Skip to main content

rustc_mir_transform/
gvn.rs

1//! Global value numbering.
2//!
3//! MIR may contain repeated and/or redundant computations. The objective of this pass is to detect
4//! such redundancies and re-use the already-computed result when possible.
5//!
6//! From those assignments, we construct a mapping `VnIndex -> Vec<(Local, Location)>` of available
7//! values, the locals in which they are stored, and the assignment location.
8//!
9//! We traverse all assignments `x = rvalue` and operands.
10//!
11//! For each SSA one, we compute a symbolic representation of values that are assigned to SSA
12//! locals. This symbolic representation is defined by the `Value` enum. Each produced instance of
13//! `Value` is interned as a `VnIndex`, which allows us to cheaply compute identical values.
14//!
15//! For each non-SSA
16//! one, we compute the `VnIndex` of the rvalue. If this `VnIndex` is associated to a constant, we
17//! replace the rvalue/operand by that constant. Otherwise, if there is an SSA local `y`
18//! associated to this `VnIndex`, and if its definition location strictly dominates the assignment
19//! to `x`, we replace the assignment by `x = y`.
20//!
21//! By opportunity, this pass simplifies some `Rvalue`s based on the accumulated knowledge.
22//!
23//! # Operational semantic
24//!
25//! Operationally, this pass attempts to prove bitwise equality between locals. Given this MIR:
26//! ```ignore (MIR)
27//! _a = some value // has VnIndex i
28//! // some MIR
29//! _b = some other value // also has VnIndex i
30//! ```
31//!
32//! We consider it to be replaceable by:
33//! ```ignore (MIR)
34//! _a = some value // has VnIndex i
35//! // some MIR
36//! _c = some other value // also has VnIndex i
37//! assume(_a bitwise equal to _c) // follows from having the same VnIndex
38//! _b = _a // follows from the `assume`
39//! ```
40//!
41//! Which is simplifiable to:
42//! ```ignore (MIR)
43//! _a = some value // has VnIndex i
44//! // some MIR
45//! _b = _a
46//! ```
47//!
48//! # Handling of references
49//!
50//! We handle references by assigning a different "provenance" index to each Ref/RawPtr rvalue.
51//! This ensure that we do not spuriously merge borrows that should not be merged. For instance:
52//! ```ignore (MIR)
53//! _x = &_a;
54//! _a = 0;
55//! _y = &_a; // cannot be turned into `_y = _x`!
56//! ```
57//!
58//! On top of that, we consider all the derefs of an immutable reference to a freeze type to give
59//! the same value:
60//! ```ignore (MIR)
61//! _a = *_b // _b is &Freeze
62//! _c = *_b // replaced by _c = _a
63//! ```
64//!
65//! # Determinism of constant propagation
66//!
67//! When registering a new `Value`, we attempt to opportunistically evaluate it as a constant.
68//! The evaluated form is inserted in `evaluated` as an `OpTy` or `None` if evaluation failed.
69//!
70//! The difficulty is non-deterministic evaluation of MIR constants. Some `Const` can have
71//! different runtime values each time they are evaluated. This happens with valtrees that
72//! generate a new allocation each time they are used. This is checked by `is_deterministic`.
73//!
74//! Meanwhile, we want to be able to read indirect constants. For instance:
75//! ```
76//! static A: &'static &'static u8 = &&63;
77//! fn foo() -> u8 {
78//!     **A // We want to replace by 63.
79//! }
80//! fn bar() -> u8 {
81//!     b"abc"[1] // We want to replace by 'b'.
82//! }
83//! ```
84//!
85//! The `Value::Constant` variant stores a possibly unevaluated constant. Evaluating that constant
86//! may be non-deterministic. When that happens, we assign a disambiguator to ensure that we do not
87//! merge the constants. See `duplicate_slice` test in `gvn.rs`.
88//!
89//! Conversely, some constants cannot cross function boundaries, which could happen because of
90//! inlining. For instance, constants that contain a fn pointer (`AllocId` pointing to a
91//! `GlobalAlloc::Function`) point to a different symbol in each codegen unit. To avoid this,
92//! when writing constants in MIR, we do not write `Const`s that contain `AllocId`s. This is
93//! checked by `may_have_provenance`. See <https://github.com/rust-lang/rust/issues/128775> for
94//! more information.
95
96use std::borrow::Cow;
97use std::hash::{Hash, Hasher};
98
99use either::Either;
100use itertools::Itertools as _;
101use rustc_abi::{self as abi, BackendRepr, FIRST_VARIANT, FieldIdx, Primitive, Size, VariantIdx};
102use rustc_arena::DroplessArena;
103use rustc_const_eval::const_eval::DummyMachine;
104use rustc_const_eval::interpret::{
105    ImmTy, Immediate, InterpCx, MemPlaceMeta, MemoryKind, OpTy, Projectable, Scalar,
106    intern_const_alloc_for_constprop,
107};
108use rustc_data_structures::fx::FxHasher;
109use rustc_data_structures::graph::dominators::Dominators;
110use rustc_data_structures::hash_table::{Entry, HashTable};
111use rustc_hir::def::DefKind;
112use rustc_index::bit_set::DenseBitSet;
113use rustc_index::{IndexVec, newtype_index};
114use rustc_middle::bug;
115use rustc_middle::mir::interpret::{AllocRange, GlobalAlloc};
116use rustc_middle::mir::visit::*;
117use rustc_middle::mir::*;
118use rustc_middle::ty::layout::HasTypingEnv;
119use rustc_middle::ty::{self, Ty, TyCtxt, Unnormalized};
120use rustc_mir_dataflow::{Analysis, ResultsCursor};
121use rustc_span::DUMMY_SP;
122use smallvec::SmallVec;
123use tracing::{debug, instrument, trace};
124
125use crate::ssa::{MaybeUninitializedLocals, SsaLocals};
126
127pub(super) struct GVN;
128
129impl<'tcx> crate::MirPass<'tcx> for GVN {
130    fn is_enabled(&self, sess: &rustc_session::Session) -> bool {
131        sess.mir_opt_level() >= 2
132    }
133
134    #[instrument(level = "trace", skip(self, tcx, body))]
135    fn run_pass(&self, tcx: TyCtxt<'tcx>, body: &mut Body<'tcx>) {
136        debug!(def_id = ?body.source.def_id());
137
138        let typing_env = body.typing_env(tcx);
139        let ssa = SsaLocals::new(tcx, body, typing_env);
140        // Clone dominators because we need them while mutating the body.
141        let dominators = body.basic_blocks.dominators().clone();
142
143        let arena = DroplessArena::default();
144        let mut state =
145            VnState::new(tcx, body, typing_env, &ssa, dominators, &body.local_decls, &arena);
146
147        for local in body.args_iter().filter(|&local| ssa.is_ssa(local)) {
148            let opaque = state.new_argument(body.local_decls[local].ty);
149            state.assign(local, opaque);
150        }
151
152        let reverse_postorder = body.basic_blocks.reverse_postorder().to_vec();
153        for bb in reverse_postorder {
154            let data = &mut body.basic_blocks.as_mut_preserves_cfg()[bb];
155            state.visit_basic_block_data(bb, data);
156        }
157
158        // When emitting storage statements, we want to retain the reused locals' storage statements,
159        // as this enables better optimizations. For each local use location, we mark it for storage removal
160        // only if it might be uninitialized at that point.
161        let storage_to_remove = if tcx.sess.emit_lifetime_markers() {
162            let maybe_uninit = MaybeUninitializedLocals
163                .iterate_to_fixpoint(tcx, body, Some("mir_opt::gvn"))
164                .into_results_cursor(body);
165
166            let mut storage_checker = StorageChecker {
167                reused_locals: &state.reused_locals,
168                storage_to_remove: DenseBitSet::new_empty(body.local_decls.len()),
169                maybe_uninit,
170            };
171
172            for (bb, data) in traversal::reachable(body) {
173                storage_checker.visit_basic_block_data(bb, data);
174            }
175
176            Some(storage_checker.storage_to_remove)
177        } else {
178            None
179        };
180
181        // If None, remove the storage statements of all the reused locals.
182        let storage_to_remove = storage_to_remove.as_ref().unwrap_or(&state.reused_locals);
183        debug!(?storage_to_remove);
184
185        StorageRemover { tcx, reused_locals: &state.reused_locals, storage_to_remove }
186            .visit_body_preserves_cfg(body);
187    }
188
189    fn is_required(&self) -> bool {
190        false
191    }
192}
193
194newtype_index! {
195    /// This represents a `Value` in the symbolic execution.
196    #[debug_format = "_v{}"]
197    struct VnIndex {}
198}
199
200/// Marker type to forbid hashing and comparing opaque values.
201/// This struct should only be constructed by `ValueSet::insert_unique` to ensure we use that
202/// method to create non-unifiable values. It will ICE if used in `ValueSet::insert`.
203#[derive(Copy, Clone, Debug, Eq)]
204struct VnOpaque;
205impl PartialEq for VnOpaque {
206    fn eq(&self, _: &VnOpaque) -> bool {
207        // ICE if we try to compare unique values
208        unreachable!()
209    }
210}
211impl Hash for VnOpaque {
212    fn hash<T: Hasher>(&self, _: &mut T) {
213        // ICE if we try to hash unique values
214        unreachable!()
215    }
216}
217
218#[derive(Copy, Clone, Debug, PartialEq, Eq, Hash)]
219enum AddressKind {
220    Ref(BorrowKind),
221    Address(RawPtrKind),
222}
223
224#[derive(Copy, Clone, Debug, PartialEq, Eq, Hash)]
225enum AddressBase {
226    /// This address is based on this local.
227    Local(Local),
228    /// This address is based on the deref of this pointer.
229    Deref(VnIndex),
230}
231
232#[derive(Copy, Clone, Debug, PartialEq, Eq, Hash)]
233enum Value<'a, 'tcx> {
234    // Root values.
235    /// Used to represent values we know nothing about.
236    Opaque(VnOpaque),
237    /// The value is a argument.
238    Argument(VnOpaque),
239    /// Evaluated or unevaluated constant value.
240    Constant {
241        value: Const<'tcx>,
242        /// Some constants do not have a deterministic value. To avoid merging two instances of the
243        /// same `Const`, we assign them an additional integer index.
244        // `disambiguator` is `None` iff the constant is deterministic.
245        disambiguator: Option<VnOpaque>,
246    },
247
248    // Aggregates.
249    /// An aggregate value, either tuple/closure/struct/enum.
250    /// This does not contain unions, as we cannot reason with the value.
251    Aggregate(VariantIdx, &'a [VnIndex]),
252    /// A union aggregate value.
253    Union(FieldIdx, VnIndex),
254    /// A raw pointer aggregate built from a thin pointer and metadata.
255    RawPtr {
256        /// Thin pointer component. This is field 0 in MIR.
257        pointer: VnIndex,
258        /// Metadata component. This is field 1 in MIR.
259        metadata: VnIndex,
260    },
261    /// This corresponds to a `[value; count]` expression.
262    Repeat(VnIndex, ty::Const<'tcx>),
263    /// The address of a place.
264    Address {
265        base: AddressBase,
266        // We do not use a plain `Place` as we want to be able to reason about indices.
267        // This does not contain any `Deref` projection.
268        projection: &'a [ProjectionElem<VnIndex, Ty<'tcx>>],
269        kind: AddressKind,
270        /// Give each borrow and pointer a different provenance, so we don't merge them.
271        provenance: VnOpaque,
272    },
273
274    // Extractions.
275    /// This is the *value* obtained by projecting another value.
276    Projection(VnIndex, ProjectionElem<VnIndex, ()>),
277    /// Discriminant of the given value.
278    Discriminant(VnIndex),
279
280    // Operations.
281    RuntimeChecks(RuntimeChecks),
282    UnaryOp(UnOp, VnIndex),
283    BinaryOp(BinOp, VnIndex, VnIndex),
284    Cast {
285        kind: CastKind,
286        value: VnIndex,
287    },
288}
289
290/// Stores and deduplicates pairs of `(Value, Ty)` into in `VnIndex` numbered values.
291///
292/// This data structure is mostly a partial reimplementation of `FxIndexMap<VnIndex, (Value, Ty)>`.
293/// We do not use a regular `FxIndexMap` to skip hashing values that are unique by construction,
294/// like opaque values, address with provenance and non-deterministic constants.
295struct ValueSet<'a, 'tcx> {
296    indices: HashTable<VnIndex>,
297    hashes: IndexVec<VnIndex, u64>,
298    values: IndexVec<VnIndex, Value<'a, 'tcx>>,
299    types: IndexVec<VnIndex, Ty<'tcx>>,
300}
301
302impl<'a, 'tcx> ValueSet<'a, 'tcx> {
303    fn new(num_values: usize) -> ValueSet<'a, 'tcx> {
304        ValueSet {
305            indices: HashTable::with_capacity(num_values),
306            hashes: IndexVec::with_capacity(num_values),
307            values: IndexVec::with_capacity(num_values),
308            types: IndexVec::with_capacity(num_values),
309        }
310    }
311
312    /// Insert a `(Value, Ty)` pair without hashing or deduplication.
313    /// This always creates a new `VnIndex`.
314    #[inline]
315    fn insert_unique(
316        &mut self,
317        ty: Ty<'tcx>,
318        value: impl FnOnce(VnOpaque) -> Value<'a, 'tcx>,
319    ) -> VnIndex {
320        let value = value(VnOpaque);
321
322        debug_assert!(match value {
323            Value::Opaque(_) | Value::Argument(_) | Value::Address { .. } => true,
324            Value::Constant { disambiguator, .. } => disambiguator.is_some(),
325            _ => false,
326        });
327
328        let index = self.hashes.push(0);
329        let _index = self.types.push(ty);
330        debug_assert_eq!(index, _index);
331        let _index = self.values.push(value);
332        debug_assert_eq!(index, _index);
333        index
334    }
335
336    /// Insert a `(Value, Ty)` pair to be deduplicated.
337    /// Returns `true` as second tuple field if this value did not exist previously.
338    #[allow(rustc::disallowed_pass_by_ref)] // closures take `&VnIndex`
339    fn insert(&mut self, ty: Ty<'tcx>, value: Value<'a, 'tcx>) -> (VnIndex, bool) {
340        debug_assert!(match value {
341            Value::Opaque(_) | Value::Address { .. } => false,
342            Value::Constant { disambiguator, .. } => disambiguator.is_none(),
343            _ => true,
344        });
345
346        let hash: u64 = {
347            let mut h = FxHasher::default();
348            value.hash(&mut h);
349            ty.hash(&mut h);
350            h.finish()
351        };
352
353        let eq = |index: &VnIndex| self.values[*index] == value && self.types[*index] == ty;
354        let hasher = |index: &VnIndex| self.hashes[*index];
355        match self.indices.entry(hash, eq, hasher) {
356            Entry::Occupied(entry) => {
357                let index = *entry.get();
358                (index, false)
359            }
360            Entry::Vacant(entry) => {
361                let index = self.hashes.push(hash);
362                entry.insert(index);
363                let _index = self.values.push(value);
364                debug_assert_eq!(index, _index);
365                let _index = self.types.push(ty);
366                debug_assert_eq!(index, _index);
367                (index, true)
368            }
369        }
370    }
371
372    /// Return the `Value` associated with the given `VnIndex`.
373    #[inline]
374    fn value(&self, index: VnIndex) -> Value<'a, 'tcx> {
375        self.values[index]
376    }
377
378    /// Return the type associated with the given `VnIndex`.
379    #[inline]
380    fn ty(&self, index: VnIndex) -> Ty<'tcx> {
381        self.types[index]
382    }
383}
384
385struct VnState<'body, 'a, 'tcx> {
386    tcx: TyCtxt<'tcx>,
387    ecx: InterpCx<'tcx, DummyMachine>,
388    local_decls: &'body LocalDecls<'tcx>,
389    is_coroutine: bool,
390    /// Value stored in each local.
391    locals: IndexVec<Local, Option<VnIndex>>,
392    /// Locals that are assigned that value.
393    // This vector does not hold all the values of `VnIndex` that we create.
394    rev_locals: IndexVec<VnIndex, SmallVec<[Local; 1]>>,
395    values: ValueSet<'a, 'tcx>,
396    /// Values evaluated as constants if possible.
397    /// - `None` are values not computed yet;
398    /// - `Some(None)` are values for which computation has failed;
399    /// - `Some(Some(op))` are successful computations.
400    evaluated: IndexVec<VnIndex, Option<Option<&'a OpTy<'tcx>>>>,
401    ssa: &'body SsaLocals,
402    dominators: Dominators<BasicBlock>,
403    reused_locals: DenseBitSet<Local>,
404    arena: &'a DroplessArena,
405}
406
407impl<'body, 'a, 'tcx> VnState<'body, 'a, 'tcx> {
408    fn new(
409        tcx: TyCtxt<'tcx>,
410        body: &Body<'tcx>,
411        typing_env: ty::TypingEnv<'tcx>,
412        ssa: &'body SsaLocals,
413        dominators: Dominators<BasicBlock>,
414        local_decls: &'body LocalDecls<'tcx>,
415        arena: &'a DroplessArena,
416    ) -> Self {
417        // Compute a rough estimate of the number of values in the body from the number of
418        // statements. This is meant to reduce the number of allocations, but it's all right if
419        // we miss the exact amount. We estimate based on 2 values per statement (one in LHS and
420        // one in RHS) and 4 values per terminator (for call operands).
421        let num_values =
422            2 * body.basic_blocks.iter().map(|bbdata| bbdata.statements.len()).sum::<usize>()
423                + 4 * body.basic_blocks.len();
424        VnState {
425            tcx,
426            ecx: InterpCx::new(tcx, DUMMY_SP, typing_env, DummyMachine),
427            local_decls,
428            is_coroutine: body.coroutine.is_some(),
429            locals: IndexVec::from_elem(None, local_decls),
430            rev_locals: IndexVec::with_capacity(num_values),
431            values: ValueSet::new(num_values),
432            evaluated: IndexVec::with_capacity(num_values),
433            ssa,
434            dominators,
435            reused_locals: DenseBitSet::new_empty(local_decls.len()),
436            arena,
437        }
438    }
439
440    fn typing_env(&self) -> ty::TypingEnv<'tcx> {
441        self.ecx.typing_env()
442    }
443
444    fn insert_unique(
445        &mut self,
446        ty: Ty<'tcx>,
447        value: impl FnOnce(VnOpaque) -> Value<'a, 'tcx>,
448    ) -> VnIndex {
449        let index = self.values.insert_unique(ty, value);
450        let _index = self.evaluated.push(None);
451        debug_assert_eq!(index, _index);
452        let _index = self.rev_locals.push(SmallVec::new());
453        debug_assert_eq!(index, _index);
454        index
455    }
456
457    #[instrument(level = "trace", skip(self), ret)]
458    fn insert(&mut self, ty: Ty<'tcx>, value: Value<'a, 'tcx>) -> VnIndex {
459        let (index, new) = self.values.insert(ty, value);
460        if new {
461            // Grow `evaluated` and `rev_locals` here to amortize the allocations.
462            let _index = self.evaluated.push(None);
463            debug_assert_eq!(index, _index);
464            let _index = self.rev_locals.push(SmallVec::new());
465            debug_assert_eq!(index, _index);
466        }
467        index
468    }
469
470    /// Create a new `Value` for which we have no information at all, except that it is distinct
471    /// from all the others.
472    #[instrument(level = "trace", skip(self), ret)]
473    fn new_opaque(&mut self, ty: Ty<'tcx>) -> VnIndex {
474        let index = self.insert_unique(ty, Value::Opaque);
475        self.evaluated[index] = Some(None);
476        index
477    }
478
479    #[instrument(level = "trace", skip(self), ret)]
480    fn new_argument(&mut self, ty: Ty<'tcx>) -> VnIndex {
481        let index = self.insert_unique(ty, Value::Argument);
482        self.evaluated[index] = Some(None);
483        index
484    }
485
486    /// Create a new `Value::Address` distinct from all the others.
487    #[instrument(level = "trace", skip(self), ret)]
488    fn new_pointer(&mut self, place: Place<'tcx>, kind: AddressKind) -> Option<VnIndex> {
489        let pty = place.ty(self.local_decls, self.tcx).ty;
490        let ty = match kind {
491            AddressKind::Ref(bk) => {
492                Ty::new_ref(self.tcx, self.tcx.lifetimes.re_erased, pty, bk.to_mutbl_lossy())
493            }
494            AddressKind::Address(mutbl) => Ty::new_ptr(self.tcx, pty, mutbl.to_mutbl_lossy()),
495        };
496
497        let mut projection = place.projection.iter();
498        let base = if place.is_indirect_first_projection() {
499            let base = self.locals[place.local]?;
500            // Skip the initial `Deref`.
501            projection.next();
502            AddressBase::Deref(base)
503        } else if self.ssa.is_ssa(place.local) {
504            // Only propagate the pointer of the SSA local.
505            AddressBase::Local(place.local)
506        } else {
507            return None;
508        };
509        // Do not try evaluating inside `Index`, this has been done by `simplify_place_projection`.
510        let projection =
511            projection.map(|proj| proj.try_map(|index| self.locals[index], |ty| ty).ok_or(()));
512        let projection = self.arena.try_alloc_from_iter(projection).ok()?;
513
514        let index = self.insert_unique(ty, |provenance| Value::Address {
515            base,
516            projection,
517            kind,
518            provenance,
519        });
520        Some(index)
521    }
522
523    #[instrument(level = "trace", skip(self), ret)]
524    fn insert_constant(&mut self, value: Const<'tcx>) -> VnIndex {
525        if is_deterministic(value) {
526            // The constant is deterministic, no need to disambiguate.
527            let constant = Value::Constant { value, disambiguator: None };
528            self.insert(value.ty(), constant)
529        } else {
530            // Multiple mentions of this constant will yield different values,
531            // so assign a different `disambiguator` to ensure they do not get the same `VnIndex`.
532            self.insert_unique(value.ty(), |disambiguator| Value::Constant {
533                value,
534                disambiguator: Some(disambiguator),
535            })
536        }
537    }
538
539    #[inline]
540    fn get(&self, index: VnIndex) -> Value<'a, 'tcx> {
541        self.values.value(index)
542    }
543
544    #[inline]
545    fn ty(&self, index: VnIndex) -> Ty<'tcx> {
546        self.values.ty(index)
547    }
548
549    /// Record that `local` is assigned `value`. `local` must be SSA.
550    #[instrument(level = "trace", skip(self))]
551    fn assign(&mut self, local: Local, value: VnIndex) {
552        debug_assert!(self.ssa.is_ssa(local));
553        self.locals[local] = Some(value);
554        self.rev_locals[value].push(local);
555    }
556
557    fn insert_bool(&mut self, flag: bool) -> VnIndex {
558        // Booleans are deterministic.
559        let value = Const::from_bool(self.tcx, flag);
560        debug_assert!(is_deterministic(value));
561        self.insert(self.tcx.types.bool, Value::Constant { value, disambiguator: None })
562    }
563
564    fn insert_scalar(&mut self, ty: Ty<'tcx>, scalar: Scalar) -> VnIndex {
565        // Scalars are deterministic.
566        let value = Const::from_scalar(self.tcx, scalar, ty);
567        debug_assert!(is_deterministic(value));
568        self.insert(ty, Value::Constant { value, disambiguator: None })
569    }
570
571    fn insert_tuple(&mut self, ty: Ty<'tcx>, values: &[VnIndex]) -> VnIndex {
572        self.insert(ty, Value::Aggregate(VariantIdx::ZERO, self.arena.alloc_slice(values)))
573    }
574
575    #[instrument(level = "trace", skip(self), ret)]
576    fn eval_to_const_inner(&mut self, value: VnIndex) -> Option<OpTy<'tcx>> {
577        use Value::*;
578        let ty = self.ty(value);
579        // Avoid computing layouts inside a coroutine, as that can cause cycles.
580        let ty = if !self.is_coroutine || ty.is_scalar() {
581            self.ecx.layout_of(ty).ok()?
582        } else {
583            return None;
584        };
585        let op = match self.get(value) {
586            _ if ty.is_zst() => ImmTy::uninit(ty).into(),
587
588            Opaque(_) | Argument(_) => return None,
589            // Keep runtime check constants as symbolic.
590            RuntimeChecks(..) => return None,
591
592            // In general, evaluating repeat expressions just consumes a lot of memory.
593            // But in the special case that the element is just Immediate::Uninit, we can evaluate
594            // it without extra memory! If we don't propagate uninit values like this, LLVM can get
595            // very confused: https://github.com/rust-lang/rust/issues/139355
596            Repeat(value, _count) => {
597                let value = self.eval_to_const(value)?;
598                if value.is_immediate_uninit() {
599                    ImmTy::uninit(ty).into()
600                } else {
601                    return None;
602                }
603            }
604            Constant { ref value, disambiguator: _ } => {
605                self.ecx.eval_mir_constant(value, DUMMY_SP, None).discard_err()?
606            }
607            Aggregate(variant, ref fields) => {
608                let fields =
609                    fields.iter().map(|&f| self.eval_to_const(f)).collect::<Option<Vec<_>>>()?;
610                let variant = if ty.ty.is_enum() { Some(variant) } else { None };
611                let (BackendRepr::Scalar(..) | BackendRepr::ScalarPair(..)) = ty.backend_repr
612                else {
613                    return None;
614                };
615                let dest = self.ecx.allocate(ty, MemoryKind::Stack).discard_err()?;
616                let variant_dest = if let Some(variant) = variant {
617                    self.ecx.project_downcast(&dest, variant).discard_err()?
618                } else {
619                    dest.clone()
620                };
621                for (field_index, op) in fields.into_iter().enumerate() {
622                    let field_dest = self
623                        .ecx
624                        .project_field(&variant_dest, FieldIdx::from_usize(field_index))
625                        .discard_err()?;
626                    self.ecx.copy_op(op, &field_dest).discard_err()?;
627                }
628                self.ecx
629                    .write_discriminant(variant.unwrap_or(FIRST_VARIANT), &dest)
630                    .discard_err()?;
631                self.ecx
632                    .alloc_mark_immutable(dest.ptr().provenance.unwrap().alloc_id())
633                    .discard_err()?;
634                dest.into()
635            }
636            Union(active_field, field) => {
637                let field = self.eval_to_const(field)?;
638                if field.layout.layout.is_zst() {
639                    ImmTy::from_immediate(Immediate::Uninit, ty).into()
640                } else if matches!(
641                    ty.backend_repr,
642                    BackendRepr::Scalar(..) | BackendRepr::ScalarPair(..)
643                ) {
644                    let dest = self.ecx.allocate(ty, MemoryKind::Stack).discard_err()?;
645                    let field_dest = self.ecx.project_field(&dest, active_field).discard_err()?;
646                    self.ecx.copy_op(field, &field_dest).discard_err()?;
647                    self.ecx
648                        .alloc_mark_immutable(dest.ptr().provenance.unwrap().alloc_id())
649                        .discard_err()?;
650                    dest.into()
651                } else {
652                    return None;
653                }
654            }
655            RawPtr { pointer, metadata } => {
656                let pointer = self.eval_to_const(pointer)?;
657                let metadata = self.eval_to_const(metadata)?;
658
659                // Pointers don't have fields, so don't `project_field` them.
660                let data = self.ecx.read_pointer(pointer).discard_err()?;
661                let meta = if metadata.layout.is_zst() {
662                    MemPlaceMeta::None
663                } else {
664                    MemPlaceMeta::Meta(self.ecx.read_scalar(metadata).discard_err()?)
665                };
666                let ptr_imm = Immediate::new_pointer_with_meta(data, meta, &self.ecx);
667                ImmTy::from_immediate(ptr_imm, ty).into()
668            }
669
670            Projection(base, elem) => {
671                let base = self.eval_to_const(base)?;
672                // `Index` by constants should have been replaced by `ConstantIndex` by
673                // `simplify_place_projection`.
674                let elem = elem.try_map(|_| None, |()| ty.ty)?;
675                self.ecx.project(base, elem).discard_err()?
676            }
677            Address { base, projection, .. } => {
678                debug_assert!(!projection.contains(&ProjectionElem::Deref));
679                let pointer = match base {
680                    AddressBase::Deref(pointer) => self.eval_to_const(pointer)?,
681                    // We have no stack to point to.
682                    AddressBase::Local(_) => return None,
683                };
684                let mut mplace = self.ecx.deref_pointer(pointer).discard_err()?;
685                for elem in projection {
686                    // `Index` by constants should have been replaced by `ConstantIndex` by
687                    // `simplify_place_projection`.
688                    let elem = elem.try_map(|_| None, |ty| ty)?;
689                    mplace = self.ecx.project(&mplace, elem).discard_err()?;
690                }
691                let pointer = mplace.to_ref(&self.ecx);
692                ImmTy::from_immediate(pointer, ty).into()
693            }
694
695            Discriminant(base) => {
696                let base = self.eval_to_const(base)?;
697                let variant = self.ecx.read_discriminant(base).discard_err()?;
698                let discr_value =
699                    self.ecx.discriminant_for_variant(base.layout.ty, variant).discard_err()?;
700                discr_value.into()
701            }
702            UnaryOp(un_op, operand) => {
703                let operand = self.eval_to_const(operand)?;
704                let operand = self.ecx.read_immediate(operand).discard_err()?;
705                let val = self.ecx.unary_op(un_op, &operand).discard_err()?;
706                val.into()
707            }
708            BinaryOp(bin_op, lhs, rhs) => {
709                let lhs = self.eval_to_const(lhs)?;
710                let rhs = self.eval_to_const(rhs)?;
711                let lhs = self.ecx.read_immediate(lhs).discard_err()?;
712                let rhs = self.ecx.read_immediate(rhs).discard_err()?;
713                let val = self.ecx.binary_op(bin_op, &lhs, &rhs).discard_err()?;
714                val.into()
715            }
716            Cast { kind, value } => match kind {
717                CastKind::IntToInt | CastKind::IntToFloat => {
718                    let value = self.eval_to_const(value)?;
719                    let value = self.ecx.read_immediate(value).discard_err()?;
720                    let res = self.ecx.int_to_int_or_float(&value, ty).discard_err()?;
721                    res.into()
722                }
723                CastKind::FloatToFloat | CastKind::FloatToInt => {
724                    let value = self.eval_to_const(value)?;
725                    let value = self.ecx.read_immediate(value).discard_err()?;
726                    let res = self.ecx.float_to_float_or_int(&value, ty).discard_err()?;
727                    res.into()
728                }
729                CastKind::Transmute | CastKind::Subtype => {
730                    let value = self.eval_to_const(value)?;
731                    // `offset` for immediates generally only supports projections that match the
732                    // type of the immediate. However, as a HACK, we exploit that it can also do
733                    // limited transmutes: it only works between types with the same layout, and
734                    // cannot transmute pointers to integers.
735                    if value.as_mplace_or_imm().is_right() {
736                        let can_transmute = match (value.layout.backend_repr, ty.backend_repr) {
737                            (BackendRepr::Scalar(s1), BackendRepr::Scalar(s2)) => {
738                                s1.size(&self.ecx) == s2.size(&self.ecx)
739                                    && !matches!(s1.primitive(), Primitive::Pointer(..))
740                            }
741                            (BackendRepr::ScalarPair(a1, b1), BackendRepr::ScalarPair(a2, b2)) => {
742                                a1.size(&self.ecx) == a2.size(&self.ecx)
743                                    && b1.size(&self.ecx) == b2.size(&self.ecx)
744                                    // The alignment of the second component determines its offset, so that also needs to match.
745                                    && b1.align(&self.ecx) == b2.align(&self.ecx)
746                                    // None of the inputs may be a pointer.
747                                    && !matches!(a1.primitive(), Primitive::Pointer(..))
748                                    && !matches!(b1.primitive(), Primitive::Pointer(..))
749                            }
750                            _ => false,
751                        };
752                        if !can_transmute {
753                            return None;
754                        }
755                    }
756                    value.offset(Size::ZERO, ty, &self.ecx).discard_err()?
757                }
758                CastKind::PointerCoercion(ty::adjustment::PointerCoercion::Unsize, _) => {
759                    let src = self.eval_to_const(value)?;
760                    let dest = self.ecx.allocate(ty, MemoryKind::Stack).discard_err()?;
761                    self.ecx.unsize_into(src, ty, &dest).discard_err()?;
762                    self.ecx
763                        .alloc_mark_immutable(dest.ptr().provenance.unwrap().alloc_id())
764                        .discard_err()?;
765                    dest.into()
766                }
767                CastKind::FnPtrToPtr | CastKind::PtrToPtr => {
768                    let src = self.eval_to_const(value)?;
769                    let src = self.ecx.read_immediate(src).discard_err()?;
770                    let ret = self.ecx.ptr_to_ptr(&src, ty).discard_err()?;
771                    ret.into()
772                }
773                CastKind::PointerCoercion(ty::adjustment::PointerCoercion::UnsafeFnPointer, _) => {
774                    let src = self.eval_to_const(value)?;
775                    let src = self.ecx.read_immediate(src).discard_err()?;
776                    ImmTy::from_immediate(*src, ty).into()
777                }
778                _ => return None,
779            },
780        };
781        Some(op)
782    }
783
784    fn eval_to_const(&mut self, index: VnIndex) -> Option<&'a OpTy<'tcx>> {
785        if let Some(op) = self.evaluated[index] {
786            return op;
787        }
788        let op = self.eval_to_const_inner(index);
789        self.evaluated[index] = Some(self.arena.alloc(op).as_ref());
790        self.evaluated[index].unwrap()
791    }
792
793    /// Represent the *value* we obtain by dereferencing an `Address` value.
794    #[instrument(level = "trace", skip(self), ret)]
795    fn dereference_address(
796        &mut self,
797        base: AddressBase,
798        projection: &[ProjectionElem<VnIndex, Ty<'tcx>>],
799    ) -> Option<VnIndex> {
800        let (mut place_ty, mut value) = match base {
801            // The base is a local, so we take the local's value and project from it.
802            AddressBase::Local(local) => {
803                let local = self.locals[local]?;
804                let place_ty = PlaceTy::from_ty(self.ty(local));
805                (place_ty, local)
806            }
807            // The base is a pointer's deref, so we introduce the implicit deref.
808            AddressBase::Deref(reborrow) => {
809                let place_ty = PlaceTy::from_ty(self.ty(reborrow));
810                self.project(place_ty, reborrow, ProjectionElem::Deref)?
811            }
812        };
813        for &proj in projection {
814            (place_ty, value) = self.project(place_ty, value, proj)?;
815        }
816        Some(value)
817    }
818
819    #[instrument(level = "trace", skip(self), ret)]
820    fn project(
821        &mut self,
822        place_ty: PlaceTy<'tcx>,
823        value: VnIndex,
824        proj: ProjectionElem<VnIndex, Ty<'tcx>>,
825    ) -> Option<(PlaceTy<'tcx>, VnIndex)> {
826        let projection_ty = place_ty.projection_ty(self.tcx, proj);
827        let proj = match proj {
828            ProjectionElem::Deref => {
829                if let Some(Mutability::Not) = place_ty.ty.ref_mutability()
830                    && projection_ty.ty.is_freeze(self.tcx, self.typing_env())
831                {
832                    if let Value::Address { base, projection, .. } = self.get(value)
833                        && let Some(value) = self.dereference_address(base, projection)
834                    {
835                        return Some((projection_ty, value));
836                    }
837                    // DO NOT reason the pointer value.
838                    // We cannot unify two pointers that dereference same local, because they may
839                    // have different lifetimes.
840                    // ```
841                    // let b: &T = *a;
842                    // ... `a` is allowed to be modified. `c` and `b` have different borrowing lifetime.
843                    // Unifying them will extend the lifetime of `b`.
844                    // let c: &T = *a;
845                    // ```
846                    if projection_ty.ty.is_ref() {
847                        return None;
848                    }
849
850                    // An immutable borrow `_x` always points to the same value for the
851                    // lifetime of the borrow, so we can merge all instances of `*_x`.
852                    let deref = self
853                        .insert(projection_ty.ty, Value::Projection(value, ProjectionElem::Deref));
854                    return Some((projection_ty, deref));
855                } else {
856                    return None;
857                }
858            }
859            ProjectionElem::Downcast(name, index) => ProjectionElem::Downcast(name, index),
860            ProjectionElem::Field(f, _) => match self.get(value) {
861                Value::Aggregate(_, fields) => return Some((projection_ty, fields[f.as_usize()])),
862                Value::Union(active, field) if active == f => return Some((projection_ty, field)),
863                Value::Projection(outer_value, ProjectionElem::Downcast(_, read_variant))
864                    if let Value::Aggregate(written_variant, fields) = self.get(outer_value)
865                    // This pass is not aware of control-flow, so we do not know whether the
866                    // replacement we are doing is actually reachable. We could be in any arm of
867                    // ```
868                    // match Some(x) {
869                    //     Some(y) => /* stuff */,
870                    //     None => /* other */,
871                    // }
872                    // ```
873                    //
874                    // In surface rust, the current statement would be unreachable.
875                    //
876                    // However, from the reference chapter on enums and RFC 2195,
877                    // accessing the wrong variant is not UB if the enum has repr.
878                    // So it's not impossible for a series of MIR opts to generate
879                    // a downcast to an inactive variant.
880                    && written_variant == read_variant =>
881                {
882                    return Some((projection_ty, fields[f.as_usize()]));
883                }
884                _ => ProjectionElem::Field(f, ()),
885            },
886            ProjectionElem::Index(idx) => {
887                if let Value::Repeat(inner, _) = self.get(value) {
888                    return Some((projection_ty, inner));
889                }
890                ProjectionElem::Index(idx)
891            }
892            ProjectionElem::ConstantIndex { offset, min_length, from_end } => {
893                match self.get(value) {
894                    Value::Repeat(inner, _) => {
895                        return Some((projection_ty, inner));
896                    }
897                    Value::Aggregate(_, operands) => {
898                        let offset = if from_end {
899                            operands.len() - offset as usize
900                        } else {
901                            offset as usize
902                        };
903                        let value = operands.get(offset).copied()?;
904                        return Some((projection_ty, value));
905                    }
906                    _ => {}
907                };
908                ProjectionElem::ConstantIndex { offset, min_length, from_end }
909            }
910            ProjectionElem::Subslice { from, to, from_end } => {
911                ProjectionElem::Subslice { from, to, from_end }
912            }
913            ProjectionElem::OpaqueCast(_) => ProjectionElem::OpaqueCast(()),
914            ProjectionElem::UnwrapUnsafeBinder(_) => ProjectionElem::UnwrapUnsafeBinder(()),
915        };
916
917        let value = self.insert(projection_ty.ty, Value::Projection(value, proj));
918        Some((projection_ty, value))
919    }
920
921    /// Simplify the projection chain if we know better.
922    #[instrument(level = "trace", skip(self))]
923    fn simplify_place_projection(&mut self, place: &mut Place<'tcx>, location: Location) {
924        // If the projection is indirect, we treat the local as a value, so can replace it with
925        // another local.
926        if place.is_indirect_first_projection()
927            && let Some(base) = self.locals[place.local]
928            && let Some(new_local) = self.try_as_local(base, location)
929            && place.local != new_local
930        {
931            place.local = new_local;
932            self.reused_locals.insert(new_local);
933        }
934
935        let mut projection = Cow::Borrowed(&place.projection[..]);
936
937        for i in 0..projection.len() {
938            let elem = projection[i];
939            if let ProjectionElem::Index(idx_local) = elem
940                && let Some(idx) = self.locals[idx_local]
941            {
942                if let Some(offset) = self.eval_to_const(idx)
943                    && let Some(offset) = self.ecx.read_target_usize(offset).discard_err()
944                    && let Some(min_length) = offset.checked_add(1)
945                {
946                    projection.to_mut()[i] =
947                        ProjectionElem::ConstantIndex { offset, min_length, from_end: false };
948                } else if let Some(new_idx_local) = self.try_as_local(idx, location)
949                    && idx_local != new_idx_local
950                {
951                    projection.to_mut()[i] = ProjectionElem::Index(new_idx_local);
952                    self.reused_locals.insert(new_idx_local);
953                }
954            }
955        }
956
957        if Cow::is_owned(&projection) {
958            place.projection = self.tcx.mk_place_elems(&projection);
959        }
960
961        trace!(?place);
962    }
963
964    /// Represent the *value* which would be read from `place`. If we succeed, return it.
965    /// If we fail, return a `PlaceRef` that contains the same value.
966    #[instrument(level = "trace", skip(self), ret)]
967    fn compute_place_value(
968        &mut self,
969        place: Place<'tcx>,
970        location: Location,
971    ) -> Result<VnIndex, PlaceRef<'tcx>> {
972        // Invariant: `place` and `place_ref` point to the same value, even if they point to
973        // different memory locations.
974        let mut place_ref = place.as_ref();
975
976        // Invariant: `value` holds the value up-to the `index`th projection excluded.
977        let Some(mut value) = self.locals[place.local] else { return Err(place_ref) };
978        // Invariant: `value` has type `place_ty`, with optional downcast variant if needed.
979        let mut place_ty = PlaceTy::from_ty(self.local_decls[place.local].ty);
980        for (index, proj) in place.projection.iter().enumerate() {
981            if let Some(local) = self.try_as_local(value, location) {
982                // Both `local` and `Place { local: place.local, projection: projection[..index] }`
983                // hold the same value. Therefore, following place holds the value in the original
984                // `place`.
985                place_ref = PlaceRef { local, projection: &place.projection[index..] };
986            }
987
988            let Some(proj) = proj.try_map(|value| self.locals[value], |ty| ty) else {
989                return Err(place_ref);
990            };
991            let Some(ty_and_value) = self.project(place_ty, value, proj) else {
992                return Err(place_ref);
993            };
994            (place_ty, value) = ty_and_value;
995        }
996
997        Ok(value)
998    }
999
1000    /// Represent the *value* which would be read from `place`, and point `place` to a preexisting
1001    /// place with the same value (if that already exists).
1002    #[instrument(level = "trace", skip(self), ret)]
1003    fn simplify_place_value(
1004        &mut self,
1005        place: &mut Place<'tcx>,
1006        location: Location,
1007    ) -> Option<VnIndex> {
1008        self.simplify_place_projection(place, location);
1009
1010        match self.compute_place_value(*place, location) {
1011            Ok(value) => {
1012                if let Some(new_place) = self.try_as_place(value, location, true)
1013                    && (new_place.local != place.local
1014                        || new_place.projection.len() < place.projection.len())
1015                {
1016                    *place = new_place;
1017                    self.reused_locals.insert(new_place.local);
1018                }
1019                Some(value)
1020            }
1021            Err(place_ref) => {
1022                if place_ref.local != place.local
1023                    || place_ref.projection.len() < place.projection.len()
1024                {
1025                    // By the invariant on `place_ref`.
1026                    *place = place_ref.project_deeper(&[], self.tcx);
1027                    self.reused_locals.insert(place_ref.local);
1028                }
1029                None
1030            }
1031        }
1032    }
1033
1034    #[instrument(level = "trace", skip(self), ret)]
1035    fn simplify_operand(
1036        &mut self,
1037        operand: &mut Operand<'tcx>,
1038        location: Location,
1039    ) -> Option<VnIndex> {
1040        let value = match *operand {
1041            Operand::RuntimeChecks(c) => self.insert(self.tcx.types.bool, Value::RuntimeChecks(c)),
1042            Operand::Constant(ref constant) => self.insert_constant(constant.const_),
1043            Operand::Copy(ref mut place) | Operand::Move(ref mut place) => {
1044                self.simplify_place_value(place, location)?
1045            }
1046        };
1047        if let Some(const_) = self.try_as_constant(value) {
1048            *operand = Operand::Constant(Box::new(const_));
1049        } else if let Value::RuntimeChecks(c) = self.get(value) {
1050            *operand = Operand::RuntimeChecks(c);
1051        }
1052        Some(value)
1053    }
1054
1055    #[instrument(level = "trace", skip(self), ret)]
1056    fn simplify_rvalue(
1057        &mut self,
1058        lhs: &Place<'tcx>,
1059        rvalue: &mut Rvalue<'tcx>,
1060        location: Location,
1061    ) -> Option<VnIndex> {
1062        let value = match *rvalue {
1063            // Forward values.
1064            Rvalue::Use(ref mut operand, _) => return self.simplify_operand(operand, location),
1065
1066            // Roots.
1067            Rvalue::Repeat(ref mut op, amount) => {
1068                let op = self.simplify_operand(op, location)?;
1069                Value::Repeat(op, amount)
1070            }
1071            Rvalue::Aggregate(..) => return self.simplify_aggregate(rvalue, location),
1072            Rvalue::Ref(_, borrow_kind, ref mut place) => {
1073                self.simplify_place_projection(place, location);
1074                return self.new_pointer(*place, AddressKind::Ref(borrow_kind));
1075            }
1076            Rvalue::RawPtr(mutbl, ref mut place) => {
1077                self.simplify_place_projection(place, location);
1078                return self.new_pointer(*place, AddressKind::Address(mutbl));
1079            }
1080            Rvalue::WrapUnsafeBinder(ref mut op, _) => {
1081                let value = self.simplify_operand(op, location)?;
1082                Value::Cast { kind: CastKind::Transmute, value }
1083            }
1084
1085            // Operations.
1086            Rvalue::Cast(ref mut kind, ref mut value, to) => {
1087                return self.simplify_cast(kind, value, to, location);
1088            }
1089            Rvalue::BinaryOp(op, box (ref mut lhs, ref mut rhs)) => {
1090                return self.simplify_binary(op, lhs, rhs, location);
1091            }
1092            Rvalue::UnaryOp(op, ref mut arg_op) => {
1093                return self.simplify_unary(op, arg_op, location);
1094            }
1095            Rvalue::Discriminant(ref mut place) => {
1096                let place = self.simplify_place_value(place, location)?;
1097                if let Some(discr) = self.simplify_discriminant(place) {
1098                    return Some(discr);
1099                }
1100                Value::Discriminant(place)
1101            }
1102
1103            // Unsupported values.
1104            Rvalue::ThreadLocalRef(..) => return None,
1105            Rvalue::CopyForDeref(_) => {
1106                bug!("forbidden in runtime MIR: {rvalue:?}")
1107            }
1108        };
1109        let ty = rvalue.ty(self.local_decls, self.tcx);
1110        Some(self.insert(ty, value))
1111    }
1112
1113    fn simplify_discriminant(&mut self, place: VnIndex) -> Option<VnIndex> {
1114        let enum_ty = self.ty(place);
1115        if enum_ty.is_enum()
1116            && let Value::Aggregate(variant, _) = self.get(place)
1117        {
1118            let discr = self.ecx.discriminant_for_variant(enum_ty, variant).discard_err()?;
1119            return Some(self.insert_scalar(discr.layout.ty, discr.to_scalar()));
1120        }
1121
1122        None
1123    }
1124
1125    fn try_as_place_elem(
1126        &mut self,
1127        ty: Ty<'tcx>,
1128        proj: ProjectionElem<VnIndex, ()>,
1129        loc: Location,
1130    ) -> Option<PlaceElem<'tcx>> {
1131        proj.try_map(
1132            |value| {
1133                let local = self.try_as_local(value, loc)?;
1134                self.reused_locals.insert(local);
1135                Some(local)
1136            },
1137            |()| ty,
1138        )
1139    }
1140
1141    fn simplify_aggregate_to_copy(
1142        &mut self,
1143        ty: Ty<'tcx>,
1144        variant_index: VariantIdx,
1145        fields: &[VnIndex],
1146    ) -> Option<VnIndex> {
1147        let Some(&first_field) = fields.first() else { return None };
1148        let Value::Projection(copy_from_value, _) = self.get(first_field) else { return None };
1149
1150        // All fields must correspond one-to-one and come from the same aggregate value.
1151        if fields.iter().enumerate().any(|(index, &v)| {
1152            if let Value::Projection(pointer, ProjectionElem::Field(from_index, _)) = self.get(v)
1153                && copy_from_value == pointer
1154                && from_index.index() == index
1155            {
1156                return false;
1157            }
1158            true
1159        }) {
1160            return None;
1161        }
1162
1163        let mut copy_from_local_value = copy_from_value;
1164        if let Value::Projection(pointer, proj) = self.get(copy_from_value)
1165            && let ProjectionElem::Downcast(_, read_variant) = proj
1166        {
1167            if variant_index == read_variant {
1168                // When copying a variant, there is no need to downcast.
1169                copy_from_local_value = pointer;
1170            } else {
1171                // The copied variant must be identical.
1172                return None;
1173            }
1174        }
1175
1176        // Both must be variants of the same type.
1177        if self.ty(copy_from_local_value) == ty { Some(copy_from_local_value) } else { None }
1178    }
1179
1180    fn simplify_aggregate(
1181        &mut self,
1182        rvalue: &mut Rvalue<'tcx>,
1183        location: Location,
1184    ) -> Option<VnIndex> {
1185        let tcx = self.tcx;
1186        let ty = rvalue.ty(self.local_decls, tcx);
1187
1188        let Rvalue::Aggregate(box ref kind, ref mut field_ops) = *rvalue else { bug!() };
1189
1190        if field_ops.is_empty() {
1191            let is_zst = match *kind {
1192                AggregateKind::Array(..)
1193                | AggregateKind::Tuple
1194                | AggregateKind::Closure(..)
1195                | AggregateKind::CoroutineClosure(..) => true,
1196                // Only enums can be non-ZST.
1197                AggregateKind::Adt(did, ..) => tcx.def_kind(did) != DefKind::Enum,
1198                // Coroutines are never ZST, as they at least contain the implicit states.
1199                AggregateKind::Coroutine(..) => false,
1200                AggregateKind::RawPtr(..) => bug!("MIR for RawPtr aggregate must have 2 fields"),
1201            };
1202
1203            if is_zst {
1204                return Some(self.insert_constant(Const::zero_sized(ty)));
1205            }
1206        }
1207
1208        let fields = self.arena.alloc_from_iter(field_ops.iter_mut().map(|op| {
1209            self.simplify_operand(op, location)
1210                .unwrap_or_else(|| self.new_opaque(op.ty(self.local_decls, self.tcx)))
1211        }));
1212
1213        let variant_index = match *kind {
1214            AggregateKind::Array(..) | AggregateKind::Tuple => {
1215                assert!(!field_ops.is_empty());
1216                FIRST_VARIANT
1217            }
1218            AggregateKind::Closure(..)
1219            | AggregateKind::CoroutineClosure(..)
1220            | AggregateKind::Coroutine(..) => FIRST_VARIANT,
1221            AggregateKind::Adt(_, variant_index, _, _, None) => variant_index,
1222            // Do not track unions.
1223            AggregateKind::Adt(_, _, _, _, Some(active_field)) => {
1224                let field = *fields.first()?;
1225                return Some(self.insert(ty, Value::Union(active_field, field)));
1226            }
1227            AggregateKind::RawPtr(..) => {
1228                assert_eq!(field_ops.len(), 2);
1229                let [mut pointer, metadata] = fields.try_into().unwrap();
1230
1231                // Any thin pointer of matching mutability is fine as the data pointer.
1232                let mut was_updated = false;
1233                while let Value::Cast { kind: CastKind::PtrToPtr, value: cast_value } =
1234                    self.get(pointer)
1235                    && let ty::RawPtr(from_pointee_ty, from_mtbl) = self.ty(cast_value).kind()
1236                    && let ty::RawPtr(_, output_mtbl) = ty.kind()
1237                    && from_mtbl == output_mtbl
1238                    && from_pointee_ty.is_sized(self.tcx, self.typing_env())
1239                {
1240                    pointer = cast_value;
1241                    was_updated = true;
1242                }
1243
1244                if was_updated && let Some(op) = self.try_as_operand(pointer, location) {
1245                    field_ops[FieldIdx::ZERO] = op;
1246                }
1247
1248                return Some(self.insert(ty, Value::RawPtr { pointer, metadata }));
1249            }
1250        };
1251
1252        if ty.is_array()
1253            && fields.len() > 4
1254            && let Ok(&first) = fields.iter().all_equal_value()
1255        {
1256            let len = ty::Const::from_target_usize(self.tcx, fields.len().try_into().unwrap());
1257            if let Some(op) = self.try_as_operand(first, location) {
1258                *rvalue = Rvalue::Repeat(op, len);
1259            }
1260            return Some(self.insert(ty, Value::Repeat(first, len)));
1261        }
1262
1263        if let Some(value) = self.simplify_aggregate_to_copy(ty, variant_index, &fields) {
1264            if let Some(place) = self.try_as_place(value, location, true) {
1265                self.reused_locals.insert(place.local);
1266                // FIXME: Is it correct to make these retagging assignments?
1267                *rvalue = Rvalue::Use(Operand::Copy(place), WithRetag::Yes);
1268            }
1269            return Some(value);
1270        }
1271
1272        Some(self.insert(ty, Value::Aggregate(variant_index, fields)))
1273    }
1274
1275    #[instrument(level = "trace", skip(self), ret)]
1276    fn simplify_unary(
1277        &mut self,
1278        op: UnOp,
1279        arg_op: &mut Operand<'tcx>,
1280        location: Location,
1281    ) -> Option<VnIndex> {
1282        let mut arg_index = self.simplify_operand(arg_op, location)?;
1283        let arg_ty = self.ty(arg_index);
1284        let ret_ty = op.ty(self.tcx, arg_ty);
1285
1286        // PtrMetadata doesn't care about *const vs *mut vs & vs &mut,
1287        // so start by removing those distinctions so we can update the `Operand`
1288        if op == UnOp::PtrMetadata {
1289            let mut was_updated = false;
1290            loop {
1291                arg_index = match self.get(arg_index) {
1292                    // Pointer casts that preserve metadata, such as
1293                    // `*const [i32]` <-> `*mut [i32]` <-> `*mut [f32]`.
1294                    // It's critical that this not eliminate cases like
1295                    // `*const [T]` -> `*const T` which remove metadata.
1296                    // We run on potentially-generic MIR, though, so unlike codegen
1297                    // we can't always know exactly what the metadata are.
1298                    // To allow things like `*mut (?A, ?T)` <-> `*mut (?B, ?T)`,
1299                    // it's fine to get a projection as the type.
1300                    Value::Cast { kind: CastKind::PtrToPtr, value: inner }
1301                        if self.pointers_have_same_metadata(self.ty(inner), arg_ty) =>
1302                    {
1303                        inner
1304                    }
1305
1306                    // We have an unsizing cast, which assigns the length to wide pointer metadata.
1307                    Value::Cast {
1308                        kind: CastKind::PointerCoercion(ty::adjustment::PointerCoercion::Unsize, _),
1309                        value: from,
1310                    } if let Some(from) = self.ty(from).builtin_deref(true)
1311                        && let ty::Array(_, len) = from.kind()
1312                        && let Some(to) = self.ty(arg_index).builtin_deref(true)
1313                        && let ty::Slice(..) = to.kind() =>
1314                    {
1315                        return Some(self.insert_constant(Const::Ty(self.tcx.types.usize, *len)));
1316                    }
1317
1318                    // `&mut *p`, `&raw *p`, etc don't change metadata.
1319                    Value::Address { base: AddressBase::Deref(reborrowed), projection, .. }
1320                        if projection.is_empty() =>
1321                    {
1322                        reborrowed
1323                    }
1324
1325                    _ => break,
1326                };
1327                was_updated = true;
1328            }
1329
1330            if was_updated && let Some(op) = self.try_as_operand(arg_index, location) {
1331                *arg_op = op;
1332            }
1333        }
1334
1335        let value = match (op, self.get(arg_index)) {
1336            (UnOp::Not, Value::UnaryOp(UnOp::Not, inner)) => return Some(inner),
1337            (UnOp::Neg, Value::UnaryOp(UnOp::Neg, inner)) => return Some(inner),
1338            (UnOp::Not, Value::BinaryOp(BinOp::Eq, lhs, rhs)) => {
1339                Value::BinaryOp(BinOp::Ne, lhs, rhs)
1340            }
1341            (UnOp::Not, Value::BinaryOp(BinOp::Ne, lhs, rhs)) => {
1342                Value::BinaryOp(BinOp::Eq, lhs, rhs)
1343            }
1344            (UnOp::PtrMetadata, Value::RawPtr { metadata, .. }) => return Some(metadata),
1345            // We have an unsizing cast, which assigns the length to wide pointer metadata.
1346            (
1347                UnOp::PtrMetadata,
1348                Value::Cast {
1349                    kind: CastKind::PointerCoercion(ty::adjustment::PointerCoercion::Unsize, _),
1350                    value: inner,
1351                },
1352            ) if let ty::Slice(..) = arg_ty.builtin_deref(true).unwrap().kind()
1353                && let ty::Array(_, len) = self.ty(inner).builtin_deref(true).unwrap().kind() =>
1354            {
1355                return Some(self.insert_constant(Const::Ty(self.tcx.types.usize, *len)));
1356            }
1357            _ => Value::UnaryOp(op, arg_index),
1358        };
1359        Some(self.insert(ret_ty, value))
1360    }
1361
1362    #[instrument(level = "trace", skip(self), ret)]
1363    fn simplify_binary(
1364        &mut self,
1365        op: BinOp,
1366        lhs_operand: &mut Operand<'tcx>,
1367        rhs_operand: &mut Operand<'tcx>,
1368        location: Location,
1369    ) -> Option<VnIndex> {
1370        let lhs = self.simplify_operand(lhs_operand, location);
1371        let rhs = self.simplify_operand(rhs_operand, location);
1372
1373        // Only short-circuit options after we called `simplify_operand`
1374        // on both operands for side effect.
1375        let mut lhs = lhs?;
1376        let mut rhs = rhs?;
1377
1378        let lhs_ty = self.ty(lhs);
1379
1380        // If we're comparing pointers, remove `PtrToPtr` casts if the from
1381        // types of both casts and the metadata all match.
1382        if let BinOp::Eq | BinOp::Ne | BinOp::Lt | BinOp::Le | BinOp::Gt | BinOp::Ge = op
1383            && lhs_ty.is_any_ptr()
1384            && let Value::Cast { kind: CastKind::PtrToPtr, value: lhs_value } = self.get(lhs)
1385            && let Value::Cast { kind: CastKind::PtrToPtr, value: rhs_value } = self.get(rhs)
1386            && let lhs_from = self.ty(lhs_value)
1387            && lhs_from == self.ty(rhs_value)
1388            && self.pointers_have_same_metadata(lhs_from, lhs_ty)
1389        {
1390            lhs = lhs_value;
1391            rhs = rhs_value;
1392            if let Some(lhs_op) = self.try_as_operand(lhs, location)
1393                && let Some(rhs_op) = self.try_as_operand(rhs, location)
1394            {
1395                *lhs_operand = lhs_op;
1396                *rhs_operand = rhs_op;
1397            }
1398        }
1399
1400        if let Some(value) = self.simplify_binary_inner(op, lhs_ty, lhs, rhs) {
1401            return Some(value);
1402        }
1403        let ty = op.ty(self.tcx, lhs_ty, self.ty(rhs));
1404        let value = Value::BinaryOp(op, lhs, rhs);
1405        Some(self.insert(ty, value))
1406    }
1407
1408    fn simplify_binary_inner(
1409        &mut self,
1410        op: BinOp,
1411        lhs_ty: Ty<'tcx>,
1412        lhs: VnIndex,
1413        rhs: VnIndex,
1414    ) -> Option<VnIndex> {
1415        // Floats are weird enough that none of the logic below applies.
1416        let reasonable_ty =
1417            lhs_ty.is_integral() || lhs_ty.is_bool() || lhs_ty.is_char() || lhs_ty.is_any_ptr();
1418        if !reasonable_ty {
1419            return None;
1420        }
1421
1422        let layout = self.ecx.layout_of(lhs_ty).ok()?;
1423
1424        let mut as_bits = |value: VnIndex| {
1425            let constant = self.eval_to_const(value)?;
1426            if layout.backend_repr.is_scalar() {
1427                let scalar = self.ecx.read_scalar(constant).discard_err()?;
1428                scalar.to_bits(constant.layout.size).discard_err()
1429            } else {
1430                // `constant` is a wide pointer. Do not evaluate to bits.
1431                None
1432            }
1433        };
1434
1435        // Represent the values as `Left(bits)` or `Right(VnIndex)`.
1436        use Either::{Left, Right};
1437        let a = as_bits(lhs).map_or(Right(lhs), Left);
1438        let b = as_bits(rhs).map_or(Right(rhs), Left);
1439
1440        let result = match (op, a, b) {
1441            // Neutral elements.
1442            (
1443                BinOp::Add
1444                | BinOp::AddWithOverflow
1445                | BinOp::AddUnchecked
1446                | BinOp::BitOr
1447                | BinOp::BitXor,
1448                Left(0),
1449                Right(p),
1450            )
1451            | (
1452                BinOp::Add
1453                | BinOp::AddWithOverflow
1454                | BinOp::AddUnchecked
1455                | BinOp::BitOr
1456                | BinOp::BitXor
1457                | BinOp::Sub
1458                | BinOp::SubWithOverflow
1459                | BinOp::SubUnchecked
1460                | BinOp::Offset
1461                | BinOp::Shl
1462                | BinOp::Shr,
1463                Right(p),
1464                Left(0),
1465            )
1466            | (BinOp::Mul | BinOp::MulWithOverflow | BinOp::MulUnchecked, Left(1), Right(p))
1467            | (
1468                BinOp::Mul | BinOp::MulWithOverflow | BinOp::MulUnchecked | BinOp::Div,
1469                Right(p),
1470                Left(1),
1471            ) => p,
1472            // Attempt to simplify `x & ALL_ONES` to `x`, with `ALL_ONES` depending on type size.
1473            (BinOp::BitAnd, Right(p), Left(ones)) | (BinOp::BitAnd, Left(ones), Right(p))
1474                if ones == layout.size.truncate(u128::MAX)
1475                    || (layout.ty.is_bool() && ones == 1) =>
1476            {
1477                p
1478            }
1479            // Absorbing elements.
1480            (
1481                BinOp::Mul | BinOp::MulWithOverflow | BinOp::MulUnchecked | BinOp::BitAnd,
1482                _,
1483                Left(0),
1484            )
1485            | (BinOp::Rem, _, Left(1))
1486            | (
1487                BinOp::Mul
1488                | BinOp::MulWithOverflow
1489                | BinOp::MulUnchecked
1490                | BinOp::Div
1491                | BinOp::Rem
1492                | BinOp::BitAnd
1493                | BinOp::Shl
1494                | BinOp::Shr,
1495                Left(0),
1496                _,
1497            ) => self.insert_scalar(lhs_ty, Scalar::from_uint(0u128, layout.size)),
1498            // Attempt to simplify `x | ALL_ONES` to `ALL_ONES`.
1499            (BinOp::BitOr, _, Left(ones)) | (BinOp::BitOr, Left(ones), _)
1500                if ones == layout.size.truncate(u128::MAX)
1501                    || (layout.ty.is_bool() && ones == 1) =>
1502            {
1503                self.insert_scalar(lhs_ty, Scalar::from_uint(ones, layout.size))
1504            }
1505            // Sub/Xor with itself.
1506            (BinOp::Sub | BinOp::SubWithOverflow | BinOp::SubUnchecked | BinOp::BitXor, a, b)
1507                if a == b =>
1508            {
1509                self.insert_scalar(lhs_ty, Scalar::from_uint(0u128, layout.size))
1510            }
1511            // Comparison:
1512            // - if both operands can be computed as bits, just compare the bits;
1513            // - if we proved that both operands have the same value, we can insert true/false;
1514            // - otherwise, do nothing, as we do not try to prove inequality.
1515            (BinOp::Eq, Left(a), Left(b)) => self.insert_bool(a == b),
1516            (BinOp::Eq, a, b) if a == b => self.insert_bool(true),
1517            (BinOp::Ne, Left(a), Left(b)) => self.insert_bool(a != b),
1518            (BinOp::Ne, a, b) if a == b => self.insert_bool(false),
1519            _ => return None,
1520        };
1521
1522        if op.is_overflowing() {
1523            let ty = Ty::new_tup(self.tcx, &[self.ty(result), self.tcx.types.bool]);
1524            let false_val = self.insert_bool(false);
1525            Some(self.insert_tuple(ty, &[result, false_val]))
1526        } else {
1527            Some(result)
1528        }
1529    }
1530
1531    fn simplify_cast(
1532        &mut self,
1533        initial_kind: &mut CastKind,
1534        initial_operand: &mut Operand<'tcx>,
1535        to: Ty<'tcx>,
1536        location: Location,
1537    ) -> Option<VnIndex> {
1538        use CastKind::*;
1539        use rustc_middle::ty::adjustment::PointerCoercion::*;
1540
1541        let mut kind = *initial_kind;
1542        let mut value = self.simplify_operand(initial_operand, location)?;
1543        let mut from = self.ty(value);
1544        if from == to {
1545            return Some(value);
1546        }
1547
1548        if let CastKind::PointerCoercion(ReifyFnPointer(_) | ClosureFnPointer(_), _) = kind {
1549            // Each reification of a generic fn may get a different pointer.
1550            // Do not try to merge them.
1551            return Some(self.new_opaque(to));
1552        }
1553
1554        let mut was_ever_updated = false;
1555        loop {
1556            let mut was_updated_this_iteration = false;
1557
1558            // Transmuting between raw pointers is just a pointer cast so long as
1559            // they have the same metadata type (like `*const i32` <=> `*mut u64`
1560            // or `*mut [i32]` <=> `*const [u64]`), including the common special
1561            // case of `*const T` <=> `*mut T`.
1562            if let Transmute = kind
1563                && from.is_raw_ptr()
1564                && to.is_raw_ptr()
1565                && self.pointers_have_same_metadata(from, to)
1566            {
1567                kind = PtrToPtr;
1568                was_updated_this_iteration = true;
1569            }
1570
1571            // If a cast just casts away the metadata again, then we can get it by
1572            // casting the original thin pointer passed to `from_raw_parts`
1573            if let PtrToPtr = kind
1574                && let Value::RawPtr { pointer, .. } = self.get(value)
1575                && let ty::RawPtr(to_pointee, _) = to.kind()
1576                && to_pointee.is_sized(self.tcx, self.typing_env())
1577            {
1578                from = self.ty(pointer);
1579                value = pointer;
1580                was_updated_this_iteration = true;
1581                if from == to {
1582                    return Some(pointer);
1583                }
1584            }
1585
1586            // Aggregate-then-Transmute can just transmute the original field value,
1587            // so long as the bytes of a value from only from a single field.
1588            if let Transmute = kind
1589                && let Value::Aggregate(variant_idx, field_values) = self.get(value)
1590                && let Some((field_idx, field_ty)) =
1591                    self.value_is_all_in_one_field(from, variant_idx)
1592            {
1593                from = field_ty;
1594                value = field_values[field_idx.as_usize()];
1595                was_updated_this_iteration = true;
1596                if field_ty == to {
1597                    return Some(value);
1598                }
1599            }
1600
1601            // Various cast-then-cast cases can be simplified.
1602            if let Value::Cast { kind: inner_kind, value: inner_value } = self.get(value) {
1603                let inner_from = self.ty(inner_value);
1604                let new_kind = match (inner_kind, kind) {
1605                    // Even if there's a narrowing cast in here that's fine, because
1606                    // things like `*mut [i32] -> *mut i32 -> *const i32` and
1607                    // `*mut [i32] -> *const [i32] -> *const i32` can skip the middle in MIR.
1608                    (PtrToPtr, PtrToPtr) => Some(PtrToPtr),
1609                    // PtrToPtr-then-Transmute is fine so long as the pointer cast is identity:
1610                    // `*const T -> *mut T -> NonNull<T>` is fine, but we need to check for narrowing
1611                    // to skip things like `*const [i32] -> *const i32 -> NonNull<T>`.
1612                    (PtrToPtr, Transmute) if self.pointers_have_same_metadata(inner_from, from) => {
1613                        Some(Transmute)
1614                    }
1615                    // Similarly, for Transmute-then-PtrToPtr. Note that we need to check different
1616                    // variables for their metadata, and thus this can't merge with the previous arm.
1617                    (Transmute, PtrToPtr) if self.pointers_have_same_metadata(from, to) => {
1618                        Some(Transmute)
1619                    }
1620                    // It would be legal to always do this, but we don't want to hide information
1621                    // from the backend that it'd otherwise be able to use for optimizations.
1622                    (Transmute, Transmute)
1623                        if !self.transmute_may_have_niche_of_interest_to_backend(
1624                            inner_from, from, to,
1625                        ) =>
1626                    {
1627                        Some(Transmute)
1628                    }
1629                    _ => None,
1630                };
1631                if let Some(new_kind) = new_kind {
1632                    kind = new_kind;
1633                    from = inner_from;
1634                    value = inner_value;
1635                    was_updated_this_iteration = true;
1636                    if inner_from == to {
1637                        return Some(inner_value);
1638                    }
1639                }
1640            }
1641
1642            if was_updated_this_iteration {
1643                was_ever_updated = true;
1644            } else {
1645                break;
1646            }
1647        }
1648
1649        if was_ever_updated && let Some(op) = self.try_as_operand(value, location) {
1650            *initial_operand = op;
1651            *initial_kind = kind;
1652        }
1653
1654        Some(self.insert(to, Value::Cast { kind, value }))
1655    }
1656
1657    fn pointers_have_same_metadata(&self, left_ptr_ty: Ty<'tcx>, right_ptr_ty: Ty<'tcx>) -> bool {
1658        let left_meta_ty = left_ptr_ty.pointee_metadata_ty_or_projection(self.tcx);
1659        let right_meta_ty = right_ptr_ty.pointee_metadata_ty_or_projection(self.tcx);
1660        if left_meta_ty == right_meta_ty {
1661            true
1662        } else if let Ok(left) = self
1663            .tcx
1664            .try_normalize_erasing_regions(self.typing_env(), Unnormalized::new_wip(left_meta_ty))
1665            && let Ok(right) = self.tcx.try_normalize_erasing_regions(
1666                self.typing_env(),
1667                Unnormalized::new_wip(right_meta_ty),
1668            )
1669        {
1670            left == right
1671        } else {
1672            false
1673        }
1674    }
1675
1676    /// Returns `false` if we're confident that the middle type doesn't have an
1677    /// interesting niche so we can skip that step when transmuting.
1678    ///
1679    /// The backend will emit `assume`s when transmuting between types with niches,
1680    /// so we want to preserve `i32 -> char -> u32` so that that data is around,
1681    /// but it's fine to skip whole-range-is-value steps like `A -> u32 -> B`.
1682    fn transmute_may_have_niche_of_interest_to_backend(
1683        &self,
1684        from_ty: Ty<'tcx>,
1685        middle_ty: Ty<'tcx>,
1686        to_ty: Ty<'tcx>,
1687    ) -> bool {
1688        let Ok(middle_layout) = self.ecx.layout_of(middle_ty) else {
1689            // If it's too generic or something, then assume it might be interesting later.
1690            return true;
1691        };
1692
1693        if middle_layout.uninhabited {
1694            return true;
1695        }
1696
1697        match middle_layout.backend_repr {
1698            BackendRepr::Scalar(mid) => {
1699                if mid.is_always_valid(&self.ecx) {
1700                    // With no niche it's never interesting, so don't bother
1701                    // looking at the layout of the other two types.
1702                    false
1703                } else if let Ok(from_layout) = self.ecx.layout_of(from_ty)
1704                    && !from_layout.uninhabited
1705                    && from_layout.size == middle_layout.size
1706                    && let BackendRepr::Scalar(from_a) = from_layout.backend_repr
1707                    && let mid_range = mid.valid_range(&self.ecx)
1708                    && let from_range = from_a.valid_range(&self.ecx)
1709                    && mid_range.contains_range(from_range, middle_layout.size)
1710                {
1711                    // The `from_range` is a (non-strict) subset of `mid_range`
1712                    // such as if we're doing `bool` -> `ascii::Char` -> `_`,
1713                    // where `from_range: 0..=1` and `mid_range: 0..=127`,
1714                    // and thus the middle doesn't tell us anything we don't
1715                    // already know from the initial type.
1716                    false
1717                } else if let Ok(to_layout) = self.ecx.layout_of(to_ty)
1718                    && !to_layout.uninhabited
1719                    && to_layout.size == middle_layout.size
1720                    && let BackendRepr::Scalar(to_a) = to_layout.backend_repr
1721                    && let mid_range = mid.valid_range(&self.ecx)
1722                    && let to_range = to_a.valid_range(&self.ecx)
1723                    && mid_range.contains_range(to_range, middle_layout.size)
1724                {
1725                    // The `to_range` is a (non-strict) subset of `mid_range`
1726                    // such as if we're doing `_` -> `ascii::Char` -> `bool`,
1727                    // where `mid_range: 0..=127` and `to_range: 0..=1`,
1728                    // and thus the middle doesn't tell us anything we don't
1729                    // already know from the final type.
1730                    false
1731                } else {
1732                    true
1733                }
1734            }
1735            BackendRepr::ScalarPair(a, b) => {
1736                !a.is_always_valid(&self.ecx) || !b.is_always_valid(&self.ecx)
1737            }
1738            BackendRepr::SimdVector { .. }
1739            | BackendRepr::SimdScalableVector { .. }
1740            | BackendRepr::Memory { .. } => false,
1741        }
1742    }
1743
1744    fn value_is_all_in_one_field(
1745        &self,
1746        ty: Ty<'tcx>,
1747        variant: VariantIdx,
1748    ) -> Option<(FieldIdx, Ty<'tcx>)> {
1749        if let Ok(layout) = self.ecx.layout_of(ty)
1750            && let abi::Variants::Single { index } = layout.variants
1751            && index == variant
1752            && let Some((field_idx, field_layout)) = layout.non_1zst_field(&self.ecx)
1753            && layout.size == field_layout.size
1754        {
1755            // We needed to check the variant to avoid trying to read the tag
1756            // field from an enum where no fields have variants, since that tag
1757            // field isn't in the `Aggregate` from which we're getting values.
1758            Some((field_idx, field_layout.ty))
1759        } else if let ty::Adt(adt, args) = ty.kind()
1760            && adt.is_struct()
1761            && adt.repr().transparent()
1762            && let [single_field] = adt.non_enum_variant().fields.raw.as_slice()
1763        {
1764            Some((FieldIdx::ZERO, single_field.ty(self.tcx, args)))
1765        } else {
1766            None
1767        }
1768    }
1769}
1770
1771/// Return true if any evaluation of this constant in the same MIR body
1772/// always returns the same value, taking into account even pointer identity tests.
1773///
1774/// In other words, this answers: is "cloning" the `Const` ok?
1775///
1776/// This returns `false` for constants that synthesize new `AllocId` when they are instantiated.
1777/// It is `true` for anything else, since a given `AllocId` *does* have a unique runtime value
1778/// within the scope of a single MIR body.
1779fn is_deterministic(c: Const<'_>) -> bool {
1780    // Primitive types cannot contain provenance and always have the same value.
1781    if c.ty().is_primitive() {
1782        return true;
1783    }
1784
1785    match c {
1786        // Some constants may generate fresh allocations for pointers they contain,
1787        // so using the same constant twice can yield two different results.
1788        // Notably, valtrees purposefully generate new allocations.
1789        Const::Ty(..) => false,
1790        // We do not know the contents, so don't attempt to do anything clever.
1791        Const::Unevaluated(..) => false,
1792        // When an evaluated constant contains provenance, it is encoded as an `AllocId`.
1793        // Cloning the constant will reuse the same `AllocId`. If this is in the same MIR
1794        // body, this same `AllocId` will result in the same pointer in codegen.
1795        Const::Val(..) => true,
1796    }
1797}
1798
1799/// Check if a constant may contain provenance information.
1800/// Can return `true` even if there is no provenance.
1801fn may_have_provenance(tcx: TyCtxt<'_>, value: ConstValue, size: Size) -> bool {
1802    match value {
1803        ConstValue::ZeroSized | ConstValue::Scalar(Scalar::Int(_)) => return false,
1804        ConstValue::Scalar(Scalar::Ptr(..)) | ConstValue::Slice { .. } => return true,
1805        ConstValue::Indirect { alloc_id, offset } => !tcx
1806            .global_alloc(alloc_id)
1807            .unwrap_memory()
1808            .inner()
1809            .provenance()
1810            .range_empty(AllocRange::from(offset..offset + size), &tcx),
1811    }
1812}
1813
1814fn op_to_prop_const<'tcx>(
1815    ecx: &mut InterpCx<'tcx, DummyMachine>,
1816    op: &OpTy<'tcx>,
1817) -> Option<ConstValue> {
1818    // Do not attempt to propagate unsized locals.
1819    if op.layout.is_unsized() {
1820        return None;
1821    }
1822
1823    // This constant is a ZST, just return an empty value.
1824    if op.layout.is_zst() {
1825        return Some(ConstValue::ZeroSized);
1826    }
1827
1828    // Do not synthetize too large constants. Codegen will just memcpy them, which we'd like to
1829    // avoid.
1830    // But we *do* want to synthesize any size constant if it is entirely uninit because that
1831    // benefits codegen, which has special handling for them.
1832    if !op.is_immediate_uninit()
1833        && !matches!(op.layout.backend_repr, BackendRepr::Scalar(..) | BackendRepr::ScalarPair(..))
1834    {
1835        return None;
1836    }
1837
1838    // If this constant has scalar ABI, return it as a `ConstValue::Scalar`.
1839    if let BackendRepr::Scalar(abi::Scalar::Initialized { .. }) = op.layout.backend_repr
1840        && let Some(scalar) = ecx.read_scalar(op).discard_err()
1841    {
1842        if !scalar.try_to_scalar_int().is_ok() {
1843            // Check that we do not leak a pointer.
1844            // Those pointers may lose part of their identity in codegen.
1845            // FIXME: remove this hack once https://github.com/rust-lang/rust/issues/128775 is fixed.
1846            return None;
1847        }
1848        return Some(ConstValue::Scalar(scalar));
1849    }
1850
1851    // If this constant is already represented as an `Allocation`,
1852    // try putting it into global memory to return it.
1853    if let Either::Left(mplace) = op.as_mplace_or_imm() {
1854        let (size, _align) = ecx.size_and_align_of_val(&mplace).discard_err()??;
1855
1856        // Do not try interning a value that contains provenance.
1857        // Due to https://github.com/rust-lang/rust/issues/128775, doing so could lead to bugs.
1858        // FIXME: remove this hack once that issue is fixed.
1859        let alloc_ref = ecx.get_ptr_alloc(mplace.ptr(), size).discard_err()??;
1860        if alloc_ref.has_provenance() {
1861            return None;
1862        }
1863
1864        let pointer = mplace.ptr().into_pointer_or_addr().ok()?;
1865        let (prov, offset) = pointer.prov_and_relative_offset();
1866        let alloc_id = prov.alloc_id();
1867        intern_const_alloc_for_constprop(ecx, alloc_id).discard_err()?;
1868
1869        // `alloc_id` may point to a static. Codegen will choke on an `Indirect` with anything
1870        // by `GlobalAlloc::Memory`, so do fall through to copying if needed.
1871        // FIXME: find a way to treat this more uniformly (probably by fixing codegen)
1872        if let GlobalAlloc::Memory(alloc) = ecx.tcx.global_alloc(alloc_id)
1873            // Transmuting a constant is just an offset in the allocation. If the alignment of the
1874            // allocation is not enough, fallback to copying into a properly aligned value.
1875            && alloc.inner().align >= op.layout.align.abi
1876        {
1877            return Some(ConstValue::Indirect { alloc_id, offset });
1878        }
1879    }
1880
1881    // Everything failed: create a new allocation to hold the data.
1882    let alloc_id =
1883        ecx.intern_with_temp_alloc(op.layout, |ecx, dest| ecx.copy_op(op, dest)).discard_err()?;
1884    Some(ConstValue::Indirect { alloc_id, offset: Size::ZERO })
1885}
1886
1887impl<'tcx> VnState<'_, '_, 'tcx> {
1888    /// If either [`Self::try_as_constant`] as [`Self::try_as_place`] succeeds,
1889    /// returns that result as an [`Operand`].
1890    fn try_as_operand(&mut self, index: VnIndex, location: Location) -> Option<Operand<'tcx>> {
1891        if let Some(const_) = self.try_as_constant(index) {
1892            Some(Operand::Constant(Box::new(const_)))
1893        } else if let Value::RuntimeChecks(c) = self.get(index) {
1894            Some(Operand::RuntimeChecks(c))
1895        } else if let Some(place) = self.try_as_place(index, location, false) {
1896            self.reused_locals.insert(place.local);
1897            Some(Operand::Copy(place))
1898        } else {
1899            None
1900        }
1901    }
1902
1903    /// If `index` is a `Value::Constant`, return the `Constant` to be put in the MIR.
1904    fn try_as_constant(&mut self, index: VnIndex) -> Option<ConstOperand<'tcx>> {
1905        let value = self.get(index);
1906
1907        // This was already an *evaluated* constant in MIR, do not change it.
1908        if let Value::Constant { value, disambiguator: None } = value
1909            && let Const::Val(..) = value
1910        {
1911            return Some(ConstOperand { span: DUMMY_SP, user_ty: None, const_: value });
1912        }
1913
1914        if let Some(value) = self.try_as_evaluated_constant(index) {
1915            return Some(ConstOperand { span: DUMMY_SP, user_ty: None, const_: value });
1916        }
1917
1918        // We failed to provide an evaluated form, fallback to using the unevaluated constant.
1919        if let Value::Constant { value, disambiguator: None } = value {
1920            return Some(ConstOperand { span: DUMMY_SP, user_ty: None, const_: value });
1921        }
1922
1923        None
1924    }
1925
1926    fn try_as_evaluated_constant(&mut self, index: VnIndex) -> Option<Const<'tcx>> {
1927        let op = self.eval_to_const(index)?;
1928        if op.layout.is_unsized() {
1929            // Do not attempt to propagate unsized locals.
1930            return None;
1931        }
1932
1933        let value = op_to_prop_const(&mut self.ecx, op)?;
1934
1935        // Check that we do not leak a pointer.
1936        // Those pointers may lose part of their identity in codegen.
1937        // FIXME: remove this hack once https://github.com/rust-lang/rust/issues/128775 is fixed.
1938        if may_have_provenance(self.tcx, value, op.layout.size) {
1939            return None;
1940        }
1941
1942        Some(Const::Val(value, op.layout.ty))
1943    }
1944
1945    /// Construct a place which holds the same value as `index` and for which all locals strictly
1946    /// dominate `loc`. If you used this place, add its base local to `reused_locals` to remove
1947    /// storage statements.
1948    #[instrument(level = "trace", skip(self), ret)]
1949    fn try_as_place(
1950        &mut self,
1951        mut index: VnIndex,
1952        loc: Location,
1953        allow_complex_projection: bool,
1954    ) -> Option<Place<'tcx>> {
1955        let mut projection = SmallVec::<[PlaceElem<'tcx>; 1]>::new();
1956        loop {
1957            if let Some(local) = self.try_as_local(index, loc) {
1958                projection.reverse();
1959                let place =
1960                    Place { local, projection: self.tcx.mk_place_elems(projection.as_slice()) };
1961                return Some(place);
1962            } else if projection.last() == Some(&PlaceElem::Deref) {
1963                // `Deref` can only be the first projection in a place.
1964                // If we are here, we failed to find a local, and we already have a `Deref`.
1965                // Trying to add projections will only result in an ill-formed place.
1966                return None;
1967            } else if let Value::Projection(pointer, proj) = self.get(index)
1968                && (allow_complex_projection || proj.is_stable_offset())
1969                && let Some(proj) = self.try_as_place_elem(self.ty(index), proj, loc)
1970            {
1971                if proj == PlaceElem::Deref {
1972                    // We can introduce a new dereference if the source value cannot be changed in the body.
1973                    // Dereferencing an immutable argument always gives the same value in the body.
1974                    match self.get(pointer) {
1975                        Value::Argument(_)
1976                            if let Some(Mutability::Not) = self.ty(pointer).ref_mutability() => {}
1977                        _ => {
1978                            return None;
1979                        }
1980                    }
1981                }
1982                projection.push(proj);
1983                index = pointer;
1984            } else {
1985                return None;
1986            }
1987        }
1988    }
1989
1990    /// If there is a local which is assigned `index`, and its assignment strictly dominates `loc`,
1991    /// return it. If you used this local, add it to `reused_locals` to remove storage statements.
1992    fn try_as_local(&mut self, index: VnIndex, loc: Location) -> Option<Local> {
1993        let other = self.rev_locals.get(index)?;
1994        other
1995            .iter()
1996            .find(|&&other| self.ssa.assignment_dominates(&self.dominators, other, loc))
1997            .copied()
1998    }
1999}
2000
2001impl<'tcx> MutVisitor<'tcx> for VnState<'_, '_, 'tcx> {
2002    fn tcx(&self) -> TyCtxt<'tcx> {
2003        self.tcx
2004    }
2005
2006    fn visit_place(&mut self, place: &mut Place<'tcx>, context: PlaceContext, location: Location) {
2007        self.simplify_place_projection(place, location);
2008        self.super_place(place, context, location);
2009    }
2010
2011    fn visit_operand(&mut self, operand: &mut Operand<'tcx>, location: Location) {
2012        self.simplify_operand(operand, location);
2013        self.super_operand(operand, location);
2014    }
2015
2016    fn visit_assign(
2017        &mut self,
2018        lhs: &mut Place<'tcx>,
2019        rvalue: &mut Rvalue<'tcx>,
2020        location: Location,
2021    ) {
2022        self.simplify_place_projection(lhs, location);
2023
2024        let value = self.simplify_rvalue(lhs, rvalue, location);
2025        if let Some(value) = value {
2026            // FIXME: Is it correct to make these retagging assignments?
2027            if let Some(const_) = self.try_as_constant(value) {
2028                *rvalue = Rvalue::Use(Operand::Constant(Box::new(const_)), WithRetag::Yes);
2029            } else if let Some(place) = self.try_as_place(value, location, false)
2030                && !matches!(rvalue, Rvalue::Use(Operand::Move(p) | Operand::Copy(p), _) if p == &place)
2031            {
2032                *rvalue = Rvalue::Use(Operand::Copy(place), WithRetag::Yes);
2033                self.reused_locals.insert(place.local);
2034            }
2035        }
2036
2037        if let Some(local) = lhs.as_local()
2038            && self.ssa.is_ssa(local)
2039            && let rvalue_ty = rvalue.ty(self.local_decls, self.tcx)
2040            // FIXME(#112651) `rvalue` may have a subtype to `local`. We can only mark
2041            // `local` as reusable if we have an exact type match.
2042            && self.local_decls[local].ty == rvalue_ty
2043        {
2044            let value = value.unwrap_or_else(|| self.new_opaque(rvalue_ty));
2045            self.assign(local, value);
2046        }
2047    }
2048
2049    fn visit_terminator(&mut self, terminator: &mut Terminator<'tcx>, location: Location) {
2050        if let Terminator { kind: TerminatorKind::Call { destination, .. }, .. } = terminator {
2051            if let Some(local) = destination.as_local()
2052                && self.ssa.is_ssa(local)
2053            {
2054                let ty = self.local_decls[local].ty;
2055                let opaque = self.new_opaque(ty);
2056                self.assign(local, opaque);
2057            }
2058        }
2059        self.super_terminator(terminator, location);
2060    }
2061}
2062
2063struct StorageRemover<'a, 'tcx> {
2064    tcx: TyCtxt<'tcx>,
2065    reused_locals: &'a DenseBitSet<Local>,
2066    storage_to_remove: &'a DenseBitSet<Local>,
2067}
2068
2069impl<'a, 'tcx> MutVisitor<'tcx> for StorageRemover<'a, 'tcx> {
2070    fn tcx(&self) -> TyCtxt<'tcx> {
2071        self.tcx
2072    }
2073
2074    fn visit_operand(&mut self, operand: &mut Operand<'tcx>, _: Location) {
2075        if let Operand::Move(place) = *operand
2076            && !place.is_indirect_first_projection()
2077            && self.reused_locals.contains(place.local)
2078        {
2079            *operand = Operand::Copy(place);
2080        }
2081    }
2082
2083    fn visit_statement(&mut self, stmt: &mut Statement<'tcx>, loc: Location) {
2084        match stmt.kind {
2085            // When removing storage statements, we need to remove both (#107511).
2086            StatementKind::StorageLive(l) | StatementKind::StorageDead(l)
2087                if self.storage_to_remove.contains(l) =>
2088            {
2089                stmt.make_nop(true)
2090            }
2091            _ => self.super_statement(stmt, loc),
2092        }
2093    }
2094}
2095
2096struct StorageChecker<'a, 'tcx> {
2097    reused_locals: &'a DenseBitSet<Local>,
2098    storage_to_remove: DenseBitSet<Local>,
2099    maybe_uninit: ResultsCursor<'a, 'tcx, MaybeUninitializedLocals>,
2100}
2101
2102impl<'a, 'tcx> Visitor<'tcx> for StorageChecker<'a, 'tcx> {
2103    fn visit_local(&mut self, local: Local, context: PlaceContext, location: Location) {
2104        match context {
2105            // These mutating uses do not require the local to be initialized,
2106            // so we cannot use our maybe-uninit check on them.
2107            // However, GVN doesn't introduce or move mutations,
2108            // so this local must already have valid storage at this location.
2109            PlaceContext::MutatingUse(MutatingUseContext::AsmOutput)
2110            | PlaceContext::MutatingUse(MutatingUseContext::Call)
2111            | PlaceContext::MutatingUse(MutatingUseContext::Store)
2112            | PlaceContext::MutatingUse(MutatingUseContext::Yield)
2113            | PlaceContext::NonUse(_) => {
2114                return;
2115            }
2116            // Must check validity for other mutating usages and all non-mutating uses.
2117            PlaceContext::MutatingUse(_) | PlaceContext::NonMutatingUse(_) => {}
2118        }
2119
2120        // We only need to check reused locals which we haven't already removed storage for.
2121        if !self.reused_locals.contains(local) || self.storage_to_remove.contains(local) {
2122            return;
2123        }
2124
2125        self.maybe_uninit.seek_before_primary_effect(location);
2126
2127        if self.maybe_uninit.get().contains(local) {
2128            debug!(
2129                ?location,
2130                ?local,
2131                "local is reused and is maybe uninit at this location, marking it for storage statement removal"
2132            );
2133            self.storage_to_remove.insert(local);
2134        }
2135    }
2136}