value = dyn_cast_or_null<MDString>(Val: Op->getOperand(I: 2));
2156 Check(Value, "float-abi metadata requires a string argument");
2157 if (Value)
2158 Check(FloatABI::parseABIType(Value->getString()).has_value(),
2159 "invalid float-abi metadata value", Op);
2160 return;
2161 }
2162
2163 if (Name == "thread-model") {
2164 Check(MFB == Module::Error,
2165 "thread-model module flag must use 'error' merge behavior", Op);
2166 const MDString *Value = dyn_cast_or_null<MDString>(Val: Op->getOperand(I: 2));
2167 Check(Value, "thread-model metadata requires a string argument");
2168 if (Value)
2169 Check(parseThreadModel(Value->getString()).has_value(),
2170 "invalid thread-model metadata value", Op);
2171 return;
2172 }
2173
2174 if (Name == "target-abi") {
2175 const MDString *Value = dyn_cast_or_null<MDString>(Val: Op->getOperand(I: 2));
2176 Check(Value && !Value->getString().empty(),
2177 "target-abi metadata requires a non-empty string argument", Op);
2178 return;
2179 }
2180
2181 if (ID->getString() == "exception-model") {
2182 Check(MFB == Module::Error,
2183 "exception-model module flag must use 'error' merge behavior", Op);
2184 const MDString *Value = dyn_cast_or_null<MDString>(Val: Op->getOperand(I: 2));
2185 Check(Value, "exception-model metadata requires a string argument");
2186 if (Value)
2187 Check(parseExceptionModel(Value->getString()).has_value(),
2188 "invalid exception-model metadata value", Op);
2189 return;
2190 }
2191
2192 if (Name == "Linker Options") {
2193 // If the llvm.linker.options named metadata exists, we assume that the
2194 // bitcode reader has upgraded the module flag. Otherwise the flag might
2195 // have been created by a client directly.
2196 Check(M.getNamedMetadata("llvm.linker.options"),
2197 "'Linker Options' named metadata no longer supported");
2198 return;
2199 }
2200
2201 if (Name == "SemanticInterposition") {
2202 ConstantInt *Value =
2203 mdconst::dyn_extract_or_null<ConstantInt>(MD: Op->getOperand(I: 2));
2204 Check(Value,
2205 "SemanticInterposition metadata requires constant integer argument");
2206 return;
2207 }
2208
2209 if (Name == "CG Profile") {
2210 for (const MDOperand &MDO : cast<MDNode>(Val: Op->getOperand(I: 2))->operands())
2211 visitModuleFlagCGProfileEntry(MDO);
2212 return;
2213 }
2214
2215 // Target-specific module flag checks.
2216 verifyAMDGPUModuleFlag(VS&: *this, ID, MFB, Op);
2217}
2218
2219void Verifier::visitModuleFlagCGProfileEntry(const MDOperand &MDO) {
2220 auto CheckFunction = [&](const MDOperand &FuncMDO) {
2221 if (!FuncMDO)
2222 return;
2223 auto F = dyn_cast<ValueAsMetadata>(Val: FuncMDO);
2224 Check(F && isa<Function>(F->getValue()->stripPointerCasts()),
2225 "expected a Function or null", FuncMDO);
2226 };
2227 auto Node = dyn_cast_or_null<MDNode>(Val: MDO);
2228 Check(Node && Node->getNumOperands() == 3, "expected a MDNode triple", MDO);
2229 CheckFunction(Node->getOperand(I: 0));
2230 CheckFunction(Node->getOperand(I: 1));
2231 auto Count = dyn_cast_or_null<ConstantAsMetadata>(Val: Node->getOperand(I: 2));
2232 Check(Count && Count->getType()->isIntegerTy(),
2233 "expected an integer constant", Node->getOperand(2));
2234}
2235
2236void Verifier::verifyAttributeTypes(AttributeSet Attrs, const Value *V) {
2237 for (Attribute A : Attrs) {
2238
2239 if (A.isStringAttribute()) {
2240#define GET_ATTR_NAMES
2241#define ATTRIBUTE_ENUM(ENUM_NAME, DISPLAY_NAME)
2242#define ATTRIBUTE_STRBOOL(ENUM_NAME, DISPLAY_NAME) \
2243 if (A.getKindAsString() == #DISPLAY_NAME) { \
2244 auto V = A.getValueAsString(); \
2245 if (!(V.empty() || V == "true" || V == "false")) \
2246 CheckFailed("invalid value for '" #DISPLAY_NAME "' attribute: " + V + \
2247 ""); \
2248 }
2249
2250#include "llvm/IR/Attributes.inc"
2251 continue;
2252 }
2253
2254 if (A.isIntAttribute() != Attribute::isIntAttrKind(Kind: A.getKindAsEnum())) {
2255 CheckFailed(Message: "Attribute '" + A.getAsString() + "' should have an Argument",
2256 V1: V);
2257 return;
2258 }
2259 }
2260}
2261
2262// VerifyParameterAttrs - Check the given attributes for an argument or return
2263// value of the specified type. The value V is printed in error messages.
2264void Verifier::verifyParameterAttrs(AttributeSet Attrs, Type *Ty,
2265 const Value *V) {
2266 if (!Attrs.hasAttributes())
2267 return;
2268
2269 verifyAttributeTypes(Attrs, V);
2270
2271 for (Attribute Attr : Attrs)
2272 Check(Attr.isStringAttribute() ||
2273 Attribute::canUseAsParamAttr(Attr.getKindAsEnum()),
2274 "Attribute '" + Attr.getAsString() + "' does not apply to parameters",
2275 V);
2276
2277 if (Attrs.hasAttribute(Kind: Attribute::ImmArg)) {
2278 unsigned AttrCount =
2279 Attrs.getNumAttributes() - Attrs.hasAttribute(Kind: Attribute::Range);
2280 Check(AttrCount == 1,
2281 "Attribute 'immarg' is incompatible with other attributes except the "
2282 "'range' attribute",
2283 V);
2284 }
2285
2286 // Check for mutually incompatible attributes. Only inreg is compatible with
2287 // sret.
2288 unsigned AttrCount = 0;
2289 AttrCount += Attrs.hasAttribute(Kind: Attribute::ByVal);
2290 AttrCount += Attrs.hasAttribute(Kind: Attribute::InAlloca);
2291 AttrCount += Attrs.hasAttribute(Kind: Attribute::Preallocated);
2292 AttrCount += Attrs.hasAttribute(Kind: Attribute::StructRet) ||
2293 Attrs.hasAttribute(Kind: Attribute::InReg);
2294 AttrCount += Attrs.hasAttribute(Kind: Attribute::Nest);
2295 AttrCount += Attrs.hasAttribute(Kind: Attribute::ByRef);
2296 Check(AttrCount <= 1,
2297 "Attributes 'byval', 'inalloca', 'preallocated', 'inreg', 'nest', "
2298 "'byref', and 'sret' are incompatible!",
2299 V);
2300
2301 Check(!(Attrs.hasAttribute(Attribute::InAlloca) &&
2302 Attrs.hasAttribute(Attribute::ReadOnly)),
2303 "Attributes "
2304 "'inalloca and readonly' are incompatible!",
2305 V);
2306
2307 Check(!(Attrs.hasAttribute(Attribute::StructRet) &&
2308 Attrs.hasAttribute(Attribute::Returned)),
2309 "Attributes "
2310 "'sret and returned' are incompatible!",
2311 V);
2312
2313 Check(!(Attrs.hasAttribute(Attribute::ZExt) &&
2314 Attrs.hasAttribute(Attribute::SExt)),
2315 "Attributes "
2316 "'zeroext and signext' are incompatible!",
2317 V);
2318
2319 Check(!(Attrs.hasAttribute(Attribute::ReadNone) &&
2320 Attrs.hasAttribute(Attribute::ReadOnly)),
2321 "Attributes "
2322 "'readnone and readonly' are incompatible!",
2323 V);
2324
2325 Check(!(Attrs.hasAttribute(Attribute::ReadNone) &&
2326 Attrs.hasAttribute(Attribute::WriteOnly)),
2327 "Attributes "
2328 "'readnone and writeonly' are incompatible!",
2329 V);
2330
2331 Check(!(Attrs.hasAttribute(Attribute::ReadOnly) &&
2332 Attrs.hasAttribute(Attribute::WriteOnly)),
2333 "Attributes "
2334 "'readonly and writeonly' are incompatible!",
2335 V);
2336
2337 Check(!(Attrs.hasAttribute(Attribute::NoInline) &&
2338 Attrs.hasAttribute(Attribute::AlwaysInline)),
2339 "Attributes "
2340 "'noinline and alwaysinline' are incompatible!",
2341 V);
2342
2343 Check(!(Attrs.hasAttribute(Attribute::Writable) &&
2344 Attrs.hasAttribute(Attribute::ReadNone)),
2345 "Attributes writable and readnone are incompatible!", V);
2346
2347 Check(!(Attrs.hasAttribute(Attribute::Writable) &&
2348 Attrs.hasAttribute(Attribute::ReadOnly)),
2349 "Attributes writable and readonly are incompatible!", V);
2350
2351 AttributeMask IncompatibleAttrs = AttributeFuncs::typeIncompatible(Ty, AS: Attrs);
2352 for (Attribute Attr : Attrs) {
2353 if (!Attr.isStringAttribute() &&
2354 IncompatibleAttrs.contains(A: Attr.getKindAsEnum())) {
2355 CheckFailed(Message: "Attribute '" + Attr.getAsString() +
2356 "' applied to incompatible type!", V1: V);
2357 return;
2358 }
2359 }
2360
2361 if (isa<PointerType>(Val: Ty)) {
2362 if (Attrs.hasAttribute(Kind: Attribute::Alignment)) {
2363 Align AttrAlign = Attrs.getAlignment().valueOrOne();
2364 Check(AttrAlign.value() <= Value::MaximumAlignment,
2365 "huge alignment values are unsupported", V);
2366 }
2367 if (Attrs.hasAttribute(Kind: Attribute::ByVal)) {
2368 Type *ByValTy = Attrs.getByValType();
2369 Check(ByValTy->isSized(),
2370 "Attribute 'byval' does not support unsized types!", V);
2371 // Check if it is or contains a target extension type that disallows being
2372 // used on the stack.
2373 Check(!ByValTy->containsNonLocalTargetExtType(),
2374 "'byval' argument has illegal target extension type", V);
2375 // The copy is placed in the caller's frame, which needs its size at
2376 // compile time.
2377 Check(!ByValTy->isScalableTy(),
2378 "scalable 'byval' arguments are unsupported", V);
2379 Check(DL.getTypeAllocSize(ByValTy).getKnownMinValue() < (1ULL << 32),
2380 "huge 'byval' arguments are unsupported", V);
2381 }
2382 if (Attrs.hasAttribute(Kind: Attribute::ByRef)) {
2383 Check(Attrs.getByRefType()->isSized(),
2384 "Attribute 'byref' does not support unsized types!", V);
2385 Check(DL.getTypeAllocSize(Attrs.getByRefType()).getKnownMinValue() <
2386 (1ULL << 32),
2387 "huge 'byref' arguments are unsupported", V);
2388 }
2389 if (Attrs.hasAttribute(Kind: Attribute::InAlloca)) {
2390 Check(Attrs.getInAllocaType()->isSized(),
2391 "Attribute 'inalloca' does not support unsized types!", V);
2392 Check(DL.getTypeAllocSize(Attrs.getInAllocaType()).getKnownMinValue() <
2393 (1ULL << 32),
2394 "huge 'inalloca' arguments are unsupported", V);
2395 }
2396 if (Attrs.hasAttribute(Kind: Attribute::Preallocated)) {
2397 Check(Attrs.getPreallocatedType()->isSized(),
2398 "Attribute 'preallocated' does not support unsized types!", V);
2399 Check(
2400 DL.getTypeAllocSize(Attrs.getPreallocatedType()).getKnownMinValue() <
2401 (1ULL << 32),
2402 "huge 'preallocated' arguments are unsupported", V);
2403 }
2404 }
2405
2406 if (Attrs.hasAttribute(Kind: Attribute::Initializes)) {
2407 auto Inits = Attrs.getAttribute(Kind: Attribute::Initializes).getInitializes();
2408 Check(!Inits.empty(), "Attribute 'initializes' does not support empty list",
2409 V);
2410 Check(ConstantRangeList::isOrderedRanges(Inits),
2411 "Attribute 'initializes' does not support unordered ranges", V);
2412 }
2413
2414 if (Attrs.hasAttribute(Kind: Attribute::NoFPClass)) {
2415 uint64_t Val = Attrs.getAttribute(Kind: Attribute::NoFPClass).getValueAsInt();
2416 Check(Val != 0, "Attribute 'nofpclass' must have at least one test bit set",
2417 V);
2418 Check((Val & ~static_cast<unsigned>(fcAllFlags)) == 0,
2419 "Invalid value for 'nofpclass' test mask", V);
2420 }
2421 if (Attrs.hasAttribute(Kind: Attribute::Range)) {
2422 const ConstantRange &CR =
2423 Attrs.getAttribute(Kind: Attribute::Range).getValueAsConstantRange();
2424 Check(Ty->isIntOrIntVectorTy(CR.getBitWidth()),
2425 "Range bit width must match type bit width!", V);
2426 }
2427}
2428
2429void Verifier::checkUnsignedBaseTenFuncAttr(AttributeList Attrs, StringRef Attr,
2430 const Value *V) {
2431 if (Attrs.hasFnAttr(Kind: Attr)) {
2432 StringRef S = Attrs.getFnAttr(Kind: Attr).getValueAsString();
2433 unsigned N;
2434 if (S.getAsInteger(Radix: 10, Result&: N))
2435 CheckFailed(Message: "\"" + Attr + "\" takes an unsigned integer: " + S, V1: V);
2436 }
2437}
2438
2439// Check parameter attributes against a function type.
2440// The value V is printed in error messages.
2441void Verifier::verifyFunctionAttrs(FunctionType *FT, AttributeList Attrs,
2442 const Value *V, bool IsIntrinsic,
2443 bool IsInlineAsm) {
2444 if (Attrs.isEmpty())
2445 return;
2446
2447 if (AttributeListsVisited.insert(Ptr: Attrs.getRawPointer()).second) {
2448 Check(Attrs.hasParentContext(Context),
2449 "Attribute list does not match Module context!", &Attrs, V);
2450 for (const auto &AttrSet : Attrs) {
2451 Check(!AttrSet.hasAttributes() || AttrSet.hasParentContext(Context),
2452 "Attribute set does not match Module context!", &AttrSet, V);
2453 for (const auto &A : AttrSet) {
2454 Check(A.hasParentContext(Context),
2455 "Attribute does not match Module context!", &A, V);
2456 }
2457 }
2458 }
2459
2460 bool SawNest = false;
2461 bool SawReturned = false;
2462 bool SawSRet = false;
2463 bool SawSwiftSelf = false;
2464 bool SawSwiftAsync = false;
2465 bool SawSwiftError = false;
2466
2467 // Verify return value attributes.
2468 AttributeSet RetAttrs = Attrs.getRetAttrs();
2469 for (Attribute RetAttr : RetAttrs)
2470 Check(RetAttr.isStringAttribute() ||
2471 Attribute::canUseAsRetAttr(RetAttr.getKindAsEnum()),
2472 "Attribute '" + RetAttr.getAsString() +
2473 "' does not apply to function return values",
2474 V);
2475
2476 unsigned MaxParameterWidth = 0;
2477 auto GetMaxParameterWidth = [&MaxParameterWidth](Type *Ty) {
2478 if (Ty->isVectorTy()) {
2479 if (auto *VT = dyn_cast<FixedVectorType>(Val: Ty)) {
2480 unsigned Size = VT->getPrimitiveSizeInBits().getFixedValue();
2481 if (Size > MaxParameterWidth)
2482 MaxParameterWidth = Size;
2483 }
2484 }
2485 };
2486 GetMaxParameterWidth(FT->getReturnType());
2487 verifyParameterAttrs(Attrs: RetAttrs, Ty: FT->getReturnType(), V);
2488
2489 // Verify parameter attributes.
2490 for (unsigned i = 0, e = FT->getNumParams(); i != e; ++i) {
2491 Type *Ty = FT->getParamType(i);
2492 AttributeSet ArgAttrs = Attrs.getParamAttrs(ArgNo: i);
2493
2494 if (!IsIntrinsic) {
2495 Check(!ArgAttrs.hasAttribute(Attribute::ImmArg),
2496 "immarg attribute only applies to intrinsics", V);
2497 if (!IsInlineAsm)
2498 Check(!ArgAttrs.hasAttribute(Attribute::ElementType),
2499 "Attribute 'elementtype' can only be applied to intrinsics"
2500 " and inline asm.",
2501 V);
2502 }
2503
2504 verifyParameterAttrs(Attrs: ArgAttrs, Ty, V);
2505 GetMaxParameterWidth(Ty);
2506
2507 if (ArgAttrs.hasAttribute(Kind: Attribute::Nest)) {
2508 Check(!SawNest, "More than one parameter has attribute nest!", V);
2509 SawNest = true;
2510 }
2511
2512 if (ArgAttrs.hasAttribute(Kind: Attribute::Returned)) {
2513 Check(!SawReturned, "More than one parameter has attribute returned!", V);
2514 Check(Ty->canLosslesslyBitCastTo(FT->getReturnType()),
2515 "Incompatible argument and return types for 'returned' attribute",
2516 V);
2517 SawReturned = true;
2518 }
2519
2520 if (ArgAttrs.hasAttribute(Kind: Attribute::StructRet)) {
2521 Check(!SawSRet, "Cannot have multiple 'sret' parameters!", V);
2522 Check(i == 0 || i == 1,
2523 "Attribute 'sret' is not on first or second parameter!", V);
2524 SawSRet = true;
2525 }
2526
2527 if (ArgAttrs.hasAttribute(Kind: Attribute::SwiftSelf)) {
2528 Check(!SawSwiftSelf, "Cannot have multiple 'swiftself' parameters!", V);
2529 SawSwiftSelf = true;
2530 }
2531
2532 if (ArgAttrs.hasAttribute(Kind: Attribute::SwiftAsync)) {
2533 Check(!SawSwiftAsync, "Cannot have multiple 'swiftasync' parameters!", V);
2534 SawSwiftAsync = true;
2535 }
2536
2537 if (ArgAttrs.hasAttribute(Kind: Attribute::SwiftError)) {
2538 Check(!SawSwiftError, "Cannot have multiple 'swifterror' parameters!", V);
2539 SawSwiftError = true;
2540 }
2541
2542 if (ArgAttrs.hasAttribute(Kind: Attribute::InAlloca)) {
2543 Check(i == FT->getNumParams() - 1,
2544 "inalloca isn't on the last parameter!", V);
2545 }
2546 }
2547
2548 if (!Attrs.hasFnAttrs())
2549 return;
2550
2551 verifyAttributeTypes(Attrs: Attrs.getFnAttrs(), V);
2552 for (Attribute FnAttr : Attrs.getFnAttrs())
2553 Check(FnAttr.isStringAttribute() ||
2554 Attribute::canUseAsFnAttr(FnAttr.getKindAsEnum()),
2555 "Attribute '" + FnAttr.getAsString() +
2556 "' does not apply to functions!",
2557 V);
2558
2559 Check(!(Attrs.hasFnAttr(Attribute::NoInline) &&
2560 Attrs.hasFnAttr(Attribute::AlwaysInline)),
2561 "Attributes 'noinline and alwaysinline' are incompatible!", V);
2562
2563 if (Attrs.hasFnAttr(Kind: Attribute::OptimizeNone)) {
2564 Check(Attrs.hasFnAttr(Attribute::NoInline),
2565 "Attribute 'optnone' requires 'noinline'!", V);
2566
2567 Check(!Attrs.hasFnAttr(Attribute::OptimizeForSize),
2568 "Attributes 'optsize and optnone' are incompatible!", V);
2569
2570 Check(!Attrs.hasFnAttr(Attribute::MinSize),
2571 "Attributes 'minsize and optnone' are incompatible!", V);
2572
2573 Check(!Attrs.hasFnAttr(Attribute::OptimizeForDebugging),
2574 "Attributes 'optdebug and optnone' are incompatible!", V);
2575 }
2576
2577 Check(!(Attrs.hasFnAttr(Attribute::SanitizeRealtime) &&
2578 Attrs.hasFnAttr(Attribute::SanitizeRealtimeBlocking)),
2579 "Attributes "
2580 "'sanitize_realtime and sanitize_realtime_blocking' are incompatible!",
2581 V);
2582
2583 if (Attrs.hasFnAttr(Kind: Attribute::OptimizeForDebugging)) {
2584 Check(!Attrs.hasFnAttr(Attribute::OptimizeForSize),
2585 "Attributes 'optsize and optdebug' are incompatible!", V);
2586
2587 Check(!Attrs.hasFnAttr(Attribute::MinSize),
2588 "Attributes 'minsize and optdebug' are incompatible!", V);
2589 }
2590
2591 Check(!Attrs.hasAttrSomewhere(Attribute::Writable) ||
2592 isModSet(Attrs.getMemoryEffects().getModRef(IRMemLocation::ArgMem)),
2593 "Attribute writable and memory without argmem: write are incompatible!",
2594 V);
2595
2596 if (Attrs.hasFnAttr(Kind: "aarch64_pstate_sm_enabled")) {
2597 Check(!Attrs.hasFnAttr("aarch64_pstate_sm_compatible"),
2598 "Attributes 'aarch64_pstate_sm_enabled and "
2599 "aarch64_pstate_sm_compatible' are incompatible!",
2600 V);
2601 }
2602
2603 Check((Attrs.hasFnAttr("aarch64_new_za") + Attrs.hasFnAttr("aarch64_in_za") +
2604 Attrs.hasFnAttr("aarch64_inout_za") +
2605 Attrs.hasFnAttr("aarch64_out_za") +
2606 Attrs.hasFnAttr("aarch64_preserves_za") +
2607 Attrs.hasFnAttr("aarch64_za_state_agnostic")) <= 1,
2608 "Attributes 'aarch64_new_za', 'aarch64_in_za', 'aarch64_out_za', "
2609 "'aarch64_inout_za', 'aarch64_preserves_za' and "
2610 "'aarch64_za_state_agnostic' are mutually exclusive",
2611 V);
2612
2613 Check((Attrs.hasFnAttr("aarch64_new_zt0") +
2614 Attrs.hasFnAttr("aarch64_in_zt0") +
2615 Attrs.hasFnAttr("aarch64_inout_zt0") +
2616 Attrs.hasFnAttr("aarch64_out_zt0") +
2617 Attrs.hasFnAttr("aarch64_preserves_zt0") +
2618 Attrs.hasFnAttr("aarch64_za_state_agnostic")) <= 1,
2619 "Attributes 'aarch64_new_zt0', 'aarch64_in_zt0', 'aarch64_out_zt0', "
2620 "'aarch64_inout_zt0', 'aarch64_preserves_zt0' and "
2621 "'aarch64_za_state_agnostic' are mutually exclusive",
2622 V);
2623
2624 if (Attrs.hasFnAttr(Kind: Attribute::JumpTable)) {
2625 const GlobalValue *GV = cast<GlobalValue>(Val: V);
2626 Check(GV->hasGlobalUnnamedAddr(),
2627 "Attribute 'jumptable' requires 'unnamed_addr'", V);
2628 }
2629
2630 if (auto Args = Attrs.getFnAttrs().getAllocSizeArgs()) {
2631 auto CheckParam = [&](StringRef Name, unsigned ParamNo) {
2632 if (ParamNo >= FT->getNumParams()) {
2633 CheckFailed(Message: "'allocsize' " + Name + " argument is out of bounds", V1: V);
2634 return false;
2635 }
2636
2637 if (!FT->getParamType(i: ParamNo)->isIntegerTy()) {
2638 CheckFailed(Message: "'allocsize' " + Name +
2639 " argument must refer to an integer parameter",
2640 V1: V);
2641 return false;
2642 }
2643
2644 return true;
2645 };
2646
2647 if (!CheckParam("element size", Args->first))
2648 return;
2649
2650 if (Args->second && !CheckParam("number of elements", *Args->second))
2651 return;
2652 }
2653
2654 if (Attrs.hasFnAttr(Kind: Attribute::AllocKind)) {
2655 AllocFnKind K = Attrs.getAllocKind();
2656 AllocFnKind Type =
2657 K & (AllocFnKind::Alloc | AllocFnKind::Realloc | AllocFnKind::Free);
2658 if (!is_contained(
2659 Set: {AllocFnKind::Alloc, AllocFnKind::Realloc, AllocFnKind::Free},
2660 Element: Type))
2661 CheckFailed(
2662 Message: "'allockind()' requires exactly one of alloc, realloc, and free");
2663 if ((Type == AllocFnKind::Free) &&
2664 ((K & (AllocFnKind::Uninitialized | AllocFnKind::Zeroed |
2665 AllocFnKind::Aligned)) != AllocFnKind::Unknown))
2666 CheckFailed(Message: "'allockind(\"free\")' doesn't allow uninitialized, zeroed, "
2667 "or aligned modifiers.");
2668 AllocFnKind ZeroedUninit = AllocFnKind::Uninitialized | AllocFnKind::Zeroed;
2669 if ((K & ZeroedUninit) == ZeroedUninit)
2670 CheckFailed(Message: "'allockind()' can't be both zeroed and uninitialized");
2671 }
2672
2673 if (Attribute A = Attrs.getFnAttr(Kind: "alloc-variant-zeroed"); A.isValid()) {
2674 StringRef S = A.getValueAsString();
2675 Check(!S.empty(), "'alloc-variant-zeroed' must not be empty");
2676 Function *Variant = M.getFunction(Name: S);
2677 if (Variant) {
2678 Attribute Family = Attrs.getFnAttr(Kind: "alloc-family");
2679 Attribute VariantFamily = Variant->getFnAttribute(Kind: "alloc-family");
2680 if (Family.isValid())
2681 Check(VariantFamily.isValid() &&
2682 VariantFamily.getValueAsString() == Family.getValueAsString(),
2683 "'alloc-variant-zeroed' must name a function belonging to the "
2684 "same 'alloc-family'");
2685
2686 Check(Variant->hasFnAttribute(Attribute::AllocKind) &&
2687 (Variant->getFnAttribute(Attribute::AllocKind).getAllocKind() &
2688 AllocFnKind::Zeroed) != AllocFnKind::Unknown,
2689 "'alloc-variant-zeroed' must name a function with "
2690 "'allockind(\"zeroed\")'");
2691
2692 Check(FT == Variant->getFunctionType(),
2693 "'alloc-variant-zeroed' must name a function with the same "
2694 "signature");
2695
2696 if (const auto *F = dyn_cast<Function>(Val: V))
2697 Check(F->getCallingConv() == Variant->getCallingConv(),
2698 "'alloc-variant-zeroed' must name a function with the same "
2699 "calling convention");
2700 }
2701 }
2702
2703 if (Attrs.hasFnAttr(Kind: Attribute::VScaleRange)) {
2704 unsigned VScaleMin = Attrs.getFnAttrs().getVScaleRangeMin();
2705 if (VScaleMin == 0)
2706 CheckFailed(Message: "'vscale_range' minimum must be greater than 0", V1: V);
2707 else if (!isPowerOf2_32(Value: VScaleMin))
2708 CheckFailed(Message: "'vscale_range' minimum must be power-of-two value", V1: V);
2709 std::optional<unsigned> VScaleMax = Attrs.getFnAttrs().getVScaleRangeMax();
2710 if (VScaleMax && VScaleMin > VScaleMax)
2711 CheckFailed(Message: "'vscale_range' minimum cannot be greater than maximum", V1: V);
2712 else if (VScaleMax && !isPowerOf2_32(Value: *VScaleMax))
2713 CheckFailed(Message: "'vscale_range' maximum must be power-of-two value", V1: V);
2714 }
2715
2716 if (Attribute FPAttr = Attrs.getFnAttr(Kind: "frame-pointer"); FPAttr.isValid()) {
2717 StringRef FP = FPAttr.getValueAsString();
2718 if (FP != "all" && FP != "non-leaf" && FP != "none" && FP != "reserved" &&
2719 FP != "non-leaf-no-reserve")
2720 CheckFailed(Message: "invalid value for 'frame-pointer' attribute: " + FP, V1: V);
2721 }
2722
2723 checkUnsignedBaseTenFuncAttr(Attrs, Attr: "tail-pad-to-size", V);
2724 checkUnsignedBaseTenFuncAttr(Attrs, Attr: "tail-pad-value", V);
2725 checkUnsignedBaseTenFuncAttr(Attrs, Attr: "patchable-function-prefix", V);
2726 checkUnsignedBaseTenFuncAttr(Attrs, Attr: "patchable-function-entry", V);
2727 if (Attrs.hasFnAttr(Kind: "patchable-function-entry-section"))
2728 Check(!Attrs.getFnAttr("patchable-function-entry-section")
2729 .getValueAsString()
2730 .empty(),
2731 "\"patchable-function-entry-section\" must not be empty");
2732 checkUnsignedBaseTenFuncAttr(Attrs, Attr: "warn-stack-size", V);
2733
2734 if (auto A = Attrs.getFnAttr(Kind: "sign-return-address"); A.isValid()) {
2735 StringRef S = A.getValueAsString();
2736 if (S != "none" && S != "all" && S != "non-leaf")
2737 CheckFailed(Message: "invalid value for 'sign-return-address' attribute: " + S, V1: V);
2738 }
2739
2740 if (auto A = Attrs.getFnAttr(Kind: "sign-return-address-key"); A.isValid()) {
2741 StringRef S = A.getValueAsString();
2742 if (S != "a_key" && S != "b_key")
2743 CheckFailed(Message: "invalid value for 'sign-return-address-key' attribute: " + S,
2744 V1: V);
2745 if (auto AA = Attrs.getFnAttr(Kind: "sign-return-address"); !AA.isValid()) {
2746 CheckFailed(
2747 Message: "'sign-return-address-key' present without `sign-return-address`");
2748 }
2749 }
2750
2751 if (auto A = Attrs.getFnAttr(Kind: "sign-return-address-harden"); A.isValid()) {
2752 StringRef S = A.getValueAsString();
2753 if (S != "load-return-address" && S != "none")
2754 CheckFailed(
2755 Message: "invalid value for 'sign-return-address-harden' attribute: " + S, V1: V);
2756 auto SignRetA = Attrs.getFnAttr(Kind: "sign-return-address");
2757 auto PAuthRetA = Attrs.getFnAttr(Kind: "ptrauth-returns");
2758 if (!SignRetA.isValid() && !PAuthRetA.isValid())
2759 CheckFailed(Message: "'sign-return-address-harden' present without "
2760 "'sign-return-address' or 'ptrauth-returns'");
2761 }
2762
2763 if (auto A = Attrs.getFnAttr(Kind: "branch-target-enforcement"); A.isValid()) {
2764 StringRef S = A.getValueAsString();
2765 if (S != "" && S != "true" && S != "false")
2766 CheckFailed(
2767 Message: "invalid value for 'branch-target-enforcement' attribute: " + S, V1: V);
2768 }
2769
2770 if (auto A = Attrs.getFnAttr(Kind: "branch-protection-pauth-lr"); A.isValid()) {
2771 StringRef S = A.getValueAsString();
2772 if (S != "" && S != "true" && S != "false")
2773 CheckFailed(
2774 Message: "invalid value for 'branch-protection-pauth-lr' attribute: " + S, V1: V);
2775 }
2776
2777 if (auto A = Attrs.getFnAttr(Kind: "guarded-control-stack"); A.isValid()) {
2778 StringRef S = A.getValueAsString();
2779 if (S != "" && S != "true" && S != "false")
2780 CheckFailed(Message: "invalid value for 'guarded-control-stack' attribute: " + S,
2781 V1: V);
2782 }
2783
2784 if (auto A = Attrs.getFnAttr(Kind: "vector-function-abi-variant"); A.isValid()) {
2785 StringRef S = A.getValueAsString();
2786 const std::optional<VFInfo> Info = VFABI::tryDemangleForVFABI(MangledName: S, FTy: FT);
2787 if (!Info)
2788 CheckFailed(Message: "invalid name for a VFABI variant: " + S, V1: V);
2789 }
2790
2791 if (auto A = Attrs.getFnAttr(Kind: "modular-format"); A.isValid()) {
2792 StringRef S = A.getValueAsString();
2793 SmallVector<StringRef> Args;
2794 S.split(A&: Args, Separator: ',');
2795 Check(Args.size() >= 5,
2796 "modular-format attribute requires at least 5 arguments", V);
2797 unsigned UpperBound = FT->getNumParams() + (FT->isVarArg() ? 1 : 0);
2798 unsigned FormatIdx;
2799 Check(!Args[1].getAsInteger(10, FormatIdx),
2800 "modular-format attribute format string index is not an integer", V);
2801 Check(FormatIdx > 0,
2802 "modular-format attribute format string index must be greater than 0",
2803 V);
2804 Check(FormatIdx <= UpperBound,
2805 "modular-format attribute format string index is out of bounds", V);
2806 unsigned FirstArgIdx;
2807 Check(!Args[2].getAsInteger(10, FirstArgIdx),
2808 "modular-format attribute first arg index is not an integer", V);
2809 Check(FirstArgIdx <= UpperBound,
2810 "modular-format attribute first arg index is out of bounds", V);
2811 Check(!Args[3].empty(),
2812 "modular-format attribute modular implementation function name "
2813 "cannot be empty",
2814 V);
2815 Check(!Args[4].empty(),
2816 "modular-format attribute implementation name cannot be empty", V);
2817 }
2818
2819 if (auto A = Attrs.getFnAttr(Kind: "target-features"); A.isValid()) {
2820 StringRef S = A.getValueAsString();
2821 if (!S.empty()) {
2822 for (auto FeatureFlag : split(Str: S, Separator: ',')) {
2823 if (FeatureFlag.empty())
2824 CheckFailed(
2825 Message: "target-features attribute should not contain an empty string");
2826 else
2827 Check(FeatureFlag[0] == '+' || FeatureFlag[0] == '-',
2828 "target feature '" + FeatureFlag +
2829 "' must start with a '+' or '-'",
2830 V);
2831 }
2832 }
2833 }
2834}
2835void Verifier::verifyUnknownProfileMetadata(MDNode *MD) {
2836 Check(MD->getNumOperands() == 2,
2837 "'unknown' !prof should have a single additional operand", MD);
2838 auto *PassName = dyn_cast<MDString>(Val: MD->getOperand(I: 1));
2839 Check(PassName != nullptr,
2840 "'unknown' !prof should have an additional operand of type "
2841 "string");
2842 Check(!PassName->getString().empty(),
2843 "the 'unknown' !prof operand should not be an empty string");
2844}
2845
2846void Verifier::verifyFunctionMetadata(
2847 ArrayRef<std::pair<unsigned, MDNode *>> MDs) {
2848 for (const auto &Pair : MDs) {
2849 if (Pair.first == LLVMContext::MD_prof) {
2850 MDNode *MD = Pair.second;
2851 Check(MD->getNumOperands() >= 2,
2852 "!prof annotations should have no less than 2 operands", MD);
2853 // We may have functions that are synthesized by the compiler, e.g. in
2854 // WPD, that we can't currently determine the entry count.
2855 if (MD->getOperand(I: 0).equalsStr(
2856 Str: MDProfLabels::UnknownBranchWeightsMarker)) {
2857 verifyUnknownProfileMetadata(MD);
2858 continue;
2859 }
2860
2861 // Check first operand.
2862 Check(MD->getOperand(0) != nullptr, "first operand should not be null",
2863 MD);
2864 Check(isa<MDString>(MD->getOperand(0)),
2865 "expected string with name of the !prof annotation", MD);
2866 MDString *MDS = cast<MDString>(Val: MD->getOperand(I: 0));
2867 StringRef ProfName = MDS->getString();
2868 Check(ProfName == MDProfLabels::FunctionEntryCount ||
2869 ProfName == MDProfLabels::SyntheticFunctionEntryCount,
2870 "first operand should be 'function_entry_count'"
2871 " or 'synthetic_function_entry_count'",
2872 MD);
2873
2874 // Check second operand.
2875 Check(MD->getOperand(1) != nullptr, "second operand should not be null",
2876 MD);
2877 Check(isa<ConstantAsMetadata>(MD->getOperand(1)),
2878 "expected integer argument to function_entry_count", MD);
2879 } else if (Pair.first == LLVMContext::MD_kcfi_type) {
2880 MDNode *MD = Pair.second;
2881 Check(MD->getNumOperands() == 1,
2882 "!kcfi_type must have exactly one operand", MD);
2883 Check(MD->getOperand(0) != nullptr, "!kcfi_type operand must not be null",
2884 MD);
2885 Check(isa<ConstantAsMetadata>(MD->getOperand(0)),
2886 "expected a constant operand for !kcfi_type", MD);
2887 Constant *C = cast<ConstantAsMetadata>(Val: MD->getOperand(I: 0))->getValue();
2888 Check(isa<ConstantInt>(C) && isa<IntegerType>(C->getType()),
2889 "expected a constant integer operand for !kcfi_type", MD);
2890 Check(cast<ConstantInt>(C)->getBitWidth() == 32,
2891 "expected a 32-bit integer constant operand for !kcfi_type", MD);
2892 } else if (Pair.first == Context.getMDKindID(Name: "reqd_work_group_size")) {
2893 MDNode *MD = Pair.second;
2894 Check(MD->getNumOperands() == 3,
2895 "reqd_work_group_size must have exactly three operands", MD);
2896 if (MD->getNumOperands() != 3)
2897 continue;
2898
2899 uint64_t Product = 1;
2900 for (unsigned I = 0; I != 3; ++I) {
2901 ConstantInt *C = mdconst::dyn_extract<ConstantInt>(MD: MD->getOperand(I));
2902 Check(C, "reqd_work_group_size operands must be integer constants", MD);
2903 if (!C)
2904 break;
2905
2906 const APInt &Value = C->getValue();
2907 Check(Value.getActiveBits() <= 64,
2908 "reqd_work_group_size operands must fit in 64 bits", MD);
2909 if (Value.getActiveBits() > 64)
2910 break;
2911
2912 uint64_t Dim = Value.getZExtValue();
2913 Check(Dim == 0 || Product <= std::numeric_limits<uint64_t>::max() / Dim,
2914 "reqd_work_group_size product must fit in 64 bits", MD);
2915 if (Dim != 0 && Product > std::numeric_limits<uint64_t>::max() / Dim)
2916 break;
2917 Product *= Dim;
2918 }
2919 }
2920 }
2921}
2922
2923void Verifier::visitConstantExprsRecursively(const Constant *EntryC) {
2924 if (EntryC->getNumOperands() == 0)
2925 return;
2926
2927 if (!ConstantExprVisited.insert(Ptr: EntryC).second)
2928 return;
2929
2930 SmallVector<const Constant *, 16> Stack;
2931 Stack.push_back(Elt: EntryC);
2932
2933 while (!Stack.empty()) {
2934 const Constant *C = Stack.pop_back_val();
2935
2936 // Check this constant expression.
2937 if (const auto *CE = dyn_cast<ConstantExpr>(Val: C))
2938 visitConstantExpr(CE);
2939
2940 if (const auto *CPA = dyn_cast<ConstantPtrAuth>(Val: C))
2941 visitConstantPtrAuth(CPA);
2942
2943 if (const auto *GV = dyn_cast<GlobalValue>(Val: C)) {
2944 // Global Values get visited separately, but we do need to make sure
2945 // that the global value is in the correct module
2946 Check(GV->getParent() == &M, "Referencing global in another module!",
2947 EntryC, &M, GV, GV->getParent());
2948 continue;
2949 }
2950
2951 // Visit all sub-expressions.
2952 for (const Use &U : C->operands()) {
2953 const auto *OpC = dyn_cast<Constant>(Val: U);
2954 if (!OpC)
2955 continue;
2956 if (!ConstantExprVisited.insert(Ptr: OpC).second)
2957 continue;
2958 Stack.push_back(Elt: OpC);
2959 }
2960 }
2961}
2962
2963void Verifier::visitConstantExpr(const ConstantExpr *CE) {
2964 if (CE->getOpcode() == Instruction::BitCast)
2965 Check(CastInst::castIsValid(Instruction::BitCast, CE->getOperand(0),
2966 CE->getType()),
2967 "Invalid bitcast", CE);
2968 else if (CE->getOpcode() == Instruction::PtrToAddr)
2969 checkPtrToAddr(SrcTy: CE->getOperand(i_nocapture: 0)->getType(), DestTy: CE->getType(), V: *CE);
2970}
2971
2972void Verifier::visitConstantPtrAuth(const ConstantPtrAuth *CPA) {
2973 Check(CPA->getPointer()->getType()->isPointerTy(),
2974 "signed ptrauth constant base pointer must have pointer type");
2975
2976 Check(CPA->getType() == CPA->getPointer()->getType(),
2977 "signed ptrauth constant must have same type as its base pointer");
2978
2979 Check(CPA->getKey()->getBitWidth() == 32,
2980 "signed ptrauth constant key must be i32 constant integer");
2981
2982 Check(CPA->getAddrDiscriminator()->getType()->isPointerTy(),
2983 "signed ptrauth constant address discriminator must be a pointer");
2984
2985 Check(CPA->getDiscriminator()->getBitWidth() == 64,
2986 "signed ptrauth constant discriminator must be i64 constant integer");
2987
2988 Check(CPA->getDeactivationSymbol()->getType()->isPointerTy(),
2989 "signed ptrauth constant deactivation symbol must be a pointer");
2990
2991 Check(isa<GlobalValue>(CPA->getDeactivationSymbol()) ||
2992 isa<ConstantPointerNull>(CPA->getDeactivationSymbol()),
2993 "signed ptrauth constant deactivation symbol must be a global value "
2994 "or null");
2995}
2996
2997bool Verifier::verifyAttributeCount(AttributeList Attrs, unsigned Params) {
2998 // There shouldn't be more attribute sets than there are parameters plus the
2999 // function and return value.
3000 return Attrs.getNumAttrSets() <= Params + 2;
3001}
3002
3003void Verifier::verifyInlineAsmCall(const CallBase &Call) {
3004 const InlineAsm *IA = cast<InlineAsm>(Val: Call.getCalledOperand());
3005 unsigned ArgNo = 0;
3006 unsigned LabelNo = 0;
3007 for (const InlineAsm::ConstraintInfo &CI : IA->ParseConstraints()) {
3008 if (CI.Type == InlineAsm::isLabel) {
3009 ++LabelNo;
3010 continue;
3011 }
3012
3013 // Only deal with constraints that correspond to call arguments.
3014 if (!CI.hasArg())
3015 continue;
3016
3017 if (CI.isIndirect) {
3018 const Value *Arg = Call.getArgOperand(i: ArgNo);
3019 Check(Arg->getType()->isPointerTy(),
3020 "Operand for indirect constraint must have pointer type", &Call);
3021
3022 Check(Call.getParamElementType(ArgNo),
3023 "Operand for indirect constraint must have elementtype attribute",
3024 &Call);
3025 } else {
3026 Check(!Call.paramHasAttr(ArgNo, Attribute::ElementType),
3027 "Elementtype attribute can only be applied for indirect "
3028 "constraints",
3029 &Call);
3030 }
3031
3032 ArgNo++;
3033 }
3034
3035 if (auto *CallBr = dyn_cast<CallBrInst>(Val: &Call)) {
3036 Check(LabelNo == CallBr->getNumIndirectDests(),
3037 "Number of label constraints does not match number of callbr dests",
3038 &Call);
3039 } else {
3040 Check(LabelNo == 0, "Label constraints can only be used with callbr",
3041 &Call);
3042 }
3043}
3044
3045/// Verify that statepoint intrinsic is well formed.
3046void Verifier::verifyStatepoint(const CallBase &Call) {
3047 assert(Call.getIntrinsicID() == Intrinsic::experimental_gc_statepoint);
3048
3049 Check(!Call.doesNotAccessMemory() && !Call.onlyReadsMemory() &&
3050 !Call.onlyAccessesArgMemory(),
3051 "gc.statepoint must read and write all memory to preserve "
3052 "reordering restrictions required by safepoint semantics",
3053 Call);
3054
3055 const int64_t NumPatchBytes =
3056 cast<ConstantInt>(Val: Call.getArgOperand(i: 1))->getSExtValue();
3057 assert(isInt<32>(NumPatchBytes) && "NumPatchBytesV is an i32!");
3058 Check(NumPatchBytes >= 0,
3059 "gc.statepoint number of patchable bytes must be "
3060 "positive",
3061 Call);
3062
3063 Type *TargetElemType = Call.getParamElementType(ArgNo: 2);
3064 Check(TargetElemType,
3065 "gc.statepoint callee argument must have elementtype attribute", Call);
3066 auto *TargetFuncType = dyn_cast<FunctionType>(Val: TargetElemType);
3067 Check(TargetFuncType,
3068 "gc.statepoint callee elementtype must be function type", Call);
3069
3070 const int NumCallArgs = cast<ConstantInt>(Val: Call.getArgOperand(i: 3))->getZExtValue();
3071 Check(NumCallArgs >= 0,
3072 "gc.statepoint number of arguments to underlying call "
3073 "must be positive",
3074 Call);
3075 const int NumParams = (int)TargetFuncType->getNumParams();
3076 if (TargetFuncType->isVarArg()) {
3077 Check(NumCallArgs >= NumParams,
3078 "gc.statepoint mismatch in number of vararg call args", Call);
3079
3080 // TODO: Remove this limitation
3081 Check(TargetFuncType->getReturnType()->isVoidTy(),
3082 "gc.statepoint doesn't support wrapping non-void "
3083 "vararg functions yet",
3084 Call);
3085 } else
3086 Check(NumCallArgs == NumParams,
3087 "gc.statepoint mismatch in number of call args", Call);
3088
3089 const uint64_t Flags
3090 = cast<ConstantInt>(Val: Call.getArgOperand(i: 4))->getZExtValue();
3091 Check((Flags & ~(uint64_t)StatepointFlags::MaskAll) == 0,
3092 "unknown flag used in gc.statepoint flags argument", Call);
3093
3094 // Verify that the types of the call parameter arguments match
3095 // the type of the wrapped callee.
3096 AttributeList Attrs = Call.getAttributes();
3097 for (int i = 0; i < NumParams; i++) {
3098 Type *ParamType = TargetFuncType->getParamType(i);
3099 Type *ArgType = Call.getArgOperand(i: 5 + i)->getType();
3100 Check(ArgType == ParamType,
3101 "gc.statepoint call argument does not match wrapped "
3102 "function type",
3103 Call);
3104
3105 if (TargetFuncType->isVarArg()) {
3106 AttributeSet ArgAttrs = Attrs.getParamAttrs(ArgNo: 5 + i);
3107 Check(!ArgAttrs.hasAttribute(Attribute::StructRet),
3108 "Attribute 'sret' cannot be used for vararg call arguments!", Call);
3109 }
3110 }
3111
3112 const int EndCallArgsInx = 4 + NumCallArgs;
3113
3114 const Value *NumTransitionArgsV = Call.getArgOperand(i: EndCallArgsInx + 1);
3115 Check(isa<ConstantInt>(NumTransitionArgsV),
3116 "gc.statepoint number of transition arguments "
3117 "must be constant integer",
3118 Call);
3119 const int NumTransitionArgs =
3120 cast<ConstantInt>(Val: NumTransitionArgsV)->getZExtValue();
3121 Check(NumTransitionArgs == 0,
3122 "gc.statepoint w/inline transition bundle is deprecated", Call);
3123 const int EndTransitionArgsInx = EndCallArgsInx + 1 + NumTransitionArgs;
3124
3125 const Value *NumDeoptArgsV = Call.getArgOperand(i: EndTransitionArgsInx + 1);
3126 Check(isa<ConstantInt>(NumDeoptArgsV),
3127 "gc.statepoint number of deoptimization arguments "
3128 "must be constant integer",
3129 Call);
3130 const int NumDeoptArgs = cast<ConstantInt>(Val: NumDeoptArgsV)->getZExtValue();
3131 Check(NumDeoptArgs == 0,
3132 "gc.statepoint w/inline deopt operands is deprecated", Call);
3133
3134 const int ExpectedNumArgs = 7 + NumCallArgs;
3135 Check(ExpectedNumArgs == (int)Call.arg_size(),
3136 "gc.statepoint too many arguments", Call);
3137
3138 // Check that the only uses of this gc.statepoint are gc.result or
3139 // gc.relocate calls which are tied to this statepoint and thus part
3140 // of the same statepoint sequence
3141 for (const User *U : Call.users()) {
3142 const auto *UserCall = dyn_cast<const CallInst>(Val: U);
3143 Check(UserCall, "illegal use of statepoint token", Call, U);
3144 if (!UserCall)
3145 continue;
3146 Check(isa<GCRelocateInst>(UserCall) || isa<GCResultInst>(UserCall),
3147 "gc.result or gc.relocate are the only value uses "
3148 "of a gc.statepoint",
3149 Call, U);
3150 if (isa<GCResultInst>(Val: UserCall)) {
3151 Check(UserCall->getArgOperand(0) == &Call,
3152 "gc.result connected to wrong gc.statepoint", Call, UserCall);
3153 } else if (isa<GCRelocateInst>(Val: Call)) {
3154 Check(UserCall->getArgOperand(0) == &Call,
3155 "gc.relocate connected to wrong gc.statepoint", Call, UserCall);
3156 }
3157 }
3158
3159 // Note: It is legal for a single derived pointer to be listed multiple
3160 // times. It's non-optimal, but it is legal. It can also happen after
3161 // insertion if we strip a bitcast away.
3162 // Note: It is really tempting to check that each base is relocated and
3163 // that a derived pointer is never reused as a base pointer. This turns
3164 // out to be problematic since optimizations run after safepoint insertion
3165 // can recognize equality properties that the insertion logic doesn't know
3166 // about. See example statepoint.ll in the verifier subdirectory
3167}
3168
3169void Verifier::verifyFrameRecoverIndices() {
3170 for (auto &Counts : FrameEscapeInfo) {
3171 Function *F = Counts.first;
3172 unsigned EscapedObjectCount = Counts.second.first;
3173 unsigned MaxRecoveredIndex = Counts.second.second;
3174 Check(MaxRecoveredIndex <= EscapedObjectCount,
3175 "all indices passed to llvm.localrecover must be less than the "
3176 "number of arguments passed to llvm.localescape in the parent "
3177 "function",
3178 F);
3179 }
3180}
3181
3182static Instruction *getSuccPad(Instruction *Terminator) {
3183 BasicBlock *UnwindDest;
3184 if (auto *II = dyn_cast<InvokeInst>(Val: Terminator))
3185 UnwindDest = II->getUnwindDest();
3186 else if (auto *CSI = dyn_cast<CatchSwitchInst>(Val: Terminator))
3187 UnwindDest = CSI->getUnwindDest();
3188 else
3189 UnwindDest = cast<CleanupReturnInst>(Val: Terminator)->getUnwindDest();
3190 return &*UnwindDest->getFirstNonPHIIt();
3191}
3192
3193void Verifier::verifySiblingFuncletUnwinds() {
3194 llvm::TimeTraceScope timeScope("Verifier verify sibling funclet unwinds");
3195 SmallPtrSet<Instruction *, 8> Visited;
3196 SmallPtrSet<Instruction *, 8> Active;
3197 for (const auto &Pair : SiblingFuncletInfo) {
3198 Instruction *PredPad = Pair.first;
3199 if (Visited.count(Ptr: PredPad))
3200 continue;
3201 Active.insert(Ptr: PredPad);
3202 Instruction *Terminator = Pair.second;
3203 do {
3204 Instruction *SuccPad = getSuccPad(Terminator);
3205 if (Active.count(Ptr: SuccPad)) {
3206 // Found a cycle; report error
3207 Instruction *CyclePad = SuccPad;
3208 SmallVector<Instruction *, 8> CycleNodes;
3209 do {
3210 CycleNodes.push_back(Elt: CyclePad);
3211 Instruction *CycleTerminator = SiblingFuncletInfo[CyclePad];
3212 if (CycleTerminator != CyclePad)
3213 CycleNodes.push_back(Elt: CycleTerminator);
3214 CyclePad = getSuccPad(Terminator: CycleTerminator);
3215 } while (CyclePad != SuccPad);
3216 Check(false, "EH pads can't handle each other's exceptions",
3217 ArrayRef<Instruction *>(CycleNodes));
3218 }
3219 // Don't re-walk a node we've already checked
3220 if (!Visited.insert(Ptr: SuccPad).second)
3221 break;
3222 // Walk to this successor if it has a map entry.
3223 PredPad = SuccPad;
3224 auto TermI = SiblingFuncletInfo.find(Key: PredPad);
3225 if (TermI == SiblingFuncletInfo.end())
3226 break;
3227 Terminator = TermI->second;
3228 Active.insert(Ptr: PredPad);
3229 } while (true);
3230 // Each node only has one successor, so we've walked all the active
3231 // nodes' successors.
3232 Active.clear();
3233 }
3234}
3235
3236// visitFunction - Verify that a function is ok.
3237//
3238void Verifier::visitFunction(const Function &F) {
3239 visitGlobalValue(GV: F);
3240
3241 // Check function arguments.
3242 FunctionType *FT = F.getFunctionType();
3243 unsigned NumArgs = F.arg_size();
3244
3245 Check(&Context == &F.getContext(),
3246 "Function context does not match Module context!", &F);
3247
3248 Check(!F.hasCommonLinkage(), "Functions may not have common linkage", &F);
3249 Check(FT->getNumParams() == NumArgs,
3250 "# formal arguments must match # of arguments for function type!", &F,
3251 FT);
3252 Check(F.getReturnType()->isFirstClassType() ||
3253 F.getReturnType()->isVoidTy() || F.getReturnType()->isStructTy(),
3254 "Functions cannot return aggregate values!", &F);
3255
3256 Check(!F.hasStructRetAttr() || F.getReturnType()->isVoidTy(),
3257 "Invalid struct return type!", &F);
3258
3259 if (MaybeAlign A = F.getAlign()) {
3260 Check(A->value() <= Value::MaximumAlignment,
3261 "huge alignment values are unsupported", &F);
3262 }
3263
3264 AttributeList Attrs = F.getAttributes();
3265
3266 Check(verifyAttributeCount(Attrs, FT->getNumParams()),
3267 "Attribute after last parameter!", &F);
3268
3269 bool IsIntrinsic = F.isIntrinsic();
3270
3271 // Check function attributes.
3272 verifyFunctionAttrs(FT, Attrs, V: &F, IsIntrinsic, /* IsInlineAsm */ false);
3273
3274 // On function declarations/definitions, we do not support the builtin
3275 // attribute. We do not check this in VerifyFunctionAttrs since that is
3276 // checking for Attributes that can/can not ever be on functions.
3277 Check(!Attrs.hasFnAttr(Attribute::Builtin),
3278 "Attribute 'builtin' can only be applied to a callsite.", &F);
3279
3280 Check(!Attrs.hasAttrSomewhere(Attribute::ElementType),
3281 "Attribute 'elementtype' can only be applied to a callsite.", &F);
3282
3283 if (Attrs.hasFnAttr(Kind: Attribute::Naked))
3284 for (const Argument &Arg : F.args())
3285 Check(Arg.use_empty(), "cannot use argument of naked function", &Arg);
3286
3287 // Check that this function meets the restrictions on this calling convention.
3288 // Sometimes varargs is used for perfectly forwarding thunks, so some of these
3289 // restrictions can be lifted.
3290 switch (F.getCallingConv()) {
3291 default:
3292 case CallingConv::C:
3293 break;
3294 case CallingConv::X86_INTR: {
3295 Check(F.arg_empty() || Attrs.hasParamAttr(0, Attribute::ByVal),
3296 "Calling convention parameter requires byval", &F);
3297 break;
3298 }
3299 case CallingConv::AMDGPU_KERNEL:
3300 case CallingConv::SPIR_KERNEL:
3301 case CallingConv::AMDGPU_CS_Chain:
3302 case CallingConv::AMDGPU_CS_ChainPreserve:
3303 Check(F.getReturnType()->isVoidTy(),
3304 "Calling convention requires void return type", &F);
3305 [[fallthrough]];
3306 case CallingConv::AMDGPU_VS:
3307 case CallingConv::AMDGPU_HS:
3308 case CallingConv::AMDGPU_GS:
3309 case CallingConv::AMDGPU_PS:
3310 case CallingConv::AMDGPU_CS:
3311 Check(!F.hasStructRetAttr(), "Calling convention does not allow sret", &F);
3312 if (F.getCallingConv() != CallingConv::SPIR_KERNEL) {
3313 const unsigned StackAS = DL.getAllocaAddrSpace();
3314 unsigned i = 0;
3315 for (const Argument &Arg : F.args()) {
3316 Check(!Attrs.hasParamAttr(i, Attribute::ByVal),
3317 "Calling convention disallows byval", &F);
3318 Check(!Attrs.hasParamAttr(i, Attribute::Preallocated),
3319 "Calling convention disallows preallocated", &F);
3320 Check(!Attrs.hasParamAttr(i, Attribute::InAlloca),
3321 "Calling convention disallows inalloca", &F);
3322
3323 if (Attrs.hasParamAttr(ArgNo: i, Kind: Attribute::ByRef)) {
3324 // FIXME: Should also disallow LDS and GDS, but we don't have the enum
3325 // value here.
3326 Check(Arg.getType()->getPointerAddressSpace() != StackAS,
3327 "Calling convention disallows stack byref", &F);
3328 }
3329
3330 ++i;
3331 }
3332 }
3333
3334 [[fallthrough]];
3335 case CallingConv::Fast:
3336 case CallingConv::Cold:
3337 case CallingConv::Intel_OCL_BI:
3338 case CallingConv::PTX_Kernel:
3339 case CallingConv::PTX_Device:
3340 Check(!F.isVarArg(),
3341 "Calling convention does not support varargs or "
3342 "perfect forwarding!",
3343 &F);
3344 break;
3345 case CallingConv::AMDGPU_Gfx_WholeWave:
3346 Check(!F.arg_empty() && F.arg_begin()->getType()->isIntegerTy(1),
3347 "Calling convention requires first argument to be i1", &F);
3348 Check(!F.arg_begin()->hasInRegAttr(),
3349 "Calling convention requires first argument to not be inreg", &F);
3350 Check(!F.isVarArg(),
3351 "Calling convention does not support varargs or "
3352 "perfect forwarding!",
3353 &F);
3354 break;
3355 }
3356
3357 // Check that the argument values match the function type for this function...
3358 unsigned i = 0;
3359 for (const Argument &Arg : F.args()) {
3360 Check(Arg.getType() == FT->getParamType(i),
3361 "Argument value does not match function argument type!", &Arg,
3362 FT->getParamType(i));
3363 Check(Arg.getType()->isFirstClassType(),
3364 "Function arguments must have first-class types!", &Arg);
3365 if (!IsIntrinsic) {
3366 Check(!Arg.getType()->isMetadataTy(),
3367 "Function takes metadata but isn't an intrinsic", &Arg, &F);
3368 Check(!Arg.getType()->isTokenLikeTy(),
3369 "Function takes token but isn't an intrinsic", &Arg, &F);
3370 Check(!Arg.getType()->isX86_AMXTy(),
3371 "Function takes x86_amx but isn't an intrinsic", &Arg, &F);
3372 }
3373
3374 // Check that swifterror argument is only used by loads and stores.
3375 if (Attrs.hasParamAttr(ArgNo: i, Kind: Attribute::SwiftError)) {
3376 verifySwiftErrorValue(SwiftErrorVal: &Arg);
3377 }
3378 ++i;
3379 }
3380
3381 if (!IsIntrinsic) {
3382 Check(!F.getReturnType()->isTokenLikeTy(),
3383 "Function returns a token but isn't an intrinsic", &F);
3384 Check(!F.getReturnType()->isX86_AMXTy(),
3385 "Function returns a x86_amx but isn't an intrinsic", &F);
3386 }
3387
3388 // Get the function metadata attachments.
3389 SmallVector<std::pair<unsigned, MDNode *>, 4> MDs;
3390 F.getAllMetadata(MDs);
3391 assert(F.hasMetadata() != MDs.empty() && "Bit out-of-sync");
3392 verifyFunctionMetadata(MDs);
3393
3394 // Target-specific function metadata checks.
3395 verifyAMDGPUFunctionMetadata(VS&: *this, F);
3396
3397 // Check validity of the personality function
3398 if (F.hasPersonalityFn()) {
3399 auto *Per = dyn_cast<Function>(Val: F.getPersonalityFn()->stripPointerCasts());
3400 if (Per)
3401 Check(Per->getParent() == F.getParent(),
3402 "Referencing personality function in another module!", &F,
3403 F.getParent(), Per, Per->getParent());
3404 }
3405
3406 // EH funclet coloring can be expensive, recompute on-demand
3407 BlockEHFuncletColors.clear();
3408
3409 if (F.isMaterializable()) {
3410 // Function has a body somewhere we can't see.
3411 Check(MDs.empty(), "unmaterialized function cannot have metadata", &F,
3412 MDs.empty() ? nullptr : MDs.front().second);
3413 } else if (F.isDeclaration()) {
3414 for (const auto &I : MDs) {
3415 // This is used for call site debug information.
3416 CheckDI(I.first != LLVMContext::MD_dbg ||
3417 !cast<DISubprogram>(I.second)->isDistinct(),
3418 "function declaration may only have a unique !dbg attachment",
3419 &F);
3420 Check(I.first != LLVMContext::MD_prof,
3421 "function declaration may not have a !prof attachment", &F);
3422
3423 // Verify the metadata itself.
3424 visitMDNode(BaseMD: *I.second, AllowLocs: AreDebugLocsAllowed::Yes);
3425 }
3426 Check(!F.hasPersonalityFn(),
3427 "Function declaration shouldn't have a personality routine", &F);
3428 } else {
3429 // Verify that this function (which has a body) is not named "llvm.*". It
3430 // is not legal to define intrinsics.
3431 Check(!IsIntrinsic, "llvm intrinsics cannot be defined!", &F);
3432
3433 // Check the entry node
3434 const BasicBlock *Entry = &F.getEntryBlock();
3435 Check(pred_empty(Entry),
3436 "Entry block to function must not have predecessors!", Entry);
3437
3438 // The address of the entry block cannot be taken, unless it is dead.
3439 if (Entry->hasAddressTaken()) {
3440 Check(!BlockAddress::lookup(Entry)->isConstantUsed(),
3441 "blockaddress may not be used with the entry block!", Entry);
3442 }
3443
3444 unsigned NumDebugAttachments = 0, NumProfAttachments = 0,
3445 NumKCFIAttachments = 0;
3446 // Visit metadata attachments.
3447 for (const auto &I : MDs) {
3448 // Verify that the attachment is legal.
3449 auto AllowLocs = AreDebugLocsAllowed::No;
3450 switch (I.first) {
3451 default:
3452 break;
3453 case LLVMContext::MD_dbg: {
3454 ++NumDebugAttachments;
3455 CheckDI(NumDebugAttachments == 1,
3456 "function must have a single !dbg attachment", &F, I.second);
3457 CheckDI(isa<DISubprogram>(I.second),
3458 "function !dbg attachment must be a subprogram", &F, I.second);
3459 CheckDI(cast<DISubprogram>(I.second)->isDistinct(),
3460 "function definition may only have a distinct !dbg attachment",
3461 &F);
3462
3463 auto *SP = cast<DISubprogram>(Val: I.second);
3464 const Function *&AttachedTo = DISubprogramAttachments[SP];
3465 CheckDI(!AttachedTo || AttachedTo == &F,
3466 "DISubprogram attached to more than one function", SP, &F);
3467 AttachedTo = &F;
3468 AllowLocs = AreDebugLocsAllowed::Yes;
3469 break;
3470 }
3471 case LLVMContext::MD_prof:
3472 ++NumProfAttachments;
3473 Check(NumProfAttachments == 1,
3474 "function must have a single !prof attachment", &F, I.second);
3475 break;
3476 case LLVMContext::MD_kcfi_type:
3477 ++NumKCFIAttachments;
3478 Check(NumKCFIAttachments == 1,
3479 "function must have a single !kcfi_type attachment", &F,
3480 I.second);
3481 break;
3482 }
3483
3484 // Verify the metadata itself.
3485 visitMDNode(BaseMD: *I.second, AllowLocs);
3486 }
3487 }
3488
3489 // If this function is actually an intrinsic, verify that it is only used in
3490 // direct call/invokes, never having its "address taken".
3491 // Only do this if the module is materialized, otherwise we don't have all the
3492 // uses.
3493 bool isMaterialized = F.getParent()->isMaterialized();
3494 if (F.isIntrinsic() && isMaterialized) {
3495 const User *U;
3496 if (F.hasAddressTaken(&U, IgnoreCallbackUses: false, IgnoreAssumeLikeCalls: true, IngoreLLVMUsed: false,
3497 /*IgnoreARCAttachedCall=*/true))
3498 Check(false, "Invalid user of intrinsic instruction!", U);
3499 }
3500
3501 // Verify if the intrinsic's signature and name are valid. We do this if
3502 // the intrinsic has at least one materialized use, or if the module is fully
3503 // materialized.
3504 Intrinsic::ID IID = F.getIntrinsicID();
3505 if (IID && (isMaterialized || !F.materialized_use_empty())) {
3506 // Verify that the intrinsic prototype lines up with what the .td files
3507 // describe.
3508 std::string ErrMsg;
3509 raw_string_ostream ErrOS(ErrMsg);
3510 SmallVector<Type *, 4> OverloadTys;
3511 bool IsValid = Intrinsic::isSignatureValid(ID: IID, FT, OverloadTys, OS&: ErrOS);
3512 Printable PrintDecl([&F](raw_ostream &OS) { F.print(OS); });
3513 Check(IsValid, ErrMsg, PrintDecl);
3514
3515 // Now that we have the intrinsic ID and the actual argument types (and we
3516 // know they are legal for the intrinsic!) get the intrinsic name through
3517 // the usual means. This allows us to verify the mangling of argument types
3518 // into the name.
3519 const std::string ExpectedName = Intrinsic::getName(
3520 Id: IID, OverloadTys, M: const_cast<Module *>(F.getParent()), FT);
3521 Check(ExpectedName == F.getName(),
3522 "Intrinsic name not mangled correctly for type arguments! "
3523 "Should be: " +
3524 ExpectedName,
3525 PrintDecl);
3526 }
3527
3528 auto *N = F.getSubprogram();
3529 HasDebugInfo = (N != nullptr);
3530 if (!HasDebugInfo)
3531 return;
3532
3533 // Check that all !dbg attachments lead to back to N.
3534 //
3535 // FIXME: Check this incrementally while visiting !dbg attachments.
3536 // FIXME: Only check when N is the canonical subprogram for F.
3537 SmallPtrSet<const MDNode *, 32> Seen;
3538 auto VisitDebugLoc = [&](const Instruction &I, const MDNode *Node) {
3539 // Be careful about using DILocation here since we might be dealing with
3540 // broken code (this is the Verifier after all).
3541 const DILocation *DL = dyn_cast_or_null<DILocation>(Val: Node);
3542 if (!DL)
3543 return;
3544 if (!Seen.insert(Ptr: DL).second)
3545 return;
3546
3547 Metadata *Parent = DL->getRawScope();
3548 CheckDI(Parent && isa<DILocalScope>(Parent),
3549 "DILocation's scope must be a DILocalScope", N, &F, &I, DL, Parent);
3550
3551 DILocalScope *Scope = DL->getInlinedAtScope();
3552 Check(Scope, "Failed to find DILocalScope", DL);
3553
3554 if (!Seen.insert(Ptr: Scope).second)
3555 return;
3556
3557 // Cycles are diagnosed when the DIScope nodes themselves are visited.
3558 if (hasDIScopeCycle(S: Scope))
3559 return;
3560
3561 DISubprogram *SP = Scope->getSubprogram();
3562
3563 // Scope and SP could be the same MDNode and we don't want to skip
3564 // validation in that case
3565 if ((Scope != SP) && !Seen.insert(Ptr: SP).second)
3566 return;
3567
3568 CheckDI(SP->describes(&F),
3569 "!dbg attachment points at wrong subprogram for function", N, &F,
3570 &I, DL, Scope, SP);
3571 };
3572 for (auto &BB : F)
3573 for (auto &I : BB) {
3574 VisitDebugLoc(I, I.getDebugLoc().getAsMDNode());
3575 // The llvm.loop annotations also contain two DILocations.
3576 if (auto MD = I.getMetadata(KindID: LLVMContext::MD_loop))
3577 for (unsigned i = 1; i < MD->getNumOperands(); ++i)
3578 VisitDebugLoc(I, dyn_cast_or_null<MDNode>(Val: MD->getOperand(I: i)));
3579 if (BrokenDebugInfo)
3580 return;
3581 }
3582}
3583
3584// verifyBasicBlock - Verify that a basic block is well formed...
3585//
3586void Verifier::visitBasicBlock(BasicBlock &BB) {
3587 InstsInThisBlock.clear();
3588 ConvergenceVerifyHelper.visit(BB);
3589
3590 // Ensure that basic blocks have terminators!
3591 Check(BB.getTerminator(), "Basic Block does not have terminator!", &BB);
3592
3593 // Check constraints that this basic block imposes on all of the PHI nodes in
3594 // it.
3595 if (isa<PHINode>(Val: BB.front())) {
3596 SmallVector<BasicBlock *, 8> Preds(predecessors(BB: &BB));
3597 SmallVector<std::pair<BasicBlock*, Value*>, 8> Values;
3598 llvm::sort(C&: Preds);
3599 for (const PHINode &PN : BB.phis()) {
3600 Check(PN.getNumIncomingValues() == Preds.size(),
3601 "PHINode should have one entry for each predecessor of its "
3602 "parent basic block!",
3603 &PN);
3604
3605 // Get and sort all incoming values in the PHI node...
3606 Values.clear();
3607 Values.reserve(N: PN.getNumIncomingValues());
3608 for (unsigned i = 0, e = PN.getNumIncomingValues(); i != e; ++i)
3609 Values.push_back(
3610 Elt: std::make_pair(x: PN.getIncomingBlock(i), y: PN.getIncomingValue(i)));
3611 llvm::sort(C&: Values);
3612
3613 for (unsigned i = 0, e = Values.size(); i != e; ++i) {
3614 // Check to make sure that if there is more than one entry for a
3615 // particular basic block in this PHI node, that the incoming values are
3616 // all identical.
3617 //
3618 Check(i == 0 || Values[i].first != Values[i - 1].first ||
3619 Values[i].second == Values[i - 1].second,
3620 "PHI node has multiple entries for the same basic block with "
3621 "different incoming values!",
3622 &PN, Values[i].first, Values[i].second, Values[i - 1].second);
3623
3624 // Check to make sure that the predecessors and PHI node entries are
3625 // matched up.
3626 Check(Values[i].first == Preds[i],
3627 "PHI node entries do not match predecessors!", &PN,
3628 Values[i].first, Preds[i]);
3629 }
3630 }
3631 }
3632
3633 // Check that all instructions have their parent pointers set up correctly.
3634 for (auto &I : BB)
3635 {
3636 Check(I.getParent() == &BB, "Instruction has bogus parent pointer!");
3637 }
3638
3639 // Confirm that no issues arise from the debug program.
3640 CheckDI(!BB.getTrailingDbgRecords(), "Basic Block has trailing DbgRecords!",
3641 &BB);
3642}
3643
3644void Verifier::visitTerminator(Instruction &I) {
3645 // Ensure that terminators only exist at the end of the basic block.
3646 Check(&I == I.getParent()->getTerminator(),
3647 "Terminator found in the middle of a basic block!", I.getParent());
3648 visitInstruction(I);
3649}
3650
3651void Verifier::visitCondBrInst(CondBrInst &BI) {
3652 Check(BI.getCondition()->getType()->isIntegerTy(1),
3653 "Branch condition is not 'i1' type!", &BI, BI.getCondition());
3654 visitTerminator(I&: BI);
3655}
3656
3657void Verifier::visitReturnInst(ReturnInst &RI) {
3658 Function *F = RI.getParent()->getParent();
3659 unsigned N = RI.getNumOperands();
3660 if (F->getReturnType()->isVoidTy())
3661 Check(N == 0,
3662 "Found return instr that returns non-void in Function of void "
3663 "return type!",
3664 &RI, F->getReturnType());
3665 else
3666 Check(N == 1 && F->getReturnType() == RI.getOperand(0)->getType(),
3667 "Function return type does not match operand "
3668 "type of return inst!",
3669 &RI, F->getReturnType());
3670
3671 // Check to make sure that the return value has necessary properties for
3672 // terminators...
3673 visitTerminator(I&: RI);
3674}
3675
3676void Verifier::visitSwitchInst(SwitchInst &SI) {
3677 Check(SI.getType()->isVoidTy(), "Switch must have void result type!", &SI);
3678 // Check to make sure that all of the constants in the switch instruction
3679 // have the same type as the switched-on value.
3680 Type *SwitchTy = SI.getCondition()->getType();
3681 SmallPtrSet<ConstantInt*, 32> Constants;
3682 for (auto &Case : SI.cases()) {
3683 Check(isa<ConstantInt>(Case.getCaseValue()),
3684 "Case value is not a constant integer.", &SI);
3685 Check(Case.getCaseValue()->getType() == SwitchTy,
3686 "Switch constants must all be same type as switch value!", &SI);
3687 Check(Constants.insert(Case.getCaseValue()).second,
3688 "Duplicate integer as switch case", &SI, Case.getCaseValue());
3689 }
3690
3691 visitTerminator(I&: SI);
3692}
3693
3694void Verifier::visitIndirectBrInst(IndirectBrInst &BI) {
3695 Check(BI.getAddress()->getType()->isPointerTy(),
3696 "Indirectbr operand must have pointer type!", &BI);
3697 for (unsigned i = 0, e = BI.getNumDestinations(); i != e; ++i)
3698 Check(BI.getDestination(i)->getType()->isLabelTy(),
3699 "Indirectbr destinations must all have pointer type!", &BI);
3700
3701 visitTerminator(I&: BI);
3702}
3703
3704static bool isSupportedCallBrIntrinsic(Intrinsic::ID ID) {
3705 // Currently we only support callbr for amdgcn.kill. Add more checks here as
3706 // needed.
3707 return isAMDGPUCallBrIntrinsic(ID);
3708}
3709
3710void Verifier::visitCallBrInst(CallBrInst &CBI) {
3711 if (!CBI.isInlineAsm()) {
3712 Check(CBI.getCalledFunction(),
3713 "callbr: indirect function / invalid signature");
3714 Check(!CBI.hasOperandBundles(),
3715 "callbr for intrinsics currently doesn't support operand bundles");
3716
3717 if (!isSupportedCallBrIntrinsic(ID: CBI.getIntrinsicID())) {
3718 CheckFailed(
3719 Message: "callbr currently only supports asm-goto and selected intrinsics");
3720 }
3721 visitIntrinsicCall(ID: CBI.getIntrinsicID(), Call&: CBI);
3722 } else {
3723 const InlineAsm *IA = cast<InlineAsm>(Val: CBI.getCalledOperand());
3724 Check(!IA->canThrow(), "Unwinding from Callbr is not allowed");
3725
3726 verifyInlineAsmCall(Call: CBI);
3727 }
3728 visitTerminator(I&: CBI);
3729}
3730
3731void Verifier::visitSelectInst(SelectInst &SI) {
3732 Check(!SelectInst::areInvalidOperands(SI.getOperand(0), SI.getOperand(1),
3733 SI.getOperand(2)),
3734 "Invalid operands for select instruction!", &SI);
3735
3736 Check(SI.getTrueValue()->getType() == SI.getType(),
3737 "Select values must have same type as select instruction!", &SI);
3738 visitInstruction(I&: SI);
3739}
3740
3741/// visitUserOp1 - User defined operators shouldn't live beyond the lifetime of
3742/// a pass, if any exist, it's an error.
3743///
3744void Verifier::visitUserOp1(Instruction &I) {
3745 Check(false, "User-defined operators should not live outside of a pass!", &I);
3746}
3747
3748void Verifier::visitTruncInst(TruncInst &I) {
3749 // Get the source and destination types
3750 Type *SrcTy = I.getOperand(i_nocapture: 0)->getType();
3751 Type *DestTy = I.getType();
3752
3753 // Get the size of the types in bits, we'll need this later
3754 unsigned SrcBitSize = SrcTy->getScalarSizeInBits();
3755 unsigned DestBitSize = DestTy->getScalarSizeInBits();
3756
3757 Check(SrcTy->isIntOrIntVectorTy(), "Trunc only operates on integer", &I);
3758 Check(DestTy->isIntOrIntVectorTy(), "Trunc only produces integer", &I);
3759 Check(SrcTy->isVectorTy() == DestTy->isVectorTy(),
3760 "trunc source and destination must both be a vector or neither", &I);
3761 Check(SrcBitSize > DestBitSize, "DestTy too big for Trunc", &I);
3762
3763 visitInstruction(I);
3764}
3765
3766void Verifier::visitZExtInst(ZExtInst &I) {
3767 // Get the source and destination types
3768 Type *SrcTy = I.getOperand(i_nocapture: 0)->getType();
3769 Type *DestTy = I.getType();
3770
3771 // Get the size of the types in bits, we'll need this later
3772 Check(SrcTy->isIntOrIntVectorTy(), "ZExt only operates on integer", &I);
3773 Check(DestTy->isIntOrIntVectorTy(), "ZExt only produces an integer", &I);
3774 Check(SrcTy->isVectorTy() == DestTy->isVectorTy(),
3775 "zext source and destination must both be a vector or neither", &I);
3776 unsigned SrcBitSize = SrcTy->getScalarSizeInBits();
3777 unsigned DestBitSize = DestTy->getScalarSizeInBits();
3778
3779 Check(SrcBitSize < DestBitSize, "Type too small for ZExt", &I);
3780
3781 visitInstruction(I);
3782}
3783
3784void Verifier::visitSExtInst(SExtInst &I) {
3785 // Get the source and destination types
3786 Type *SrcTy = I.getOperand(i_nocapture: 0)->getType();
3787 Type *DestTy = I.getType();
3788
3789 // Get the size of the types in bits, we'll need this later
3790 unsigned SrcBitSize = SrcTy->getScalarSizeInBits();
3791 unsigned DestBitSize = DestTy->getScalarSizeInBits();
3792
3793 Check(SrcTy->isIntOrIntVectorTy(), "SExt only operates on integer", &I);
3794 Check(DestTy->isIntOrIntVectorTy(), "SExt only produces an integer", &I);
3795 Check(SrcTy->isVectorTy() == DestTy->isVectorTy(),
3796 "sext source and destination must both be a vector or neither", &I);
3797 Check(SrcBitSize < DestBitSize, "Type too small for SExt", &I);
3798
3799 visitInstruction(I);
3800}
3801
3802void Verifier::visitFPTruncInst(FPTruncInst &I) {
3803 // Get the source and destination types
3804 Type *SrcTy = I.getOperand(i_nocapture: 0)->getType();
3805 Type *DestTy = I.getType();
3806 // Get the size of the types in bits, we'll need this later
3807 unsigned SrcBitSize = SrcTy->getScalarSizeInBits();
3808 unsigned DestBitSize = DestTy->getScalarSizeInBits();
3809
3810 Check(SrcTy->isFPOrFPVectorTy(), "FPTrunc only operates on FP", &I);
3811 Check(DestTy->isFPOrFPVectorTy(), "FPTrunc only produces an FP", &I);
3812 Check(SrcTy->isVectorTy() == DestTy->isVectorTy(),
3813 "fptrunc source and destination must both be a vector or neither", &I);
3814 Check(SrcBitSize > DestBitSize, "DestTy too big for FPTrunc", &I);
3815
3816 visitInstruction(I);
3817}
3818
3819void Verifier::visitFPExtInst(FPExtInst &I) {
3820 // Get the source and destination types
3821 Type *SrcTy = I.getOperand(i_nocapture: 0)->getType();
3822 Type *DestTy = I.getType();
3823
3824 // Get the size of the types in bits, we'll need this later
3825 unsigned SrcBitSize = SrcTy->getScalarSizeInBits();
3826 unsigned DestBitSize = DestTy->getScalarSizeInBits();
3827
3828 Check(SrcTy->isFPOrFPVectorTy(), "FPExt only operates on FP", &I);
3829 Check(DestTy->isFPOrFPVectorTy(), "FPExt only produces an FP", &I);
3830 Check(SrcTy->isVectorTy() == DestTy->isVectorTy(),
3831 "fpext source and destination must both be a vector or neither", &I);
3832 Check(SrcBitSize < DestBitSize, "DestTy too small for FPExt", &I);
3833
3834 visitInstruction(I);
3835}
3836
3837void Verifier::visitUIToFPInst(UIToFPInst &I) {
3838 // Get the source and destination types
3839 Type *SrcTy = I.getOperand(i_nocapture: 0)->getType();
3840 Type *DestTy = I.getType();
3841
3842 bool SrcVec = SrcTy->isVectorTy();
3843 bool DstVec = DestTy->isVectorTy();
3844
3845 Check(SrcVec == DstVec,
3846 "UIToFP source and dest must both be vector or scalar", &I);
3847 Check(SrcTy->isIntOrIntVectorTy(),
3848 "UIToFP source must be integer or integer vector", &I);
3849 Check(DestTy->isFPOrFPVectorTy(), "UIToFP result must be FP or FP vector",
3850 &I);
3851
3852 if (SrcVec && DstVec)
3853 Check(cast<VectorType>(SrcTy)->getElementCount() ==
3854 cast<VectorType>(DestTy)->getElementCount(),
3855 "UIToFP source and dest vector length mismatch", &I);
3856
3857 visitInstruction(I);
3858}
3859
3860void Verifier::visitSIToFPInst(SIToFPInst &I) {
3861 // Get the source and destination types
3862 Type *SrcTy = I.getOperand(i_nocapture: 0)->getType();
3863 Type *DestTy = I.getType();
3864
3865 bool SrcVec = SrcTy->isVectorTy();
3866 bool DstVec = DestTy->isVectorTy();
3867
3868 Check(SrcVec == DstVec,
3869 "SIToFP source and dest must both be vector or scalar", &I);
3870 Check(SrcTy->isIntOrIntVectorTy(),
3871 "SIToFP source must be integer or integer vector", &I);
3872 Check(DestTy->isFPOrFPVectorTy(), "SIToFP result must be FP or FP vector",
3873 &I);
3874
3875 if (SrcVec && DstVec)
3876 Check(cast<VectorType>(SrcTy)->getElementCount() ==
3877 cast<VectorType>(DestTy)->getElementCount(),
3878 "SIToFP source and dest vector length mismatch", &I);
3879
3880 visitInstruction(I);
3881}
3882
3883void Verifier::visitFPToUIInst(FPToUIInst &I) {
3884 // Get the source and destination types
3885 Type *SrcTy = I.getOperand(i_nocapture: 0)->getType();
3886 Type *DestTy = I.getType();
3887
3888 bool SrcVec = SrcTy->isVectorTy();
3889 bool DstVec = DestTy->isVectorTy();
3890
3891 Check(SrcVec == DstVec,
3892 "FPToUI source and dest must both be vector or scalar", &I);
3893 Check(SrcTy->isFPOrFPVectorTy(), "FPToUI source must be FP or FP vector", &I);
3894 Check(DestTy->isIntOrIntVectorTy(),
3895 "FPToUI result must be integer or integer vector", &I);
3896
3897 if (SrcVec && DstVec)
3898 Check(cast<VectorType>(SrcTy)->getElementCount() ==
3899 cast<VectorType>(DestTy)->getElementCount(),
3900 "FPToUI source and dest vector length mismatch", &I);
3901
3902 visitInstruction(I);
3903}
3904
3905void Verifier::visitFPToSIInst(FPToSIInst &I) {
3906 // Get the source and destination types
3907 Type *SrcTy = I.getOperand(i_nocapture: 0)->getType();
3908 Type *DestTy = I.getType();
3909
3910 bool SrcVec = SrcTy->isVectorTy();
3911 bool DstVec = DestTy->isVectorTy();
3912
3913 Check(SrcVec == DstVec,
3914 "FPToSI source and dest must both be vector or scalar", &I);
3915 Check(SrcTy->isFPOrFPVectorTy(), "FPToSI source must be FP or FP vector", &I);
3916 Check(DestTy->isIntOrIntVectorTy(),
3917 "FPToSI result must be integer or integer vector", &I);
3918
3919 if (SrcVec && DstVec)
3920 Check(cast<VectorType>(SrcTy)->getElementCount() ==
3921 cast<VectorType>(DestTy)->getElementCount(),
3922 "FPToSI source and dest vector length mismatch", &I);
3923
3924 visitInstruction(I);
3925}
3926
3927void Verifier::checkPtrToAddr(Type *SrcTy, Type *DestTy, const Value &V) {
3928 Check(SrcTy->isPtrOrPtrVectorTy(), "PtrToAddr source must be pointer", V);
3929 Check(DestTy->isIntOrIntVectorTy(), "PtrToAddr result must be integral", V);
3930 Check(SrcTy->isVectorTy() == DestTy->isVectorTy(), "PtrToAddr type mismatch",
3931 V);
3932
3933 if (SrcTy->isVectorTy()) {
3934 auto *VSrc = cast<VectorType>(Val: SrcTy);
3935 auto *VDest = cast<VectorType>(Val: DestTy);
3936 Check(VSrc->getElementCount() == VDest->getElementCount(),
3937 "PtrToAddr vector length mismatch", V);
3938 }
3939
3940 Type *AddrTy = DL.getAddressType(PtrTy: SrcTy);
3941 Check(AddrTy == DestTy, "PtrToAddr result must be address width", V);
3942}
3943
3944void Verifier::visitPtrToAddrInst(PtrToAddrInst &I) {
3945 checkPtrToAddr(SrcTy: I.getOperand(i_nocapture: 0)->getType(), DestTy: I.getType(), V: I);
3946 visitInstruction(I);
3947}
3948
3949void Verifier::visitPtrToIntInst(PtrToIntInst &I) {
3950 // Get the source and destination types
3951 Type *SrcTy = I.getOperand(i_nocapture: 0)->getType();
3952 Type *DestTy = I.getType();
3953
3954 Check(SrcTy->isPtrOrPtrVectorTy(), "PtrToInt source must be pointer", &I);
3955
3956 Check(DestTy->isIntOrIntVectorTy(), "PtrToInt result must be integral", &I);
3957 Check(SrcTy->isVectorTy() == DestTy->isVectorTy(), "PtrToInt type mismatch",
3958 &I);
3959
3960 if (SrcTy->isVectorTy()) {
3961 auto *VSrc = cast<VectorType>(Val: SrcTy);
3962 auto *VDest = cast<VectorType>(Val: DestTy);
3963 Check(VSrc->getElementCount() == VDest->getElementCount(),
3964 "PtrToInt Vector length mismatch", &I);
3965 }
3966
3967 visitInstruction(I);
3968}
3969
3970void Verifier::visitIntToPtrInst(IntToPtrInst &I) {
3971 // Get the source and destination types
3972 Type *SrcTy = I.getOperand(i_nocapture: 0)->getType();
3973 Type *DestTy = I.getType();
3974
3975 Check(SrcTy->isIntOrIntVectorTy(), "IntToPtr source must be an integral", &I);
3976 Check(DestTy->isPtrOrPtrVectorTy(), "IntToPtr result must be a pointer", &I);
3977
3978 Check(SrcTy->isVectorTy() == DestTy->isVectorTy(), "IntToPtr type mismatch",
3979 &I);
3980 if (SrcTy->isVectorTy()) {
3981 auto *VSrc = cast<VectorType>(Val: SrcTy);
3982 auto *VDest = cast<VectorType>(Val: DestTy);
3983 Check(VSrc->getElementCount() == VDest->getElementCount(),
3984 "IntToPtr Vector length mismatch", &I);
3985 }
3986 visitInstruction(I);
3987}
3988
3989void Verifier::visitBitCastInst(BitCastInst &I) {
3990 Check(
3991 CastInst::castIsValid(Instruction::BitCast, I.getOperand(0), I.getType()),
3992 "Invalid bitcast", &I);
3993 visitInstruction(I);
3994}
3995
3996void Verifier::visitAddrSpaceCastInst(AddrSpaceCastInst &I) {
3997 Type *SrcTy = I.getOperand(i_nocapture: 0)->getType();
3998 Type *DestTy = I.getType();
3999
4000 Check(SrcTy->isPtrOrPtrVectorTy(), "AddrSpaceCast source must be a pointer",
4001 &I);
4002 Check(DestTy->isPtrOrPtrVectorTy(), "AddrSpaceCast result must be a pointer",
4003 &I);
4004 Check(SrcTy->getPointerAddressSpace() != DestTy->getPointerAddressSpace(),
4005 "AddrSpaceCast must be between different address spaces", &I);
4006 if (auto *SrcVTy = dyn_cast<VectorType>(Val: SrcTy))
4007 Check(SrcVTy->getElementCount() ==
4008 cast<VectorType>(DestTy)->getElementCount(),
4009 "AddrSpaceCast vector pointer number of elements mismatch", &I);
4010 visitInstruction(I);
4011}
4012
4013/// visitPHINode - Ensure that a PHI node is well formed.
4014///
4015void Verifier::visitPHINode(PHINode &PN) {
4016 // Ensure that the PHI nodes are all grouped together at the top of the block.
4017 // This can be tested by checking whether the instruction before this is
4018 // either nonexistent (because this is begin()) or is a PHI node. If not,
4019 // then there is some other instruction before a PHI.
4020 Check(&PN == &PN.getParent()->front() ||
4021 isa<PHINode>(--BasicBlock::iterator(&PN)),
4022 "PHI nodes not grouped at top of basic block!", &PN, PN.getParent());
4023
4024 // Check that a PHI doesn't yield a Token.
4025 Check(!PN.getType()->isTokenLikeTy(), "PHI nodes cannot have token type!");
4026
4027 // Check that all of the values of the PHI node have the same type as the
4028 // result.
4029 for (Value *IncValue : PN.incoming_values()) {
4030 Check(PN.getType() == IncValue->getType(),
4031 "PHI node operands are not the same type as the result!", &PN);
4032 }
4033
4034 // All other PHI node constraints are checked in the visitBasicBlock method.
4035
4036 visitInstruction(I&: PN);
4037}
4038
4039void Verifier::visitCallBase(CallBase &Call) {
4040 Check(Call.getCalledOperand()->getType()->isPointerTy(),
4041 "Called function must be a pointer!", Call);
4042 FunctionType *FTy = Call.getFunctionType();
4043
4044 // Verify that the correct number of arguments are being passed
4045 if (FTy->isVarArg())
4046 Check(Call.arg_size() >= FTy->getNumParams(),
4047 "Called function requires more parameters than were provided!", Call);
4048 else
4049 Check(Call.arg_size() == FTy->getNumParams(),
4050 "Incorrect number of arguments passed to called function!", Call);
4051
4052 // Verify that all arguments to the call match the function type.
4053 for (unsigned i = 0, e = FTy->getNumParams(); i != e; ++i)
4054 Check(Call.getArgOperand(i)->getType() == FTy->getParamType(i),
4055 "Call parameter type does not match function signature!",
4056 Call.getArgOperand(i), FTy->getParamType(i), Call);
4057
4058 AttributeList Attrs = Call.getAttributes();
4059
4060 Check(verifyAttributeCount(Attrs, Call.arg_size()),
4061 "Attribute after last parameter!", Call);
4062
4063 auto *Callee =
4064 dyn_cast<Function>(Val: Call.getCalledOperand()->stripPointerCasts());
4065 bool IsIntrinsic = Callee && Callee->isIntrinsic();
4066 if (IsIntrinsic)
4067 Check(Callee->getFunctionType() == FTy,
4068 "Intrinsic called with incompatible signature", Call);
4069
4070 // Verify if the calling convention of the callee is callable.
4071 Check(isCallableCC(Call.getCallingConv()),
4072 "calling convention does not permit calls", Call);
4073
4074 // Disallow passing/returning values with alignment higher than we can
4075 // represent.
4076 // FIXME: Consider making DataLayout cap the alignment, so this isn't
4077 // necessary.
4078 auto VerifyTypeAlign = [&](Type *Ty, const Twine &Message) {
4079 if (!Ty->isSized())
4080 return;
4081 Align ABIAlign = DL.getABITypeAlign(Ty);
4082 Check(ABIAlign.value() <= Value::MaximumAlignment,
4083 "Incorrect alignment of " + Message + " to called function!", Call);
4084 };
4085
4086 if (!IsIntrinsic) {
4087 VerifyTypeAlign(FTy->getReturnType(), "return type");
4088 for (unsigned i = 0, e = FTy->getNumParams(); i != e; ++i) {
4089 Type *Ty = FTy->getParamType(i);
4090 VerifyTypeAlign(Ty, "argument passed");
4091 }
4092 }
4093
4094 if (Attrs.hasFnAttr(Kind: Attribute::Speculatable)) {
4095 // Don't allow speculatable on call sites, unless the underlying function
4096 // declaration is also speculatable.
4097 Check(Callee && Callee->isSpeculatable(),
4098 "speculatable attribute may not apply to call sites", Call);
4099 }
4100
4101 if (Attrs.hasFnAttr(Kind: Attribute::Preallocated)) {
4102 Check(Call.getIntrinsicID() == Intrinsic::call_preallocated_arg,
4103 "preallocated as a call site attribute can only be on "
4104 "llvm.call.preallocated.arg");
4105 }
4106
4107 Check(!Attrs.hasFnAttr(Attribute::DenormalFPEnv),
4108 "denormal_fpenv attribute may not apply to call sites", Call);
4109
4110 // Verify call attributes.
4111 verifyFunctionAttrs(FT: FTy, Attrs, V: &Call, IsIntrinsic, IsInlineAsm: Call.isInlineAsm());
4112
4113 // Conservatively check the inalloca argument.
4114 // We have a bug if we can find that there is an underlying alloca without
4115 // inalloca.
4116 if (Call.hasInAllocaArgument()) {
4117 Value *InAllocaArg = Call.getArgOperand(i: FTy->getNumParams() - 1);
4118 if (auto AI = dyn_cast<AllocaInst>(Val: InAllocaArg->stripInBoundsOffsets()))
4119 Check(AI->isUsedWithInAlloca(),
4120 "inalloca argument for call has mismatched alloca", AI, Call);
4121 }
4122
4123 // For each argument of the callsite, if it has the swifterror argument,
4124 // make sure the underlying alloca/parameter it comes from has a swifterror as
4125 // well.
4126 for (unsigned i = 0, e = FTy->getNumParams(); i != e; ++i) {
4127 if (Call.paramHasAttr(ArgNo: i, Kind: Attribute::SwiftError)) {
4128 Value *SwiftErrorArg = Call.getArgOperand(i);
4129 if (auto AI = dyn_cast<AllocaInst>(Val: SwiftErrorArg->stripInBoundsOffsets())) {
4130 Check(AI->isSwiftError(),
4131 "swifterror argument for call has mismatched alloca", AI, Call);
4132 continue;
4133 }
4134 auto ArgI = dyn_cast<Argument>(Val: SwiftErrorArg);
4135 Check(ArgI, "swifterror argument should come from an alloca or parameter",
4136 SwiftErrorArg, Call);
4137 Check(ArgI->hasSwiftErrorAttr(),
4138 "swifterror argument for call has mismatched parameter", ArgI,
4139 Call);
4140 }
4141
4142 if (Attrs.hasParamAttr(ArgNo: i, Kind: Attribute::ImmArg)) {
4143 // Don't allow immarg on call sites, unless the underlying declaration
4144 // also has the matching immarg.
4145 Check(Callee && Callee->hasParamAttribute(i, Attribute::ImmArg),
4146 "immarg may not apply only to call sites", Call.getArgOperand(i),
4147 Call);
4148 }
4149
4150 if (Call.paramHasAttr(ArgNo: i, Kind: Attribute::ImmArg)) {
4151 Value *ArgVal = Call.getArgOperand(i);
4152 Check((isa<ConstantInt>(ArgVal) || isa<ConstantFP>(ArgVal)) &&
4153 !isa<VectorType>(ArgVal->getType()),
4154 "immarg operand has non-immediate parameter", ArgVal, Call);
4155
4156 // If the imm-arg is an integer and also has a range attached,
4157 // check if the given value is within the range.
4158 if (Call.paramHasAttr(ArgNo: i, Kind: Attribute::Range)) {
4159 if (auto *CI = dyn_cast<ConstantInt>(Val: ArgVal)) {
4160 const ConstantRange &CR =
4161 Call.getParamAttr(ArgNo: i, Kind: Attribute::Range).getValueAsConstantRange();
4162 Check(CR.contains(CI->getValue()),
4163 formatv("immarg value {} for arg {} out of range {}",
4164 CI->getValue(), i, CR),
4165 Call);
4166 }
4167 }
4168 if (auto *CI = dyn_cast<ConstantInt>(Val: ArgVal))
4169 Check(Intrinsic::isImmArgValueInRangeSet(Call.getIntrinsicID(), i,
4170 CI->getValue()),
4171 formatv("immarg value {} for arg {} out of range set",
4172 CI->getValue(), i),
4173 Call);
4174 }
4175
4176 if (Call.paramHasAttr(ArgNo: i, Kind: Attribute::Preallocated)) {
4177 Value *ArgVal = Call.getArgOperand(i);
4178 bool hasOB =
4179 Call.countOperandBundlesOfType(ID: LLVMContext::OB_preallocated) != 0;
4180 bool isMustTail = Call.isMustTailCall();
4181 Check(hasOB != isMustTail,
4182 "preallocated operand either requires a preallocated bundle or "
4183 "the call to be musttail (but not both)",
4184 ArgVal, Call);
4185 }
4186 }
4187
4188 if (FTy->isVarArg()) {
4189 // FIXME? is 'nest' even legal here?
4190 bool SawNest = false;
4191 bool SawReturned = false;
4192
4193 for (unsigned Idx = 0; Idx < FTy->getNumParams(); ++Idx) {
4194 if (Attrs.hasParamAttr(ArgNo: Idx, Kind: Attribute::Nest))
4195 SawNest = true;
4196 if (Attrs.hasParamAttr(ArgNo: Idx, Kind: Attribute::Returned))
4197 SawReturned = true;
4198 }
4199
4200 // Check attributes on the varargs part.
4201 for (unsigned Idx = FTy->getNumParams(); Idx < Call.arg_size(); ++Idx) {
4202 Type *Ty = Call.getArgOperand(i: Idx)->getType();
4203 AttributeSet ArgAttrs = Attrs.getParamAttrs(ArgNo: Idx);
4204 verifyParameterAttrs(Attrs: ArgAttrs, Ty, V: &Call);
4205
4206 if (ArgAttrs.hasAttribute(Kind: Attribute::Nest)) {
4207 Check(!SawNest, "More than one parameter has attribute nest!", Call);
4208 SawNest = true;
4209 }
4210
4211 if (ArgAttrs.hasAttribute(Kind: Attribute::Returned)) {
4212 Check(!SawReturned, "More than one parameter has attribute returned!",
4213 Call);
4214 Check(Ty->canLosslesslyBitCastTo(FTy->getReturnType()),
4215 "Incompatible argument and return types for 'returned' "
4216 "attribute",
4217 Call);
4218 SawReturned = true;
4219 }
4220
4221 // Statepoint intrinsic is vararg but the wrapped function may be not.
4222 // Allow sret here and check the wrapped function in verifyStatepoint.
4223 if (Call.getIntrinsicID() != Intrinsic::experimental_gc_statepoint)
4224 Check(!ArgAttrs.hasAttribute(Attribute::StructRet),
4225 "Attribute 'sret' cannot be used for vararg call arguments!",
4226 Call);
4227
4228 if (ArgAttrs.hasAttribute(Kind: Attribute::InAlloca))
4229 Check(Idx == Call.arg_size() - 1,
4230 "inalloca isn't on the last argument!", Call);
4231 }
4232 }
4233
4234 // Verify that there's no metadata unless it's a direct call to an intrinsic.
4235 if (!IsIntrinsic) {
4236 for (Type *ParamTy : FTy->params()) {
4237 Check(!ParamTy->isMetadataTy(),
4238 "Function has metadata parameter but isn't an intrinsic", Call);
4239 Check(!ParamTy->isTokenLikeTy(),
4240 "Function has token parameter but isn't an intrinsic", Call);
4241 }
4242 }
4243
4244 // Verify that indirect calls don't return tokens.
4245 if (!Call.getCalledFunction()) {
4246 Check(!FTy->getReturnType()->isTokenLikeTy(),
4247 "Return type cannot be token for indirect call!");
4248 Check(!FTy->getReturnType()->isX86_AMXTy(),
4249 "Return type cannot be x86_amx for indirect call!");
4250 }
4251
4252 if (Intrinsic::ID ID = Call.getIntrinsicID())
4253 visitIntrinsicCall(ID, Call);
4254
4255 // Verify that a callsite has at most one "deopt", at most one "funclet", at
4256 // most one "gc-transition", at most one "cfguardtarget", at most one
4257 // "preallocated" operand bundle, and at most one "ptrauth" operand bundle.
4258 bool FoundDeoptBundle = false, FoundFuncletBundle = false,
4259 FoundGCTransitionBundle = false, FoundCFGuardTargetBundle = false,
4260 FoundPreallocatedBundle = false, FoundGCLiveBundle = false,
4261 FoundPtrauthBundle = false, FoundKCFIBundle = false,
4262 FoundAttachedCallBundle = false;
4263 for (unsigned i = 0, e = Call.getNumOperandBundles(); i < e; ++i) {
4264 OperandBundleUse BU = Call.getOperandBundleAt(Index: i);
4265 for (const Value *Input : BU.Inputs)
4266 Check(!Input->getType()->isLabelTy(),
4267 "Operand bundle operands cannot be labels", Call);
4268 uint32_t Tag = BU.getTagID();
4269 if (Tag == LLVMContext::OB_deopt) {
4270 Check(!FoundDeoptBundle, "Multiple deopt operand bundles", Call);
4271 FoundDeoptBundle = true;
4272 } else if (Tag == LLVMContext::OB_gc_transition) {
4273 Check(!FoundGCTransitionBundle, "Multiple gc-transition operand bundles",
4274 Call);
4275 FoundGCTransitionBundle = true;
4276 } else if (Tag == LLVMContext::OB_funclet) {
4277 Check(!FoundFuncletBundle, "Multiple funclet operand bundles", Call);
4278 FoundFuncletBundle = true;
4279 Check(BU.Inputs.size() == 1,
4280 "Expected exactly one funclet bundle operand", Call);
4281 Check(isa<FuncletPadInst>(BU.Inputs.front()),
4282 "Funclet bundle operands should correspond to a FuncletPadInst",
4283 Call);
4284 } else if (Tag == LLVMContext::OB_cfguardtarget) {
4285 Check(!FoundCFGuardTargetBundle, "Multiple CFGuardTarget operand bundles",
4286 Call);
4287 FoundCFGuardTargetBundle = true;
4288 Check(BU.Inputs.size() == 1,
4289 "Expected exactly one cfguardtarget bundle operand", Call);
4290 } else if (Tag == LLVMContext::OB_ptrauth) {
4291 Check(!FoundPtrauthBundle, "Multiple ptrauth operand bundles", Call);
4292 FoundPtrauthBundle = true;
4293 Check(BU.Inputs.size() == 2,
4294 "Expected exactly two ptrauth bundle operands", Call);
4295 Check(isa<ConstantInt>(BU.Inputs[0]) &&
4296 BU.Inputs[0]->getType()->isIntegerTy(32),
4297 "Ptrauth bundle key operand must be an i32 constant", Call);
4298 Check(BU.Inputs[1]->getType()->isIntegerTy(64),
4299 "Ptrauth bundle discriminator operand must be an i64", Call);
4300 } else if (Tag == LLVMContext::OB_kcfi) {
4301 Check(!FoundKCFIBundle, "Multiple kcfi operand bundles", Call);
4302 FoundKCFIBundle = true;
4303 Check(BU.Inputs.size() == 1, "Expected exactly one kcfi bundle operand",
4304 Call);
4305 Check(isa<ConstantInt>(BU.Inputs[0]) &&
4306 BU.Inputs[0]->getType()->isIntegerTy(32),
4307 "Kcfi bundle operand must be an i32 constant", Call);
4308 } else if (Tag == LLVMContext::OB_preallocated) {
4309 Check(!FoundPreallocatedBundle, "Multiple preallocated operand bundles",
4310 Call);
4311 FoundPreallocatedBundle = true;
4312 Check(BU.Inputs.size() == 1,
4313 "Expected exactly one preallocated bundle operand", Call);
4314 auto Input = dyn_cast<IntrinsicInst>(Val: BU.Inputs.front());
4315 Check(Input &&
4316 Input->getIntrinsicID() == Intrinsic::call_preallocated_setup,
4317 "\"preallocated\" argument must be a token from "
4318 "llvm.call.preallocated.setup",
4319 Call);
4320 } else if (Tag == LLVMContext::OB_gc_live) {
4321 Check(!FoundGCLiveBundle, "Multiple gc-live operand bundles", Call);
4322 FoundGCLiveBundle = true;
4323 } else if (Tag == LLVMContext::OB_clang_arc_attachedcall) {
4324 Check(!FoundAttachedCallBundle,
4325 "Multiple \"clang.arc.attachedcall\" operand bundles", Call);
4326 FoundAttachedCallBundle = true;
4327 verifyAttachedCallBundle(Call, BU);
4328 }
4329 }
4330
4331 // Verify that callee and callsite agree on whether to use pointer auth.
4332 Check(!(Call.getCalledFunction() && FoundPtrauthBundle),
4333 "Direct call cannot have a ptrauth bundle", Call);
4334
4335 // Verify that each inlinable callsite of a debug-info-bearing function in a
4336 // debug-info-bearing function has a debug location attached to it. Failure to
4337 // do so causes assertion failures when the inliner sets up inline scope info
4338 // (Interposable functions are not inlinable, neither are functions without
4339 // definitions. noipa does not prevent inlining, so it is ignored here.)
4340 if (Call.getFunction()->getSubprogram() && Call.getCalledFunction() &&
4341 !Call.getCalledFunction()->isInterposable(/*CheckNoIPA=*/false) &&
4342 !Call.getCalledFunction()->isDeclaration() &&
4343 Call.getCalledFunction()->getSubprogram())
4344 CheckDI(Call.getDebugLoc(),
4345 "inlinable function call in a function with "
4346 "debug info must have a !dbg location",
4347 Call);
4348
4349 if (Call.isInlineAsm())
4350 verifyInlineAsmCall(Call);
4351
4352 ConvergenceVerifyHelper.visit(I: Call);
4353
4354 visitInstruction(I&: Call);
4355}
4356
4357void Verifier::verifyTailCCMustTailAttrs(const AttrBuilder &Attrs,
4358 StringRef Context) {
4359 Check(!Attrs.contains(Attribute::InAlloca),
4360 Twine("inalloca attribute not allowed in ") + Context);
4361 Check(!Attrs.contains(Attribute::InReg),
4362 Twine("inreg attribute not allowed in ") + Context);
4363 Check(!Attrs.contains(Attribute::SwiftError),
4364 Twine("swifterror attribute not allowed in ") + Context);
4365 Check(!Attrs.contains(Attribute::Preallocated),
4366 Twine("preallocated attribute not allowed in ") + Context);
4367 Check(!Attrs.contains(Attribute::ByRef),
4368 Twine("byref attribute not allowed in ") + Context);
4369}
4370
4371static AttrBuilder getParameterABIAttributes(LLVMContext& C, unsigned I, AttributeList Attrs) {
4372 static const Attribute::AttrKind ABIAttrs[] = {
4373 Attribute::StructRet, Attribute::ByVal, Attribute::InAlloca,
4374 Attribute::InReg, Attribute::StackAlignment, Attribute::SwiftSelf,
4375 Attribute::SwiftAsync, Attribute::SwiftError, Attribute::Preallocated,
4376 Attribute::ByRef};
4377 AttrBuilder Copy(C);
4378 for (auto AK : ABIAttrs) {
4379 Attribute Attr = Attrs.getParamAttrs(ArgNo: I).getAttribute(Kind: AK);
4380 if (Attr.isValid())
4381 Copy.addAttribute(A: Attr);
4382 }
4383
4384 // `align` is ABI-affecting only in combination with `byval` or `byref`.
4385 if (Attrs.hasParamAttr(ArgNo: I, Kind: Attribute::Alignment) &&
4386 (Attrs.hasParamAttr(ArgNo: I, Kind: Attribute::ByVal) ||
4387 Attrs.hasParamAttr(ArgNo: I, Kind: Attribute::ByRef)))
4388 Copy.addAlignmentAttr(Align: Attrs.getParamAlignment(ArgNo: I));
4389 return Copy;
4390}
4391
4392void Verifier::verifyMustTailCall(CallInst &CI) {
4393 Check(!CI.isInlineAsm(), "cannot use musttail call with inline asm", &CI);
4394
4395 Function *F = CI.getParent()->getParent();
4396 FunctionType *CallerTy = F->getFunctionType();
4397 FunctionType *CalleeTy = CI.getFunctionType();
4398 Check(CallerTy->isVarArg() == CalleeTy->isVarArg(),
4399 "cannot guarantee tail call due to mismatched varargs", &CI);
4400 Check(CallerTy->getReturnType() == CalleeTy->getReturnType(),
4401 "cannot guarantee tail call due to mismatched return types", &CI);
4402
4403 // - The calling conventions of the caller and callee must match.
4404 Check(F->getCallingConv() == CI.getCallingConv(),
4405 "cannot guarantee tail call due to mismatched calling conv", &CI);
4406
4407 // - The call must immediately precede a :ref:`ret <i_ret>` instruction.
4408 // - The ret instruction must return the value produced by the call or void.
4409 Instruction *Next = CI.getNextNode();
4410
4411 // Check the return.
4412 ReturnInst *Ret = dyn_cast_or_null<ReturnInst>(Val: Next);
4413 Check(Ret, "musttail call must precede a ret", &CI);
4414 Check(!Ret->getReturnValue() || Ret->getReturnValue() == &CI ||
4415 isa<UndefValue>(Ret->getReturnValue()),
4416 "musttail call result must be returned", Ret);
4417
4418 AttributeList CallerAttrs = F->getAttributes();
4419 AttributeList CalleeAttrs = CI.getAttributes();
4420 if (CI.getCallingConv() == CallingConv::SwiftTail ||
4421 CI.getCallingConv() == CallingConv::Tail) {
4422 StringRef CCName =
4423 CI.getCallingConv() == CallingConv::Tail ? "tailcc" : "swifttailcc";
4424
4425 // - Only sret, byval, swiftself, and swiftasync ABI-impacting attributes
4426 // are allowed in swifttailcc call
4427 for (unsigned I = 0, E = CallerTy->getNumParams(); I != E; ++I) {
4428 AttrBuilder ABIAttrs = getParameterABIAttributes(C&: F->getContext(), I, Attrs: CallerAttrs);
4429 SmallString<32> Context{CCName, StringRef(" musttail caller")};
4430 verifyTailCCMustTailAttrs(Attrs: ABIAttrs, Context);
4431 }
4432 for (unsigned I = 0, E = CalleeTy->getNumParams(); I != E; ++I) {
4433 AttrBuilder ABIAttrs = getParameterABIAttributes(C&: F->getContext(), I, Attrs: CalleeAttrs);
4434 SmallString<32> Context{CCName, StringRef(" musttail callee")};
4435 verifyTailCCMustTailAttrs(Attrs: ABIAttrs, Context);
4436 }
4437 // - Varargs functions are not allowed
4438 Check(!CallerTy->isVarArg(), Twine("cannot guarantee ") + CCName +
4439 " tail call for varargs function");
4440 return;
4441 }
4442
4443 // - The caller and callee prototypes must match.
4444 if (!CI.getIntrinsicID()) {
4445 Check(CallerTy->getNumParams() == CalleeTy->getNumParams(),
4446 "cannot guarantee tail call due to mismatched parameter counts", &CI);
4447 for (unsigned I = 0, E = CallerTy->getNumParams(); I != E; ++I) {
4448 Check(CallerTy->getParamType(I) == CalleeTy->getParamType(I),
4449 "cannot guarantee tail call due to mismatched parameter types",
4450 &CI);
4451 }
4452 }
4453
4454 // - All ABI-impacting function attributes, such as sret, byval, inreg,
4455 // returned, preallocated, and inalloca, must match.
4456 for (unsigned I = 0, E = CallerTy->getNumParams(); I != E; ++I) {
4457 AttrBuilder CallerABIAttrs = getParameterABIAttributes(C&: F->getContext(), I, Attrs: CallerAttrs);
4458 AttrBuilder CalleeABIAttrs = getParameterABIAttributes(C&: F->getContext(), I, Attrs: CalleeAttrs);
4459 Check(CallerABIAttrs == CalleeABIAttrs,
4460 "cannot guarantee tail call due to mismatched ABI impacting "
4461 "function attributes",
4462 &CI, CI.getOperand(I));
4463 }
4464}
4465
4466void Verifier::visitCallInst(CallInst &CI) {
4467 visitCallBase(Call&: CI);
4468
4469 if (CI.isMustTailCall())
4470 verifyMustTailCall(CI);
4471}
4472
4473void Verifier::visitInvokeInst(InvokeInst &II) {
4474 visitCallBase(Call&: II);
4475
4476 // Verify that the first non-PHI instruction of the unwind destination is an
4477 // exception handling instruction.
4478 Check(
4479 II.getUnwindDest()->isEHPad(),
4480 "The unwind destination does not have an exception handling instruction!",
4481 &II);
4482
4483 visitTerminator(I&: II);
4484}
4485
4486/// visitUnaryOperator - Check the argument to the unary operator.
4487///
4488void Verifier::visitUnaryOperator(UnaryOperator &U) {
4489 Check(U.getType() == U.getOperand(0)->getType(),
4490 "Unary operators must have same type for"
4491 "operands and result!",
4492 &U);
4493
4494 switch (U.getOpcode()) {
4495 // Check that floating-point arithmetic operators are only used with
4496 // floating-point operands.
4497 case Instruction::FNeg:
4498 Check(U.getType()->isFPOrFPVectorTy(),
4499 "FNeg operator only works with float types!", &U);
4500 break;
4501 default:
4502 llvm_unreachable("Unknown UnaryOperator opcode!");
4503 }
4504
4505 visitInstruction(I&: U);
4506}
4507
4508/// visitBinaryOperator - Check that both arguments to the binary operator are
4509/// of the same type!
4510///
4511void Verifier::visitBinaryOperator(BinaryOperator &B) {
4512 Check(B.getOperand(0)->getType() == B.getOperand(1)->getType(),
4513 "Both operands to a binary operator are not of the same type!", &B);
4514
4515 switch (B.getOpcode()) {
4516 // Check that integer arithmetic operators are only used with
4517 // integral operands.
4518 case Instruction::Add:
4519 case Instruction::Sub:
4520 case Instruction::Mul:
4521 case Instruction::SDiv:
4522 case Instruction::UDiv:
4523 case Instruction::SRem:
4524 case Instruction::URem:
4525 Check(B.getType()->isIntOrIntVectorTy(),
4526 "Integer arithmetic operators only work with integral types!", &B);
4527 Check(B.getType() == B.getOperand(0)->getType(),
4528 "Integer arithmetic operators must have same type "
4529 "for operands and result!",
4530 &B);
4531 break;
4532 // Check that floating-point arithmetic operators are only used with
4533 // floating-point operands.
4534 case Instruction::FAdd:
4535 case Instruction::FSub:
4536 case Instruction::FMul:
4537 case Instruction::FDiv:
4538 case Instruction::FRem:
4539 Check(B.getType()->isFPOrFPVectorTy(),
4540 "Floating-point arithmetic operators only work with "
4541 "floating-point types!",
4542 &B);
4543 Check(B.getType() == B.getOperand(0)->getType(),
4544 "Floating-point arithmetic operators must have same type "
4545 "for operands and result!",
4546 &B);
4547 break;
4548 // Check that logical operators are only used with integral operands.
4549 case Instruction::And:
4550 case Instruction::Or:
4551 case Instruction::Xor:
4552 Check(B.getType()->isIntOrIntVectorTy(),
4553 "Logical operators only work with integral types!", &B);
4554 Check(B.getType() == B.getOperand(0)->getType(),
4555 "Logical operators must have same type for operands and result!", &B);
4556 break;
4557 case Instruction::Shl:
4558 case Instruction::LShr:
4559 case Instruction::AShr:
4560 Check(B.getType()->isIntOrIntVectorTy(),
4561 "Shifts only work with integral types!", &B);
4562 Check(B.getType() == B.getOperand(0)->getType(),
4563 "Shift return type must be same as operands!", &B);
4564 break;
4565 default:
4566 llvm_unreachable("Unknown BinaryOperator opcode!");
4567 }
4568
4569 visitInstruction(I&: B);
4570}
4571
4572void Verifier::visitICmpInst(ICmpInst &IC) {
4573 // Check that the operands are the same type
4574 Type *Op0Ty = IC.getOperand(i_nocapture: 0)->getType();
4575 Type *Op1Ty = IC.getOperand(i_nocapture: 1)->getType();
4576 Check(Op0Ty == Op1Ty,
4577 "Both operands to ICmp instruction are not of the same type!", &IC);
4578 // Check that the operands are the right type
4579 Check(Op0Ty->isIntOrIntVectorTy() || Op0Ty->isPtrOrPtrVectorTy(),
4580 "Invalid operand types for ICmp instruction", &IC);
4581 // Check that the predicate is valid.
4582 Check(IC.isIntPredicate(), "Invalid predicate in ICmp instruction!", &IC);
4583
4584 visitInstruction(I&: IC);
4585}
4586
4587void Verifier::visitFCmpInst(FCmpInst &FC) {
4588 // Check that the operands are the same type
4589 Type *Op0Ty = FC.getOperand(i_nocapture: 0)->getType();
4590 Type *Op1Ty = FC.getOperand(i_nocapture: 1)->getType();
4591 Check(Op0Ty == Op1Ty,
4592 "Both operands to FCmp instruction are not of the same type!", &FC);
4593 // Check that the operands are the right type
4594 Check(Op0Ty->isFPOrFPVectorTy(), "Invalid operand types for FCmp instruction",
4595 &FC);
4596 // Check that the predicate is valid.
4597 Check(FC.isFPPredicate(), "Invalid predicate in FCmp instruction!", &FC);
4598
4599 visitInstruction(I&: FC);
4600}
4601
4602void Verifier::visitExtractElementInst(ExtractElementInst &EI) {
4603 Check(ExtractElementInst::isValidOperands(EI.getOperand(0), EI.getOperand(1)),
4604 "Invalid extractelement operands!", &EI);
4605 visitInstruction(I&: EI);
4606}
4607
4608void Verifier::visitInsertElementInst(InsertElementInst &IE) {
4609 Check(InsertElementInst::isValidOperands(IE.getOperand(0), IE.getOperand(1),
4610 IE.getOperand(2)),
4611 "Invalid insertelement operands!", &IE);
4612 visitInstruction(I&: IE);
4613}
4614
4615void Verifier::visitShuffleVectorInst(ShuffleVectorInst &SV) {
4616 Check(ShuffleVectorInst::isValidOperands(SV.getOperand(0), SV.getOperand(1),
4617 SV.getShuffleMask()),
4618 "Invalid shufflevector operands!", &SV);
4619 visitInstruction(I&: SV);
4620}
4621
4622void Verifier::visitBitInsertInst(BitInsertInst &BII) {
4623 if (const char *Reason = BitInsertInst::areInvalidOperands(
4624 Base: BII.getOperand(i_nocapture: 0), Val: BII.getOperand(i_nocapture: 1), Offset: BII.getOperand(i_nocapture: 2)))
4625 Check(false, Reason, &BII);
4626 Check(DL.getTypeSizeInBits(BII.getOperand(0)->getType()) >=
4627 DL.getTypeSizeInBits(BII.getOperand(1)->getType()),
4628 "bitinsert val type cannot be wider than base type!", &BII);
4629 visitInstruction(I&: BII);
4630}
4631
4632void Verifier::visitBitExtractInst(BitExtractInst &BEI) {
4633 if (const char *Reason = BitExtractInst::areInvalidOperands(
4634 Ty: BEI.getType(), Val: BEI.getOperand(i_nocapture: 0), Offset: BEI.getOperand(i_nocapture: 1)))
4635 Check(false, Reason, &BEI);
4636 Check(DL.getTypeSizeInBits(BEI.getType()) <=
4637 DL.getTypeSizeInBits(BEI.getOperand(0)->getType()),
4638 "bitextract result type cannot be wider than source type!", &BEI);
4639 visitInstruction(I&: BEI);
4640}
4641
4642void Verifier::visitGetElementPtrInst(GetElementPtrInst &GEP) {
4643 if (auto *MD = mdconst::extract_or_null<ConstantInt>(
4644 MD: GEP.getModule()->getModuleFlag(Key: "require-logical-pointer")))
4645 Check(!MD->getZExtValue(),
4646 "Non-logical getelementptr disallowed for this module.");
4647
4648 Type *TargetTy = GEP.getPointerOperandType()->getScalarType();
4649
4650 Check(isa<PointerType>(TargetTy),
4651 "GEP base pointer is not a vector or a vector of pointers", &GEP);
4652 Check(GEP.getSourceElementType()->isSized(), "GEP into unsized type!", &GEP);
4653
4654 if (auto *STy = dyn_cast<StructType>(Val: GEP.getSourceElementType())) {
4655 Check(!STy->isScalableTy(),
4656 "getelementptr cannot target structure that contains scalable vector"
4657 "type",
4658 &GEP);
4659 }
4660
4661 SmallVector<Value *, 16> Idxs(GEP.indices());
4662 Check(
4663 all_of(Idxs, [](Value *V) { return V->getType()->isIntOrIntVectorTy(); }),
4664 "GEP indexes must be integers", &GEP);
4665 Type *ElTy =
4666 GetElementPtrInst::getIndexedType(Ty: GEP.getSourceElementType(), IdxList: Idxs);
4667 Check(ElTy, "Invalid indices for GEP pointer type!", &GEP);
4668
4669 auto *PtrTy = dyn_cast<PointerType>(Val: GEP.getType()->getScalarType());
4670
4671 Check(PtrTy && GEP.getResultElementType() == ElTy,
4672 "GEP is not of right type for indices!", &GEP, ElTy);
4673
4674 if (auto *GEPVTy = dyn_cast<VectorType>(Val: GEP.getType())) {
4675 // Additional checks for vector GEPs.
4676 ElementCount GEPWidth = GEPVTy->getElementCount();
4677 if (GEP.getPointerOperandType()->isVectorTy())
4678 Check(
4679 GEPWidth ==
4680 cast<VectorType>(GEP.getPointerOperandType())->getElementCount(),
4681 "Vector GEP result width doesn't match operand's", &GEP);
4682 for (Value *Idx : Idxs) {
4683 Type *IndexTy = Idx->getType();
4684 if (auto *IndexVTy = dyn_cast<VectorType>(Val: IndexTy)) {
4685 ElementCount IndexWidth = IndexVTy->getElementCount();
4686 Check(IndexWidth == GEPWidth, "Invalid GEP index vector width", &GEP);
4687 }
4688 Check(IndexTy->isIntOrIntVectorTy(),
4689 "All GEP indices should be of integer type");
4690 }
4691 }
4692
4693 // Check that GEP does not index into a vector with non-byte-addressable
4694 // elements.
4695 for (gep_type_iterator GTI = gep_type_begin(GEP), GTE = gep_type_end(GEP);
4696 GTI != GTE; ++GTI) {
4697 if (GTI.isVector()) {
4698 Type *ElemTy = GTI.getIndexedType();
4699 Check(DL.typeSizeEqualsStoreSize(ElemTy),
4700 "GEP into vector with non-byte-addressable element type", &GEP);
4701 }
4702 }
4703
4704 Check(GEP.getAddressSpace() == PtrTy->getAddressSpace(),
4705 "GEP address space doesn't match type", &GEP);
4706
4707 visitInstruction(I&: GEP);
4708}
4709
4710static bool isContiguous(const ConstantRange &A, const ConstantRange &B) {
4711 return A.getUpper() == B.getLower() || A.getLower() == B.getUpper();
4712}
4713
4714/// Verify !range and !absolute_symbol metadata. These have the same
4715/// restrictions, except !absolute_symbol allows the full set.
4716void Verifier::verifyRangeLikeMetadata(const Value &I, const MDNode *Range,
4717 Type *Ty, RangeLikeMetadataKind Kind) {
4718 unsigned NumOperands = Range->getNumOperands();
4719 Check(NumOperands % 2 == 0, "Unfinished range!", Range);
4720 unsigned NumRanges = NumOperands / 2;
4721 Check(NumRanges >= 1, "It should have at least one range!", Range);
4722
4723 ConstantRange LastRange(1, true); // Dummy initial value
4724 for (unsigned i = 0; i < NumRanges; ++i) {
4725 ConstantInt *Low =
4726 mdconst::dyn_extract<ConstantInt>(MD: Range->getOperand(I: 2 * i));
4727 Check(Low, "The lower limit must be an integer!", Low);
4728 ConstantInt *High =
4729 mdconst::dyn_extract<ConstantInt>(MD: Range->getOperand(I: 2 * i + 1));
4730 Check(High, "The upper limit must be an integer!", High);
4731
4732 Check(High->getType() == Low->getType(), "Range pair types must match!",
4733 &I);
4734
4735 if (Kind == RangeLikeMetadataKind::NoaliasAddrspace) {
4736 Check(High->getType()->isIntegerTy(32),
4737 "noalias.addrspace type must be i32!", &I);
4738 } else {
4739 Check(High->getType() == Ty->getScalarType(),
4740 "Range types must match instruction type!", &I);
4741 }
4742
4743 APInt HighV = High->getValue();
4744 APInt LowV = Low->getValue();
4745
4746 // ConstantRange asserts if the ranges are the same except for the min/max
4747 // value. Leave the cases it tolerates for the empty range error below.
4748 Check(LowV != HighV || LowV.isMaxValue() || LowV.isMinValue(),
4749 "The upper and lower limits cannot be the same value", &I);
4750
4751 ConstantRange CurRange(LowV, HighV);
4752 Check(!CurRange.isEmptySet() &&
4753 (Kind == RangeLikeMetadataKind::AbsoluteSymbol ||
4754 !CurRange.isFullSet()),
4755 "Range must not be empty!", Range);
4756 if (i != 0) {
4757 Check(CurRange.intersectWith(LastRange).isEmptySet(),
4758 "Intervals are overlapping", Range);
4759 Check(LowV.sgt(LastRange.getLower()), "Intervals are not in order",
4760 Range);
4761 Check(!isContiguous(CurRange, LastRange), "Intervals are contiguous",
4762 Range);
4763 }
4764 LastRange = ConstantRange(LowV, HighV);
4765 }
4766 if (NumRanges > 2) {
4767 APInt FirstLow =
4768 mdconst::dyn_extract<ConstantInt>(MD: Range->getOperand(I: 0))->getValue();
4769 APInt FirstHigh =
4770 mdconst::dyn_extract<ConstantInt>(MD: Range->getOperand(I: 1))->getValue();
4771 ConstantRange FirstRange(FirstLow, FirstHigh);
4772 Check(FirstRange.intersectWith(LastRange).isEmptySet(),
4773 "Intervals are overlapping", Range);
4774 Check(!isContiguous(FirstRange, LastRange), "Intervals are contiguous",
4775 Range);
4776 }
4777}
4778
4779void Verifier::visitRangeMetadata(Instruction &I, MDNode *Range, Type *Ty) {
4780 assert(Range && Range == I.getMetadata(LLVMContext::MD_range) &&
4781 "precondition violation");
4782 verifyRangeLikeMetadata(I, Range, Ty, Kind: RangeLikeMetadataKind::Range);
4783}
4784
4785void Verifier::visitNoFPClassMetadata(Instruction &I, MDNode *NoFPClass,
4786 Type *Ty) {
4787 Check(AttributeFuncs::isNoFPClassCompatibleType(Ty),
4788 "nofpclass only applies to floating-point typed loads", I);
4789
4790 Check(NoFPClass->getNumOperands() == 1,
4791 "nofpclass must have exactly one entry", NoFPClass);
4792 ConstantInt *MaskVal =
4793 mdconst::dyn_extract<ConstantInt>(MD: NoFPClass->getOperand(I: 0));
4794 Check(MaskVal && MaskVal->getType()->isIntegerTy(32),
4795 "nofpclass entry must be a constant i32", NoFPClass);
4796 uint32_t Val = MaskVal->getZExtValue();
4797 Check(Val != 0, "'nofpclass' must have at least one test bit set", NoFPClass,
4798 I);
4799
4800 Check((Val & ~static_cast<unsigned>(fcAllFlags)) == 0,
4801 "Invalid value for 'nofpclass' test mask", NoFPClass, I);
4802}
4803
4804void Verifier::visitNoaliasAddrspaceMetadata(Instruction &I, MDNode *Range,
4805 Type *Ty) {
4806 assert(Range && Range == I.getMetadata(LLVMContext::MD_noalias_addrspace) &&
4807 "precondition violation");
4808 verifyRangeLikeMetadata(I, Range, Ty,
4809 Kind: RangeLikeMetadataKind::NoaliasAddrspace);
4810}
4811
4812void Verifier::checkAtomicMemAccessSize(Type *Ty, const Instruction *I) {
4813 unsigned Size = DL.getTypeSizeInBits(Ty).getFixedValue();
4814 Check(Size >= 8, "atomic memory access' size must be byte-sized", Ty, I);
4815 Check(!(Size & (Size - 1)),
4816 "atomic memory access' operand must have a power-of-two size", Ty, I);
4817}
4818
4819void Verifier::visitLoadInst(LoadInst &LI) {
4820 auto *PTy = dyn_cast<PointerType>(Val: LI.getOperand(i_nocapture: 0)->getType());
4821 Check(PTy, "Load operand must be a pointer.", &LI);
4822 Type *ElTy = LI.getType();
4823 if (MaybeAlign A = LI.getAlign()) {
4824 Check(A->value() <= Value::MaximumAlignment,
4825 "huge alignment values are unsupported", &LI);
4826 }
4827 Check(ElTy->isSized(), "loading unsized types is not allowed", &LI);
4828 if (LI.isAtomic()) {
4829 Check(LI.getOrdering() != AtomicOrdering::Release &&
4830 LI.getOrdering() != AtomicOrdering::AcquireRelease,
4831 "Load cannot have Release ordering", &LI);
4832
4833 if (LI.isElementwise()) {
4834 Check(LI.getOrdering() != AtomicOrdering::SequentiallyConsistent,
4835 "atomic elementwise load cannot be sequentially consistent.", &LI);
4836 auto *VecTy = dyn_cast<FixedVectorType>(Val: ElTy);
4837 Check(VecTy,
4838 "atomic elementwise load operand must have fixed vector type!", &LI,
4839 ElTy);
4840 if (VecTy)
4841 checkAtomicMemAccessSize(Ty: VecTy->getElementType(), I: &LI);
4842 }
4843
4844 Check(ElTy->getScalarType()->isIntOrPtrTy() ||
4845 ElTy->getScalarType()->isByteTy() ||
4846 ElTy->getScalarType()->isFloatingPointTy(),
4847 "atomic load operand must have integer, byte, pointer, floating "
4848 "point, or vector type!",
4849 ElTy, &LI);
4850
4851 checkAtomicMemAccessSize(Ty: ElTy, I: &LI);
4852 } else {
4853 Check(!LI.isElementwise(), "non-atomic load cannot be elementwise", &LI);
4854 Check(LI.getSyncScopeID() == SyncScope::System,
4855 "Non-atomic load cannot have SynchronizationScope specified", &LI);
4856 }
4857
4858 visitInstruction(I&: LI);
4859}
4860
4861void Verifier::visitStoreInst(StoreInst &SI) {
4862 auto *PTy = dyn_cast<PointerType>(Val: SI.getOperand(i_nocapture: 1)->getType());
4863 Check(PTy, "Store operand must be a pointer.", &SI);
4864 Type *ElTy = SI.getOperand(i_nocapture: 0)->getType();
4865 if (MaybeAlign A = SI.getAlign()) {
4866 Check(A->value() <= Value::MaximumAlignment,
4867 "huge alignment values are unsupported", &SI);
4868 }
4869 Check(ElTy->isSized(), "storing unsized types is not allowed", &SI);
4870 if (SI.isAtomic()) {
4871 Check(SI.getOrdering() != AtomicOrdering::Acquire &&
4872 SI.getOrdering() != AtomicOrdering::AcquireRelease,
4873 "Store cannot have Acquire ordering", &SI);
4874
4875 if (SI.isElementwise()) {
4876 Check(SI.getOrdering() != AtomicOrdering::SequentiallyConsistent,
4877 "atomic elementwise store cannot be sequentially consistent.", &SI);
4878
4879 auto *VecTy = dyn_cast<FixedVectorType>(Val: ElTy);
4880 Check(VecTy,
4881 "atomic elementwise store operand must have fixed vector type!",
4882 &SI, ElTy);
4883 if (VecTy)
4884 checkAtomicMemAccessSize(Ty: VecTy->getElementType(), I: &SI);
4885 }
4886
4887 Check(ElTy->getScalarType()->isIntOrPtrTy() ||
4888 ElTy->getScalarType()->isByteTy() ||
4889 ElTy->getScalarType()->isFloatingPointTy(),
4890 "atomic store operand must have integer, byte, pointer, floating "
4891 "point, or vector type!",
4892 ElTy, &SI);
4893 checkAtomicMemAccessSize(Ty: ElTy, I: &SI);
4894 } else {
4895 Check(!SI.isElementwise(), "non-atomic store cannot be elementwise", &SI);
4896 Check(SI.getSyncScopeID() == SyncScope::System,
4897 "Non-atomic store cannot have SynchronizationScope specified", &SI);
4898 }
4899 visitInstruction(I&: SI);
4900}
4901
4902/// Check that SwiftErrorVal is used as a swifterror argument in CS.
4903void Verifier::verifySwiftErrorCall(CallBase &Call,
4904 const Value *SwiftErrorVal) {
4905 for (const auto &I : llvm::enumerate(First: Call.args())) {
4906 if (I.value() == SwiftErrorVal) {
4907 Check(Call.paramHasAttr(I.index(), Attribute::SwiftError),
4908 "swifterror value when used in a callsite should be marked "
4909 "with swifterror attribute",
4910 SwiftErrorVal, Call);
4911 }
4912 }
4913}
4914
4915void Verifier::verifySwiftErrorValue(const Value *SwiftErrorVal) {
4916 // Check that swifterror value is only used by loads, stores, or as
4917 // a swifterror argument.
4918 for (const User *U : SwiftErrorVal->users()) {
4919 Check(isa<LoadInst>(U) || isa<StoreInst>(U) || isa<CallInst>(U) ||
4920 isa<InvokeInst>(U),
4921 "swifterror value can only be loaded and stored from, or "
4922 "as a swifterror argument!",
4923 SwiftErrorVal, U);
4924 // If it is used by a store, check it is the second operand.
4925 if (auto StoreI = dyn_cast<StoreInst>(Val: U))
4926 Check(StoreI->getOperand(1) == SwiftErrorVal,
4927 "swifterror value should be the second operand when used "
4928 "by stores",
4929 SwiftErrorVal, U);
4930 if (auto *Call = dyn_cast<CallBase>(Val: U))
4931 verifySwiftErrorCall(Call&: *const_cast<CallBase *>(Call), SwiftErrorVal);
4932 }
4933}
4934
4935void Verifier::visitAllocaInst(AllocaInst &AI) {
4936 if (auto *MD = mdconst::extract_or_null<ConstantInt>(
4937 MD: AI.getModule()->getModuleFlag(Key: "require-logical-pointer")))
4938 Check(!MD->getZExtValue(),
4939 "Non-logical alloca disallowed for this module.");
4940
4941 Type *Ty = AI.getAllocatedType();
4942 Check(Ty->isSized(), "Cannot allocate unsized type", &AI);
4943 // Check if it's a target extension type that disallows being used on the
4944 // stack.
4945 Check(!Ty->containsNonLocalTargetExtType(),
4946 "Alloca has illegal target extension type", &AI);
4947 Check(AI.getArraySize()->getType()->isIntegerTy(),
4948 "Alloca array size must have integer type", &AI);
4949 if (MaybeAlign A = AI.getAlign()) {
4950 Check(A->value() <= Value::MaximumAlignment,
4951 "huge alignment values are unsupported", &AI);
4952 }
4953
4954 if (AI.isSwiftError()) {
4955 Check(Ty->isPointerTy(), "swifterror alloca must have pointer type", &AI);
4956 Check(!AI.isArrayAllocation(),
4957 "swifterror alloca must not be array allocation", &AI);
4958 verifySwiftErrorValue(SwiftErrorVal: &AI);
4959 }
4960
4961 visitInstruction(I&: AI);
4962
4963 // Target-specific alloca checks.
4964 verifyAMDGPUAlloca(VS&: *this, AI);
4965}
4966
4967void Verifier::visitAtomicCmpXchgInst(AtomicCmpXchgInst &CXI) {
4968 Type *ElTy = CXI.getOperand(i_nocapture: 1)->getType();
4969 Check(ElTy->isIntOrPtrTy(),
4970 "cmpxchg operand must have integer or pointer type", ElTy, &CXI);
4971 checkAtomicMemAccessSize(Ty: ElTy, I: &CXI);
4972 visitInstruction(I&: CXI);
4973}
4974
4975void Verifier::visitAtomicRMWInst(AtomicRMWInst &RMWI) {
4976 Check(RMWI.getOrdering() != AtomicOrdering::Unordered,
4977 "atomicrmw instructions cannot be unordered.", &RMWI);
4978 auto Op = RMWI.getOperation();
4979 Type *ElTy = RMWI.getOperand(i_nocapture: 1)->getType();
4980 Check(!ElTy->isScalableTy(), "atomicrmw operand may not be scalable", &RMWI);
4981 if (RMWI.isElementwise()) {
4982 Check(RMWI.getOrdering() != AtomicOrdering::SequentiallyConsistent,
4983 "atomicrmw elementwise cannot be sequentially consistent.", &RMWI);
4984 auto *VecTy = dyn_cast<FixedVectorType>(Val: ElTy);
4985 Check(VecTy, "atomicrmw elementwise operand must have fixed vector type!",
4986 &RMWI, ElTy);
4987 if (VecTy)
4988 checkAtomicMemAccessSize(Ty: VecTy->getElementType(), I: &RMWI);
4989 }
4990
4991 if (Op == AtomicRMWInst::Xchg) {
4992 Check((ElTy->isIntOrIntVectorTy() || ElTy->isFPOrFPVectorTy() ||
4993 ElTy->isPtrOrPtrVectorTy()),
4994 "atomicrmw " + AtomicRMWInst::getOperationName(Op) +
4995 " operand must be an integer type, a floating-point type, a "
4996 "pointer type, or a fixed vector of any of these types!",
4997 &RMWI, ElTy);
4998 } else if (AtomicRMWInst::isFPOperation(Op)) {
4999 Check(ElTy->isFPOrFPVectorTy(),
5000 "atomicrmw " + AtomicRMWInst::getOperationName(Op) +
5001 " operand must have floating-point or fixed vector of "
5002 "floating-point "
5003 "type!",
5004 &RMWI, ElTy);
5005 } else {
5006 Check(ElTy->isIntOrIntVectorTy(),
5007 "atomicrmw " + AtomicRMWInst::getOperationName(Op) +
5008 " operand must have integer or fixed vector of integer type!",
5009 &RMWI, ElTy);
5010 }
5011 checkAtomicMemAccessSize(Ty: ElTy, I: &RMWI);
5012 Check(AtomicRMWInst::FIRST_BINOP <= Op && Op <= AtomicRMWInst::LAST_BINOP,
5013 "Invalid binary operation!", &RMWI);
5014 visitInstruction(I&: RMWI);
5015}
5016
5017void Verifier::visitFenceInst(FenceInst &FI) {
5018 const AtomicOrdering Ordering = FI.getOrdering();
5019 Check(Ordering == AtomicOrdering::Acquire ||
5020 Ordering == AtomicOrdering::Release ||
5021 Ordering == AtomicOrdering::AcquireRelease ||
5022 Ordering == AtomicOrdering::SequentiallyConsistent,
5023 "fence instructions may only have acquire, release, acq_rel, or "
5024 "seq_cst ordering.",
5025 &FI);
5026 visitInstruction(I&: FI);
5027}
5028
5029void Verifier::visitExtractValueInst(ExtractValueInst &EVI) {
5030 Check(ExtractValueInst::getIndexedType(EVI.getAggregateOperand()->getType(),
5031 EVI.getIndices()) == EVI.getType(),
5032 "Invalid ExtractValueInst operands!", &EVI);
5033
5034 visitInstruction(I&: EVI);
5035}
5036
5037void Verifier::visitInsertValueInst(InsertValueInst &IVI) {
5038 Check(ExtractValueInst::getIndexedType(IVI.getAggregateOperand()->getType(),
5039 IVI.getIndices()) ==
5040 IVI.getOperand(1)->getType(),
5041 "Invalid InsertValueInst operands!", &IVI);
5042
5043 visitInstruction(I&: IVI);
5044}
5045
5046static Value *getParentPad(Value *EHPad) {
5047 if (auto *FPI = dyn_cast<FuncletPadInst>(Val: EHPad))
5048 return FPI->getParentPad();
5049
5050 return cast<CatchSwitchInst>(Val: EHPad)->getParentPad();
5051}
5052
5053void Verifier::visitEHPadPredecessors(Instruction &I) {
5054 assert(I.isEHPad());
5055
5056 BasicBlock *BB = I.getParent();
5057 Function *F = BB->getParent();
5058
5059 Check(BB != &F->getEntryBlock(), "EH pad cannot be in entry block.", &I);
5060
5061 if (auto *LPI = dyn_cast<LandingPadInst>(Val: &I)) {
5062 // The landingpad instruction defines its parent as a landing pad block. The
5063 // landing pad block may be branched to only by the unwind edge of an
5064 // invoke.
5065 for (BasicBlock *PredBB : predecessors(BB)) {
5066 const auto *II = dyn_cast<InvokeInst>(Val: PredBB->getTerminator());
5067 Check(II && II->getUnwindDest() == BB && II->getNormalDest() != BB,
5068 "Block containing LandingPadInst must be jumped to "
5069 "only by the unwind edge of an invoke.",
5070 LPI);
5071 }
5072 return;
5073 }
5074 if (auto *CPI = dyn_cast<CatchPadInst>(Val: &I)) {
5075 if (!pred_empty(BB))
5076 Check(BB->getUniquePredecessor() == CPI->getCatchSwitch()->getParent(),
5077 "Block containg CatchPadInst must be jumped to "
5078 "only by its catchswitch.",
5079 CPI);
5080 Check(BB != CPI->getCatchSwitch()->getUnwindDest(),
5081 "Catchswitch cannot unwind to one of its catchpads",
5082 CPI->getCatchSwitch(), CPI);
5083 return;
5084 }
5085
5086 // Verify that each pred has a legal terminator with a legal to/from EH
5087 // pad relationship.
5088 Instruction *ToPad = &I;
5089 Value *ToPadParent = getParentPad(EHPad: ToPad);
5090 for (BasicBlock *PredBB : predecessors(BB)) {
5091 Instruction *TI = PredBB->getTerminator();
5092 Value *FromPad;
5093 if (auto *II = dyn_cast<InvokeInst>(Val: TI)) {
5094 Check(II->getUnwindDest() == BB && II->getNormalDest() != BB,
5095 "EH pad must be jumped to via an unwind edge", ToPad, II);
5096 auto *CalledFn =
5097 dyn_cast<Function>(Val: II->getCalledOperand()->stripPointerCasts());
5098 if (CalledFn && CalledFn->isIntrinsic() && II->doesNotThrow() &&
5099 !IntrinsicInst::mayLowerToFunctionCall(IID: CalledFn->getIntrinsicID()))
5100 continue;
5101 if (auto Bundle = II->getOperandBundle(ID: LLVMContext::OB_funclet))
5102 FromPad = Bundle->Inputs[0];
5103 else
5104 FromPad = ConstantTokenNone::get(Context&: II->getContext());
5105 } else if (auto *CRI = dyn_cast<CleanupReturnInst>(Val: TI)) {
5106 FromPad = CRI->getOperand(i_nocapture: 0);
5107 Check(FromPad != ToPadParent, "A cleanupret must exit its cleanup", CRI);
5108 } else if (auto *CSI = dyn_cast<CatchSwitchInst>(Val: TI)) {
5109 FromPad = CSI;
5110 } else {
5111 Check(false, "EH pad must be jumped to via an unwind edge", ToPad, TI);
5112 }
5113
5114 // The edge may exit from zero or more nested pads.
5115 SmallPtrSet<Value *, 8> Seen;
5116 for (;; FromPad = getParentPad(EHPad: FromPad)) {
5117 Check(FromPad != ToPad,
5118 "EH pad cannot handle exceptions raised within it", FromPad, TI);
5119 if (FromPad == ToPadParent) {
5120 // This is a legal unwind edge.
5121 break;
5122 }
5123 Check(!isa<ConstantTokenNone>(FromPad),
5124 "A single unwind edge may only enter one EH pad", TI);
5125 Check(Seen.insert(FromPad).second, "EH pad jumps through a cycle of pads",
5126 FromPad);
5127
5128 // This will be diagnosed on the corresponding instruction already. We
5129 // need the extra check here to make sure getParentPad() works.
5130 Check(isa<FuncletPadInst>(FromPad) || isa<CatchSwitchInst>(FromPad),
5131 "Parent pad must be catchpad/cleanuppad/catchswitch", TI);
5132 }
5133 }
5134}
5135
5136void Verifier::visitLandingPadInst(LandingPadInst &LPI) {
5137 // The landingpad instruction is ill-formed if it doesn't have any clauses and
5138 // isn't a cleanup.
5139 Check(LPI.getNumClauses() > 0 || LPI.isCleanup(),
5140 "LandingPadInst needs at least one clause or to be a cleanup.", &LPI);
5141
5142 visitEHPadPredecessors(I&: LPI);
5143
5144 if (!LandingPadResultTy)
5145 LandingPadResultTy = LPI.getType();
5146 else
5147 Check(LandingPadResultTy == LPI.getType(),
5148 "The landingpad instruction should have a consistent result type "
5149 "inside a function.",
5150 &LPI);
5151
5152 Function *F = LPI.getParent()->getParent();
5153 Check(F->hasPersonalityFn(),
5154 "LandingPadInst needs to be in a function with a personality.", &LPI);
5155
5156 // The landingpad instruction must be the first non-PHI instruction in the
5157 // block.
5158 Check(LPI.getParent()->getLandingPadInst() == &LPI,
5159 "LandingPadInst not the first non-PHI instruction in the block.", &LPI);
5160
5161 for (unsigned i = 0, e = LPI.getNumClauses(); i < e; ++i) {
5162 Constant *Clause = LPI.getClause(Idx: i);
5163 if (LPI.isCatch(Idx: i)) {
5164 Check(isa<PointerType>(Clause->getType()),
5165 "Catch operand does not have pointer type!", &LPI);
5166 } else {
5167 Check(LPI.isFilter(i), "Clause is neither catch nor filter!", &LPI);
5168 Check(isa<ConstantArray>(Clause) || isa<ConstantAggregateZero>(Clause),
5169 "Filter operand is not an array of constants!", &LPI);
5170 }
5171 }
5172
5173 visitInstruction(I&: LPI);
5174}
5175
5176void Verifier::visitResumeInst(ResumeInst &RI) {
5177 Check(RI.getFunction()->hasPersonalityFn(),
5178 "ResumeInst needs to be in a function with a personality.", &RI);
5179
5180 if (!LandingPadResultTy)
5181 LandingPadResultTy = RI.getValue()->getType();
5182 else
5183 Check(LandingPadResultTy == RI.getValue()->getType(),
5184 "The resume instruction should have a consistent result type "
5185 "inside a function.",
5186 &RI);
5187
5188 visitTerminator(I&: RI);
5189}
5190
5191void Verifier::visitCatchPadInst(CatchPadInst &CPI) {
5192 BasicBlock *BB = CPI.getParent();
5193
5194 Function *F = BB->getParent();
5195 Check(F->hasPersonalityFn(),
5196 "CatchPadInst needs to be in a function with a personality.", &CPI);
5197
5198 Check(isa<CatchSwitchInst>(CPI.getParentPad()),
5199 "CatchPadInst needs to be directly nested in a CatchSwitchInst.",
5200 CPI.getParentPad());
5201
5202 // The catchpad instruction must be the first non-PHI instruction in the
5203 // block.
5204 Check(&*BB->getFirstNonPHIIt() == &CPI,
5205 "CatchPadInst not the first non-PHI instruction in the block.", &CPI);
5206
5207 Check(llvm::all_of(CPI.arg_operands(),
5208 [](Use &U) {
5209 auto *V = U.get();
5210 return isa<Constant>(V) || isa<AllocaInst>(V);
5211 }),
5212 "Argument operand must be alloca or constant.", &CPI);
5213
5214 visitEHPadPredecessors(I&: CPI);
5215 visitFuncletPadInst(FPI&: CPI);
5216}
5217
5218void Verifier::visitCatchReturnInst(CatchReturnInst &CatchReturn) {
5219 Check(isa<CatchPadInst>(CatchReturn.getOperand(0)),
5220 "CatchReturnInst needs to be provided a CatchPad", &CatchReturn,
5221 CatchReturn.getOperand(0));
5222
5223 visitTerminator(I&: CatchReturn);
5224}
5225
5226void Verifier::visitCleanupPadInst(CleanupPadInst &CPI) {
5227 BasicBlock *BB = CPI.getParent();
5228
5229 Function *F = BB->getParent();
5230 Check(F->hasPersonalityFn(),
5231 "CleanupPadInst needs to be in a function with a personality.", &CPI);
5232
5233 // The cleanuppad instruction must be the first non-PHI instruction in the
5234 // block.
5235 Check(&*BB->getFirstNonPHIIt() == &CPI,
5236 "CleanupPadInst not the first non-PHI instruction in the block.", &CPI);
5237
5238 auto *ParentPad = CPI.getParentPad();
5239 Check(isa<ConstantTokenNone>(ParentPad) || isa<FuncletPadInst>(ParentPad),
5240 "CleanupPadInst has an invalid parent.", &CPI);
5241
5242 visitEHPadPredecessors(I&: CPI);
5243 visitFuncletPadInst(FPI&: CPI);
5244}
5245
5246void Verifier::visitFuncletPadInst(FuncletPadInst &FPI) {
5247 User *FirstUser = nullptr;
5248 Value *FirstUnwindPad = nullptr;
5249 SmallVector<FuncletPadInst *, 8> Worklist({&FPI});
5250 SmallPtrSet<FuncletPadInst *, 8> Seen;
5251
5252 while (!Worklist.empty()) {
5253 FuncletPadInst *CurrentPad = Worklist.pop_back_val();
5254 Check(Seen.insert(CurrentPad).second,
5255 "FuncletPadInst must not be nested within itself", CurrentPad);
5256 Value *UnresolvedAncestorPad = nullptr;
5257 for (User *U : CurrentPad->users()) {
5258 BasicBlock *UnwindDest;
5259 if (auto *CRI = dyn_cast<CleanupReturnInst>(Val: U)) {
5260 UnwindDest = CRI->getUnwindDest();
5261 } else if (auto *CSI = dyn_cast<CatchSwitchInst>(Val: U)) {
5262 // We allow catchswitch unwind to caller to nest
5263 // within an outer pad that unwinds somewhere else,
5264 // because catchswitch doesn't have a nounwind variant.
5265 // See e.g. SimplifyCFGOpt::SimplifyUnreachable.
5266 if (CSI->unwindsToCaller())
5267 continue;
5268 UnwindDest = CSI->getUnwindDest();
5269 } else if (auto *II = dyn_cast<InvokeInst>(Val: U)) {
5270 UnwindDest = II->getUnwindDest();
5271 } else if (isa<CallInst>(Val: U)) {
5272 // Calls which don't unwind may be found inside funclet
5273 // pads that unwind somewhere else. We don't *require*
5274 // such calls to be annotated nounwind.
5275 continue;
5276 } else if (auto *CPI = dyn_cast<CleanupPadInst>(Val: U)) {
5277 // The unwind dest for a cleanup can only be found by
5278 // recursive search. Add it to the worklist, and we'll
5279 // search for its first use that determines where it unwinds.
5280 Worklist.push_back(Elt: CPI);
5281 continue;
5282 } else {
5283 Check(isa<CatchReturnInst>(U), "Bogus funclet pad use", U);
5284 continue;
5285 }
5286
5287 Value *UnwindPad;
5288 bool ExitsFPI;
5289 if (UnwindDest) {
5290 UnwindPad = &*UnwindDest->getFirstNonPHIIt();
5291 if (!cast<Instruction>(Val: UnwindPad)->isEHPad())
5292 continue;
5293 Value *UnwindParent = getParentPad(EHPad: UnwindPad);
5294 // Ignore unwind edges that don't exit CurrentPad.
5295 if (UnwindParent == CurrentPad)
5296 continue;
5297 // Determine whether the original funclet pad is exited,
5298 // and if we are scanning nested pads determine how many
5299 // of them are exited so we can stop searching their
5300 // children.
5301 Value *ExitedPad = CurrentPad;
5302 ExitsFPI = false;
5303 do {
5304 if (ExitedPad == &FPI) {
5305 ExitsFPI = true;
5306 // Now we can resolve any ancestors of CurrentPad up to
5307 // FPI, but not including FPI since we need to make sure
5308 // to check all direct users of FPI for consistency.
5309 UnresolvedAncestorPad = &FPI;
5310 break;
5311 }
5312 Value *ExitedParent = getParentPad(EHPad: ExitedPad);
5313 if (ExitedParent == UnwindParent) {
5314 // ExitedPad is the ancestor-most pad which this unwind
5315 // edge exits, so we can resolve up to it, meaning that
5316 // ExitedParent is the first ancestor still unresolved.
5317 UnresolvedAncestorPad = ExitedParent;
5318 break;
5319 }
5320 ExitedPad = ExitedParent;
5321 } while (!isa<ConstantTokenNone>(Val: ExitedPad));
5322 } else {
5323 // Unwinding to caller exits all pads.
5324 UnwindPad = ConstantTokenNone::get(Context&: FPI.getContext());
5325 ExitsFPI = true;
5326 UnresolvedAncestorPad = &FPI;
5327 }
5328
5329 if (ExitsFPI) {
5330 // This unwind edge exits FPI. Make sure it agrees with other
5331 // such edges.
5332 if (FirstUser) {
5333 Check(UnwindPad == FirstUnwindPad,
5334 "Unwind edges out of a funclet "
5335 "pad must have the same unwind "
5336 "dest",
5337 &FPI, U, FirstUser);
5338 } else {
5339 FirstUser = U;
5340 FirstUnwindPad = UnwindPad;
5341 // Record cleanup sibling unwinds for verifySiblingFuncletUnwinds
5342 if (isa<CleanupPadInst>(Val: &FPI) && !isa<ConstantTokenNone>(Val: UnwindPad) &&
5343 getParentPad(EHPad: UnwindPad) == getParentPad(EHPad: &FPI))
5344 SiblingFuncletInfo[&FPI] = cast<Instruction>(Val: U);
5345 }
5346 }
5347 // Make sure we visit all uses of FPI, but for nested pads stop as
5348 // soon as we know where they unwind to.
5349 if (CurrentPad != &FPI)
5350 break;
5351 }
5352 if (UnresolvedAncestorPad) {
5353 if (CurrentPad == UnresolvedAncestorPad) {
5354 // When CurrentPad is FPI itself, we don't mark it as resolved even if
5355 // we've found an unwind edge that exits it, because we need to verify
5356 // all direct uses of FPI.
5357 assert(CurrentPad == &FPI);
5358 continue;
5359 }
5360 // Pop off the worklist any nested pads that we've found an unwind
5361 // destination for. The pads on the worklist are the uncles,
5362 // great-uncles, etc. of CurrentPad. We've found an unwind destination
5363 // for all ancestors of CurrentPad up to but not including
5364 // UnresolvedAncestorPad.
5365 Value *ResolvedPad = CurrentPad;
5366 while (!Worklist.empty()) {
5367 Value *UnclePad = Worklist.back();
5368 Value *AncestorPad = getParentPad(EHPad: UnclePad);
5369 // Walk ResolvedPad up the ancestor list until we either find the
5370 // uncle's parent or the last resolved ancestor.
5371 while (ResolvedPad != AncestorPad) {
5372 Value *ResolvedParent = getParentPad(EHPad: ResolvedPad);
5373 if (ResolvedParent == UnresolvedAncestorPad) {
5374 break;
5375 }
5376 ResolvedPad = ResolvedParent;
5377 }
5378 // If the resolved ancestor search didn't find the uncle's parent,
5379 // then the uncle is not yet resolved.
5380 if (ResolvedPad != AncestorPad)
5381 break;
5382 // This uncle is resolved, so pop it from the worklist.
5383 Worklist.pop_back();
5384 }
5385 }
5386 }
5387
5388 if (FirstUnwindPad) {
5389 if (auto *CatchSwitch = dyn_cast<CatchSwitchInst>(Val: FPI.getParentPad())) {
5390 BasicBlock *SwitchUnwindDest = CatchSwitch->getUnwindDest();
5391 Value *SwitchUnwindPad;
5392 if (SwitchUnwindDest)
5393 SwitchUnwindPad = &*SwitchUnwindDest->getFirstNonPHIIt();
5394 else
5395 SwitchUnwindPad = ConstantTokenNone::get(Context&: FPI.getContext());
5396 Check(SwitchUnwindPad == FirstUnwindPad,
5397 "Unwind edges out of a catch must have the same unwind dest as "
5398 "the parent catchswitch",
5399 &FPI, FirstUser, CatchSwitch);
5400 }
5401 }
5402
5403 visitInstruction(I&: FPI);
5404}
5405
5406void Verifier::visitCatchSwitchInst(CatchSwitchInst &CatchSwitch) {
5407 BasicBlock *BB = CatchSwitch.getParent();
5408
5409 Function *F = BB->getParent();
5410 Check(F->hasPersonalityFn(),
5411 "CatchSwitchInst needs to be in a function with a personality.",
5412 &CatchSwitch);
5413
5414 // The catchswitch instruction must be the first non-PHI instruction in the
5415 // block.
5416 Check(&*BB->getFirstNonPHIIt() == &CatchSwitch,
5417 "CatchSwitchInst not the first non-PHI instruction in the block.",
5418 &CatchSwitch);
5419
5420 auto *ParentPad = CatchSwitch.getParentPad();
5421 Check(isa<ConstantTokenNone>(ParentPad) || isa<FuncletPadInst>(ParentPad),
5422 "CatchSwitchInst has an invalid parent.", ParentPad);
5423
5424 if (BasicBlock *UnwindDest = CatchSwitch.getUnwindDest()) {
5425 BasicBlock::iterator I = UnwindDest->getFirstNonPHIIt();
5426 Check(I->isEHPad() && !isa<LandingPadInst>(I),
5427 "CatchSwitchInst must unwind to an EH block which is not a "
5428 "landingpad.",
5429 &CatchSwitch);
5430
5431 // Record catchswitch sibling unwinds for verifySiblingFuncletUnwinds
5432 if (getParentPad(EHPad: &*I) == ParentPad)
5433 SiblingFuncletInfo[&CatchSwitch] = &CatchSwitch;
5434 }
5435
5436 Check(CatchSwitch.getNumHandlers() != 0,
5437 "CatchSwitchInst cannot have empty handler list", &CatchSwitch);
5438
5439 for (BasicBlock *Handler : CatchSwitch.handlers()) {
5440 Check(isa<CatchPadInst>(Handler->getFirstNonPHIIt()),
5441 "CatchSwitchInst handlers must be catchpads", &CatchSwitch, Handler);
5442 }
5443
5444 visitEHPadPredecessors(I&: CatchSwitch);
5445 visitTerminator(I&: CatchSwitch);
5446}
5447
5448void Verifier::visitCleanupReturnInst(CleanupReturnInst &CRI) {
5449 Check(isa<CleanupPadInst>(CRI.getOperand(0)),
5450 "CleanupReturnInst needs to be provided a CleanupPad", &CRI,
5451 CRI.getOperand(0));
5452
5453 if (BasicBlock *UnwindDest = CRI.getUnwindDest()) {
5454 BasicBlock::iterator I = UnwindDest->getFirstNonPHIIt();
5455 Check(I->isEHPad() && !isa<LandingPadInst>(I),
5456 "CleanupReturnInst must unwind to an EH block which is not a "
5457 "landingpad.",
5458 &CRI);
5459 }
5460
5461 visitTerminator(I&: CRI);
5462}
5463
5464void Verifier::verifyDominatesUse(Instruction &I, unsigned i) {
5465 Instruction *Op = cast<Instruction>(Val: I.getOperand(i));
5466 // If the we have an invalid invoke, don't try to compute the dominance.
5467 // We already reject it in the invoke specific checks and the dominance
5468 // computation doesn't handle multiple edges.
5469 if (auto *II = dyn_cast<InvokeInst>(Val: Op)) {
5470 if (II->getNormalDest() == II->getUnwindDest())
5471 return;
5472 }
5473
5474 // Quick check whether the def has already been encountered in the same block.
5475 // PHI nodes are not checked to prevent accepting preceding PHIs, because PHI
5476 // uses are defined to happen on the incoming edge, not at the instruction.
5477 //
5478 // FIXME: If this operand is a MetadataAsValue (wrapping a LocalAsMetadata)
5479 // wrapping an SSA value, assert that we've already encountered it. See
5480 // related FIXME in Mapper::mapLocalAsMetadata in ValueMapper.cpp.
5481 if (!isa<PHINode>(Val: I) && InstsInThisBlock.count(Ptr: Op))
5482 return;
5483
5484 const Use &U = I.getOperandUse(i);
5485 Check(DT.dominates(Op, U), "Instruction does not dominate all uses!", Op, &I);
5486}
5487
5488void Verifier::visitDereferenceableMetadata(Instruction& I, MDNode* MD) {
5489 Check(I.getType()->isPointerTy(),
5490 "dereferenceable, dereferenceable_or_null "
5491 "apply only to pointer types",
5492 &I);
5493 Check((isa<LoadInst>(I) || isa<IntToPtrInst>(I)),
5494 "dereferenceable, dereferenceable_or_null apply only to load"
5495 " and inttoptr instructions, use attributes for calls or invokes",
5496 &I);
5497 Check(MD->getNumOperands() == 1,
5498 "dereferenceable, dereferenceable_or_null "
5499 "take one operand!",
5500 &I);
5501 ConstantInt *CI = mdconst::dyn_extract<ConstantInt>(MD: MD->getOperand(I: 0));
5502 Check(CI && CI->getType()->isIntegerTy(64),
5503 "dereferenceable, "
5504 "dereferenceable_or_null metadata value must be an i64!",
5505 &I);
5506}
5507
5508void Verifier::visitNoFreeObjMetadata(Instruction &I, MDNode *MD) {
5509 Check(I.getType()->isPointerTy(), "nofreeobj applies only to pointer types",
5510 &I);
5511 Check((isa<IntToPtrInst>(I)),
5512 "nofreeobj applies only to inttoptr instruction", &I);
5513 Check(MD->getNumOperands() == 0, "nofreeobj metadata must be empty", &I);
5514}
5515
5516void Verifier::visitProfMetadata(Instruction &I, MDNode *MD) {
5517 auto GetBranchingTerminatorNumOperands = [&]() {
5518 unsigned ExpectedNumOperands = 0;
5519 if (auto *BI = dyn_cast<CondBrInst>(Val: &I))
5520 ExpectedNumOperands = BI->getNumSuccessors();
5521 else if (auto *SI = dyn_cast<SwitchInst>(Val: &I))
5522 ExpectedNumOperands = SI->getNumSuccessors();
5523 else if (isa<CallInst>(Val: &I))
5524 ExpectedNumOperands = 1;
5525 else if (auto *IBI = dyn_cast<IndirectBrInst>(Val: &I))
5526 ExpectedNumOperands = IBI->getNumDestinations();
5527 else if (isa<SelectInst>(Val: &I))
5528 ExpectedNumOperands = 2;
5529 else if (auto *CI = dyn_cast<CallBrInst>(Val: &I))
5530 ExpectedNumOperands = CI->getNumSuccessors();
5531 return ExpectedNumOperands;
5532 };
5533 Check(MD->getNumOperands() >= 1,
5534 "!prof annotations should have at least 1 operand", MD);
5535 // Check first operand.
5536 Check(MD->getOperand(0) != nullptr, "first operand should not be null", MD);
5537 Check(isa<MDString>(MD->getOperand(0)),
5538 "expected string with name of the !prof annotation", MD);
5539 MDString *MDS = cast<MDString>(Val: MD->getOperand(I: 0));
5540 StringRef ProfName = MDS->getString();
5541
5542 if (ProfName == MDProfLabels::UnknownBranchWeightsMarker) {
5543 Check(GetBranchingTerminatorNumOperands() != 0 || isa<InvokeInst>(I),
5544 "'unknown' !prof should only appear on instructions on which "
5545 "'branch_weights' would",
5546 MD);
5547 verifyUnknownProfileMetadata(MD);
5548 return;
5549 }
5550
5551 Check(MD->getNumOperands() >= 2,
5552 "!prof annotations should have no less than 2 operands", MD);
5553
5554 // Check consistency of !prof branch_weights metadata.
5555 if (ProfName == MDProfLabels::BranchWeights) {
5556 unsigned NumBranchWeights = getNumBranchWeights(ProfileData: *MD);
5557 if (isa<InvokeInst>(Val: &I)) {
5558 Check(NumBranchWeights == 1 || NumBranchWeights == 2,
5559 "Wrong number of InvokeInst branch_weights operands", MD);
5560 } else {
5561 const unsigned ExpectedNumOperands = GetBranchingTerminatorNumOperands();
5562 if (ExpectedNumOperands == 0)
5563 CheckFailed(Message: "!prof branch_weights are not allowed for this instruction",
5564 V1: MD);
5565
5566 Check(NumBranchWeights == ExpectedNumOperands, "Wrong number of operands",
5567 MD);
5568 }
5569 for (unsigned i = getBranchWeightOffset(ProfileData: MD); i < MD->getNumOperands();
5570 ++i) {
5571 auto &MDO = MD->getOperand(I: i);
5572 Check(MDO, "second operand should not be null", MD);
5573 Check(mdconst::dyn_extract<ConstantInt>(MDO),
5574 "!prof brunch_weights operand is not a const int");
5575 }
5576 } else if (ProfName == MDProfLabels::ValueProfile) {
5577 Check(isValueProfileMD(MD), "invalid value profiling metadata", MD);
5578 ConstantInt *KindInt = mdconst::dyn_extract<ConstantInt>(MD: MD->getOperand(I: 1));
5579 Check(KindInt, "VP !prof missing kind argument", MD);
5580
5581 auto Kind = KindInt->getZExtValue();
5582 Check(Kind >= InstrProfValueKind::IPVK_First &&
5583 Kind <= InstrProfValueKind::IPVK_Last,
5584 "Invalid VP !prof kind", MD);
5585 Check(MD->getNumOperands() % 2 == 1,
5586 "VP !prof should have an even number "
5587 "of arguments after 'VP'",
5588 MD);
5589 if (Kind == InstrProfValueKind::IPVK_IndirectCallTarget ||
5590 Kind == InstrProfValueKind::IPVK_MemOPSize)
5591 Check(isa<CallBase>(I),
5592 "VP !prof indirect call or memop size expected to be applied to "
5593 "CallBase instructions only",
5594 MD);
5595
5596 DenseSet<uint64_t> ProfileValues;
5597 for (unsigned I = 3; I < MD->getNumOperands(); I += 2) {
5598 ConstantInt *ProfileValue =
5599 mdconst::dyn_extract<ConstantInt>(MD: MD->getOperand(I));
5600 Check(ProfileValue, "VP !prof value operand is not a const int", MD);
5601 uint64_t ProfileValueInt = ProfileValue->getZExtValue();
5602 auto [ValueIt, Inserted] = ProfileValues.insert(V: ProfileValueInt);
5603 Check(Inserted, "VP !prof should not have duplicate profile values", MD);
5604 }
5605 } else {
5606 CheckFailed(Message: "expected either branch_weights or VP profile name", V1: MD);
5607 }
5608}
5609
5610void Verifier::visitDIAssignIDMetadata(Instruction &I, MDNode *MD) {
5611 assert(I.hasMetadata(LLVMContext::MD_DIAssignID));
5612 // DIAssignID metadata must be attached to either an alloca or some form of
5613 // store/memory-writing instruction.
5614 // FIXME: We allow all intrinsic insts here to avoid trying to enumerate all
5615 // possible store intrinsics.
5616 bool ExpectedInstTy =
5617 isa<AllocaInst>(Val: I) || isa<StoreInst>(Val: I) || isa<IntrinsicInst>(Val: I);
5618 CheckDI(ExpectedInstTy, "!DIAssignID attached to unexpected instruction kind",
5619 I, MD);
5620 // Iterate over the MetadataAsValue uses of the DIAssignID - these should
5621 // only be found as DbgAssignIntrinsic operands.
5622 if (auto *AsValue = MetadataAsValue::getIfExists(Context, MD)) {
5623 for (auto *User : AsValue->users()) {
5624 CheckDI(isa<DbgAssignIntrinsic>(User),
5625 "!DIAssignID should only be used by llvm.dbg.assign intrinsics",
5626 MD, User);
5627 // All of the dbg.assign intrinsics should be in the same function as I.
5628 if (auto *DAI = dyn_cast<DbgAssignIntrinsic>(Val: User))
5629 CheckDI(DAI->getFunction() == I.getFunction(),
5630 "dbg.assign not in same function as inst", DAI, &I);
5631 }
5632 }
5633 for (DbgVariableRecord *DVR : at::getAssignmentMarkers(ID: cast<DIAssignID>(Val: MD)))
5634 CheckDI(DVR->getFunction() == I.getFunction(),
5635 "DVRAssign not in same function as inst", DVR, &I);
5636}
5637
5638void Verifier::visitMMRAMetadata(Instruction &I, MDNode *MD) {
5639 Check(canInstructionHaveMMRAs(I),
5640 "!mmra metadata attached to unexpected instruction kind", I, MD);
5641
5642 // MMRA Metadata should either be a tag, e.g. !{!"foo", !"bar"}, or a
5643 // list of tags such as !2 in the following example:
5644 // !0 = !{!"a", !"b"}
5645 // !1 = !{!"c", !"d"}
5646 // !2 = !{!0, !1}
5647 if (MMRAMetadata::isTagMD(MD))
5648 return;
5649
5650 Check(isa<MDTuple>(MD), "!mmra expected to be a metadata tuple", I, MD);
5651 for (const MDOperand &MDOp : MD->operands())
5652 Check(MMRAMetadata::isTagMD(MDOp.get()),
5653 "!mmra metadata tuple operand is not an MMRA tag", I, MDOp.get());
5654}
5655
5656void Verifier::visitCallStackMetadata(MDNode *MD) {
5657 // Call stack metadata should consist of a list of at least 1 constant int
5658 // (representing a hash of the location).
5659 Check(MD->getNumOperands() >= 1,
5660 "call stack metadata should have at least 1 operand", MD);
5661
5662 for (const auto &Op : MD->operands())
5663 Check(mdconst::dyn_extract_or_null<ConstantInt>(Op),
5664 "call stack metadata operand should be constant integer", Op);
5665}
5666
5667void Verifier::visitMemProfMetadata(Instruction &I, MDNode *MD) {
5668 Check(isa<CallBase>(I), "!memprof metadata should only exist on calls", &I);
5669 if (isa<CallBase>(Val: I))
5670 Check(I.hasMetadata(LLVMContext::MD_callsite),
5671 "!memprof metadata requires !callsite metadata", &I, MD);
5672 Check(MD->getNumOperands() >= 1,
5673 "!memprof annotations should have at least 1 metadata operand "
5674 "(MemInfoBlock)",
5675 MD);
5676
5677 // Check each MIB
5678 for (auto &MIBOp : MD->operands()) {
5679 auto *MIB = dyn_cast<MDNode>(Val: MIBOp);
5680 // The first operand of an MIB should be the call stack metadata.
5681 // There rest of the operands should be MDString tags, and there should be
5682 // at least one.
5683 Check(MIB->getNumOperands() >= 2,
5684 "Each !memprof MemInfoBlock should have at least 2 operands", MIB);
5685
5686 // Check call stack metadata (first operand).
5687 Check(MIB->getOperand(0) != nullptr,
5688 "!memprof MemInfoBlock first operand should not be null", MIB);
5689 Check(isa<MDNode>(MIB->getOperand(0)),
5690 "!memprof MemInfoBlock first operand should be an MDNode", MIB);
5691 auto *StackMD = dyn_cast<MDNode>(Val: MIB->getOperand(I: 0));
5692 visitCallStackMetadata(MD: StackMD);
5693
5694 // The second MIB operand should be MDString.
5695 Check(isa<MDString>(MIB->getOperand(1)),
5696 "!memprof MemInfoBlock second operand should be an MDString", MIB);
5697
5698 // Any remaining should be MDNode that are pairs of integers
5699 for (unsigned I = 2; I < MIB->getNumOperands(); ++I) {
5700 auto *OpNode = dyn_cast<MDNode>(Val: MIB->getOperand(I));
5701 Check(OpNode, "Not all !memprof MemInfoBlock operands 2 to N are MDNode",
5702 MIB);
5703 Check(OpNode->getNumOperands() == 2,
5704 "Not all !memprof MemInfoBlock operands 2 to N are MDNode with 2 "
5705 "operands",
5706 MIB);
5707 // Check that all of Op's operands are ConstantInt.
5708 Check(llvm::all_of(OpNode->operands(),
5709 [](const MDOperand &Op) {
5710 return mdconst::hasa<ConstantInt>(Op);
5711 }),
5712 "Not all !memprof MemInfoBlock operands 2 to N are MDNode with "
5713 "ConstantInt operands",
5714 MIB);
5715 }
5716 }
5717}
5718
5719void Verifier::visitCallsiteMetadata(Instruction &I, MDNode *MD) {
5720 Check(isa<CallBase>(I), "!callsite metadata should only exist on calls", &I);
5721 // Verify the partial callstack annotated from memprof profiles. This callsite
5722 // is a part of a profiled allocation callstack.
5723 visitCallStackMetadata(MD);
5724}
5725
5726void Verifier::visitCalleeTypeMetadata(Instruction &I, MDNode *MD) {
5727 Check(isa<CallBase>(I), "!callee_type metadata should only exist on calls",
5728 &I);
5729 for (Metadata *Op : MD->operands()) {
5730 Check(isa<MDNode>(Op),
5731 "The callee_type metadata must be a list of callgraph metadata nodes",
5732 Op);
5733 auto *CallgraphMD = cast<MDNode>(Val: Op);
5734 Check(CallgraphMD->getNumOperands() == 1,
5735 "Well-formed callgraph metadata must contain exactly one "
5736 "operand",
5737 Op);
5738 Check(isa<MDString>(CallgraphMD->getOperand(0)),
5739 "The operand of callgraph metadata for functions must be an MDString",
5740 Op);
5741 }
5742}
5743
5744void Verifier::visitAnnotationMetadata(MDNode *Annotation) {
5745 Check(isa<MDTuple>(Annotation), "annotation must be a tuple");
5746 Check(Annotation->getNumOperands() >= 1,
5747 "annotation must have at least one operand");
5748 for (const MDOperand &Op : Annotation->operands()) {
5749 bool TupleOfStrings =
5750 isa<MDTuple>(Val: Op.get()) &&
5751 all_of(Range: cast<MDTuple>(Val: Op)->operands(), P: [](auto &Annotation) {
5752 return isa<MDString>(Annotation.get());
5753 });
5754 Check(isa<MDString>(Op.get()) || TupleOfStrings,
5755 "operands must be a string or a tuple of strings");
5756 }
5757}
5758
5759void Verifier::visitAliasScopeMetadata(const MDNode *MD) {
5760 unsigned NumOps = MD->getNumOperands();
5761 Check(NumOps >= 2 && NumOps <= 3, "scope must have two or three operands",
5762 MD);
5763 Check(MD->getOperand(0).get() == MD || isa<MDString>(MD->getOperand(0)),
5764 "first scope operand must be self-referential or string", MD);
5765 if (NumOps == 3)
5766 Check(isa<MDString>(MD->getOperand(2)),
5767 "third scope operand must be string (if used)", MD);
5768
5769 auto *Domain = dyn_cast<MDNode>(Val: MD->getOperand(I: 1));
5770 Check(Domain != nullptr, "second scope operand must be MDNode", MD);
5771
5772 unsigned NumDomainOps = Domain->getNumOperands();
5773 Check(NumDomainOps >= 2 && NumDomainOps <= 3,
5774 "domain must have two or three operands", Domain);
5775 Check(Domain->getOperand(0).get() == Domain ||
5776 isa<MDString>(Domain->getOperand(0)),
5777 "first domain operand must be self-referential or string", Domain);
5778 const auto *Disjoint =
5779 mdconst::dyn_extract_or_null<ConstantInt>(MD: Domain->getOperand(I: 1));
5780 Check(Disjoint && Disjoint->getBitWidth() == 1,
5781 "second domain operand must be an i1 constant", Domain);
5782 if (NumDomainOps == 3)
5783 Check(isa<MDString>(Domain->getOperand(2)),
5784 "third domain operand must be string (if used)", Domain);
5785}
5786
5787void Verifier::visitAliasScopeListMetadata(const MDNode *MD) {
5788 for (const MDOperand &Op : MD->operands()) {
5789 const auto *OpMD = dyn_cast<MDNode>(Val: Op);
5790 Check(OpMD != nullptr, "scope list must consist of MDNodes", MD);
5791 visitAliasScopeMetadata(MD: OpMD);
5792 }
5793}
5794
5795void Verifier::visitAccessGroupMetadata(const MDNode *MD) {
5796 auto IsValidAccessScope = [](const MDNode *MD) {
5797 return MD->getNumOperands() == 0 && MD->isDistinct();
5798 };
5799
5800 // An empty node is an access scope, and it must be 'distinct'. It is never a
5801 // list, because an empty list is not allowed: it would look the same as an
5802 // access scope.
5803 if (MD->getNumOperands() == 0) {
5804 Check(MD->isDistinct(), "Access scope must be 'distinct'", MD);
5805 return;
5806 }
5807
5808 // A non-empty node is a list of access scopes.
5809 for (const MDOperand &Op : MD->operands()) {
5810 const auto *OpMD = dyn_cast<MDNode>(Val: Op);
5811 Check(OpMD != nullptr, "Access scope list must consist of MDNodes", MD);
5812 Check(IsValidAccessScope(OpMD),
5813 "Access scope list contains invalid access scope", MD);
5814 }
5815}
5816
5817void Verifier::visitCapturesMetadata(Instruction &I, const MDNode *Captures) {
5818 static const char *ValidArgs[] = {"address_is_null", "address",
5819 "read_provenance", "provenance"};
5820
5821 auto *SI = dyn_cast<StoreInst>(Val: &I);
5822 Check(SI, "!captures metadata can only be applied to store instructions", &I);
5823 Check(SI->getValueOperand()->getType()->isPointerTy(),
5824 "!captures metadata can only be applied to store with value operand of "
5825 "pointer type",
5826 &I);
5827 Check(Captures->getNumOperands() != 0, "!captures metadata cannot be empty",
5828 &I);
5829
5830 for (Metadata *Op : Captures->operands()) {
5831 auto *Str = dyn_cast<MDString>(Val: Op);
5832 Check(Str, "!captures metadata must be a list of strings", &I);
5833 Check(is_contained(ValidArgs, Str->getString()),
5834 "invalid entry in !captures metadata", &I, Str);
5835 }
5836}
5837
5838void Verifier::visitAllocTokenMetadata(Instruction &I, MDNode *MD) {
5839 Check(isa<CallBase>(I), "!alloc_token should only exist on calls", &I);
5840 Check(MD->getNumOperands() == 2 || MD->getNumOperands() == 3,
5841 "!alloc_token must have 2 or 3 operands", MD);
5842 Check(isa_and_nonnull<MDString>(MD->getOperand(0)), "expected string", MD);
5843 Check(mdconst::dyn_extract_or_null<ConstantInt>(MD->getOperand(1)),
5844 "expected integer constant", MD);
5845 if (MD->getNumOperands() == 3)
5846 Check(isa_and_nonnull<MDString>(MD->getOperand(2)),
5847 "expected function name string", MD);
5848}
5849
5850void Verifier::visitInlineHistoryMetadata(Instruction &I, MDNode *MD) {
5851 Check(isa<CallBase>(I), "!inline_history should only exist on calls", &I);
5852 for (Metadata *Op : MD->operands()) {
5853 // Can be null when a function is erased.
5854 if (!Op)
5855 continue;
5856 Check(isa<ValueAsMetadata>(Op) &&
5857 isa<Function>(cast<ValueAsMetadata>(Op)
5858 ->getValue()
5859 ->stripPointerCastsAndAliases()),
5860 "!inline_history operands must be functions or null", MD);
5861 }
5862}
5863
5864void Verifier::visitMemCacheHintMetadata(Instruction &I, MDNode *MD) {
5865 Check(I.mayReadOrWriteMemory(),
5866 "!mem.cache_hint is only valid on memory operations", &I);
5867
5868 Check(MD->getNumOperands() % 2 == 0,
5869 "!mem.cache_hint must have even number of operands "
5870 "(operand_no, hint_node pairs)",
5871 MD);
5872
5873 const auto *CB = dyn_cast<CallBase>(Val: &I);
5874 if (CB)
5875 Check(CB->getIntrinsicID() != Intrinsic::not_intrinsic,
5876 "!mem.cache_hint is not supported on non-intrinsic calls", &I);
5877
5878 unsigned NumOperands = CB ? CB->arg_size() : I.getNumOperands();
5879
5880 SmallDenseSet<unsigned, 4> SeenOperandNos;
5881 std::optional<uint64_t> LastOperandNo;
5882
5883 // Top-level metadata alternates: i32 operand_no, MDNode hint_node.
5884 for (unsigned J = 0; J + 1 < MD->getNumOperands(); J += 2) {
5885 auto *OpNoCI = mdconst::dyn_extract<ConstantInt>(MD: MD->getOperand(I: J));
5886 Check(OpNoCI,
5887 "!mem.cache_hint must alternate between i32 operand numbers and "
5888 "metadata hint nodes",
5889 MD);
5890
5891 Check(OpNoCI->getValue().isNonNegative(),
5892 "!mem.cache_hint operand number must be non-negative", MD);
5893
5894 uint64_t OperandNo = OpNoCI->getZExtValue();
5895 Check(OperandNo < NumOperands,
5896 "!mem.cache_hint operand number is out of range", &I);
5897
5898 Value *Operand =
5899 CB ? CB->getArgOperand(i: OperandNo) : I.getOperand(i: OperandNo);
5900 Check(Operand->getType()->isPtrOrPtrVectorTy(),
5901 "!mem.cache_hint operand number must refer to a pointer operand", &I);
5902
5903 bool Inserted = SeenOperandNos.insert(V: OperandNo).second;
5904 Check(Inserted, "!mem.cache_hint contains duplicate operand number", MD);
5905
5906 Check(!Inserted || !LastOperandNo || OperandNo > *LastOperandNo,
5907 "!mem.cache_hint operand numbers must be in increasing order", MD);
5908 LastOperandNo = OperandNo;
5909
5910 const auto *Node = dyn_cast<MDNode>(Val: MD->getOperand(I: J + 1));
5911 Check(Node,
5912 "!mem.cache_hint must alternate between i32 operand numbers and "
5913 "metadata hint nodes",
5914 MD);
5915
5916 Check(Node->getNumOperands() % 2 == 0,
5917 "!mem.cache_hint hint node must have even number of operands "
5918 "(key-value pairs)",
5919 Node);
5920
5921 StringSet<> SeenKeys;
5922 for (unsigned K = 0; K + 1 < Node->getNumOperands(); K += 2) {
5923 const auto *Key = dyn_cast<MDString>(Val: Node->getOperand(I: K));
5924 Check(Key, "!mem.cache_hint key must be a string", Node);
5925
5926 StringRef KeyStr = Key->getString();
5927 Check(SeenKeys.insert(KeyStr).second,
5928 "!mem.cache_hint hint node contains duplicate key", Node);
5929
5930 const Metadata *Value = Node->getOperand(I: K + 1).get();
5931 Check(isa_and_nonnull<MDString>(Value) ||
5932 mdconst::dyn_extract<ConstantInt>(Value),
5933 "!mem.cache_hint value must be a string or integer", Node);
5934 }
5935 }
5936}
5937
5938/// verifyInstruction - Verify that an instruction is well formed.
5939///
5940void Verifier::visitInstruction(Instruction &I) {
5941 BasicBlock *BB = I.getParent();
5942 Check(BB, "Instruction not embedded in basic block!", &I);
5943
5944 if (!isa<PHINode>(Val: I)) { // Check that non-phi nodes are not self referential
5945 for (User *U : I.users()) {
5946 Check(U != (User *)&I || !DT.isReachableFromEntry(BB),
5947 "Only PHI nodes may reference their own value!", &I);
5948 }
5949 }
5950
5951 // Check that void typed values don't have names
5952 Check(!I.getType()->isVoidTy() || !I.hasName(),
5953 "Instruction has a name, but provides a void value!", &I);
5954
5955 // Check that the return value of the instruction is either void or a legal
5956 // value type.
5957 Check(I.getType()->isVoidTy() || I.getType()->isFirstClassType(),
5958 "Instruction returns a non-scalar type!", &I);
5959
5960 // Check that the instruction doesn't produce metadata. Calls are already
5961 // checked against the callee type.
5962 Check(!I.getType()->isMetadataTy() || isa<CallInst>(I) || isa<InvokeInst>(I),
5963 "Invalid use of metadata!", &I);
5964
5965 // Check that all uses of the instruction, if they are instructions
5966 // themselves, actually have parent basic blocks. If the use is not an
5967 // instruction, it is an error!
5968 for (Use &U : I.uses()) {
5969 if (auto *Used = dyn_cast<Instruction>(Val: U.getUser()))
5970 Check(Used->getParent() != nullptr,
5971 "Instruction referencing"
5972 " instruction not embedded in a basic block!",
5973 &I, Used);
5974 else {
5975 CheckFailed(Message: "Use of instruction is not an instruction!", V1: U);
5976 return;
5977 }
5978 }
5979
5980 // Get a pointer to the call base of the instruction if it is some form of
5981 // call.
5982 const auto *CBI = dyn_cast<CallBase>(Val: &I);
5983
5984 for (unsigned i = 0, e = I.getNumOperands(); i != e; ++i) {
5985 Check(I.getOperand(i) != nullptr, "Instruction has null operand!", &I);
5986
5987 // Check to make sure that only first-class-values are operands to
5988 // instructions.
5989 if (!I.getOperand(i)->getType()->isFirstClassType()) {
5990 Check(false, "Instruction operands must be first-class values!", &I);
5991 }
5992
5993 if (auto *F = dyn_cast<Function>(Val: I.getOperand(i))) {
5994 // This code checks whether the function is used as the operand of a
5995 // clang_arc_attachedcall operand bundle.
5996 auto IsAttachedCallOperand = [](Function *F, const CallBase *CBI,
5997 int Idx) {
5998 return CBI && CBI->isOperandBundleOfType(
5999 ID: LLVMContext::OB_clang_arc_attachedcall, Idx);
6000 };
6001
6002 // Check to make sure that the "address of" an intrinsic function is never
6003 // taken. Ignore cases where the address of the intrinsic function is used
6004 // as the argument of operand bundle "clang.arc.attachedcall" as those
6005 // cases are handled in verifyAttachedCallBundle.
6006 Check((!F->isIntrinsic() ||
6007 (CBI && &CBI->getCalledOperandUse() == &I.getOperandUse(i)) ||
6008 IsAttachedCallOperand(F, CBI, i)),
6009 "Cannot take the address of an intrinsic!", &I);
6010 Check(!F->isIntrinsic() || isa<CallInst>(I) || isa<CallBrInst>(I) ||
6011 F->getIntrinsicID() == Intrinsic::donothing ||
6012 F->getIntrinsicID() == Intrinsic::seh_try_begin ||
6013 F->getIntrinsicID() == Intrinsic::seh_try_end ||
6014 F->getIntrinsicID() == Intrinsic::seh_scope_begin ||
6015 F->getIntrinsicID() == Intrinsic::seh_scope_end ||
6016 F->getIntrinsicID() == Intrinsic::coro_resume ||
6017 F->getIntrinsicID() == Intrinsic::coro_destroy ||
6018 F->getIntrinsicID() == Intrinsic::coro_await_suspend_void ||
6019 F->getIntrinsicID() == Intrinsic::coro_await_suspend_bool ||
6020 F->getIntrinsicID() == Intrinsic::coro_await_suspend_handle ||
6021 F->getIntrinsicID() ==
6022 Intrinsic::experimental_patchpoint_void ||
6023 F->getIntrinsicID() == Intrinsic::experimental_patchpoint ||
6024 F->getIntrinsicID() == Intrinsic::fake_use ||
6025 F->getIntrinsicID() == Intrinsic::experimental_gc_statepoint ||
6026 F->getIntrinsicID() == Intrinsic::wasm_throw ||
6027 F->getIntrinsicID() == Intrinsic::wasm_rethrow ||
6028 IsAttachedCallOperand(F, CBI, i),
6029 "Cannot invoke an intrinsic other than donothing, patchpoint, "
6030 "statepoint, coro_resume, coro_destroy, clang.arc.attachedcall or "
6031 "wasm.(re)throw",
6032 &I);
6033 Check(F->getParent() == &M, "Referencing function in another module!", &I,
6034 &M, F, F->getParent());
6035 } else if (auto *OpBB = dyn_cast<BasicBlock>(Val: I.getOperand(i))) {
6036 Check(OpBB->getParent() == BB->getParent(),
6037 "Referring to a basic block in another function!", &I);
6038 } else if (auto *OpArg = dyn_cast<Argument>(Val: I.getOperand(i))) {
6039 Check(OpArg->getParent() == BB->getParent(),
6040 "Referring to an argument in another function!", &I);
6041 } else if (auto *GV = dyn_cast<GlobalValue>(Val: I.getOperand(i))) {
6042 Check(GV->getParent() == &M, "Referencing global in another module!", &I,
6043 &M, GV, GV->getParent());
6044 } else if (auto *OpInst = dyn_cast<Instruction>(Val: I.getOperand(i))) {
6045 Check(OpInst->getFunction() == BB->getParent(),
6046 "Referring to an instruction in another function!", &I);
6047 verifyDominatesUse(I, i);
6048 } else if (isa<InlineAsm>(Val: I.getOperand(i))) {
6049 Check(CBI && &CBI->getCalledOperandUse() == &I.getOperandUse(i),
6050 "Cannot take the address of an inline asm!", &I);
6051 } else if (auto *C = dyn_cast<Constant>(Val: I.getOperand(i))) {
6052 visitConstantExprsRecursively(EntryC: C);
6053 }
6054 }
6055
6056 if (MDNode *MD = I.getMetadata(KindID: LLVMContext::MD_fpmath)) {
6057 Check(FPMathOperator::isSupportedFloatingPointType(I.getType()),
6058 "fpmath requires a floating point result!", &I);
6059 Check(MD->getNumOperands() == 1, "fpmath takes one operand!", &I);
6060 if (ConstantFP *CFP0 =
6061 mdconst::dyn_extract_or_null<ConstantFP>(MD: MD->getOperand(I: 0))) {
6062 const APFloat &Accuracy = CFP0->getValueAPF();
6063 Check(&Accuracy.getSemantics() == &APFloat::IEEEsingle(),
6064 "fpmath accuracy must have float type", &I);
6065 Check(Accuracy.isFiniteNonZero() && !Accuracy.isNegative(),
6066 "fpmath accuracy not a positive number!", &I);
6067 } else {
6068 Check(false, "invalid fpmath accuracy!", &I);
6069 }
6070 }
6071
6072 if (MDNode *Range = I.getMetadata(KindID: LLVMContext::MD_range)) {
6073 Check(isa<LoadInst>(I) || isa<CallInst>(I) || isa<InvokeInst>(I),
6074 "Ranges are only for loads, calls and invokes!", &I);
6075 visitRangeMetadata(I, Range, Ty: I.getType());
6076 }
6077
6078 if (MDNode *MD = I.getMetadata(KindID: LLVMContext::MD_nofpclass)) {
6079 Check(isa<LoadInst>(I), "nofpclass is only for loads", &I);
6080 visitNoFPClassMetadata(I, NoFPClass: MD, Ty: I.getType());
6081 }
6082
6083 if (MDNode *Range = I.getMetadata(KindID: LLVMContext::MD_noalias_addrspace)) {
6084 Check(isa<LoadInst>(I) || isa<StoreInst>(I) || isa<AtomicRMWInst>(I) ||
6085 isa<AtomicCmpXchgInst>(I) || isa<CallInst>(I),
6086 "noalias.addrspace are only for memory operations!", &I);
6087 visitNoaliasAddrspaceMetadata(I, Range, Ty: I.getType());
6088 }
6089
6090 if (I.hasMetadata(KindID: LLVMContext::MD_invariant_group)) {
6091 Check(isa<LoadInst>(I) || isa<StoreInst>(I),
6092 "invariant.group metadata is only for loads and stores", &I);
6093 }
6094
6095 if (I.hasMetadata(KindID: LLVMContext::MD_invariant_load)) {
6096 auto *II = dyn_cast<IntrinsicInst>(Val: &I);
6097 Check(isa<LoadInst>(I) || (II && II->onlyReadsMemory()),
6098 "invariant.load metadata is only for loads and readonly "
6099 "intrinsic calls",
6100 &I);
6101 }
6102
6103 if (MDNode *MD = I.getMetadata(KindID: LLVMContext::MD_nonnull)) {
6104 Check(I.getType()->isPointerTy(), "nonnull applies only to pointer types",
6105 &I);
6106 Check(isa<LoadInst>(I),
6107 "nonnull applies only to load instructions, use attributes"
6108 " for calls or invokes",
6109 &I);
6110 Check(MD->getNumOperands() == 0, "nonnull metadata must be empty", &I);
6111 }
6112
6113 if (MDNode *MD = I.getMetadata(KindID: LLVMContext::MD_noundef)) {
6114 Check(isa<LoadInst>(I), "noundef applies only to load instructions", &I);
6115 Check(MD->getNumOperands() == 0, "noundef metadata must be empty", &I);
6116 }
6117
6118 if (MDNode *MD = I.getMetadata(KindID: LLVMContext::MD_dereferenceable))
6119 visitDereferenceableMetadata(I, MD);
6120
6121 if (MDNode *MD = I.getMetadata(KindID: LLVMContext::MD_dereferenceable_or_null))
6122 visitDereferenceableMetadata(I, MD);
6123
6124 if (MDNode *MD = I.getMetadata(KindID: LLVMContext::MD_nofreeobj))
6125 visitNoFreeObjMetadata(I, MD);
6126
6127 if (MDNode *TBAA = I.getMetadata(KindID: LLVMContext::MD_tbaa))
6128 TBAAVerifyHelper.visitTBAAMetadata(I: &I, MD: TBAA);
6129
6130 if (MDNode *TBAAStruct = I.getMetadata(KindID: LLVMContext::MD_tbaa_struct))
6131 TBAAVerifyHelper.visitTBAAStructMetadata(I: &I, MD: TBAAStruct);
6132
6133 if (MDNode *MD = I.getMetadata(KindID: LLVMContext::MD_noalias))
6134 visitAliasScopeListMetadata(MD);
6135 if (MDNode *MD = I.getMetadata(KindID: LLVMContext::MD_alias_scope))
6136 visitAliasScopeListMetadata(MD);
6137
6138 if (MDNode *MD = I.getMetadata(KindID: LLVMContext::MD_access_group))
6139 visitAccessGroupMetadata(MD);
6140
6141 if (MDNode *AlignMD = I.getMetadata(KindID: LLVMContext::MD_align)) {
6142 Check(I.getType()->isPointerTy(), "align applies only to pointer types",
6143 &I);
6144 Check(isa<LoadInst>(I),
6145 "align applies only to load instructions, "
6146 "use attributes for calls or invokes",
6147 &I);
6148 Check(AlignMD->getNumOperands() == 1, "align takes one operand!", &I);
6149 ConstantInt *CI = mdconst::dyn_extract<ConstantInt>(MD: AlignMD->getOperand(I: 0));
6150 Check(CI && CI->getType()->isIntegerTy(64),
6151 "align metadata value must be an i64!", &I);
6152 uint64_t Align = CI->getZExtValue();
6153 Check(isPowerOf2_64(Align), "align metadata value must be a power of 2!",
6154 &I);
6155 Check(Align <= Value::MaximumAlignment,
6156 "alignment is larger that implementation defined limit", &I);
6157 }
6158
6159 if (MDNode *MD = I.getMetadata(KindID: LLVMContext::MD_prof))
6160 visitProfMetadata(I, MD);
6161
6162 if (MDNode *MD = I.getMetadata(KindID: LLVMContext::MD_memprof))
6163 visitMemProfMetadata(I, MD);
6164
6165 if (MDNode *MD = I.getMetadata(KindID: LLVMContext::MD_callsite))
6166 visitCallsiteMetadata(I, MD);
6167
6168 if (MDNode *MD = I.getMetadata(KindID: LLVMContext::MD_callee_type))
6169 visitCalleeTypeMetadata(I, MD);
6170
6171 if (MDNode *MD = I.getMetadata(KindID: LLVMContext::MD_DIAssignID))
6172 visitDIAssignIDMetadata(I, MD);
6173
6174 if (MDNode *MMRA = I.getMetadata(KindID: LLVMContext::MD_mmra))
6175 visitMMRAMetadata(I, MD: MMRA);
6176
6177 if (MDNode *Annotation = I.getMetadata(KindID: LLVMContext::MD_annotation))
6178 visitAnnotationMetadata(Annotation);
6179
6180 if (MDNode *Captures = I.getMetadata(KindID: LLVMContext::MD_captures))
6181 visitCapturesMetadata(I, Captures);
6182
6183 if (MDNode *MD = I.getMetadata(KindID: LLVMContext::MD_alloc_token))
6184 visitAllocTokenMetadata(I, MD);
6185
6186 if (MDNode *MD = I.getMetadata(KindID: LLVMContext::MD_inline_history))
6187 visitInlineHistoryMetadata(I, MD);
6188
6189 if (MDNode *MD = I.getMetadata(KindID: LLVMContext::MD_mem_cache_hint))
6190 visitMemCacheHintMetadata(I, MD);
6191
6192 if (MDNode *MD = I.getMetadata(Kind: "amdgpu.expected.active.lanes")) {
6193 Check(MD->getNumOperands() == 1,
6194 "!amdgpu.expected.active.lanes must have exactly one operand", &I,
6195 MD);
6196 ConstantInt *CI =
6197 mdconst::dyn_extract_or_null<ConstantInt>(MD: MD->getOperand(I: 0));
6198 Check(CI && CI->getType()->isIntegerTy(32),
6199 "!amdgpu.expected.active.lanes operand must be an i32 constant", &I,
6200 MD);
6201 }
6202
6203 if (MDNode *N = I.getDebugLoc().getAsMDNode()) {
6204 CheckDI(isa<DILocation>(N), "invalid !dbg metadata attachment", &I, N);
6205 visitMDNode(BaseMD: *N, AllowLocs: AreDebugLocsAllowed::Yes);
6206
6207 if (auto *DL = dyn_cast<DILocation>(Val: N)) {
6208 if (DL->getAtomGroup()) {
6209 DISubprogram *SP = getSubprogram(LocalScope: DL->getRawScope());
6210 CheckDI(SP && SP->getKeyInstructionsEnabled(),
6211 "DbgLoc uses atomGroup but DISubprogram doesn't have Key "
6212 "Instructions enabled",
6213 DL, SP);
6214 }
6215 }
6216 }
6217
6218 SmallVector<std::pair<unsigned, MDNode *>, 4> MDs;
6219 I.getAllMetadata(MDs);
6220 for (auto Attachment : MDs) {
6221 unsigned Kind = Attachment.first;
6222 auto AllowLocs =
6223 (Kind == LLVMContext::MD_dbg || Kind == LLVMContext::MD_loop)
6224 ? AreDebugLocsAllowed::Yes
6225 : AreDebugLocsAllowed::No;
6226 visitMDNode(BaseMD: *Attachment.second, AllowLocs);
6227 }
6228
6229 InstsInThisBlock.insert(Ptr: &I);
6230}
6231
6232/// Allow intrinsics to be verified in different ways.
6233void Verifier::visitIntrinsicCall(Intrinsic::ID ID, CallBase &Call) {
6234 Function *IF = Call.getCalledFunction();
6235
6236 // If the intrinsic takes MDNode arguments, verify that they are either global
6237 // or are local to *this* function.
6238 for (Value *V : Call.args()) {
6239 if (auto *MD = dyn_cast<MetadataAsValue>(Val: V))
6240 visitMetadataAsValue(MDV: *MD, F: Call.getCaller());
6241 if (auto *Const = dyn_cast<Constant>(Val: V))
6242 Check(!Const->getType()->isX86_AMXTy(),
6243 "const x86_amx is not allowed in argument!");
6244 }
6245
6246 // Verify intrinsic signature, so following checks can rely on it. The actual
6247 // error is reported at the intrinsic declaration.
6248 SmallVector<Type *, 4> OverloadTys;
6249 if (!Intrinsic::isSignatureValid(ID, FT: Call.getFunctionType(), OverloadTys))
6250 return;
6251
6252 switch (ID) {
6253 default:
6254 break;
6255 case Intrinsic::assume: {
6256 if (Call.hasOperandBundles()) {
6257 auto *Cond = dyn_cast<ConstantInt>(Val: Call.getArgOperand(i: 0));
6258 Check(Cond && Cond->isOne(),
6259 "assume with operand bundles must have i1 true condition", Call);
6260 }
6261 for (auto OBU : Call.operand_bundles()) {
6262 // Separate storage assumptions are special insofar as they're the only
6263 // operand bundles allowed on assumes that aren't parameter attributes.
6264
6265 auto GetTypeAt = [&](unsigned Index) {
6266 return OBU.Inputs[Index]->getType();
6267 };
6268
6269 switch (getBundleAttrFromOBU(OBU)) {
6270 case BundleAttr::None:
6271 CheckFailed(Message: "tags must be valid attribute names", V1: Call);
6272 break;
6273 case BundleAttr::Align:
6274 Check(OBU.Inputs.size() >= 2 && OBU.Inputs.size() <= 3,
6275 "alignment assumptions should have 2 or 3 arguments", Call);
6276 Check(GetTypeAt(0)->isPointerTy(), "first argument should be a pointer",
6277 Call);
6278 Check(GetTypeAt(1)->isIntegerTy() &&
6279 GetTypeAt(1)->getIntegerBitWidth() <= 64,
6280 "second argument should be an integer with a maximum width of 64 "
6281 "bits",
6282 Call);
6283 Check(OBU.Inputs.size() < 3 ||
6284 (GetTypeAt(2)->isIntegerTy() &&
6285 GetTypeAt(2)->getIntegerBitWidth() <= 64),
6286 "third argument should be an integer with a maximum width of 64 "
6287 "bits if present",
6288 Call);
6289 break;
6290 case BundleAttr::Cold:
6291 Check(OBU.Inputs.size() == 0,
6292 "cold assumptions should have no arguments", Call);
6293 break;
6294 case BundleAttr::Dereferenceable:
6295 case BundleAttr::DereferenceableOrNull:
6296 Check(OBU.Inputs.size() == 2,
6297 "dereferenceable assumptions should have 2 arguments", Call);
6298 Check(GetTypeAt(0)->isPointerTy(), "first argument should be a pointer",
6299 Call);
6300 Check(GetTypeAt(1)->isIntegerTy() &&
6301 GetTypeAt(1)->getIntegerBitWidth() <= 64,
6302 "second argument should be an integer with a maximum width of 64 "
6303 "bits",
6304 Call);
6305 break;
6306 case BundleAttr::Ignore:
6307 break;
6308 case BundleAttr::NonNull:
6309 Check(OBU.Inputs.size() == 1,
6310 "nonnull assumptions should have 1 argument", Call);
6311 Check(GetTypeAt(0)->isPointerTy(), "first argument should be a pointer",
6312 Call);
6313 break;
6314 case BundleAttr::NoUndef:
6315 Check(OBU.Inputs.size() == 1,
6316 "noundef assumptions should have 1 argument", Call);
6317 break;
6318 case BundleAttr::SeparateStorage:
6319 Check(OBU.Inputs.size() == 2,
6320 "separate_storage assumptions should have 2 arguments", Call);
6321 Check(GetTypeAt(0)->isPointerTy() && GetTypeAt(1)->isPointerTy(),
6322 "arguments to separate_storage assumptions should be pointers",
6323 Call);
6324 break;
6325 }
6326 }
6327 break;
6328 }
6329 case Intrinsic::ucmp:
6330 case Intrinsic::scmp: {
6331 Type *SrcTy = Call.getOperand(i_nocapture: 0)->getType();
6332 Type *DestTy = Call.getType();
6333
6334 Check(DestTy->getScalarSizeInBits() >= 2,
6335 "result type must be at least 2 bits wide", Call);
6336
6337 bool IsDestTypeVector = DestTy->isVectorTy();
6338 Check(SrcTy->isVectorTy() == IsDestTypeVector,
6339 "ucmp/scmp argument and result types must both be either vector or "
6340 "scalar types",
6341 Call);
6342 if (IsDestTypeVector) {
6343 auto SrcVecLen = cast<VectorType>(Val: SrcTy)->getElementCount();
6344 auto DestVecLen = cast<VectorType>(Val: DestTy)->getElementCount();
6345 Check(SrcVecLen == DestVecLen,
6346 "return type and arguments must have the same number of "
6347 "elements",
6348 Call);
6349 }
6350 break;
6351 }
6352 case Intrinsic::coro_begin:
6353 case Intrinsic::coro_begin_custom_abi:
6354 Check(isa<AnyCoroIdInst>(Call.getArgOperand(0)),
6355 "id argument of llvm.coro.begin must refer to coro.id");
6356 break;
6357 case Intrinsic::coro_id: {
6358 Check(isa<ConstantInt>(Call.getArgOperand(0)),
6359 "align argument only accepts constants");
6360 auto *Promise = Call.getArgOperand(i: 1);
6361 Check(isa<ConstantPointerNull>(Promise) || isa<AllocaInst>(Promise),
6362 "promise argument must refer to an alloca");
6363
6364 auto *CoroAddr = Call.getArgOperand(i: 2)->stripPointerCastsAndAliases();
6365 bool BeforeCoroEarly = isa<ConstantPointerNull>(Val: CoroAddr);
6366 Check(BeforeCoroEarly || isa<Function>(CoroAddr),
6367 "coro argument must refer to a function");
6368
6369 auto *InfoArg = Call.getArgOperand(i: 3);
6370 bool BeforeCoroSplit = isa<ConstantPointerNull>(Val: InfoArg);
6371 if (BeforeCoroSplit)
6372 break;
6373
6374 Check(!BeforeCoroEarly, "cannot run CoroSplit before CoroEarly");
6375 auto *GV = dyn_cast<GlobalVariable>(Val: InfoArg);
6376 Check(GV && GV->isConstant() && GV->hasDefinitiveInitializer(),
6377 "info argument of llvm.coro.id must refer to an initialized "
6378 "constant");
6379 Constant *Init = GV->getInitializer();
6380 Check(isa<ConstantStruct>(Init) || isa<ConstantArray>(Init),
6381 "info argument of llvm.coro.id must refer to either a struct or "
6382 "an array");
6383 break;
6384 }
6385 case Intrinsic::is_fpclass: {
6386 const ConstantInt *TestMask = cast<ConstantInt>(Val: Call.getOperand(i_nocapture: 1));
6387 Check((TestMask->getZExtValue() & ~static_cast<unsigned>(fcAllFlags)) == 0,
6388 "unsupported bits for llvm.is.fpclass test mask");
6389 break;
6390 }
6391 case Intrinsic::fptrunc_round: {
6392 // Check the rounding mode
6393 Metadata *MD = nullptr;
6394 auto *MAV = dyn_cast<MetadataAsValue>(Val: Call.getOperand(i_nocapture: 1));
6395 if (MAV)
6396 MD = MAV->getMetadata();
6397
6398 Check(MD != nullptr, "missing rounding mode argument", Call);
6399
6400 Check(isa<MDString>(MD),
6401 ("invalid value for llvm.fptrunc.round metadata operand"
6402 " (the operand should be a string)"),
6403 MD);
6404
6405 std::optional<RoundingMode> RoundMode =
6406 convertStrToRoundingMode(cast<MDString>(Val: MD)->getString());
6407 Check(RoundMode && *RoundMode != RoundingMode::Dynamic,
6408 "unsupported rounding mode argument", Call);
6409 break;
6410 }
6411 case Intrinsic::convert_to_arbitrary_fp: {
6412 // Check that vector element counts are consistent.
6413 Type *ValueTy = Call.getArgOperand(i: 0)->getType();
6414 Type *IntTy = Call.getType();
6415
6416 if (auto *ValueVecTy = dyn_cast<VectorType>(Val: ValueTy)) {
6417 auto *IntVecTy = dyn_cast<VectorType>(Val: IntTy);
6418 Check(IntVecTy,
6419 "if floating-point operand is a vector, integer operand must also "
6420 "be a vector",
6421 Call);
6422 Check(ValueVecTy->getElementCount() == IntVecTy->getElementCount(),
6423 "floating-point and integer vector operands must have the same "
6424 "element count",
6425 Call);
6426 }
6427
6428 // Check interpretation metadata (argoperand 1).
6429 auto *InterpMAV = dyn_cast<MetadataAsValue>(Val: Call.getArgOperand(i: 1));
6430 Check(InterpMAV, "missing interpretation metadata operand", Call);
6431 auto *InterpStr = dyn_cast<MDString>(Val: InterpMAV->getMetadata());
6432 Check(InterpStr, "interpretation metadata operand must be a string", Call);
6433 StringRef Interp = InterpStr->getString();
6434
6435 Check(!Interp.empty(), "interpretation metadata string must not be empty",
6436 Call);
6437
6438 // Valid interpretation strings: mini-float format names.
6439 Check(APFloatBase::isValidArbitraryFPFormat(Interp),
6440 "unsupported interpretation metadata string", Call);
6441
6442 // The integer type width must equal the arbitrary FP format width.
6443 if (unsigned FormatBits =
6444 APFloatBase::getArbitraryFPFormatSizeInBits(Format: Interp))
6445 Check(IntTy->getScalarSizeInBits() == FormatBits,
6446 "integer type bit width must equal the arbitrary FP format width",
6447 Call);
6448
6449 // Check rounding mode metadata (argoperand 2).
6450 auto *RoundingMAV = dyn_cast<MetadataAsValue>(Val: Call.getArgOperand(i: 2));
6451 Check(RoundingMAV, "missing rounding mode metadata operand", Call);
6452 auto *RoundingStr = dyn_cast<MDString>(Val: RoundingMAV->getMetadata());
6453 Check(RoundingStr, "rounding mode metadata operand must be a string", Call);
6454
6455 std::optional<RoundingMode> RM =
6456 convertStrToRoundingMode(RoundingStr->getString());
6457 Check(RM && *RM != RoundingMode::Dynamic,
6458 "unsupported rounding mode argument", Call);
6459 break;
6460 }
6461 case Intrinsic::convert_from_arbitrary_fp: {
6462 // Check that vector element counts are consistent.
6463 Type *IntTy = Call.getArgOperand(i: 0)->getType();
6464 Type *ValueTy = Call.getType();
6465
6466 if (auto *ValueVecTy = dyn_cast<VectorType>(Val: ValueTy)) {
6467 auto *IntVecTy = dyn_cast<VectorType>(Val: IntTy);
6468 Check(IntVecTy,
6469 "if floating-point operand is a vector, integer operand must also "
6470 "be a vector",
6471 Call);
6472 Check(ValueVecTy->getElementCount() == IntVecTy->getElementCount(),
6473 "floating-point and integer vector operands must have the same "
6474 "element count",
6475 Call);
6476 }
6477
6478 // Check interpretation metadata (argoperand 1).
6479 auto *InterpMAV = dyn_cast<MetadataAsValue>(Val: Call.getArgOperand(i: 1));
6480 Check(InterpMAV, "missing interpretation metadata operand", Call);
6481 auto *InterpStr = dyn_cast<MDString>(Val: InterpMAV->getMetadata());
6482 Check(InterpStr, "interpretation metadata operand must be a string", Call);
6483 StringRef Interp = InterpStr->getString();
6484
6485 Check(!Interp.empty(), "interpretation metadata string must not be empty",
6486 Call);
6487
6488 // Valid interpretation strings: mini-float format names.
6489 Check(APFloatBase::isValidArbitraryFPFormat(Interp),
6490 "unsupported interpretation metadata string", Call);
6491
6492 // The integer type width must equal the arbitrary FP format width.
6493 if (unsigned FormatBits =
6494 APFloatBase::getArbitraryFPFormatSizeInBits(Format: Interp))
6495 Check(IntTy->getScalarSizeInBits() == FormatBits,
6496 "integer type bit width must equal the arbitrary FP format width",
6497 Call);
6498 break;
6499 }
6500#define BEGIN_REGISTER_VP_INTRINSIC(VPID, ...) case Intrinsic::VPID:
6501#include "llvm/IR/VPIntrinsics.def"
6502#undef BEGIN_REGISTER_VP_INTRINSIC
6503 visitVPIntrinsic(VPI&: cast<VPIntrinsic>(Val&: Call));
6504 break;
6505#define INSTRUCTION(NAME, NARGS, ROUND_MODE, INTRINSIC) \
6506 case Intrinsic::INTRINSIC:
6507#include "llvm/IR/ConstrainedOps.def"
6508#undef INSTRUCTION
6509 visitConstrainedFPIntrinsic(FPI&: cast<ConstrainedFPIntrinsic>(Val&: Call));
6510 break;
6511 case Intrinsic::dbg_declare: // llvm.dbg.declare
6512 case Intrinsic::dbg_value: // llvm.dbg.value
6513 case Intrinsic::dbg_assign: // llvm.dbg.assign
6514 case Intrinsic::dbg_label: // llvm.dbg.label
6515 // We no longer interpret debug intrinsics (the old variable-location
6516 // design). They're meaningless as far as LLVM is concerned we could make
6517 // it an error for them to appear, but it's possible we'll have users
6518 // converting back to intrinsics for the forseeable future (such as DXIL),
6519 // so tolerate their existance.
6520 break;
6521 case Intrinsic::memcpy:
6522 case Intrinsic::memcpy_inline:
6523 case Intrinsic::memmove:
6524 case Intrinsic::memset:
6525 case Intrinsic::memset_inline:
6526 break;
6527 case Intrinsic::experimental_memset_pattern: {
6528 const auto Memset = cast<MemSetPatternInst>(Val: &Call);
6529 Check(Memset->getValue()->getType()->isSized(),
6530 "unsized types cannot be used as memset patterns", Call);
6531 break;
6532 }
6533 case Intrinsic::memcpy_element_unordered_atomic:
6534 case Intrinsic::memmove_element_unordered_atomic:
6535 case Intrinsic::memset_element_unordered_atomic: {
6536 const auto *AMI = cast<AnyMemIntrinsic>(Val: &Call);
6537
6538 ConstantInt *ElementSizeCI =
6539 cast<ConstantInt>(Val: AMI->getRawElementSizeInBytes());
6540 const APInt &ElementSizeVal = ElementSizeCI->getValue();
6541 Check(ElementSizeVal.isPowerOf2(),
6542 "element size of the element-wise atomic memory intrinsic "
6543 "must be a power of 2",
6544 Call);
6545
6546 auto IsValidAlignment = [&](MaybeAlign Alignment) {
6547 return Alignment && ElementSizeVal.ule(RHS: Alignment->value());
6548 };
6549 Check(IsValidAlignment(AMI->getDestAlign()),
6550 "incorrect alignment of the destination argument", Call);
6551 if (const auto *AMT = dyn_cast<AnyMemTransferInst>(Val: AMI)) {
6552 Check(IsValidAlignment(AMT->getSourceAlign()),
6553 "incorrect alignment of the source argument", Call);
6554 }
6555 break;
6556 }
6557 case Intrinsic::call_preallocated_setup: {
6558 auto *NumArgs = cast<ConstantInt>(Val: Call.getArgOperand(i: 0));
6559 bool FoundCall = false;
6560 for (User *U : Call.users()) {
6561 auto *UseCall = dyn_cast<CallBase>(Val: U);
6562 Check(UseCall != nullptr,
6563 "Uses of llvm.call.preallocated.setup must be calls");
6564 Intrinsic::ID IID = UseCall->getIntrinsicID();
6565 if (IID == Intrinsic::call_preallocated_arg) {
6566 auto *AllocArgIndex = dyn_cast<ConstantInt>(Val: UseCall->getArgOperand(i: 1));
6567 Check(AllocArgIndex != nullptr,
6568 "llvm.call.preallocated.alloc arg index must be a constant");
6569 auto AllocArgIndexInt = AllocArgIndex->getValue();
6570 Check(AllocArgIndexInt.sge(0) &&
6571 AllocArgIndexInt.slt(NumArgs->getValue()),
6572 "llvm.call.preallocated.alloc arg index must be between 0 and "
6573 "corresponding "
6574 "llvm.call.preallocated.setup's argument count");
6575 } else if (IID == Intrinsic::call_preallocated_teardown) {
6576 // nothing to do
6577 } else {
6578 Check(!FoundCall, "Can have at most one call corresponding to a "
6579 "llvm.call.preallocated.setup");
6580 FoundCall = true;
6581 size_t NumPreallocatedArgs = 0;
6582 for (unsigned i = 0; i < UseCall->arg_size(); i++) {
6583 if (UseCall->paramHasAttr(ArgNo: i, Kind: Attribute::Preallocated)) {
6584 ++NumPreallocatedArgs;
6585 }
6586 }
6587 Check(NumPreallocatedArgs != 0,
6588 "cannot use preallocated intrinsics on a call without "
6589 "preallocated arguments");
6590 Check(NumArgs->equalsInt(NumPreallocatedArgs),
6591 "llvm.call.preallocated.setup arg size must be equal to number "
6592 "of preallocated arguments "
6593 "at call site",
6594 Call, *UseCall);
6595 // getOperandBundle() cannot be called if more than one of the operand
6596 // bundle exists. There is already a check elsewhere for this, so skip
6597 // here if we see more than one.
6598 if (UseCall->countOperandBundlesOfType(ID: LLVMContext::OB_preallocated) >
6599 1) {
6600 return;
6601 }
6602 auto PreallocatedBundle =
6603 UseCall->getOperandBundle(ID: LLVMContext::OB_preallocated);
6604 Check(PreallocatedBundle,
6605 "Use of llvm.call.preallocated.setup outside intrinsics "
6606 "must be in \"preallocated\" operand bundle");
6607 Check(PreallocatedBundle->Inputs.front().get() == &Call,
6608 "preallocated bundle must have token from corresponding "
6609 "llvm.call.preallocated.setup");
6610 }
6611 }
6612 break;
6613 }
6614 case Intrinsic::call_preallocated_arg: {
6615 auto *Token = dyn_cast<CallBase>(Val: Call.getArgOperand(i: 0));
6616 Check(Token &&
6617 Token->getIntrinsicID() == Intrinsic::call_preallocated_setup,
6618 "llvm.call.preallocated.arg token argument must be a "
6619 "llvm.call.preallocated.setup");
6620 Check(Call.hasFnAttr(Attribute::Preallocated),
6621 "llvm.call.preallocated.arg must be called with a \"preallocated\" "
6622 "call site attribute");
6623 break;
6624 }
6625 case Intrinsic::call_preallocated_teardown: {
6626 auto *Token = dyn_cast<CallBase>(Val: Call.getArgOperand(i: 0));
6627 Check(Token &&
6628 Token->getIntrinsicID() == Intrinsic::call_preallocated_setup,
6629 "llvm.call.preallocated.teardown token argument must be a "
6630 "llvm.call.preallocated.setup");
6631 break;
6632 }
6633 case Intrinsic::gcroot:
6634 case Intrinsic::gcwrite:
6635 case Intrinsic::gcread:
6636 if (ID == Intrinsic::gcroot) {
6637 auto *AI =
6638 dyn_cast<AllocaInst>(Val: Call.getArgOperand(i: 0)->stripPointerCasts());
6639 Check(AI, "llvm.gcroot parameter #1 must be an alloca.", Call);
6640 Check(isa<Constant>(Call.getArgOperand(1)),
6641 "llvm.gcroot parameter #2 must be a constant.", Call);
6642 if (!AI->getAllocatedType()->isPointerTy()) {
6643 Check(!isa<ConstantPointerNull>(Call.getArgOperand(1)),
6644 "llvm.gcroot parameter #1 must either be a pointer alloca, "
6645 "or argument #2 must be a non-null constant.",
6646 Call);
6647 }
6648 }
6649
6650 Check(Call.getParent()->getParent()->hasGC(),
6651 "Enclosing function does not use GC.", Call);
6652 break;
6653 case Intrinsic::init_trampoline:
6654 Check(isa<Function>(Call.getArgOperand(1)->stripPointerCasts()),
6655 "llvm.init_trampoline parameter #2 must resolve to a function.",
6656 Call);
6657 break;
6658 case Intrinsic::reloc_none: {
6659 Check(isa<MDString>(
6660 cast<MetadataAsValue>(Call.getArgOperand(0))->getMetadata()),
6661 "llvm.reloc.none argument must be a metadata string", &Call);
6662 break;
6663 }
6664 case Intrinsic::stackprotector:
6665 Check(isa<AllocaInst>(Call.getArgOperand(1)->stripPointerCasts()),
6666 "llvm.stackprotector parameter #2 must resolve to an alloca.", Call);
6667 break;
6668 case Intrinsic::localescape: {
6669 BasicBlock *BB = Call.getParent();
6670 Check(BB->isEntryBlock(), "llvm.localescape used outside of entry block",
6671 Call);
6672 Check(!SawFrameEscape, "multiple calls to llvm.localescape in one function",
6673 Call);
6674 for (Value *Arg : Call.args()) {
6675 if (isa<ConstantPointerNull>(Val: Arg))
6676 continue; // Null values are allowed as placeholders.
6677 auto *AI = dyn_cast<AllocaInst>(Val: Arg->stripPointerCasts());
6678 Check(AI && AI->isStaticAlloca(),
6679 "llvm.localescape only accepts static allocas", Call);
6680 }
6681 FrameEscapeInfo[BB->getParent()].first = Call.arg_size();
6682 SawFrameEscape = true;
6683 break;
6684 }
6685 case Intrinsic::localrecover: {
6686 Value *FnArg = Call.getArgOperand(i: 0)->stripPointerCasts();
6687 auto *Fn = dyn_cast<Function>(Val: FnArg);
6688 Check(Fn && !Fn->isDeclaration(),
6689 "llvm.localrecover first "
6690 "argument must be function defined in this module",
6691 Call);
6692 auto *IdxArg = cast<ConstantInt>(Val: Call.getArgOperand(i: 2));
6693 auto &Entry = FrameEscapeInfo[Fn];
6694 Entry.second = unsigned(
6695 std::max(a: uint64_t(Entry.second), b: IdxArg->getLimitedValue(Limit: ~0U) + 1));
6696 break;
6697 }
6698
6699 case Intrinsic::experimental_gc_statepoint:
6700 if (auto *CI = dyn_cast<CallInst>(Val: &Call))
6701 Check(!CI->isInlineAsm(),
6702 "gc.statepoint support for inline assembly unimplemented", CI);
6703 Check(Call.getParent()->getParent()->hasGC(),
6704 "Enclosing function does not use GC.", Call);
6705
6706 verifyStatepoint(Call);
6707 break;
6708 case Intrinsic::experimental_gc_result: {
6709 Check(Call.getParent()->getParent()->hasGC(),
6710 "Enclosing function does not use GC.", Call);
6711
6712 auto *Statepoint = Call.getArgOperand(i: 0);
6713 if (isa<UndefValue>(Val: Statepoint))
6714 break;
6715
6716 // Are we tied to a statepoint properly?
6717 const auto *StatepointCall = dyn_cast<CallBase>(Val: Statepoint);
6718 Check(StatepointCall && StatepointCall->getIntrinsicID() ==
6719 Intrinsic::experimental_gc_statepoint,
6720 "gc.result operand #1 must be from a statepoint", Call,
6721 Call.getArgOperand(0));
6722
6723 // Check that result type matches wrapped callee.
6724 auto *TargetFuncType =
6725 cast<FunctionType>(Val: StatepointCall->getParamElementType(ArgNo: 2));
6726 Check(Call.getType() == TargetFuncType->getReturnType(),
6727 "gc.result result type does not match wrapped callee", Call);
6728 break;
6729 }
6730 case Intrinsic::experimental_gc_relocate: {
6731 Check(isa<PointerType>(Call.getType()->getScalarType()),
6732 "gc.relocate must return a pointer or a vector of pointers", Call);
6733
6734 // Check that this relocate is correctly tied to the statepoint
6735
6736 // This is case for relocate on the unwinding path of an invoke statepoint
6737 if (auto *LandingPad = dyn_cast<LandingPadInst>(Val: Call.getArgOperand(i: 0))) {
6738
6739 const BasicBlock *InvokeBB =
6740 LandingPad->getParent()->getUniquePredecessor();
6741
6742 // Landingpad relocates should have only one predecessor with invoke
6743 // statepoint terminator
6744 Check(InvokeBB, "safepoints should have unique landingpads",
6745 LandingPad->getParent());
6746 Check(InvokeBB->getTerminator(), "safepoint block should be well formed",
6747 InvokeBB);
6748 Check(isa<GCStatepointInst>(InvokeBB->getTerminator()),
6749 "gc relocate should be linked to a statepoint", InvokeBB);
6750 } else {
6751 // In all other cases relocate should be tied to the statepoint directly.
6752 // This covers relocates on a normal return path of invoke statepoint and
6753 // relocates of a call statepoint.
6754 auto *Token = Call.getArgOperand(i: 0);
6755 Check(isa<GCStatepointInst>(Token) || isa<UndefValue>(Token),
6756 "gc relocate is incorrectly tied to the statepoint", Call, Token);
6757 }
6758
6759 // Verify rest of the relocate arguments.
6760 const Value &StatepointCall = *cast<GCRelocateInst>(Val&: Call).getStatepoint();
6761
6762 // Both the base and derived must be piped through the safepoint.
6763 Value *Base = Call.getArgOperand(i: 1);
6764 Check(isa<ConstantInt>(Base),
6765 "gc.relocate operand #2 must be integer offset", Call);
6766
6767 Value *Derived = Call.getArgOperand(i: 2);
6768 Check(isa<ConstantInt>(Derived),
6769 "gc.relocate operand #3 must be integer offset", Call);
6770
6771 const uint64_t BaseIndex = cast<ConstantInt>(Val: Base)->getZExtValue();
6772 const uint64_t DerivedIndex = cast<ConstantInt>(Val: Derived)->getZExtValue();
6773
6774 // Check the bounds
6775 if (isa<UndefValue>(Val: StatepointCall))
6776 break;
6777 if (auto Opt = cast<GCStatepointInst>(Val: StatepointCall)
6778 .getOperandBundle(ID: LLVMContext::OB_gc_live)) {
6779 Check(BaseIndex < Opt->Inputs.size(),
6780 "gc.relocate: statepoint base index out of bounds", Call);
6781 Check(DerivedIndex < Opt->Inputs.size(),
6782 "gc.relocate: statepoint derived index out of bounds", Call);
6783 }
6784
6785 // Relocated value must be either a pointer type or vector-of-pointer type,
6786 // but gc_relocate does not need to return the same pointer type as the
6787 // relocated pointer. It can be casted to the correct type later if it's
6788 // desired. However, they must have the same address space and 'vectorness'
6789 GCRelocateInst &Relocate = cast<GCRelocateInst>(Val&: Call);
6790 auto *ResultType = Call.getType();
6791 auto *DerivedType = Relocate.getDerivedPtr()->getType();
6792 auto *BaseType = Relocate.getBasePtr()->getType();
6793
6794 Check(BaseType->isPtrOrPtrVectorTy(),
6795 "gc.relocate: relocated value must be a pointer", Call);
6796 Check(DerivedType->isPtrOrPtrVectorTy(),
6797 "gc.relocate: relocated value must be a pointer", Call);
6798
6799 Check(ResultType->isVectorTy() == DerivedType->isVectorTy(),
6800 "gc.relocate: vector relocates to vector and pointer to pointer",
6801 Call);
6802 Check(
6803 ResultType->getPointerAddressSpace() ==
6804 DerivedType->getPointerAddressSpace(),
6805 "gc.relocate: relocating a pointer shouldn't change its address space",
6806 Call);
6807
6808 auto GC = llvm::getGCStrategy(Name: Relocate.getFunction()->getGC());
6809 Check(GC, "gc.relocate: calling function must have GCStrategy",
6810 Call.getFunction());
6811 if (GC) {
6812 auto isGCPtr = [&GC](Type *PTy) {
6813 return GC->isGCManagedPointer(Ty: PTy->getScalarType()).value_or(u: true);
6814 };
6815 Check(isGCPtr(ResultType), "gc.relocate: must return gc pointer", Call);
6816 Check(isGCPtr(BaseType),
6817 "gc.relocate: relocated value must be a gc pointer", Call);
6818 Check(isGCPtr(DerivedType),
6819 "gc.relocate: relocated value must be a gc pointer", Call);
6820 }
6821 break;
6822 }
6823 case Intrinsic::experimental_patchpoint: {
6824 if (Call.getCallingConv() == CallingConv::AnyReg) {
6825 Check(Call.getType()->isSingleValueType(),
6826 "patchpoint: invalid return type used with anyregcc", Call);
6827 }
6828 break;
6829 }
6830 case Intrinsic::eh_exceptioncode:
6831 case Intrinsic::eh_exceptionpointer: {
6832 Check(isa<CatchPadInst>(Call.getArgOperand(0)),
6833 "eh.exceptionpointer argument must be a catchpad", Call);
6834 break;
6835 }
6836 case Intrinsic::get_active_lane_mask: {
6837 Type *ElemTy = Call.getType()->getScalarType();
6838 Check(ElemTy->isIntegerTy(1),
6839 "get_active_lane_mask: element type is not i1", Call);
6840 break;
6841 }
6842 case Intrinsic::mask_beforefirst: {
6843 Check(Call.getType()->getScalarType()->isIntegerTy(1),
6844 "mask.beforefirst element type must be i1", Call);
6845 break;
6846 }
6847 case Intrinsic::experimental_get_vector_length: {
6848 auto *VF = cast<ConstantInt>(Val: Call.getArgOperand(i: 1));
6849 Check(!VF->isNegative() && !VF->isZero(),
6850 "get_vector_length: VF must be positive", Call);
6851 break;
6852 }
6853 case Intrinsic::experimental_guard: {
6854 Check(isa<CallInst>(Call), "experimental_guard cannot be invoked", Call);
6855 Check(Call.countOperandBundlesOfType(LLVMContext::OB_deopt) == 1,
6856 "experimental_guard must have exactly one "
6857 "\"deopt\" operand bundle");
6858 break;
6859 }
6860
6861 case Intrinsic::experimental_deoptimize: {
6862 Check(isa<CallInst>(Call), "experimental_deoptimize cannot be invoked",
6863 Call);
6864 Check(Call.countOperandBundlesOfType(LLVMContext::OB_deopt) == 1,
6865 "experimental_deoptimize must have exactly one "
6866 "\"deopt\" operand bundle");
6867 Check(Call.getType() == Call.getFunction()->getReturnType(),
6868 "experimental_deoptimize return type must match caller return type");
6869
6870 if (isa<CallInst>(Val: Call)) {
6871 auto *RI = dyn_cast<ReturnInst>(Val: Call.getNextNode());
6872 Check(RI,
6873 "calls to experimental_deoptimize must be followed by a return");
6874
6875 if (!Call.getType()->isVoidTy() && RI)
6876 Check(RI->getReturnValue() == &Call,
6877 "calls to experimental_deoptimize must be followed by a return "
6878 "of the value computed by experimental_deoptimize");
6879 }
6880
6881 break;
6882 }
6883 case Intrinsic::vastart: {
6884 Check(Call.getFunction()->isVarArg(),
6885 "va_start called in a non-varargs function");
6886 break;
6887 }
6888 case Intrinsic::get_dynamic_area_offset: {
6889 Check(DL.getPointerSizeInBits(DL.getAllocaAddrSpace()) ==
6890 Call.getType()->getIntegerBitWidth(),
6891 "get_dynamic_area_offset result type must match alloca address "
6892 "space width",
6893 Call);
6894 break;
6895 }
6896 case Intrinsic::smul_fix:
6897 case Intrinsic::smul_fix_sat:
6898 case Intrinsic::umul_fix:
6899 case Intrinsic::umul_fix_sat:
6900 case Intrinsic::sdiv_fix:
6901 case Intrinsic::sdiv_fix_sat:
6902 case Intrinsic::udiv_fix:
6903 case Intrinsic::udiv_fix_sat: {
6904 Value *Op1 = Call.getArgOperand(i: 0);
6905 auto *Op3 = cast<ConstantInt>(Val: Call.getArgOperand(i: 2));
6906
6907 if (ID == Intrinsic::smul_fix || ID == Intrinsic::smul_fix_sat ||
6908 ID == Intrinsic::sdiv_fix || ID == Intrinsic::sdiv_fix_sat) {
6909 Check(Op3->getZExtValue() < Op1->getType()->getScalarSizeInBits(),
6910 "the scale of s[mul|div]_fix[_sat] must be less than the width of "
6911 "the operands");
6912 } else {
6913 Check(Op3->getZExtValue() <= Op1->getType()->getScalarSizeInBits(),
6914 "the scale of u[mul|div]_fix[_sat] must be less than or equal "
6915 "to the width of the operands");
6916 }
6917 break;
6918 }
6919 case Intrinsic::lrint:
6920 case Intrinsic::llrint:
6921 case Intrinsic::lround:
6922 case Intrinsic::llround: {
6923 Type *ValTy = Call.getArgOperand(i: 0)->getType();
6924 Type *ResultTy = Call.getType();
6925 Check(ValTy->isVectorTy() == ResultTy->isVectorTy(),
6926 IF->getName() + ": argument and result disagree on vector use",
6927 &Call);
6928 if (auto *VTy = dyn_cast<VectorType>(Val: ValTy)) {
6929 auto *RTy = dyn_cast<VectorType>(Val: ResultTy);
6930 Check(VTy->getElementCount() == RTy->getElementCount(),
6931 IF->getName() + ": argument must be same length as result", &Call);
6932 }
6933 break;
6934 }
6935 case Intrinsic::bswap: {
6936 Type *Ty = Call.getType();
6937 unsigned Size = Ty->getScalarSizeInBits();
6938 Check(Size % 16 == 0, "bswap must be an even number of bytes", &Call);
6939 break;
6940 }
6941 case Intrinsic::invariant_start: {
6942 auto *InvariantSize = dyn_cast<ConstantInt>(Val: Call.getArgOperand(i: 0));
6943 Check(InvariantSize &&
6944 (!InvariantSize->isNegative() || InvariantSize->isMinusOne()),
6945 "invariant_start parameter must be -1, 0 or a positive number",
6946 &Call);
6947 break;
6948 }
6949 case Intrinsic::matrix_multiply:
6950 case Intrinsic::matrix_transpose:
6951 case Intrinsic::matrix_column_major_load:
6952 case Intrinsic::matrix_column_major_store: {
6953 Function *IF = Call.getCalledFunction();
6954 Value *Stride = nullptr;
6955 ConstantInt *NumRows;
6956 ConstantInt *NumColumns;
6957 FixedVectorType *ResultTy;
6958 Type *Op0ElemTy = nullptr;
6959 Type *Op1ElemTy = nullptr;
6960 switch (ID) {
6961 case Intrinsic::matrix_multiply: {
6962 NumRows = cast<ConstantInt>(Val: Call.getArgOperand(i: 2));
6963 ConstantInt *N = cast<ConstantInt>(Val: Call.getArgOperand(i: 3));
6964 NumColumns = cast<ConstantInt>(Val: Call.getArgOperand(i: 4));
6965 auto *Op0Ty = dyn_cast<FixedVectorType>(Val: Call.getArgOperand(i: 0)->getType());
6966 auto *Op1Ty = dyn_cast<FixedVectorType>(Val: Call.getArgOperand(i: 1)->getType());
6967 auto *RetTy = dyn_cast<FixedVectorType>(Val: Call.getType());
6968 Check(Op0Ty && Op1Ty && RetTy,
6969 "Matrix operations require fixed-length vectors!", &Call);
6970 Check(Op0Ty->getNumElements() ==
6971 NumRows->getZExtValue() * N->getZExtValue(),
6972 "First argument of a matrix operation does not match specified "
6973 "shape!");
6974 Check(Op1Ty->getNumElements() ==
6975 N->getZExtValue() * NumColumns->getZExtValue(),
6976 "Second argument of a matrix operation does not match specified "
6977 "shape!");
6978
6979 ResultTy = RetTy;
6980 Op0ElemTy = Op0Ty->getElementType();
6981 Op1ElemTy = Op1Ty->getElementType();
6982 break;
6983 }
6984 case Intrinsic::matrix_transpose: {
6985 NumRows = cast<ConstantInt>(Val: Call.getArgOperand(i: 1));
6986 NumColumns = cast<ConstantInt>(Val: Call.getArgOperand(i: 2));
6987 auto *Op0Ty = dyn_cast<FixedVectorType>(Val: Call.getArgOperand(i: 0)->getType());
6988 auto *RetTy = dyn_cast<FixedVectorType>(Val: Call.getType());
6989 Check(Op0Ty && RetTy, "Matrix operations require fixed-length vectors!",
6990 &Call);
6991 ResultTy = RetTy;
6992 Op0ElemTy = Op0Ty->getElementType();
6993 break;
6994 }
6995 case Intrinsic::matrix_column_major_load: {
6996 Stride = Call.getArgOperand(i: 1);
6997 NumRows = cast<ConstantInt>(Val: Call.getArgOperand(i: 3));
6998 NumColumns = cast<ConstantInt>(Val: Call.getArgOperand(i: 4));
6999 auto *RetTy = dyn_cast<FixedVectorType>(Val: Call.getType());
7000 Check(RetTy, "Matrix operations require fixed-length vectors!", &Call);
7001 ResultTy = RetTy;
7002 break;
7003 }
7004 case Intrinsic::matrix_column_major_store: {
7005 Stride = Call.getArgOperand(i: 2);
7006 NumRows = cast<ConstantInt>(Val: Call.getArgOperand(i: 4));
7007 NumColumns = cast<ConstantInt>(Val: Call.getArgOperand(i: 5));
7008 auto *Op0Ty = dyn_cast<FixedVectorType>(Val: Call.getArgOperand(i: 0)->getType());
7009 Check(Op0Ty, "Matrix operations require fixed-length vectors!", &Call);
7010 ResultTy = Op0Ty;
7011 Op0ElemTy = Op0Ty->getElementType();
7012 break;
7013 }
7014 default:
7015 llvm_unreachable("unexpected intrinsic");
7016 }
7017
7018 Check(ResultTy->getElementType()->isIntegerTy() ||
7019 ResultTy->getElementType()->isFloatingPointTy(),
7020 "Result type must be an integer or floating-point type!", IF);
7021
7022 if (Op0ElemTy)
7023 Check(ResultTy->getElementType() == Op0ElemTy,
7024 "Vector element type mismatch of the result and first operand "
7025 "vector!",
7026 IF);
7027
7028 if (Op1ElemTy)
7029 Check(ResultTy->getElementType() == Op1ElemTy,
7030 "Vector element type mismatch of the result and second operand "
7031 "vector!",
7032 IF);
7033
7034 Check(ResultTy->getNumElements() ==
7035 NumRows->getZExtValue() * NumColumns->getZExtValue(),
7036 "Result of a matrix operation does not fit in the returned vector!");
7037
7038 if (Stride)
7039 Check(Stride->getType()->getIntegerBitWidth() <= 64,
7040 "Stride bitwidth cannot exceed 64!", IF);
7041
7042 break;
7043 }
7044 case Intrinsic::stepvector: {
7045 auto *VecTy = cast<VectorType>(Val: Call.getType());
7046 Check(VecTy->getScalarSizeInBits() >= 8,
7047 "stepvector only supported for vectors of integers "
7048 "with a bitwidth of at least 8.",
7049 &Call);
7050 break;
7051 }
7052 case Intrinsic::experimental_vector_match: {
7053 Value *Op1 = Call.getArgOperand(i: 0);
7054 Value *Op2 = Call.getArgOperand(i: 1);
7055
7056 auto *Op1Ty = cast<VectorType>(Val: Op1->getType());
7057 auto *Op2Ty = cast<VectorType>(Val: Op2->getType());
7058
7059 Check(isa<FixedVectorType>(Op2Ty),
7060 "Second operand must be a fixed length vector.", &Call);
7061 Check(Op1Ty->getElementType() == Op2Ty->getElementType(),
7062 "First two operands must have the same element type.", &Call);
7063 break;
7064 }
7065 case Intrinsic::speculative_load: {
7066 Type *LoadTy = Call.getType();
7067 Check(LoadTy->isByteTy() || LoadTy->isVectorTy(),
7068 "llvm.speculative.load return type must be a byte type or a "
7069 "vector type",
7070 &Call);
7071 if (LoadTy->isByteOrByteVectorTy()) {
7072 unsigned BitWidth = LoadTy->getScalarType()->getByteBitWidth();
7073 Check((BitWidth % 8) == 0,
7074 "llvm.speculative.load byte type must have a bit width that is "
7075 "a multiple of 8",
7076 &Call);
7077 }
7078
7079 uint64_t MinSizeInBits = DL.getTypeSizeInBits(Ty: LoadTy).getKnownMinValue();
7080 Check((MinSizeInBits % 8) == 0 && isPowerOf2_64(MinSizeInBits / 8),
7081 "llvm.speculative.load return type size in bytes must be a "
7082 "positive power of 2",
7083 &Call);
7084
7085 constexpr unsigned NumFixedArgs = 3;
7086 unsigned NumArgs = Call.arg_size();
7087 Check(NumArgs >= NumFixedArgs,
7088 "llvm.speculative.load requires at least 3 arguments", &Call);
7089
7090 Value *PayloadArg = Call.getArgOperand(i: NumFixedArgs - 1);
7091 if (PayloadArg->getType()->isIntegerTy(BitWidth: 64)) {
7092 // Direct form: (ptr, i1 from_end, i64 num_accessible_bytes)
7093 Check(NumArgs == NumFixedArgs,
7094 "llvm.speculative.load direct form has too many arguments", &Call);
7095 } else {
7096 // Oracle form: (ptr, i1 from_end, oracle_fn_ptr, args...)
7097 auto *OracleFn = dyn_cast<Function>(Val: PayloadArg);
7098 Check(OracleFn,
7099 "llvm.speculative.load third argument must be i64 or a direct "
7100 "reference to an oracle function",
7101 &Call);
7102
7103 // Make sure the called oracle matches the attributes of the intrinsic.
7104 Check(OracleFn->onlyReadsMemory() && OracleFn->onlyAccessesArgMemory() &&
7105 OracleFn->doesNotThrow() && OracleFn->hasNoSync() &&
7106 OracleFn->willReturn(),
7107 "llvm.speculative.load oracle function must be nounwind, nosync "
7108 "and willreturn, must not have side effects and may only read "
7109 "memory through its arguments",
7110 &Call);
7111
7112 FunctionType *FTy = OracleFn->getFunctionType();
7113 Check(FTy->getReturnType()->isIntegerTy(64),
7114 "llvm.speculative.load oracle function must return i64", &Call);
7115
7116 Check(!FTy->isVarArg(),
7117 "llvm.speculative.load oracle function must have a fixed argument "
7118 "list",
7119 &Call);
7120 Check(NumArgs - NumFixedArgs == FTy->getNumParams(),
7121 "llvm.speculative.load oracle function argument count mismatch",
7122 &Call);
7123 for (auto [ParamTy, Arg] :
7124 zip_equal(t: FTy->params(), u: drop_begin(RangeOrContainer: Call.args(), N: NumFixedArgs)))
7125 Check(ParamTy == Arg->getType(),
7126 "llvm.speculative.load oracle function argument type mismatch",
7127 &Call);
7128 }
7129 break;
7130 }
7131 case Intrinsic::vector_repeat: {
7132 auto *ResultTy = dyn_cast<ScalableVectorType>(Val: Call.getType());
7133 auto *ArgTy = dyn_cast<FixedVectorType>(Val: Call.getArgOperand(i: 0)->getType());
7134
7135 Check(ArgTy, "vector_repeat argument must be a fixed-length vector.",
7136 &Call);
7137 Check(ResultTy, "vector_repeat result must be a scalable vector.", &Call);
7138 Check(ResultTy->getElementType() == ArgTy->getElementType(),
7139 "vector_repeat argument and result must have the same element "
7140 "type.",
7141 &Call);
7142 Check(ArgTy->getNumElements() == ResultTy->getMinNumElements(),
7143 "vector_repeat argument and result must have the same minimum "
7144 "element count.",
7145 &Call);
7146 break;
7147 }
7148 case Intrinsic::vector_insert: {
7149 Value *Vec = Call.getArgOperand(i: 0);
7150 Value *SubVec = Call.getArgOperand(i: 1);
7151 Value *Idx = Call.getArgOperand(i: 2);
7152 unsigned IdxN = cast<ConstantInt>(Val: Idx)->getZExtValue();
7153
7154 VectorType *VecTy = cast<VectorType>(Val: Vec->getType());
7155 VectorType *SubVecTy = cast<VectorType>(Val: SubVec->getType());
7156
7157 ElementCount VecEC = VecTy->getElementCount();
7158 ElementCount SubVecEC = SubVecTy->getElementCount();
7159 Check(VecTy->getElementType() == SubVecTy->getElementType(),
7160 "vector_insert parameters must have the same element "
7161 "type.",
7162 &Call);
7163 Check(IdxN % SubVecEC.getKnownMinValue() == 0,
7164 "vector_insert index must be a constant multiple of "
7165 "the subvector's known minimum vector length.");
7166
7167 // The only allowed 'mixed' case is inserting a fixed vector into a
7168 // scalable vector.
7169 if (SubVecEC.isScalable()) {
7170 Check(VecEC.isScalable(), "cannot vector_insert a scalable vector into "
7171 "a fixed vector.");
7172 }
7173
7174 // If this insertion is not the 'mixed' case where a fixed vector is
7175 // inserted into a scalable vector, ensure that the insertion of the
7176 // subvector does not overrun the parent vector.
7177 if (VecEC.isScalable() == SubVecEC.isScalable()) {
7178 Check(IdxN < VecEC.getKnownMinValue() &&
7179 IdxN + SubVecEC.getKnownMinValue() <= VecEC.getKnownMinValue(),
7180 "subvector operand of vector_insert would overrun the "
7181 "vector being inserted into.");
7182 }
7183 break;
7184 }
7185 case Intrinsic::vector_extract: {
7186 Value *Vec = Call.getArgOperand(i: 0);
7187 Value *Idx = Call.getArgOperand(i: 1);
7188 unsigned IdxN = cast<ConstantInt>(Val: Idx)->getZExtValue();
7189
7190 VectorType *ResultTy = cast<VectorType>(Val: Call.getType());
7191 VectorType *VecTy = cast<VectorType>(Val: Vec->getType());
7192
7193 ElementCount VecEC = VecTy->getElementCount();
7194 ElementCount ResultEC = ResultTy->getElementCount();
7195
7196 Check(ResultTy->getElementType() == VecTy->getElementType(),
7197 "vector_extract result must have the same element "
7198 "type as the input vector.",
7199 &Call);
7200 Check(IdxN % ResultEC.getKnownMinValue() == 0,
7201 "vector_extract index must be a constant multiple of "
7202 "the result type's known minimum vector length.");
7203
7204 // The only allowed 'mixed' case is extracting a fixed vector from a
7205 // scalable vector.
7206 if (ResultEC.isScalable()) {
7207 Check(VecEC.isScalable(), "cannot vector_extract a scalable vector from "
7208 "a fixed vector.");
7209 }
7210
7211 // If this extraction is not the 'mixed' case where a fixed vector is
7212 // extracted from a scalable vector, ensure that the extraction does not
7213 // overrun the parent vector.
7214 if (VecEC.isScalable() == ResultEC.isScalable()) {
7215 Check(IdxN < VecEC.getKnownMinValue() &&
7216 IdxN + ResultEC.getKnownMinValue() <= VecEC.getKnownMinValue(),
7217 "vector_extract would overrun.");
7218 }
7219 break;
7220 }
7221 case Intrinsic::vector_partial_reduce_fadd:
7222 case Intrinsic::vector_partial_reduce_add: {
7223 VectorType *AccTy = cast<VectorType>(Val: Call.getArgOperand(i: 0)->getType());
7224 VectorType *VecTy = cast<VectorType>(Val: Call.getArgOperand(i: 1)->getType());
7225
7226 unsigned VecWidth = VecTy->getElementCount().getKnownMinValue();
7227 unsigned AccWidth = AccTy->getElementCount().getKnownMinValue();
7228
7229 Check((VecWidth % AccWidth) == 0,
7230 "Invalid vector widths for partial "
7231 "reduction. The width of the input vector "
7232 "must be a positive integer multiple of "
7233 "the width of the accumulator vector.");
7234
7235 Check(AccTy->getElementType() == VecTy->getElementType(),
7236 "The element type of the input vector must match the element type "
7237 "of the accumulator vector.",
7238 &Call);
7239 break;
7240 }
7241 case Intrinsic::experimental_noalias_scope_decl: {
7242 NoAliasScopeDecls.push_back(Elt: cast<IntrinsicInst>(Val: &Call));
7243 break;
7244 }
7245 case Intrinsic::preserve_array_access_index:
7246 case Intrinsic::preserve_struct_access_index:
7247 case Intrinsic::aarch64_ldaxr:
7248 case Intrinsic::aarch64_ldxr:
7249 case Intrinsic::arm_ldaex:
7250 case Intrinsic::arm_ldrex: {
7251 Type *ElemTy = Call.getParamElementType(ArgNo: 0);
7252 Check(ElemTy, "Intrinsic requires elementtype attribute on first argument.",
7253 &Call);
7254 break;
7255 }
7256 case Intrinsic::aarch64_stlxr:
7257 case Intrinsic::aarch64_stxr:
7258 case Intrinsic::arm_stlex:
7259 case Intrinsic::arm_strex: {
7260 Type *ElemTy = Call.getAttributes().getParamElementType(ArgNo: 1);
7261 Check(ElemTy,
7262 "Intrinsic requires elementtype attribute on second argument.",
7263 &Call);
7264 break;
7265 }
7266 case Intrinsic::aarch64_prefetch: {
7267 Check(cast<ConstantInt>(Call.getArgOperand(1))->getZExtValue() < 2,
7268 "write argument to llvm.aarch64.prefetch must be 0 or 1", Call);
7269 Check(cast<ConstantInt>(Call.getArgOperand(2))->getZExtValue() < 4,
7270 "target argument to llvm.aarch64.prefetch must be 0-3", Call);
7271 Check(cast<ConstantInt>(Call.getArgOperand(3))->getZExtValue() < 2,
7272 "stream argument to llvm.aarch64.prefetch must be 0 or 1", Call);
7273 Check(cast<ConstantInt>(Call.getArgOperand(4))->getZExtValue() < 2,
7274 "isdata argument to llvm.aarch64.prefetch must be 0 or 1", Call);
7275 break;
7276 }
7277 case Intrinsic::aarch64_range_prefetch: {
7278 Check(cast<ConstantInt>(Call.getArgOperand(1))->getZExtValue() < 2,
7279 "write argument to llvm.aarch64.range.prefetch must be 0 or 1", Call);
7280 Check(cast<ConstantInt>(Call.getArgOperand(2))->getZExtValue() < 2,
7281 "stream argument to llvm.aarch64.range.prefetch must be 0 or 1",
7282 Call);
7283 break;
7284 }
7285 case Intrinsic::riscv_vsetvli:
7286 case Intrinsic::riscv_vsetvlimax: {
7287 // The result models VLMAX (or a VL bounded by it) and is only defined for
7288 // XLen (i32/i64). Narrower types cannot represent the architectural VLMAX
7289 // range of [1, 65536], which value analyses rely on.
7290 Check(Call.getType()->isIntegerTy(32) || Call.getType()->isIntegerTy(64),
7291 "llvm.riscv.vsetvli/vsetvlimax result must be i32 or i64", &Call);
7292
7293 // VSEW and VLMUL select the vtype and must encode a valid SEW/LMUL pair.
7294 bool HasAVL = ID == Intrinsic::riscv_vsetvli;
7295 unsigned Offset = HasAVL ? 1 : 0;
7296 uint64_t VSEW =
7297 cast<ConstantInt>(Val: Call.getArgOperand(i: Offset))->getZExtValue();
7298 uint64_t VLMUL =
7299 cast<ConstantInt>(Val: Call.getArgOperand(i: Offset + 1))->getZExtValue();
7300 Check(VSEW <= 3, "llvm.riscv.vsetvli/vsetvlimax VSEW must be 0-3", &Call);
7301 Check(VLMUL <= 7 && VLMUL != RISCVVType::LMUL_RESERVED,
7302 "llvm.riscv.vsetvli/vsetvlimax VLMUL is reserved", &Call);
7303 break;
7304 }
7305 case Intrinsic::callbr_landingpad: {
7306 const auto *CBR = dyn_cast<CallBrInst>(Val: Call.getOperand(i_nocapture: 0));
7307 Check(CBR, "intrinstic requires callbr operand", &Call);
7308 if (!CBR)
7309 break;
7310
7311 const BasicBlock *LandingPadBB = Call.getParent();
7312 const BasicBlock *PredBB = LandingPadBB->getUniquePredecessor();
7313 if (!PredBB) {
7314 CheckFailed(Message: "Intrinsic in block must have 1 unique predecessor", V1: &Call);
7315 break;
7316 }
7317 if (!isa<CallBrInst>(Val: PredBB->getTerminator())) {
7318 CheckFailed(Message: "Intrinsic must have corresponding callbr in predecessor",
7319 V1: &Call);
7320 break;
7321 }
7322 Check(llvm::is_contained(CBR->getIndirectDests(), LandingPadBB),
7323 "Intrinsic's corresponding callbr must have intrinsic's parent basic "
7324 "block in indirect destination list",
7325 &Call);
7326 const Instruction &First = *LandingPadBB->begin();
7327 Check(&First == &Call, "No other instructions may proceed intrinsic",
7328 &Call);
7329 break;
7330 }
7331 case Intrinsic::structured_gep: {
7332 // Parser should refuse those 2 cases.
7333 assert(Call.arg_size() >= 1);
7334 assert(Call.getOperand(0)->getType()->isPointerTy());
7335
7336 Check(Call.paramHasAttr(0, Attribute::ElementType),
7337 "Intrinsic first parameter is missing an ElementType attribute",
7338 &Call);
7339
7340 Type *T = Call.getParamAttr(ArgNo: 0, Kind: Attribute::ElementType).getValueAsType();
7341 for (unsigned I = 1; I < Call.arg_size(); ++I) {
7342 Value *Index = Call.getOperand(i_nocapture: I);
7343 auto *CI = dyn_cast<ConstantInt>(Val: Index);
7344 Check(Index->getType()->isIntegerTy(),
7345 "Index operand type must be an integer", &Call);
7346
7347 if (auto *AT = dyn_cast<ArrayType>(Val: T)) {
7348 T = AT->getElementType();
7349 } else if (auto *ST = dyn_cast<StructType>(Val: T)) {
7350 Check(CI, "Indexing into a struct requires a constant int", &Call);
7351 Check(CI->getZExtValue() < ST->getNumElements(),
7352 "Indexing in a struct should be inbounds", &Call);
7353 T = ST->getElementType(N: CI->getZExtValue());
7354 } else if (auto *VT = dyn_cast<VectorType>(Val: T)) {
7355 T = VT->getElementType();
7356 } else {
7357 CheckFailed(Message: "Reached a non-composite type with more indices to process",
7358 V1: &Call);
7359 }
7360 }
7361 break;
7362 }
7363 case Intrinsic::structured_alloca:
7364 Check(Call.hasRetAttr(Attribute::ElementType),
7365 "@llvm.structured.alloca calls require elementtype attribute.",
7366 &Call);
7367 break;
7368 case Intrinsic::nvvm_setmaxnreg_inc_sync_aligned_u32:
7369 case Intrinsic::nvvm_setmaxnreg_dec_sync_aligned_u32: {
7370 Value *V = Call.getArgOperand(i: 0);
7371 unsigned RegCount = cast<ConstantInt>(Val: V)->getZExtValue();
7372 Check(RegCount % 8 == 0,
7373 "reg_count argument to nvvm.setmaxnreg must be in multiples of 8");
7374 break;
7375 }
7376 case Intrinsic::nvvm_cp_async_bulk_global_to_shared_cta:
7377 case Intrinsic::nvvm_cp_async_bulk_global_to_shared_cta_relaxed: {
7378 const unsigned ArgSize = Call.arg_size();
7379 const unsigned FlagValidPatternIndex = ArgSize - 1;
7380 const unsigned IgnoreOOBFlagIndex = 8;
7381 bool IgnoreOOB =
7382 cast<ConstantInt>(Val: Call.getArgOperand(i: IgnoreOOBFlagIndex))->isOne();
7383 const auto *FlagValidPattern =
7384 cast<ConstantInt>(Val: Call.getArgOperand(i: FlagValidPatternIndex));
7385 Check(!IgnoreOOB || FlagValidPattern->isZero(),
7386 "flag_valid_pattern must be 0 (disabled) when ignore_oob is enabled",
7387 &Call);
7388 break;
7389 }
7390 case Intrinsic::experimental_convergence_entry:
7391 case Intrinsic::experimental_convergence_anchor:
7392 break;
7393 case Intrinsic::experimental_convergence_loop:
7394 break;
7395 case Intrinsic::ptrmask: {
7396 Type *Ty0 = Call.getArgOperand(i: 0)->getType();
7397 Type *Ty1 = Call.getArgOperand(i: 1)->getType();
7398 Check(Ty0->isPtrOrPtrVectorTy(),
7399 "llvm.ptrmask intrinsic first argument must be pointer or vector "
7400 "of pointers",
7401 &Call);
7402 Check(
7403 Ty0->isVectorTy() == Ty1->isVectorTy(),
7404 "llvm.ptrmask intrinsic arguments must be both scalars or both vectors",
7405 &Call);
7406 if (Ty0->isVectorTy())
7407 Check(cast<VectorType>(Ty0)->getElementCount() ==
7408 cast<VectorType>(Ty1)->getElementCount(),
7409 "llvm.ptrmask intrinsic arguments must have the same number of "
7410 "elements",
7411 &Call);
7412 Check(DL.getIndexTypeSizeInBits(Ty0) == Ty1->getScalarSizeInBits(),
7413 "llvm.ptrmask intrinsic second argument bitwidth must match "
7414 "pointer index type size of first argument",
7415 &Call);
7416 break;
7417 }
7418 case Intrinsic::thread_pointer: {
7419 Check(Call.getType()->getPointerAddressSpace() ==
7420 DL.getDefaultGlobalsAddressSpace(),
7421 "llvm.thread.pointer intrinsic return type must be for the globals "
7422 "address space",
7423 &Call);
7424 break;
7425 }
7426 case Intrinsic::threadlocal_address: {
7427 const Value &Arg0 = *Call.getArgOperand(i: 0);
7428 Check(isa<GlobalValue>(Arg0),
7429 "llvm.threadlocal.address first argument must be a GlobalValue");
7430 Check(cast<GlobalValue>(Arg0).isThreadLocal(),
7431 "llvm.threadlocal.address operand isThreadLocal() must be true");
7432 break;
7433 }
7434 case Intrinsic::lifetime_start:
7435 case Intrinsic::lifetime_end: {
7436 Value *Ptr = Call.getArgOperand(i: 0);
7437 auto *II = dyn_cast<IntrinsicInst>(Val: Ptr);
7438 Check(isa<AllocaInst>(Ptr) || isa<PoisonValue>(Ptr) ||
7439 (II && II->getIntrinsicID() == Intrinsic::structured_alloca),
7440 "llvm.lifetime.start/end can only be used on alloca or poison",
7441 &Call);
7442 break;
7443 }
7444 case Intrinsic::sponentry: {
7445 const unsigned StackAS = DL.getAllocaAddrSpace();
7446 const Type *RetTy = Call.getFunctionType()->getReturnType();
7447 Check(RetTy->getPointerAddressSpace() == StackAS,
7448 "llvm.sponentry must return a pointer to the stack", &Call);
7449 break;
7450 }
7451 case Intrinsic::write_volatile_register: {
7452 auto *MD = cast<MDNode>(
7453 Val: cast<MetadataAsValue>(Val: Call.getArgOperand(i: 0))->getMetadata());
7454 Check(MD->getNumOperands() == 1 && isa<MDString>(MD->getOperand(0)),
7455 "llvm.write_volatile_register metadata must be a single MDString",
7456 &Call);
7457 break;
7458 }
7459 case Intrinsic::ptrauth_auth_with_pc_and_resign: {
7460 // Verify that the auth key is IA (0) or IB (1), not DA (2) or DB (3)
7461 auto *AuthKey = cast<ConstantInt>(Val: Call.getArgOperand(i: 1));
7462 uint64_t Key = AuthKey->getZExtValue();
7463 Check(Key == 0 || Key == 1,
7464 "ptrauth.auth.with.pc.and.resign key must be IA (0) or IB (1)",
7465 &Call);
7466 break;
7467 }
7468 };
7469
7470 // Verify that there aren't any unmediated control transfers between funclets.
7471 if (IntrinsicInst::mayLowerToFunctionCall(IID: ID)) {
7472 Function *F = Call.getParent()->getParent();
7473 if (F->hasPersonalityFn() &&
7474 isScopedEHPersonality(Pers: classifyEHPersonality(Pers: F->getPersonalityFn()))) {
7475 // Run EH funclet coloring on-demand and cache results for other intrinsic
7476 // calls in this function
7477 if (BlockEHFuncletColors.empty())
7478 BlockEHFuncletColors = colorEHFunclets(F&: *F);
7479
7480 // colorEHFunclets() leaves unreachable blocks colorless. Such a call
7481 // is in no funclet and WinEHPrepare will not see it, so there is
7482 // nothing to check.
7483 BasicBlock *CallBB = Call.getParent();
7484 auto ColorsIt = BlockEHFuncletColors.find(Val: CallBB);
7485 if (ColorsIt != BlockEHFuncletColors.end()) {
7486 // Check for catch-/cleanup-pad in first funclet block
7487 bool InEHFunclet = false;
7488 const ColorVector &CV = ColorsIt->second;
7489 assert(CV.size() > 0 && "Uncolored block");
7490 for (BasicBlock *ColorFirstBB : CV)
7491 if (auto It = ColorFirstBB->getFirstNonPHIIt();
7492 It != ColorFirstBB->end())
7493 if (isa_and_nonnull<FuncletPadInst>(Val: &*It))
7494 InEHFunclet = true;
7495
7496 // Check for funclet operand bundle
7497 bool HasToken = false;
7498 for (unsigned I = 0, E = Call.getNumOperandBundles(); I != E; ++I)
7499 if (Call.getOperandBundleAt(Index: I).getTagID() == LLVMContext::OB_funclet)
7500 HasToken = true;
7501
7502 // This would cause silent code truncation in WinEHPrepare
7503 if (InEHFunclet)
7504 Check(HasToken, "Missing funclet token on intrinsic call", &Call);
7505 }
7506 }
7507 }
7508
7509 // Target-specific intrinsic call checks.
7510 verifyAMDGPUIntrinsicCall(VS&: *this, ID, Call);
7511 verifyNVVMIntrinsicCall(VS&: *this, ID, Call);
7512}
7513
7514/// Carefully grab the subprogram from a local scope.
7515///
7516/// This carefully grabs the subprogram from a local scope, avoiding the
7517/// built-in assertions that would typically fire.
7518DISubprogram *Verifier::getSubprogram(Metadata *LocalScope) {
7519 if (hasDIScopeCycle(S: LocalScope))
7520 return nullptr;
7521
7522 if (!LocalScope)
7523 return nullptr;
7524
7525 if (auto *SP = dyn_cast<DISubprogram>(Val: LocalScope))
7526 return SP;
7527
7528 if (auto *LB = dyn_cast<DILexicalBlockBase>(Val: LocalScope))
7529 return getSubprogram(LocalScope: LB->getRawScope());
7530
7531 // Just return null; broken scope chains are checked elsewhere.
7532 assert(!isa<DILocalScope>(LocalScope) && "Unknown type of local scope");
7533 return nullptr;
7534}
7535
7536void Verifier::visit(DbgLabelRecord &DLR) {
7537 CheckDI(isa<DILabel>(DLR.getRawLabel()),
7538 "invalid #dbg_label intrinsic variable", &DLR, DLR.getRawLabel());
7539
7540 // Ignore broken !dbg attachments; they're checked elsewhere.
7541 if (MDNode *N = DLR.getDebugLoc().getAsMDNode())
7542 if (!isa<DILocation>(Val: N))
7543 return;
7544
7545 BasicBlock *BB = DLR.getParent();
7546 Function *F = BB ? BB->getParent() : nullptr;
7547
7548 // The scopes for variables and !dbg attachments must agree.
7549 DILabel *Label = DLR.getLabel();
7550 DILocation *Loc = DLR.getDebugLoc();
7551 CheckDI(Loc, "#dbg_label record requires a !dbg attachment", &DLR, BB, F);
7552
7553 DISubprogram *LabelSP = getSubprogram(LocalScope: Label->getRawScope());
7554 DISubprogram *LocSP = getSubprogram(LocalScope: Loc->getRawScope());
7555 if (!LabelSP || !LocSP)
7556 return;
7557
7558 CheckDI(LabelSP == LocSP,
7559 "mismatched subprogram between #dbg_label label and !dbg attachment",
7560 &DLR, BB, F, Label, Label->getScope()->getSubprogram(), Loc,
7561 Loc->getScope()->getSubprogram());
7562}
7563
7564void Verifier::visit(DbgVariableRecord &DVR) {
7565 BasicBlock *BB = DVR.getParent();
7566 Function *F = BB->getParent();
7567
7568 CheckDI(DVR.getType() == DbgVariableRecord::LocationType::Value ||
7569 DVR.getType() == DbgVariableRecord::LocationType::Declare ||
7570 DVR.getType() == DbgVariableRecord::LocationType::DeclareValue ||
7571 DVR.getType() == DbgVariableRecord::LocationType::Assign,
7572 "invalid #dbg record type", &DVR, DVR.getType(), BB, F);
7573
7574 // The location for a DbgVariableRecord must be either a ValueAsMetadata,
7575 // DIArgList, or an empty MDNode (which is a legacy representation for an
7576 // "undef" location).
7577 auto *MD = DVR.getRawLocation();
7578 CheckDI(MD && (isa<ValueAsMetadata>(MD) || isa<DIArgList>(MD) ||
7579 (isa<MDNode>(MD) && !cast<MDNode>(MD)->getNumOperands())),
7580 "invalid #dbg record address/value", &DVR, MD, BB, F);
7581 CheckDI(DVR.isDbgAssign() || !isa<DIAssignID>(MD),
7582 "!DIAssignID should only be used by Assign DVRs.", MD, &DVR);
7583 if (auto *VAM = dyn_cast<ValueAsMetadata>(Val: MD)) {
7584 visitValueAsMetadata(MD: *VAM, F);
7585 if (DVR.isDbgDeclare()) {
7586 // Allow integers here to support inttoptr salvage.
7587 Type *Ty = VAM->getValue()->getType();
7588 CheckDI(Ty->isPointerTy() || Ty->isIntegerTy(),
7589 "location of #dbg_declare must be a pointer or int", &DVR, MD, BB,
7590 F);
7591 }
7592 } else if (auto *AL = dyn_cast<DIArgList>(Val: MD)) {
7593 visitDIArgList(AL: *AL, F);
7594 }
7595
7596 CheckDI(isa_and_nonnull<DILocalVariable>(DVR.getRawVariable()),
7597 "invalid #dbg record variable", &DVR, DVR.getRawVariable(), BB, F);
7598 visitMDNode(BaseMD: *DVR.getRawVariable(), AllowLocs: AreDebugLocsAllowed::No);
7599
7600 CheckDI(isa_and_nonnull<DIExpression>(DVR.getRawExpression()),
7601 "invalid #dbg record expression", &DVR, DVR.getRawExpression(), BB,
7602 F);
7603 visitMDNode(BaseMD: *DVR.getExpression(), AllowLocs: AreDebugLocsAllowed::No);
7604
7605 const DIExpression *Expr = DVR.getExpression();
7606 if (Expr->isValid() && !DVR.isKillLocation() &&
7607 (isa<ValueAsMetadata>(Val: MD) || isa<DIArgList>(Val: MD))) {
7608 unsigned NumLocationOps = DVR.getNumVariableLocationOps();
7609 for (DIExpression::ExprOperand Op : Expr->expr_ops()) {
7610 if (Op.getOp() != dwarf::DW_OP_LLVM_arg)
7611 continue;
7612 CheckDI(Op.getArg(0) < NumLocationOps,
7613 "#dbg record expression references nonexistent location operand",
7614 &DVR, Expr, BB, F);
7615 }
7616 }
7617
7618 if (DVR.isDbgAssign()) {
7619 CheckDI(isa_and_nonnull<DIAssignID>(DVR.getRawAssignID()),
7620 "invalid #dbg_assign DIAssignID", &DVR, DVR.getRawAssignID(), BB,
7621 F);
7622 visitMDNode(BaseMD: *cast<DIAssignID>(Val: DVR.getRawAssignID()),
7623 AllowLocs: AreDebugLocsAllowed::No);
7624
7625 const auto *RawAddr = DVR.getRawAddress();
7626 // Similarly to the location above, the address for an assign
7627 // DbgVariableRecord must be a ValueAsMetadata or an empty MDNode, which
7628 // represents an undef address.
7629 CheckDI(
7630 isa<ValueAsMetadata>(RawAddr) ||
7631 (isa<MDNode>(RawAddr) && !cast<MDNode>(RawAddr)->getNumOperands()),
7632 "invalid #dbg_assign address", &DVR, DVR.getRawAddress(), BB, F);
7633 if (auto *VAM = dyn_cast<ValueAsMetadata>(Val: RawAddr))
7634 visitValueAsMetadata(MD: *VAM, F);
7635
7636 CheckDI(isa_and_nonnull<DIExpression>(DVR.getRawAddressExpression()),
7637 "invalid #dbg_assign address expression", &DVR,
7638 DVR.getRawAddressExpression(), BB, F);
7639 visitMDNode(BaseMD: *DVR.getAddressExpression(), AllowLocs: AreDebugLocsAllowed::No);
7640
7641 // All of the linked instructions should be in the same function as DVR.
7642 for (Instruction *I : at::getAssignmentInsts(DVR: &DVR))
7643 CheckDI(DVR.getFunction() == I->getFunction(),
7644 "inst not in same function as #dbg_assign", I, &DVR, BB, F);
7645 }
7646
7647 // This check is redundant with one in visitLocalVariable().
7648 DILocalVariable *Var = DVR.getVariable();
7649 CheckDI(isType(Var->getRawType()), "invalid type ref", Var, Var->getRawType(),
7650 BB, F);
7651
7652 auto *DLNode = DVR.getDebugLoc().getAsMDNode();
7653 CheckDI(isa_and_nonnull<DILocation>(DLNode), "invalid #dbg record DILocation",
7654 &DVR, DLNode, BB, F);
7655 DILocation *Loc = DVR.getDebugLoc();
7656
7657 // The scopes for variables and !dbg attachments must agree.
7658 DISubprogram *VarSP = getSubprogram(LocalScope: Var->getRawScope());
7659 DISubprogram *LocSP = getSubprogram(LocalScope: Loc->getRawScope());
7660 if (!VarSP || !LocSP)
7661 return; // Broken scope chains are checked elsewhere.
7662
7663 CheckDI(VarSP == LocSP,
7664 "mismatched subprogram between #dbg record variable and DILocation",
7665 &DVR, BB, F, Var, Var->getScope()->getSubprogram(), Loc,
7666 Loc->getScope()->getSubprogram(), BB, F);
7667
7668 verifyFnArgs(DVR);
7669}
7670
7671void Verifier::visitVPIntrinsic(VPIntrinsic &VPI) {
7672 switch (VPI.getIntrinsicID()) {
7673 case Intrinsic::experimental_vp_splice: {
7674 VectorType *VecTy = cast<VectorType>(Val: VPI.getType());
7675 int64_t Idx = cast<ConstantInt>(Val: VPI.getArgOperand(i: 2))->getSExtValue();
7676 int64_t KnownMinNumElements = VecTy->getElementCount().getKnownMinValue();
7677 if (VPI.getParent() && VPI.getParent()->getParent()) {
7678 AttributeList Attrs = VPI.getParent()->getParent()->getAttributes();
7679 if (Attrs.hasFnAttr(Kind: Attribute::VScaleRange))
7680 KnownMinNumElements *= Attrs.getFnAttrs().getVScaleRangeMin();
7681 }
7682 Check((Idx < 0 && std::abs(Idx) <= KnownMinNumElements) ||
7683 (Idx >= 0 && Idx < KnownMinNumElements),
7684 "The splice index exceeds the range [-VL, VL-1] where VL is the "
7685 "known minimum number of elements in the vector. For scalable "
7686 "vectors the minimum number of elements is determined from "
7687 "vscale_range.",
7688 &VPI);
7689 break;
7690 }
7691 }
7692}
7693
7694void Verifier::visitConstrainedFPIntrinsic(ConstrainedFPIntrinsic &FPI) {
7695 switch (FPI.getIntrinsicID()) {
7696 case Intrinsic::experimental_constrained_fcmp:
7697 case Intrinsic::experimental_constrained_fcmps: {
7698 auto Pred = cast<ConstrainedFPCmpIntrinsic>(Val: &FPI)->getPredicate();
7699 Check(CmpInst::isFPPredicate(Pred),
7700 "invalid predicate for constrained FP comparison intrinsic", &FPI);
7701 break;
7702 }
7703
7704 case Intrinsic::experimental_constrained_fptosi:
7705 case Intrinsic::experimental_constrained_fptoui: {
7706 Value *Operand = FPI.getArgOperand(i: 0);
7707 ElementCount SrcEC;
7708 if (auto *OperandT = dyn_cast<VectorType>(Val: Operand->getType())) {
7709 SrcEC = cast<VectorType>(Val: OperandT)->getElementCount();
7710 }
7711
7712 Operand = &FPI;
7713 Check(SrcEC.isNonZero() == Operand->getType()->isVectorTy(),
7714 "Intrinsic first argument and result disagree on vector use", &FPI);
7715 if (auto *OperandT = dyn_cast<VectorType>(Val: Operand->getType())) {
7716 Check(SrcEC == cast<VectorType>(OperandT)->getElementCount(),
7717 "Intrinsic first argument and result vector lengths must be equal",
7718 &FPI);
7719 }
7720 break;
7721 }
7722
7723 case Intrinsic::experimental_constrained_sitofp:
7724 case Intrinsic::experimental_constrained_uitofp: {
7725 Value *Operand = FPI.getArgOperand(i: 0);
7726 ElementCount SrcEC;
7727 if (auto *OperandT = dyn_cast<VectorType>(Val: Operand->getType())) {
7728 SrcEC = cast<VectorType>(Val: OperandT)->getElementCount();
7729 }
7730
7731 Operand = &FPI;
7732 Check(SrcEC.isNonZero() == Operand->getType()->isVectorTy(),
7733 "Intrinsic first argument and result disagree on vector use", &FPI);
7734 if (auto *OperandT = dyn_cast<VectorType>(Val: Operand->getType())) {
7735 Check(SrcEC == cast<VectorType>(OperandT)->getElementCount(),
7736 "Intrinsic first argument and result vector lengths must be equal",
7737 &FPI);
7738 }
7739 break;
7740 }
7741
7742 case Intrinsic::experimental_constrained_fptrunc:
7743 case Intrinsic::experimental_constrained_fpext: {
7744 Value *Operand = FPI.getArgOperand(i: 0);
7745 Type *OperandTy = Operand->getType();
7746 Value *Result = &FPI;
7747 Type *ResultTy = Result->getType();
7748 Check(OperandTy->isVectorTy() == ResultTy->isVectorTy(),
7749 "Intrinsic first argument and result disagree on vector use", &FPI);
7750 if (OperandTy->isVectorTy()) {
7751 Check(cast<VectorType>(OperandTy)->getElementCount() ==
7752 cast<VectorType>(ResultTy)->getElementCount(),
7753 "Intrinsic first argument and result vector lengths must be equal",
7754 &FPI);
7755 }
7756 if (FPI.getIntrinsicID() == Intrinsic::experimental_constrained_fptrunc) {
7757 Check(OperandTy->getScalarSizeInBits() > ResultTy->getScalarSizeInBits(),
7758 "Intrinsic first argument's type must be larger than result type",
7759 &FPI);
7760 } else {
7761 Check(OperandTy->getScalarSizeInBits() < ResultTy->getScalarSizeInBits(),
7762 "Intrinsic first argument's type must be smaller than result type",
7763 &FPI);
7764 }
7765 break;
7766 }
7767
7768 default:
7769 break;
7770 }
7771
7772 // If a non-metadata argument is passed in a metadata slot then the
7773 // error will be caught earlier when the incorrect argument doesn't
7774 // match the specification in the intrinsic call table. Thus, no
7775 // argument type check is needed here.
7776
7777 Check(FPI.getExceptionBehavior().has_value(),
7778 "invalid exception behavior argument", &FPI);
7779 if (Intrinsic::hasConstrainedFPRoundingModeOperand(QID: FPI.getIntrinsicID())) {
7780 Check(FPI.getRoundingMode().has_value(), "invalid rounding mode argument",
7781 &FPI);
7782 }
7783}
7784
7785void Verifier::verifyFragmentExpression(const DbgVariableRecord &DVR) {
7786 DILocalVariable *V = dyn_cast_or_null<DILocalVariable>(Val: DVR.getRawVariable());
7787 DIExpression *E = dyn_cast_or_null<DIExpression>(Val: DVR.getRawExpression());
7788
7789 // We don't know whether this intrinsic verified correctly.
7790 if (!V || !E || !E->isValid())
7791 return;
7792
7793 // Nothing to do if this isn't a DW_OP_LLVM_fragment expression.
7794 auto Fragment = E->getFragmentInfo();
7795 if (!Fragment)
7796 return;
7797
7798 // The frontend helps out GDB by emitting the members of local anonymous
7799 // unions as artificial local variables with shared storage. When SROA splits
7800 // the storage for artificial local variables that are smaller than the entire
7801 // union, the overhang piece will be outside of the allotted space for the
7802 // variable and this check fails.
7803 // FIXME: Remove this check as soon as clang stops doing this; it hides bugs.
7804 if (V->isArtificial())
7805 return;
7806
7807 verifyFragmentExpression(V: *V, Fragment: *Fragment, Desc: &DVR);
7808}
7809
7810template <typename ValueOrMetadata>
7811void Verifier::verifyFragmentExpression(const DIVariable &V,
7812 DIExpression::FragmentInfo Fragment,
7813 ValueOrMetadata *Desc) {
7814 // If there's no size, the type is broken, but that should be checked
7815 // elsewhere.
7816 auto VarSize = V.getSizeInBits();
7817 if (!VarSize)
7818 return;
7819
7820 unsigned FragSize = Fragment.SizeInBits;
7821 unsigned FragOffset = Fragment.OffsetInBits;
7822 CheckDI(FragSize + FragOffset <= *VarSize,
7823 "fragment is larger than or outside of variable", Desc, &V);
7824 CheckDI(FragSize != *VarSize, "fragment covers entire variable", Desc, &V);
7825}
7826
7827void Verifier::verifyFnArgs(const DbgVariableRecord &DVR) {
7828 // This function does not take the scope of noninlined function arguments into
7829 // account. Don't run it if current function is nodebug, because it may
7830 // contain inlined debug intrinsics.
7831 if (!HasDebugInfo)
7832 return;
7833
7834 // For performance reasons only check non-inlined ones.
7835 if (DVR.getDebugLoc()->getInlinedAt())
7836 return;
7837
7838 DILocalVariable *Var = DVR.getVariable();
7839 CheckDI(Var, "#dbg record without variable");
7840
7841 unsigned ArgNo = Var->getArg();
7842 if (!ArgNo)
7843 return;
7844
7845 // Verify there are no duplicate function argument debug info entries.
7846 // These will cause hard-to-debug assertions in the DWARF backend.
7847 if (DebugFnArgs.size() < ArgNo)
7848 DebugFnArgs.resize(N: ArgNo, NV: nullptr);
7849
7850 auto *Prev = DebugFnArgs[ArgNo - 1];
7851 DebugFnArgs[ArgNo - 1] = Var;
7852 CheckDI(!Prev || (Prev == Var), "conflicting debug info for argument", &DVR,
7853 Prev, Var);
7854}
7855
7856void Verifier::verifyNotEntryValue(const DbgVariableRecord &DVR) {
7857 DIExpression *E = dyn_cast_or_null<DIExpression>(Val: DVR.getRawExpression());
7858
7859 // We don't know whether this intrinsic verified correctly.
7860 if (!E || !E->isValid())
7861 return;
7862
7863 if (isa<ValueAsMetadata>(Val: DVR.getRawLocation())) {
7864 Value *VarValue = DVR.getVariableLocationOp(OpIdx: 0);
7865 if (isa<UndefValue>(Val: VarValue) || isa<PoisonValue>(Val: VarValue))
7866 return;
7867 // We allow EntryValues for swift async arguments, as they have an
7868 // ABI-guarantee to be turned into a specific register.
7869 if (auto *ArgLoc = dyn_cast_or_null<Argument>(Val: VarValue);
7870 ArgLoc && ArgLoc->hasAttribute(Kind: Attribute::SwiftAsync))
7871 return;
7872 }
7873
7874 CheckDI(!E->isEntryValue(),
7875 "Entry values are only allowed in MIR unless they target a "
7876 "swiftasync Argument",
7877 &DVR);
7878}
7879
7880void Verifier::verifyCompileUnits() {
7881 // When more than one Module is imported into the same context, such as during
7882 // an LTO build before linking the modules, ODR type uniquing may cause types
7883 // to point to a different CU. This check does not make sense in this case.
7884 if (M.getContext().isODRUniquingDebugTypes())
7885 return;
7886 auto *CUs = M.getNamedMetadata(Name: "llvm.dbg.cu");
7887 SmallPtrSet<const Metadata *, 2> Listed;
7888 if (CUs)
7889 Listed.insert_range(R: CUs->operands());
7890 for (const auto *CU : CUVisited)
7891 CheckDI(Listed.count(CU), "DICompileUnit not listed in llvm.dbg.cu", CU);
7892 CUVisited.clear();
7893}
7894
7895void Verifier::verifyDeoptimizeCallingConvs() {
7896 if (DeoptimizeDeclarations.empty())
7897 return;
7898
7899 const Function *First = DeoptimizeDeclarations[0];
7900 for (const auto *F : ArrayRef(DeoptimizeDeclarations).slice(N: 1)) {
7901 Check(First->getCallingConv() == F->getCallingConv(),
7902 "All llvm.experimental.deoptimize declarations must have the same "
7903 "calling convention",
7904 First, F);
7905 }
7906}
7907
7908void Verifier::verifyAttachedCallBundle(const CallBase &Call,
7909 const OperandBundleUse &BU) {
7910 FunctionType *FTy = Call.getFunctionType();
7911
7912 Check((FTy->getReturnType()->isPointerTy() ||
7913 (Call.doesNotReturn() && FTy->getReturnType()->isVoidTy())),
7914 "a call with operand bundle \"clang.arc.attachedcall\" must call a "
7915 "function returning a pointer or a non-returning function that has a "
7916 "void return type",
7917 Call);
7918
7919 Check(BU.Inputs.size() == 1 && isa<Function>(BU.Inputs.front()),
7920 "operand bundle \"clang.arc.attachedcall\" requires one function as "
7921 "an argument",
7922 Call);
7923
7924 auto *Fn = cast<Function>(Val: BU.Inputs.front());
7925 Intrinsic::ID IID = Fn->getIntrinsicID();
7926
7927 if (IID) {
7928 Check((IID == Intrinsic::objc_retainAutoreleasedReturnValue ||
7929 IID == Intrinsic::objc_claimAutoreleasedReturnValue ||
7930 IID == Intrinsic::objc_unsafeClaimAutoreleasedReturnValue),
7931 "invalid function argument", Call);
7932 } else {
7933 StringRef FnName = Fn->getName();
7934 Check((FnName == "objc_retainAutoreleasedReturnValue" ||
7935 FnName == "objc_claimAutoreleasedReturnValue" ||
7936 FnName == "objc_unsafeClaimAutoreleasedReturnValue"),
7937 "invalid function argument", Call);
7938 }
7939}
7940
7941void Verifier::verifyNoAliasScopeDecl() {
7942 if (NoAliasScopeDecls.empty())
7943 return;
7944
7945 // only a single scope must be declared at a time.
7946 for (auto *II : NoAliasScopeDecls) {
7947 assert(II->getIntrinsicID() == Intrinsic::experimental_noalias_scope_decl &&
7948 "Not a llvm.experimental.noalias.scope.decl ?");
7949 const auto *ScopeListMV = dyn_cast<MetadataAsValue>(
7950 Val: II->getOperand(i_nocapture: Intrinsic::NoAliasScopeDeclScopeArg));
7951 Check(ScopeListMV != nullptr,
7952 "llvm.experimental.noalias.scope.decl must have a MetadataAsValue "
7953 "argument",
7954 II);
7955
7956 const auto *ScopeListMD = dyn_cast<MDNode>(Val: ScopeListMV->getMetadata());
7957 Check(ScopeListMD != nullptr, "!id.scope.list must point to an MDNode", II);
7958 Check(ScopeListMD->getNumOperands() == 1,
7959 "!id.scope.list must point to a list with a single scope", II);
7960 visitAliasScopeListMetadata(MD: ScopeListMD);
7961 }
7962
7963 // Only check the domination rule when requested. Once all passes have been
7964 // adapted this option can go away.
7965 if (!VerifyNoAliasScopeDomination)
7966 return;
7967
7968 // Now sort the intrinsics based on the scope MDNode so that declarations of
7969 // the same scopes are next to each other.
7970 auto GetScope = [](IntrinsicInst *II) {
7971 const auto *ScopeListMV = cast<MetadataAsValue>(
7972 Val: II->getOperand(i_nocapture: Intrinsic::NoAliasScopeDeclScopeArg));
7973 return &cast<MDNode>(Val: ScopeListMV->getMetadata())->getOperand(I: 0);
7974 };
7975
7976 // We are sorting on MDNode pointers here. For valid input IR this is ok.
7977 // TODO: Sort on Metadata ID to avoid non-deterministic error messages.
7978 auto Compare = [GetScope](IntrinsicInst *Lhs, IntrinsicInst *Rhs) {
7979 return GetScope(Lhs) < GetScope(Rhs);
7980 };
7981
7982 llvm::sort(C&: NoAliasScopeDecls, Comp: Compare);
7983
7984 // Go over the intrinsics and check that for the same scope, they are not
7985 // dominating each other.
7986 auto ItCurrent = NoAliasScopeDecls.begin();
7987 while (ItCurrent != NoAliasScopeDecls.end()) {
7988 auto CurScope = GetScope(*ItCurrent);
7989 auto ItNext = ItCurrent;
7990 do {
7991 ++ItNext;
7992 } while (ItNext != NoAliasScopeDecls.end() &&
7993 GetScope(*ItNext) == CurScope);
7994
7995 // [ItCurrent, ItNext) represents the declarations for the same scope.
7996 // Ensure they are not dominating each other.. but only if it is not too
7997 // expensive.
7998 if (ItNext - ItCurrent < 32)
7999 for (auto *I : llvm::make_range(x: ItCurrent, y: ItNext))
8000 for (auto *J : llvm::make_range(x: ItCurrent, y: ItNext))
8001 if (I != J)
8002 Check(!DT.dominates(I, J),
8003 "llvm.experimental.noalias.scope.decl dominates another one "
8004 "with the same scope",
8005 I);
8006 ItCurrent = ItNext;
8007 }
8008}
8009
8010//===----------------------------------------------------------------------===//
8011// Implement the public interfaces to this file...
8012//===----------------------------------------------------------------------===//
8013
8014bool llvm::verifyFunction(const Function &f, raw_ostream *OS) {
8015 Function &F = const_cast<Function &>(f);
8016
8017 // Don't use a raw_null_ostream. Printing IR is expensive.
8018 Verifier V(OS, /*ShouldTreatBrokenDebugInfoAsError=*/true, *f.getParent());
8019
8020 // Note that this function's return value is inverted from what you would
8021 // expect of a function called "verify".
8022 return !V.verify(F);
8023}
8024
8025bool llvm::verifyModule(const Module &M, raw_ostream *OS,
8026 bool *BrokenDebugInfo) {
8027 // Don't use a raw_null_ostream. Printing IR is expensive.
8028 Verifier V(OS, /*ShouldTreatBrokenDebugInfoAsError=*/!BrokenDebugInfo, M);
8029
8030 bool Broken = false;
8031 for (const Function &F : M)
8032 Broken |= !V.verify(F);
8033
8034 Broken |= !V.verify();
8035 if (BrokenDebugInfo)
8036 *BrokenDebugInfo = V.hasBrokenDebugInfo();
8037 // Note that this function's return value is inverted from what you would
8038 // expect of a function called "verify".
8039 return Broken;
8040}
8041
8042namespace {
8043
8044struct VerifierLegacyPass : public FunctionPass {
8045 static char ID;
8046
8047 std::unique_ptr<Verifier> V;
8048 bool FatalErrors = true;
8049
8050 VerifierLegacyPass() : FunctionPass(ID) {}
8051 explicit VerifierLegacyPass(bool FatalErrors)
8052 : FunctionPass(ID), FatalErrors(FatalErrors) {}
8053
8054 bool doInitialization(Module &M) override {
8055 V = std::make_unique<Verifier>(
8056 args: &dbgs(), /*ShouldTreatBrokenDebugInfoAsError=*/args: false, args&: M);
8057 return false;
8058 }
8059
8060 bool runOnFunction(Function &F) override {
8061 if (!V->verify(F) && FatalErrors) {
8062 errs() << "in function " << F.getName() << '\n';
8063 report_fatal_error(reason: "Broken function found, compilation aborted!");
8064 }
8065 return false;
8066 }
8067
8068 bool doFinalization(Module &M) override {
8069 bool HasErrors = false;
8070 for (Function &F : M)
8071 if (F.isDeclaration())
8072 HasErrors |= !V->verify(F);
8073
8074 HasErrors |= !V->verify();
8075 if (FatalErrors && (HasErrors || V->hasBrokenDebugInfo()))
8076 report_fatal_error(reason: "Broken module found, compilation aborted!");
8077 return false;
8078 }
8079
8080 void getAnalysisUsage(AnalysisUsage &AU) const override {
8081 AU.setPreservesAll();
8082 }
8083};
8084
8085} // end anonymous namespace
8086
8087/// Helper to issue failure from the TBAA verification
8088template <typename... Tys> void TBAAVerifier::CheckFailed(Tys &&... Args) {
8089 if (Diagnostic)
8090 return Diagnostic->CheckFailed(Args...);
8091}
8092
8093#define CheckTBAA(C, ...) \
8094 do { \
8095 if (!(C)) { \
8096 CheckFailed(__VA_ARGS__); \
8097 return false; \
8098 } \
8099 } while (false)
8100
8101/// Verify that \p BaseNode can be used as the "base type" in the struct-path
8102/// TBAA scheme. This means \p BaseNode is either a scalar node, or a
8103/// struct-type node describing an aggregate data structure (like a struct).
8104TBAAVerifier::TBAABaseNodeSummary
8105TBAAVerifier::verifyTBAABaseNode(const Instruction *I, const MDNode *BaseNode,
8106 bool IsNewFormat) {
8107 if (BaseNode->getNumOperands() < 2) {
8108 CheckFailed(Args: "Base nodes must have at least two operands", Args&: I, Args&: BaseNode);
8109 return {true, ~0u};
8110 }
8111
8112 auto Itr = TBAABaseNodes.find(Val: BaseNode);
8113 if (Itr != TBAABaseNodes.end())
8114 return Itr->second;
8115
8116 auto Result = verifyTBAABaseNodeImpl(I, BaseNode, IsNewFormat);
8117 auto InsertResult = TBAABaseNodes.insert(KV: {BaseNode, Result});
8118 (void)InsertResult;
8119 assert(InsertResult.second && "We just checked!");
8120 return Result;
8121}
8122
8123TBAAVerifier::TBAABaseNodeSummary
8124TBAAVerifier::verifyTBAABaseNodeImpl(const Instruction *I,
8125 const MDNode *BaseNode, bool IsNewFormat) {
8126 const TBAAVerifier::TBAABaseNodeSummary InvalidNode = {true, ~0u};
8127
8128 if (BaseNode->getNumOperands() == 2) {
8129 // Scalar nodes can only be accessed at offset 0.
8130 return isValidScalarTBAANode(MD: BaseNode)
8131 ? TBAAVerifier::TBAABaseNodeSummary({false, 0})
8132 : InvalidNode;
8133 }
8134
8135 if (IsNewFormat) {
8136 if (BaseNode->getNumOperands() % 3 != 0) {
8137 CheckFailed(Args: "Access tag nodes must have the number of operands that is a "
8138 "multiple of 3!", Args&: BaseNode);
8139 return InvalidNode;
8140 }
8141 } else {
8142 if (BaseNode->getNumOperands() % 2 != 1) {
8143 CheckFailed(Args: "Struct tag nodes must have an odd number of operands!",
8144 Args&: BaseNode);
8145 return InvalidNode;
8146 }
8147 }
8148
8149 // Check the type size field.
8150 if (IsNewFormat) {
8151 auto *TypeSizeNode = mdconst::dyn_extract_or_null<ConstantInt>(
8152 MD: BaseNode->getOperand(I: 1));
8153 if (!TypeSizeNode) {
8154 CheckFailed(Args: "Type size nodes must be constants!", Args&: I, Args&: BaseNode);
8155 return InvalidNode;
8156 }
8157 }
8158
8159 // Check the type name field. In the new format it can be anything.
8160 if (!IsNewFormat && !isa<MDString>(Val: BaseNode->getOperand(I: 0))) {
8161 CheckFailed(Args: "Struct tag nodes have a string as their first operand",
8162 Args&: BaseNode);
8163 return InvalidNode;
8164 }
8165
8166 bool Failed = false;
8167
8168 std::optional<APInt> PrevOffset;
8169 unsigned BitWidth = ~0u;
8170
8171 // We've already checked that BaseNode is not a degenerate root node with one
8172 // operand in \c verifyTBAABaseNode, so this loop should run at least once.
8173 unsigned FirstFieldOpNo = IsNewFormat ? 3 : 1;
8174 unsigned NumOpsPerField = IsNewFormat ? 3 : 2;
8175 for (unsigned Idx = FirstFieldOpNo; Idx < BaseNode->getNumOperands();
8176 Idx += NumOpsPerField) {
8177 const MDOperand &FieldTy = BaseNode->getOperand(I: Idx);
8178 const MDOperand &FieldOffset = BaseNode->getOperand(I: Idx + 1);
8179 if (!isa<MDNode>(Val: FieldTy)) {
8180 CheckFailed(Args: "Incorrect field entry in struct type node!", Args&: I, Args&: BaseNode);
8181 Failed = true;
8182 continue;
8183 }
8184
8185 auto *OffsetEntryCI =
8186 mdconst::dyn_extract_or_null<ConstantInt>(MD: FieldOffset);
8187 if (!OffsetEntryCI) {
8188 CheckFailed(Args: "Offset entries must be constants!", Args&: I, Args&: BaseNode);
8189 Failed = true;
8190 continue;
8191 }
8192
8193 if (BitWidth == ~0u)
8194 BitWidth = OffsetEntryCI->getBitWidth();
8195
8196 if (OffsetEntryCI->getBitWidth() != BitWidth) {
8197 CheckFailed(
8198 Args: "Bitwidth between the offsets and struct type entries must match", Args&: I,
8199 Args&: BaseNode);
8200 Failed = true;
8201 continue;
8202 }
8203
8204 // NB! As far as I can tell, we generate a non-strictly increasing offset
8205 // sequence only from structs that have zero size bit fields. When
8206 // recursing into a contained struct in \c getFieldNodeFromTBAABaseNode we
8207 // pick the field lexically the latest in struct type metadata node. This
8208 // mirrors the actual behavior of the alias analysis implementation.
8209 bool IsAscending =
8210 !PrevOffset || PrevOffset->ule(RHS: OffsetEntryCI->getValue());
8211
8212 if (!IsAscending) {
8213 CheckFailed(Args: "Offsets must be increasing!", Args&: I, Args&: BaseNode);
8214 Failed = true;
8215 }
8216
8217 PrevOffset = OffsetEntryCI->getValue();
8218
8219 if (IsNewFormat) {
8220 auto *MemberSizeNode = mdconst::dyn_extract_or_null<ConstantInt>(
8221 MD: BaseNode->getOperand(I: Idx + 2));
8222 if (!MemberSizeNode) {
8223 CheckFailed(Args: "Member size entries must be constants!", Args&: I, Args&: BaseNode);
8224 Failed = true;
8225 continue;
8226 }
8227 }
8228 }
8229
8230 return Failed ? InvalidNode
8231 : TBAAVerifier::TBAABaseNodeSummary(false, BitWidth);
8232}
8233
8234static bool IsRootTBAANode(const MDNode *MD) {
8235 return MD->getNumOperands() < 2;
8236}
8237
8238static bool IsScalarTBAANodeImpl(const MDNode *MD,
8239 SmallPtrSetImpl<const MDNode *> &Visited) {
8240 if (MD->getNumOperands() != 2 && MD->getNumOperands() != 3)
8241 return false;
8242
8243 if (!isa<MDString>(Val: MD->getOperand(I: 0)))
8244 return false;
8245
8246 if (MD->getNumOperands() == 3) {
8247 auto *Offset = mdconst::dyn_extract<ConstantInt>(MD: MD->getOperand(I: 2));
8248 if (!(Offset && Offset->isZero() && isa<MDString>(Val: MD->getOperand(I: 0))))
8249 return false;
8250 }
8251
8252 auto *Parent = dyn_cast_or_null<MDNode>(Val: MD->getOperand(I: 1));
8253 return Parent && Visited.insert(Ptr: Parent).second &&
8254 (IsRootTBAANode(MD: Parent) || IsScalarTBAANodeImpl(MD: Parent, Visited));
8255}
8256
8257bool TBAAVerifier::isValidScalarTBAANode(const MDNode *MD) {
8258 auto ResultIt = TBAAScalarNodes.find(Val: MD);
8259 if (ResultIt != TBAAScalarNodes.end())
8260 return ResultIt->second;
8261
8262 SmallPtrSet<const MDNode *, 4> Visited;
8263 bool Result = IsScalarTBAANodeImpl(MD, Visited);
8264 auto InsertResult = TBAAScalarNodes.insert(KV: {MD, Result});
8265 (void)InsertResult;
8266 assert(InsertResult.second && "Just checked!");
8267
8268 return Result;
8269}
8270
8271/// Returns the field node at the offset \p Offset in \p BaseNode. Update \p
8272/// Offset in place to be the offset within the field node returned.
8273///
8274/// We assume we've okayed \p BaseNode via \c verifyTBAABaseNode.
8275MDNode *TBAAVerifier::getFieldNodeFromTBAABaseNode(const Instruction *I,
8276 const MDNode *BaseNode,
8277 APInt &Offset,
8278 bool IsNewFormat) {
8279 assert(BaseNode->getNumOperands() >= 2 && "Invalid base node!");
8280
8281 // Scalar nodes have only one possible "field" -- their parent in the access
8282 // hierarchy. Offset must be zero at this point, but our caller is supposed
8283 // to check that.
8284 if (BaseNode->getNumOperands() == 2)
8285 return cast<MDNode>(Val: BaseNode->getOperand(I: 1));
8286
8287 unsigned FirstFieldOpNo = IsNewFormat ? 3 : 1;
8288 unsigned NumOpsPerField = IsNewFormat ? 3 : 2;
8289 for (unsigned Idx = FirstFieldOpNo; Idx < BaseNode->getNumOperands();
8290 Idx += NumOpsPerField) {
8291 auto *OffsetEntryCI =
8292 mdconst::extract<ConstantInt>(MD: BaseNode->getOperand(I: Idx + 1));
8293 if (OffsetEntryCI->getValue().ugt(RHS: Offset)) {
8294 if (Idx == FirstFieldOpNo) {
8295 CheckFailed(Args: "Could not find TBAA parent in struct type node", Args&: I,
8296 Args&: BaseNode, Args: &Offset);
8297 return nullptr;
8298 }
8299
8300 unsigned PrevIdx = Idx - NumOpsPerField;
8301 auto *PrevOffsetEntryCI =
8302 mdconst::extract<ConstantInt>(MD: BaseNode->getOperand(I: PrevIdx + 1));
8303 Offset -= PrevOffsetEntryCI->getValue();
8304 return cast<MDNode>(Val: BaseNode->getOperand(I: PrevIdx));
8305 }
8306 }
8307
8308 unsigned LastIdx = BaseNode->getNumOperands() - NumOpsPerField;
8309 auto *LastOffsetEntryCI = mdconst::extract<ConstantInt>(
8310 MD: BaseNode->getOperand(I: LastIdx + 1));
8311 Offset -= LastOffsetEntryCI->getValue();
8312 return cast<MDNode>(Val: BaseNode->getOperand(I: LastIdx));
8313}
8314
8315static bool isNewFormatTBAATypeNode(llvm::MDNode *Type) {
8316 if (!Type || Type->getNumOperands() < 3)
8317 return false;
8318
8319 // In the new format type nodes shall have a reference to the parent type as
8320 // its first operand.
8321 return isa_and_nonnull<MDNode>(Val: Type->getOperand(I: 0));
8322}
8323
8324bool TBAAVerifier::visitTBAAMetadata(const Instruction *I, const MDNode *MD) {
8325 CheckTBAA(MD->getNumOperands() > 0, "TBAA metadata cannot have 0 operands", I,
8326 MD);
8327
8328 if (I)
8329 CheckTBAA(isa<LoadInst>(I) || isa<StoreInst>(I) || isa<CallInst>(I) ||
8330 isa<VAArgInst>(I) || isa<AtomicRMWInst>(I) ||
8331 isa<AtomicCmpXchgInst>(I),
8332 "This instruction shall not have a TBAA access tag!", I);
8333
8334 bool IsStructPathTBAA =
8335 isa<MDNode>(Val: MD->getOperand(I: 0)) && MD->getNumOperands() >= 3;
8336
8337 CheckTBAA(IsStructPathTBAA,
8338 "Old-style TBAA is no longer allowed, use struct-path TBAA instead",
8339 I);
8340
8341 auto *BaseNode = dyn_cast_or_null<MDNode>(Val: MD->getOperand(I: 0));
8342 auto *AccessType = dyn_cast_or_null<MDNode>(Val: MD->getOperand(I: 1));
8343
8344 bool IsNewFormat = isNewFormatTBAATypeNode(Type: AccessType);
8345
8346 if (IsNewFormat) {
8347 CheckTBAA(MD->getNumOperands() == 4 || MD->getNumOperands() == 5,
8348 "Access tag metadata must have either 4 or 5 operands", I, MD);
8349 } else {
8350 CheckTBAA(MD->getNumOperands() < 5,
8351 "Struct tag metadata must have either 3 or 4 operands", I, MD);
8352 }
8353
8354 // Check the access size field.
8355 if (IsNewFormat) {
8356 auto *AccessSizeNode = mdconst::dyn_extract_or_null<ConstantInt>(
8357 MD: MD->getOperand(I: 3));
8358 CheckTBAA(AccessSizeNode, "Access size field must be a constant", I, MD);
8359 }
8360
8361 // Check the immutability flag.
8362 unsigned ImmutabilityFlagOpNo = IsNewFormat ? 4 : 3;
8363 if (MD->getNumOperands() == ImmutabilityFlagOpNo + 1) {
8364 auto *IsImmutableCI = mdconst::dyn_extract_or_null<ConstantInt>(
8365 MD: MD->getOperand(I: ImmutabilityFlagOpNo));
8366 CheckTBAA(IsImmutableCI,
8367 "Immutability tag on struct tag metadata must be a constant", I,
8368 MD);
8369 CheckTBAA(
8370 IsImmutableCI->isZero() || IsImmutableCI->isOne(),
8371 "Immutability part of the struct tag metadata must be either 0 or 1", I,
8372 MD);
8373 }
8374
8375 CheckTBAA(BaseNode && AccessType,
8376 "Malformed struct tag metadata: base and access-type "
8377 "should be non-null and point to Metadata nodes",
8378 I, MD, BaseNode, AccessType);
8379
8380 if (!IsNewFormat) {
8381 CheckTBAA(isValidScalarTBAANode(AccessType),
8382 "Access type node must be a valid scalar type", I, MD,
8383 AccessType);
8384 }
8385
8386 auto *OffsetCI = mdconst::dyn_extract_or_null<ConstantInt>(MD: MD->getOperand(I: 2));
8387 CheckTBAA(OffsetCI, "Offset must be constant integer", I, MD);
8388
8389 APInt Offset = OffsetCI->getValue();
8390 bool SeenAccessTypeInPath = false;
8391
8392 SmallPtrSet<MDNode *, 4> StructPath;
8393
8394 for (/* empty */; BaseNode && !IsRootTBAANode(MD: BaseNode);
8395 BaseNode =
8396 getFieldNodeFromTBAABaseNode(I, BaseNode, Offset, IsNewFormat)) {
8397 if (!StructPath.insert(Ptr: BaseNode).second) {
8398 CheckFailed(Args: "Cycle detected in struct path", Args&: I, Args&: MD);
8399 return false;
8400 }
8401
8402 bool Invalid;
8403 unsigned BaseNodeBitWidth;
8404 std::tie(args&: Invalid, args&: BaseNodeBitWidth) =
8405 verifyTBAABaseNode(I, BaseNode, IsNewFormat);
8406
8407 // If the base node is invalid in itself, then we've already printed all the
8408 // errors we wanted to print.
8409 if (Invalid)
8410 return false;
8411
8412 SeenAccessTypeInPath |= BaseNode == AccessType;
8413
8414 if (isValidScalarTBAANode(MD: BaseNode) || BaseNode == AccessType)
8415 CheckTBAA(Offset == 0, "Offset not zero at the point of scalar access", I,
8416 MD, &Offset);
8417
8418 CheckTBAA(BaseNodeBitWidth == Offset.getBitWidth() ||
8419 (BaseNodeBitWidth == 0 && Offset == 0) ||
8420 (IsNewFormat && BaseNodeBitWidth == ~0u),
8421 "Access bit-width not the same as description bit-width", I, MD,
8422 BaseNodeBitWidth, Offset.getBitWidth());
8423
8424 if (IsNewFormat && SeenAccessTypeInPath)
8425 break;
8426 }
8427
8428 CheckTBAA(SeenAccessTypeInPath, "Did not see access type in access path!", I,
8429 MD);
8430 return true;
8431}
8432
8433bool TBAAVerifier::visitTBAAStructMetadata(const Instruction *I,
8434 const MDNode *MD) {
8435 // !tbaa.struct is a list of (offset, size, tag) triples with ascending
8436 // offsets. Offset and size must be constants; a tag must be null or a valid
8437 // access tag.
8438 CheckTBAA(MD->getNumOperands() % 3 == 0,
8439 "!tbaa.struct operands must come in groups of three", I, MD);
8440
8441 std::optional<APInt> PrevOffset;
8442 for (unsigned Idx = 0, E = MD->getNumOperands(); Idx != E; Idx += 3) {
8443 auto *OffsetCI =
8444 mdconst::dyn_extract_or_null<ConstantInt>(MD: MD->getOperand(I: Idx));
8445 CheckTBAA(OffsetCI, "!tbaa.struct field offset must be a constant integer",
8446 I, MD);
8447 CheckTBAA(
8448 mdconst::dyn_extract_or_null<ConstantInt>(MD->getOperand(Idx + 1)),
8449 "!tbaa.struct field size must be a constant integer", I, MD);
8450 if (const Metadata *TagMD = MD->getOperand(I: Idx + 2)) {
8451 auto *Tag = dyn_cast<MDNode>(Val: TagMD);
8452 CheckTBAA(Tag, "!tbaa.struct field tag must be null or an MDNode", I, MD);
8453 if (!visitTBAAMetadata(I, MD: Tag))
8454 return false;
8455 }
8456
8457 const APInt &Offset = OffsetCI->getValue();
8458 if (PrevOffset) {
8459 unsigned Width =
8460 std::max(a: PrevOffset->getBitWidth(), b: Offset.getBitWidth());
8461 CheckTBAA(PrevOffset->zext(Width).ule(Offset.zext(Width)),
8462 "!tbaa.struct field offsets must be non-decreasing", I, MD);
8463 }
8464 PrevOffset = Offset;
8465 }
8466 return true;
8467}
8468
8469char VerifierLegacyPass::ID = 0;
8470INITIALIZE_PASS(VerifierLegacyPass, "verify", "Module Verifier", false, false)
8471
8472FunctionPass *llvm::createVerifierPass(bool FatalErrors) {
8473 return new VerifierLegacyPass(FatalErrors);
8474}
8475
8476AnalysisKey VerifierAnalysis::Key;
8477VerifierAnalysis::Result VerifierAnalysis::run(Module &M,
8478 ModuleAnalysisManager &) {
8479 Result Res;
8480 Res.IRBroken = llvm::verifyModule(M, OS: &dbgs(), BrokenDebugInfo: &Res.DebugInfoBroken);
8481 return Res;
8482}
8483
8484VerifierAnalysis::Result VerifierAnalysis::run(Function &F,
8485 FunctionAnalysisManager &) {
8486 return { .IRBroken: llvm::verifyFunction(f: F, OS: &dbgs()), .DebugInfoBroken: false };
8487}
8488
8489PreservedAnalyses VerifierPass::run(Module &M, ModuleAnalysisManager &AM) {
8490 auto Res = AM.getResult<VerifierAnalysis>(IR&: M);
8491 if (FatalErrors && (Res.IRBroken || Res.DebugInfoBroken))
8492 report_fatal_error(reason: "Broken module found, compilation aborted!");
8493
8494 return PreservedAnalyses::all();
8495}
8496
8497PreservedAnalyses VerifierPass::run(Function &F, FunctionAnalysisManager &AM) {
8498 auto res = AM.getResult<VerifierAnalysis>(IR&: F);
8499 if (res.IRBroken && FatalErrors)
8500 report_fatal_error(reason: "Broken function found, compilation aborted!");
8501
8502 return PreservedAnalyses::all();
8503}
8504