Skip to main content

rucc_codegen/
slots.rs

1//! One stack slot allocator: every byte a function asks for itself, placed together.
2//!
3//! Design: `spec/optimizer/36-lowering-and-isel.md` section 36.7.
4//!
5//! A frame holds two kinds of thing the function asked for. Locals are what an `alloca` becomes and
6//! the lowering knows about them before anything else runs. Spill slots are what the allocator
7//! gives a value it ran out of registers for, and nothing knows how many of those there are until
8//! it has finished. Placed apart, the frame is the sum of the two areas. Placed together it is the
9//! most either of them needs at any one moment, because two things that are never both wanted can
10//! be the same bytes. That is the same answer the allocator gives about registers and it is the
11//! same reason.
12//!
13//! This runs after allocation and reads the allocator's own liveness rather than working one out.
14//! Running before it would mean guessing which values are spilled, and a guess has to be either
15//! conservative or wrong. Asking again afterwards would mean two answers about one function that
16//! are free to disagree, and the one the machine runs is the allocator's.
17//!
18//! # What a cell is
19//!
20//! A [`Cell`] is a run of bytes in the frame, as wide and as aligned as the widest and strictest
21//! thing in it. [`Slots`] says which cell every local and every spill slot went in, and
22//! [`crate::frame`] is what turns cells into offsets. Nothing else changes: an instruction reading
23//! a local still asks the frame where that local is and gets back an offset, and two locals sharing
24//! a cell get the same one.
25//!
26//! # What may share
27//!
28//! A spill slot holds one value, so where the slot is wanted is where that value is live, and the
29//! allocator has already said where that is.
30//!
31//! A local is harder, because what a local is wanted over is not the live range of anything. The
32//! bytes are reached through an address, the address is a value like any other, and the bytes go on
33//! meaning something for exactly as long as anything can still come by that address. So the
34//! question asked here is where the address gets to, and the answer has to be the whole of it or
35//! the local does not share at all. [`reach`] asks it. An address read as the base of a load or a
36//! store is a read of the local at that instruction and goes no further. An address read by another
37//! address computation is the same local under a second name and is followed. An address read any
38//! other way is one this pass cannot follow to the end, and the local it belongs to is left out.
39//!
40//! Left out is therefore the answer for every local whose address is handed to a call, stored into
41//! memory, or carried between blocks as an argument. That is what section 36.7 means by an address
42//! taken local: not one the program wrote an `&` in front of, which is a question the types
43//! answered and the types are gone by here, but one whose bytes something can reach at a moment
44//! liveness does not know about.
45//!
46//! # Where a local is wanted is not where its address is live
47//!
48//! Knowing which instructions reach a local is only half of it. The address that reaches it is a
49//! value and the object is not, so an address register that dies right after the store through it
50//! says nothing about how long those bytes have to go on holding what was stored. A local written
51//! at one point and read at another has to hold its contents through everything in between, however
52//! little of what is in between mentions the local at all.
53//!
54//! So the area of a local is worked out as its own question over the control flow graph: its bytes
55//! matter at every point that has a touch behind it and a touch in front of it. A point with
56//! nothing in front is one where the object is finished with, and a point with nothing behind is
57//! one where it holds nothing anybody may read, since the contents of a local nothing has written
58//! yet are not contents. The two halves of that question are reachability over the graph rather
59//! than over the line the function was laid out in. Over the line would be wrong for a loop: a
60//! local written at the bottom of a body and read at the top of the next turn is one whose bytes
61//! matter across the header too, and the header is laid out before either of the two touches.
62//!
63//! # The moves count too
64//!
65//! Where a spilled value is live is not quite everywhere its slot is touched. The store that fills
66//! the slot goes after the instruction that wrote the value, the reload that empties it goes before
67//! the instruction that reads it, and the moves an edge turns into go at the end of a block or the
68//! start of one, none of which is a point the value is live at. The edge moves are the ones that
69//! matter: the sequencer put them in an order that works because it was told every place in them
70//! was a different place, and two slots it was told apart are two this pass must not put together
71//! behind its back.
72//!
73//! So the moves are read as well as the liveness. Every edit that names a slot puts a point either
74//! side of where it stands into that slot's area, which is the gap between two points the edit
75//! really sits in, and after that the question is the same question everywhere else in this file.
76//!
77//! # A spill slot is not a variable
78//!
79//! The two kinds are asked about separately, because the reason a frame ever lays two things out
80//! apart that could share is the debugger, and that reason covers one kind and not the other. A
81//! local is a variable somebody wrote down and can ask the value of, so two locals sharing bytes
82//! means a variable that is out of scope reads as whatever took its place, which is what `-O0`
83//! exists not to do and what `-fstack-reuse=none` turns off at every level. A spill slot holds a
84//! value the allocator ran out of registers for, it has no name, nothing can ask for it, and the
85//! only thing that ever reads it is the instruction the allocator wrote. Laying those out one
86//! each buys a debugger nothing and costs a frame everything, since most frames are mostly spill
87//! slots.
88//!
89//! So spill slots share at every level and locals share only where the level says they may. What
90//! says which is whether this pass is handed a [`Reach`]: with one, the locals it followed join
91//! in, and without one every local gets bytes of its own and the spill slots are fitted around
92//! them.
93//!
94//! # How big it is allowed to get
95//!
96//! Fitting each thing into the first cell it does not clash with compares it against the cells so
97//! far, so a function whose things mostly cannot share costs the square of how many there are.
98//! What bounds that is a budget of comparisons rather than a count of things: the fit spends
99//! [`BUDGET`] of them and lays out whatever is left one cell each. A function whose things do
100//! share never comes near it, because what each one is compared against is the cells and not the
101//! things, and the whole point of sharing is that there are far fewer cells than things. lua's
102//! interpreter, which is 2802 slots fitted into 144 cells and the largest function in the corpus,
103//! spends an eighth of the budget and adds a seventh of a second to the file it is in. A function
104//! with that many slots that are all live at once would spend the lot, and it gets the layout it
105//! would have got anyway.
106
107use std::collections::{HashMap, HashSet};
108
109use rucc_base::Interner;
110use rucc_mir::{Func, Inst, Opcode, Reg};
111use rucc_regalloc::Allocation;
112use rucc_regalloc::assign::Place;
113use rucc_regalloc::live::{Area, Live, Range};
114use rucc_regalloc::order::Order;
115use rucc_regalloc::rewrite::At;
116use rucc_target::FrameInsts;
117
118use crate::frame::Local;
119
120/// How many cells the fit may look at before it stops pairing things up and gives everything left
121/// a cell of its own.
122///
123/// See the note on how big it is allowed to get in the module documentation. One unit is one thing
124/// compared against one cell, which is what costs. The largest function in the corpus spends an
125/// eighth of this, so the budget is a guard against a generated file rather than something the
126/// ordinary path meets.
127pub const BUDGET: usize = 1 << 20;
128
129/// One run of bytes in the frame, holding one local, one spill slot, or several of each.
130#[derive(Debug, Clone, Copy, PartialEq, Eq)]
131pub struct Cell {
132    /// How many bytes of it there are, which is as many as the largest thing in it needs.
133    pub size: u32,
134    /// What its address has to be a multiple of, which is the strictest thing in it.
135    pub align: u32,
136}
137
138/// Which cell of the frame every local and every spill slot of a function is in.
139#[derive(Debug, Clone, Default, PartialEq, Eq)]
140pub struct Slots {
141    cells: Vec<Cell>,
142    locals: Vec<usize>,
143    slots: Vec<usize>,
144}
145
146impl Slots {
147    /// The frame with nothing sharing anything: a cell of its own for every local and every spill
148    /// slot, in the order the two lists are in.
149    ///
150    /// This is the layout there was before this pass, and it is what a frame gets when nothing has
151    /// asked for sharing and what it falls back to on a function with too many slots to pair up
152    /// cheaply.
153    #[must_use]
154    pub fn apart(locals: &[Local], widths: &[u32]) -> Self {
155        let mut cells = Vec::with_capacity(locals.len() + widths.len());
156        for &Local { size, align } in locals {
157            cells.push(Cell { size, align });
158        }
159        for &width in widths {
160            cells.push(Cell { size: width, align: width });
161        }
162        Self {
163            locals: (0..locals.len()).collect(),
164            slots: (locals.len()..cells.len()).collect(),
165            cells,
166        }
167    }
168
169    /// The frame with everything that can share sharing, worked out from the allocator's liveness.
170    ///
171    /// `reach` is what [`reach`] said about this function before the allocator ran, or `None` for a
172    /// build whose locals keep bytes of their own, which is `-O0` and `-fstack-reuse=none`. The
173    /// spill slots share either way, for the reason in the module documentation. `widths` is how
174    /// many bytes a slot of each of the allocation's spill slots takes, and `locals` is the
175    /// function's own objects in the order the lowering recorded them. `func` is the function the
176    /// allocator has finished with, which is asked for the shape of its control flow and nothing
177    /// else: the rewrite took the values away but it left every block and every edge where it was.
178    #[must_use]
179    pub fn share(
180        func: &Func,
181        reach: Option<&Reach>,
182        allocation: &Allocation,
183        locals: &[Local],
184        widths: &[u32],
185    ) -> Self {
186        let mut wants = Vec::with_capacity(locals.len() + widths.len());
187        let mut reached = reach
188            .map(|reach| areas(func, reach, &allocation.live, &allocation.order))
189            .unwrap_or_default();
190        for (local, &Local { size, align }) in locals.iter().enumerate() {
191            let area = reached.get_mut(local).and_then(Option::take);
192            wants.push(Want { what: What::Local(local), size, align, area });
193        }
194        let held = spilled(allocation, widths.len());
195        let moved = moved(allocation, widths.len());
196        for (slot, &width) in widths.iter().enumerate() {
197            let area = held[slot]
198                .and_then(|reg| allocation.live.area(reg))
199                .map(|live| merged(live.pieces().chain(moved[slot].iter().copied())));
200            wants.push(Want { what: What::Slot(slot), size: width, align: width, area });
201        }
202        fit(wants, locals.len(), widths.len(), BUDGET)
203    }
204
205    /// The cells the frame is made of, which is what [`crate::frame`] places.
206    #[must_use]
207    pub fn cells(&self) -> &[Cell] {
208        &self.cells
209    }
210
211    /// Which cell a local is in.
212    #[must_use]
213    pub fn local(&self, local: usize) -> Option<usize> {
214        self.locals.get(local).copied()
215    }
216
217    /// Which cell a spill slot is in.
218    #[must_use]
219    pub fn slot(&self, slot: u32) -> Option<usize> {
220        self.slots.get(usize::try_from(slot).ok()?).copied()
221    }
222
223    /// How many cells were saved by sharing, which is how many things went in beside something
224    /// else.
225    ///
226    /// This is a count rather than a number of bytes, because how many bytes it saved is the
227    /// difference between two frames and a frame is not worked out here.
228    #[must_use]
229    pub fn saved(&self) -> usize {
230        self.locals.len() + self.slots.len() - self.cells.len()
231    }
232}
233
234/// One thing that wants bytes in the frame, and everywhere it wants them.
235#[derive(Debug)]
236struct Want {
237    what: What,
238    size: u32,
239    align: u32,
240    /// Where it is wanted, or `None` for one this pass could not follow, which shares with nothing.
241    area: Option<Vec<Range>>,
242}
243
244/// Which of the two lists a want came off.
245#[derive(Debug, Clone, Copy)]
246enum What {
247    Local(usize),
248    Slot(usize),
249}
250
251/// Fits every want into the fewest cells, largest and strictest first.
252///
253/// Largest first because a cell only ever grows to hold what goes in it, and starting with the
254/// small ones means growing a cell to several times the size of the thing that opened it, which
255/// leaves the same bytes taken and a worse chance for everything after. The order is settled
256/// entirely by the want rather than partly by which came first, so the same function lays out the
257/// same way every time.
258///
259/// What `budget` is is comparisons of one thing against one cell, which is what costs. Past that
260/// everything left opens a cell of its own, which is the layout a frame had before this pass
261/// existed, and the wants are in a settled order so which ones those are is settled too.
262fn fit(mut wants: Vec<Want>, locals: usize, slots: usize, mut budget: usize) -> Slots {
263    let mut order: Vec<usize> = (0..wants.len()).collect();
264    order.sort_by_key(|&want| {
265        let Want { size, align, .. } = wants[want];
266        (std::cmp::Reverse(align), std::cmp::Reverse(size), want)
267    });
268
269    let mut cells: Vec<Cell> = Vec::new();
270    // `None` is a cell nothing else may go in, which is what a thing this pass could not follow
271    // opens. A cell with an area is one anything that does not clash with that area may join.
272    let mut busy: Vec<Option<Vec<Range>>> = Vec::new();
273    let mut of_local = vec![0; locals];
274    let mut of_slot = vec![0; slots];
275    for want in order {
276        let Want { what, size, align, area } = std::mem::replace(
277            &mut wants[want],
278            Want { what: What::Local(0), size: 0, align: 0, area: None },
279        );
280        let mut into = None;
281        if let Some(area) = &area {
282            for (cell, held) in busy.iter().enumerate() {
283                if budget == 0 {
284                    break;
285                }
286                budget -= 1;
287                if held.as_ref().is_some_and(|held| !clashes(held, area)) {
288                    into = Some(cell);
289                    break;
290                }
291            }
292        }
293        let cell = match into {
294            Some(cell) => {
295                cells[cell].size = cells[cell].size.max(size);
296                cells[cell].align = cells[cell].align.max(align);
297                let held = busy[cell].take().unwrap_or_default();
298                busy[cell] = Some(merged(held.into_iter().chain(area.into_iter().flatten())));
299                cell
300            }
301            None => {
302                cells.push(Cell { size, align });
303                busy.push(area);
304                cells.len() - 1
305            }
306        };
307        match what {
308            What::Local(local) => of_local[local] = cell,
309            What::Slot(slot) => of_slot[slot] = cell,
310        }
311    }
312    Slots { cells, locals: of_local, slots: of_slot }
313}
314
315/// Which value the allocator put in each spill slot, by slot number.
316///
317/// A slot holds one value, because the allocator takes a fresh one every time it spills, so this is
318/// the assignment read the other way round.
319fn spilled(allocation: &Allocation, slots: usize) -> Vec<Option<Reg>> {
320    let mut held = vec![None; slots];
321    for (reg, place) in allocation.assignment.placed() {
322        if let Place::Slot(slot) = place {
323            if let Some(at) = usize::try_from(slot).ok().and_then(|slot| held.get_mut(slot)) {
324                *at = Some(reg);
325            }
326        }
327    }
328    held
329}
330
331/// What carries the address of each of a function's locals, or `None` for one whose address gets
332/// away somewhere this pass cannot follow.
333///
334/// Worked out before allocation, because it is a question about values and a value is written once
335/// only until the allocator's rewrite has been through. Read after it, because that is when the
336/// liveness these names are looked up in exists.
337#[derive(Debug, Clone, Default)]
338pub struct Reach {
339    through: Vec<Option<Carried>>,
340}
341
342impl Reach {
343    /// Every point one local is touched at, which is where its address is live and where an
344    /// instruction that swallowed the address stands.
345    fn touches(&self, local: usize, live: &Live, order: &Order) -> Option<Vec<Range>> {
346        let held = self.through.get(local)?.as_ref()?;
347        let mut spots: Vec<Range> = Vec::new();
348        for &reg in &held.regs {
349            spots.extend(live.area(reg).into_iter().flat_map(Area::pieces));
350        }
351        for &inst in &held.at {
352            spots.push(Range { start: order.early(inst), end: order.late(inst) });
353        }
354        Some(spots)
355    }
356
357    /// Whether a local may share its bytes with anything, which is what the tests ask.
358    #[must_use]
359    pub fn shares(&self, local: usize) -> bool {
360        self.through.get(local).is_some_and(Option::is_some)
361    }
362}
363
364/// Everywhere the bytes of each local have to go on holding what was put in them.
365///
366/// A point counts if a touch of that local can have happened before it and another can still
367/// happen after it. Before is reachability forward through the graph from the blocks that touch
368/// the local, after is the same walk backwards, and the bytes matter where the two meet. See the
369/// note in the module documentation on why this is asked over the graph and not over the line the
370/// function was laid out in.
371///
372/// A local this pass could not follow the address of comes back `None`, which is the answer that
373/// shares with nothing.
374fn areas(func: &Func, reach: &Reach, live: &Live, order: &Order) -> Vec<Option<Vec<Range>>> {
375    let blocks = order.blocks();
376    let count = reach.through.len();
377    let words = count.div_ceil(64);
378
379    // Where each block starts, which is ascending, so the block a point is in is a search.
380    let starts: Vec<u32> = blocks.iter().map(|&block| order.start(block)).collect();
381    let holding = |point: u32| starts.partition_point(|&start| start <= point).saturating_sub(1);
382
383    // Which locals each block touches, as bits for the walk and as a range for the answer.
384    let mut touched = vec![vec![0u64; words]; blocks.len()];
385    let mut inside: Vec<Vec<(usize, Range)>> = vec![Vec::new(); blocks.len()];
386    for local in 0..count {
387        let Some(spots) = reach.touches(local, live, order) else { continue };
388        for spot in spots {
389            for at in holding(spot.start)..=holding(spot.end) {
390                let block = blocks[at];
391                let start = spot.start.max(order.start(block));
392                let end = spot.end.min(order.end(block));
393                touched[at][local / 64] |= 1 << (local % 64);
394                inside[at].push((local, Range { start, end }));
395            }
396        }
397    }
398
399    // One range per block per local, from the first touch in the block to the last. A block runs
400    // top to bottom, so whatever sits between two touches of the same local is between them in the
401    // run as well, and the bytes have to have held what they hold all the way through it.
402    for spots in inside.iter_mut() {
403        spots.sort_unstable_by_key(|&(local, Range { start, .. })| (local, start));
404        let mut kept = 0;
405        for at in 1..spots.len() {
406            if spots[at].0 == spots[kept].0 {
407                spots[kept].1.end = spots[kept].1.end.max(spots[at].1.end);
408            } else {
409                kept += 1;
410                spots[kept] = spots[at];
411            }
412        }
413        spots.truncate(spots.len().min(kept + 1));
414    }
415
416    // The graph, by position in the line rather than by block, because everything else here is.
417    let mut place = vec![0usize; func.block_count()];
418    for (at, &block) in blocks.iter().enumerate() {
419        place[block.index()] = at;
420    }
421    let mut ahead: Vec<Vec<usize>> = vec![Vec::new(); blocks.len()];
422    let mut behind: Vec<Vec<usize>> = vec![Vec::new(); blocks.len()];
423    for (at, &block) in blocks.iter().enumerate() {
424        for call in &func[block].succs {
425            let to = place[call.block.index()];
426            ahead[at].push(to);
427            behind[to].push(at);
428        }
429    }
430
431    let written = spread(&behind, &touched, words, true);
432    let read = spread(&ahead, &touched, words, false);
433
434    let mut out = vec![None; count];
435    for (local, pieces) in out.iter_mut().enumerate() {
436        if reach.shares(local) {
437            *pieces = Some(Vec::new());
438        }
439    }
440    for (at, &block) in blocks.iter().enumerate() {
441        let whole = Range { start: order.start(block), end: order.end(block) };
442        for word in 0..words {
443            let mut bits = written[at][word] & read[at][word];
444            while bits != 0 {
445                let local = word * 64 + bits.trailing_zeros() as usize;
446                bits &= bits - 1;
447                if let Some(pieces) = out[local].as_mut() {
448                    pieces.push(whole);
449                }
450            }
451        }
452        // A block that touches the local is covered from the touch, or from the top of the block
453        // if something above already wrote it, and to the touch, or to the bottom if something
454        // below still reads it.
455        for &(local, spot) in &inside[at] {
456            let held = |bits: &[Vec<u64>]| bits[at][local / 64] & (1 << (local % 64)) != 0;
457            let start = if held(&written) { whole.start } else { spot.start };
458            let end = if held(&read) { whole.end } else { spot.end };
459            if let Some(pieces) = out[local].as_mut() {
460                pieces.push(Range { start, end });
461            }
462        }
463    }
464    for pieces in out.iter_mut().flatten() {
465        *pieces = merged(std::mem::take(pieces));
466    }
467    out
468}
469
470/// Which locals a touch of can reach the start of each block, following the given edges.
471///
472/// One walk stands for both directions. Handed the edges into each block it says which locals were
473/// touched somewhere above, and handed the edges out of each block it says which are touched
474/// somewhere below. The sweep goes the way the edges point so that a straight line settles in one
475/// pass and only a loop costs a second.
476///
477/// A block is allowed to be its own neighbour, which is what a loop of one block is, and the row it
478/// is working on is a copy for that reason. Reading a block's own answer back is a no change either
479/// way, since the answer being built is the one being read, but what a block touches does come back
480/// to itself around a back edge and that is the half that has to arrive. tamnd/rucc#1207.
481fn spread(
482    edges: &[Vec<usize>],
483    touched: &[Vec<u64>],
484    words: usize,
485    forward: bool,
486) -> Vec<Vec<u64>> {
487    let mut out = vec![vec![0u64; words]; edges.len()];
488    let mut going = true;
489    while going {
490        going = false;
491        for at in 0..edges.len() {
492            let at = if forward { at } else { edges.len() - 1 - at };
493            let mut row = out[at].clone();
494            for &from in &edges[at] {
495                for word in 0..words {
496                    let had = row[word];
497                    row[word] |= out[from][word] | touched[from][word];
498                    going |= row[word] != had;
499                }
500            }
501            out[at] = row;
502        }
503    }
504    out
505}
506
507/// Everywhere one local is reached from.
508#[derive(Debug, Clone, Default)]
509struct Carried {
510    /// The values that hold its address.
511    regs: Vec<Reg>,
512    /// The instructions that reach it with no value in between, which is what an address folded
513    /// into its reader leaves behind.
514    at: Vec<Inst>,
515}
516
517/// Follows the address of every local of a function as far as it goes.
518///
519/// `addresses` is the list [`crate::lower`] built and [`crate::fold`] rewrote, which says which
520/// instruction carries the address of which local. `count` is how many locals there are, since a
521/// local nothing on that list names is one this has no account of rather than one nothing touches.
522///
523/// Run after the fold and before allocation. After the fold because an address that ended up inside
524/// its reader is an address no value holds and this has to see it that way. Before allocation
525/// because every answer here is about a virtual register, and the rewrite the allocator ends with
526/// is what stops there being one.
527#[must_use]
528pub fn reach(
529    func: &Func,
530    addresses: &[(Inst, usize)],
531    count: usize,
532    insts: &FrameInsts,
533    names: &mut Interner,
534) -> Reach {
535    let lea = Opcode::new(names.intern(&format!("{}{}", insts.prefix, insts.lea)));
536    let mut through: Vec<Option<Carried>> = vec![None; count];
537    for &(inst, local) in addresses {
538        let Some(held) = through.get_mut(local) else { continue };
539        let held = held.get_or_insert_with(Carried::default);
540        // Either the `lea` the lowering wrote, whose result is the address and goes on from here,
541        // or a reader the fold put the address inside, which touches the local where it stands and
542        // hands nothing on. The opcode is the whole of the difference: a reader that is itself a
543        // `lea` really does hand an address on, and this reads it as one.
544        if func[inst].opcode == lea {
545            match def(func, inst) {
546                Some(reg) => held.regs.push(reg),
547                None => {
548                    through[local] = None;
549                    continue;
550                }
551            }
552        }
553        // On the list either way, so that a local whose address nothing reads is still wanted where
554        // the address of it was taken rather than nowhere at all.
555        held.at.push(inst);
556    }
557
558    let readers = readers(func);
559    let crossing = crossing(func);
560    for held in &mut through {
561        if let Some(carried) = held.take() {
562            *held = follow(func, lea, &readers, &crossing, carried);
563        }
564    }
565    Reach { through }
566}
567
568/// Follows every address a local is reached through to every value that address becomes.
569///
570/// Gives back nothing for a local whose address is read some way this cannot account for, which is
571/// any way but as the base or the index of a memory operand. A call argument is one of those, a
572/// value stored into memory is another, and so is a value carried into a block as an argument,
573/// which is the one that is not an operand at all.
574fn follow(
575    func: &Func,
576    lea: Opcode,
577    readers: &HashMap<Reg, Vec<Inst>>,
578    crossing: &HashSet<Reg>,
579    mut held: Carried,
580) -> Option<Carried> {
581    let mut seen: HashSet<Reg> = held.regs.iter().copied().collect();
582    let mut queue = held.regs.clone();
583    while let Some(reg) = queue.pop() {
584        if crossing.contains(&reg) {
585            return None;
586        }
587        for &inst in readers.get(&reg).map(Vec::as_slice).unwrap_or_default() {
588            if !addressed(func, inst, reg) {
589                return None;
590            }
591            if func[inst].opcode == lea {
592                let next = def(func, inst)?;
593                if seen.insert(next) {
594                    held.regs.push(next);
595                    queue.push(next);
596                }
597            }
598        }
599    }
600    Some(held)
601}
602
603/// Whether every read of a value by an instruction is as part of the address it works on.
604///
605/// Anything else is a read this pass cannot follow: the value has gone somewhere that is not an
606/// address into this frame any more, and where its bytes are reached from afterwards is no longer a
607/// question about liveness.
608fn addressed(func: &Func, inst: Inst, reg: Reg) -> bool {
609    let data = &func[inst];
610    let Some(mem) = data.mem else { return false };
611    let amode = func[mem];
612    func[data.operands].iter().enumerate().all(|(at, operand)| {
613        if operand.reg != reg || operand.role.is_def() {
614            return true;
615        }
616        let at = u8::try_from(at).ok();
617        at.is_some() && (amode.base == at || amode.index == at)
618    })
619}
620
621/// The one virtual register an instruction writes, or nothing when it writes none or several.
622fn def(func: &Func, inst: Inst) -> Option<Reg> {
623    let mut found = None;
624    for operand in &func[func[inst].operands] {
625        if !operand.role.is_def() {
626            continue;
627        }
628        if operand.reg.number().is_none() || found.is_some() {
629            return None;
630        }
631        found = Some(operand.reg);
632    }
633    found
634}
635
636/// Which instructions read each virtual register.
637fn readers(func: &Func) -> HashMap<Reg, Vec<Inst>> {
638    let mut readers: HashMap<Reg, Vec<Inst>> = HashMap::new();
639    for block in func.blocks() {
640        for inst in func.insts(block) {
641            for operand in &func[func[inst].operands] {
642                if operand.role.is_def() || operand.reg.number().is_none() {
643                    continue;
644                }
645                let at = readers.entry(operand.reg).or_default();
646                if at.last() != Some(&inst) {
647                    at.push(inst);
648                }
649            }
650        }
651    }
652    readers
653}
654
655/// Every virtual register that goes between blocks, as an argument an edge carries or as a
656/// parameter one arrives in.
657///
658/// These are the reads that are not operands, so the walk above would not see them, and an address
659/// that goes round a loop this way is one whose local is left out rather than one followed into a
660/// second name.
661fn crossing(func: &Func) -> HashSet<Reg> {
662    let mut crossing = HashSet::new();
663    for block in func.blocks() {
664        crossing.extend(func[block].params.iter().map(|param| param.reg));
665        for call in &func[block].succs {
666            crossing.extend(call.args.iter().copied());
667        }
668    }
669    crossing
670}
671
672/// Where the moves the allocator handed back touch each slot of the frame.
673///
674/// A point either side of where each of them stands, which is the gap between two points the move
675/// really goes in. See the note on the moves in the module documentation.
676fn moved(allocation: &Allocation, slots: usize) -> Vec<Vec<Range>> {
677    let order = &allocation.order;
678    let mut moved = vec![Vec::new(); slots];
679    for edit in &allocation.edits {
680        let at = match edit.at {
681            At::Before(inst) => order.early(inst),
682            At::After(inst) => order.late(inst),
683            At::StartOf(block) => order.start(block),
684            At::EndOf(block) => order.end(block),
685        };
686        let around =
687            Range { start: at.saturating_sub(1), end: at.saturating_add(1).min(order.points()) };
688        for place in [edit.mov.to, edit.mov.from] {
689            if let Place::Slot(slot) = place {
690                if let Some(at) = usize::try_from(slot).ok().and_then(|slot| moved.get_mut(slot)) {
691                    at.push(around);
692                }
693            }
694        }
695    }
696    moved
697}
698
699/// The same stretches of the function, in order, with everything that touches joined up.
700fn merged(pieces: impl IntoIterator<Item = Range>) -> Vec<Range> {
701    let mut pieces: Vec<Range> = pieces.into_iter().collect();
702    pieces.sort_by_key(|piece| (piece.start, piece.end));
703    let mut merged: Vec<Range> = Vec::with_capacity(pieces.len());
704    for piece in pieces {
705        match merged.last_mut() {
706            Some(last) if piece.start <= last.end => last.end = last.end.max(piece.end),
707            _ => merged.push(piece),
708        }
709    }
710    merged
711}
712
713/// Whether two stretches of a function are both wanted anywhere, which is what stops two things
714/// sharing a cell.
715///
716/// Both lists are in order and neither is long, so this walks them together and stops at the first
717/// pair that touches rather than comparing every piece with every other.
718fn clashes(one: &[Range], two: &[Range]) -> bool {
719    let (mut mine, mut theirs) = (0, 0);
720    while mine < one.len() && theirs < two.len() {
721        if one[mine].overlaps(two[theirs]) {
722            return true;
723        }
724        if one[mine].end < two[theirs].end {
725            mine += 1;
726        } else {
727            theirs += 1;
728        }
729    }
730    false
731}
732
733#[cfg(test)]
734mod tests {
735    use rucc_base::Interner;
736    use rucc_mir::{Block, BlockCall, Mem, Operand};
737    use rucc_regalloc::assign::Env;
738    use rucc_regalloc::order::Point;
739    use rucc_target::x86_64::{FRAME, GPR, REGS, SYSV};
740
741    use super::*;
742    use crate::frame::{Frame, Layout};
743
744    /// A function being built, with the names and the opcodes a test needs to hand.
745    struct Building {
746        names: Interner,
747        func: Func,
748        lea: Opcode,
749        nop: Opcode,
750        addresses: Vec<(Inst, usize)>,
751    }
752
753    impl Building {
754        /// An empty function of one block.
755        fn new() -> (Self, Block) {
756            let mut names = Interner::new();
757            let func = Func::new(names.intern("f"));
758            let lea = Opcode::new(names.intern(&format!("{}{}", FRAME.prefix, FRAME.lea)));
759            let nop = Opcode::new(names.intern("x64.nop"));
760            let mut building = Self { names, func, lea, nop, addresses: Vec::new() };
761            let block = building.func.create_block();
762            (building, block)
763        }
764
765        /// The address of a local, taken the way the lowering takes one: a `lea` off the stack
766        /// pointer with nothing in its displacement yet.
767        fn local(&mut self, block: Block, which: usize) -> Reg {
768            let sp = Operand::read(Reg::physical(SYSV.stack_pointer), GPR);
769            let reg = self.func.new_vreg(GPR);
770            let inst = self.func.build(block, self.lea).def(reg, GPR).mem(Mem::at(sp)).finish();
771            self.addresses.push((inst, which));
772            reg
773        }
774
775        /// An instruction that reads a local through its address, which is every ordinary use of
776        /// one.
777        fn through(&mut self, block: Block, addr: Reg) {
778            let at = Operand::read(addr, GPR);
779            self.func.build(block, self.nop).mem(Mem::at(at)).finish();
780        }
781
782        /// An instruction that reads a value as a value, which is what handing an address to a
783        /// call looks like from here.
784        fn held(&mut self, block: Block, reg: Reg) {
785            self.func.build(block, self.nop).uses(reg, GPR).finish();
786        }
787
788        /// A value written and then read, which is one more thing wanting a register in between.
789        fn value(&mut self, block: Block) -> Reg {
790            let reg = self.func.new_vreg(GPR);
791            self.func.build(block, self.nop).def(reg, GPR).finish();
792            reg
793        }
794
795        /// What this pass says about the function, and then what the allocator says, in that
796        /// order because the first question is about values and the second takes them away.
797        fn allocate(&mut self, locals: usize, registers: usize) -> (Reach, Allocation) {
798            let reach = reach(&self.func, &self.addresses, locals, &FRAME, &mut self.names);
799            let env =
800                Env::new().with(GPR, &SYSV.int_order[..registers], &SYSV.int_order[registers..]);
801            let allocation = rucc_regalloc::run(&mut self.func, &env, "test", true);
802            (reach, allocation)
803        }
804    }
805
806    /// A local of one word, which is what most of them are.
807    const WORD: Local = Local { size: 8, align: 8 };
808
809    #[test]
810    fn two_locals_that_are_never_both_wanted_are_the_same_bytes() {
811        let (mut building, block) = Building::new();
812        let first = building.local(block, 0);
813        building.through(block, first);
814        let second = building.local(block, 1);
815        building.through(block, second);
816        let (reach, allocation) = building.allocate(2, 4);
817
818        let plan = Slots::share(&building.func, Some(&reach), &allocation, &[WORD, WORD], &[]);
819        assert_eq!(plan.cells().len(), 1, "one run of bytes for the two of them");
820        assert_eq!(plan.local(0), plan.local(1));
821        assert_eq!(plan.saved(), 1);
822    }
823
824    #[test]
825    fn two_locals_that_are_both_wanted_at_once_are_not() {
826        let (mut building, block) = Building::new();
827        let first = building.local(block, 0);
828        let second = building.local(block, 1);
829        // Both addresses are live at this point, which is the whole of the difference from the
830        // test above.
831        building.through(block, first);
832        building.through(block, second);
833        let (reach, allocation) = building.allocate(2, 4);
834
835        let plan = Slots::share(&building.func, Some(&reach), &allocation, &[WORD, WORD], &[]);
836        assert_eq!(plan.cells().len(), 2);
837        assert_ne!(plan.local(0), plan.local(1));
838        assert_eq!(plan.saved(), 0);
839    }
840
841    #[test]
842    fn a_local_and_a_spilled_value_that_do_not_meet_share_one_run_of_bytes() {
843        let (mut building, block) = Building::new();
844        let addr = building.local(block, 0);
845        building.through(block, addr);
846        // Three values wanted at once with two registers to hand out, after the local is finished
847        // with, so what spills is spilled over a stretch the local is not wanted over.
848        let values: Vec<Reg> = (0..3).map(|_| building.value(block)).collect();
849        for &reg in &values {
850            building.held(block, reg);
851        }
852        let (reach, allocation) = building.allocate(1, 2);
853
854        assert_eq!(allocation.assignment.spilled(), 1, "one value went to the stack");
855        let plan = Slots::share(&building.func, Some(&reach), &allocation, &[WORD], &[8]);
856        assert_eq!(plan.cells().len(), 1);
857        assert_eq!(plan.local(0), plan.slot(0));
858    }
859
860    #[test]
861    fn a_local_whose_address_is_handed_to_something_shares_with_nothing() {
862        let (mut building, block) = Building::new();
863        let first = building.local(block, 0);
864        // Read as a value rather than as an address, which is what a call argument is and is the
865        // point past which this pass cannot say where the bytes are reached from.
866        building.held(block, first);
867        let second = building.local(block, 1);
868        building.through(block, second);
869        let (reach, allocation) = building.allocate(2, 4);
870
871        assert!(!reach.shares(0), "an address that got away");
872        assert!(reach.shares(1));
873        let plan = Slots::share(&building.func, Some(&reach), &allocation, &[WORD, WORD], &[]);
874        assert_eq!(plan.cells().len(), 2);
875        assert_ne!(plan.local(0), plan.local(1));
876    }
877
878    #[test]
879    fn a_local_whose_address_is_carried_into_a_block_shares_with_nothing() {
880        let (mut building, block) = Building::new();
881        let addr = building.local(block, 0);
882        let next = building.func.create_block();
883        let param = building.func.append_param(next, GPR);
884        building.func.build(block, building.nop).finish();
885        building.func.succs_mut(block).push(BlockCall::with(next, vec![addr]));
886        building.through(next, param);
887        let (reach, _) = building.allocate(1, 4);
888
889        assert!(!reach.shares(0), "an address that goes between blocks");
890    }
891
892    #[test]
893    fn a_local_touched_again_later_keeps_its_bytes_over_everything_in_between() {
894        let (mut building, block) = Building::new();
895        let first = building.local(block, 0);
896        building.through(block, first);
897        // Another local in the stretch between the two touches of the first one. Nothing mentions
898        // the first local in here, which is exactly the case: it is not being read, but what it
899        // holds is still wanted below, so these cannot be the same bytes.
900        let second = building.local(block, 1);
901        building.through(block, second);
902        // The first local again, reached through an address worked out a second time.
903        let again = building.local(block, 0);
904        building.through(block, again);
905        let (reach, allocation) = building.allocate(2, 4);
906
907        let plan = Slots::share(&building.func, Some(&reach), &allocation, &[WORD, WORD], &[]);
908        assert_ne!(plan.local(0), plan.local(1));
909        assert_eq!(plan.saved(), 0);
910    }
911
912    #[test]
913    fn a_local_touched_in_a_loop_keeps_its_bytes_over_the_rest_of_the_loop() {
914        let (mut building, block) = Building::new();
915        let header = building.func.create_block();
916        let body = building.func.create_block();
917        building.func.build(block, building.nop).finish();
918        building.func.succs_mut(block).push(BlockCall::to(header));
919
920        // The header is laid out before the body and touches a local of its own.
921        let held = building.local(header, 1);
922        building.through(header, held);
923        building.func.build(header, building.nop).finish();
924        building.func.succs_mut(header).push(BlockCall::to(body));
925
926        // The body touches the other one, every turn of the loop, and the header runs between one
927        // turn and the next. So the body's local is wanted over the header as well, which is a
928        // thing only the edges say: in the line the function is laid out in, the header is above
929        // the only touch there is.
930        let addr = building.local(body, 0);
931        building.through(body, addr);
932        building.func.build(body, building.nop).finish();
933        building.func.succs_mut(body).push(BlockCall::to(header));
934        let (reach, allocation) = building.allocate(2, 4);
935
936        let plan = Slots::share(&building.func, Some(&reach), &allocation, &[WORD, WORD], &[]);
937        assert_ne!(plan.local(0), plan.local(1));
938    }
939
940    /// A loop of one block, which is a block that is its own predecessor and its own successor.
941    /// The walk over the graph has to take that rather than fall over it, and what comes back is
942    /// the same answer the two block loop above gets: the body runs again, so a local touched at
943    /// the bottom of it is wanted at the top. tamnd/rucc#1207.
944    #[test]
945    fn a_block_that_is_its_own_neighbour_is_a_loop_like_any_other() {
946        let (mut building, block) = Building::new();
947        let loops = building.func.create_block();
948        building.func.build(block, building.nop).finish();
949        building.func.succs_mut(block).push(BlockCall::to(loops));
950
951        // One local touched at the top of the block and the other at the bottom. The edge back to
952        // the top is what puts the second one over the first.
953        let held = building.local(loops, 1);
954        building.through(loops, held);
955        let addr = building.local(loops, 0);
956        building.through(loops, addr);
957        building.func.build(loops, building.nop).finish();
958        building.func.succs_mut(loops).push(BlockCall::to(loops));
959        let (reach, allocation) = building.allocate(2, 4);
960
961        let plan = Slots::share(&building.func, Some(&reach), &allocation, &[WORD, WORD], &[]);
962        assert_ne!(plan.local(0), plan.local(1));
963    }
964
965    #[test]
966    fn an_address_a_second_address_computation_reads_is_the_same_local_followed_on() {
967        let (mut building, block) = Building::new();
968        let first = building.local(block, 0);
969        // `lea` off a `lea`, which is what the address of a field of a local is. The local is
970        // wanted wherever the second address is, not only where the first one is.
971        let derived = building.func.new_vreg(GPR);
972        let at = Operand::read(first, GPR);
973        building.func.build(block, building.lea).def(derived, GPR).mem(Mem::at(at)).finish();
974        let second = building.local(block, 1);
975        building.through(block, second);
976        building.through(block, derived);
977        let (reach, allocation) = building.allocate(2, 4);
978
979        assert!(reach.shares(0), "a derived address is still an address into this frame");
980        let plan = Slots::share(&building.func, Some(&reach), &allocation, &[WORD, WORD], &[]);
981        assert_eq!(plan.cells().len(), 2, "the two locals are wanted at once after all");
982    }
983
984    #[test]
985    fn a_cell_two_things_share_is_as_wide_and_as_strict_as_both_of_them() {
986        let (mut building, block) = Building::new();
987        let first = building.local(block, 0);
988        building.through(block, first);
989        let second = building.local(block, 1);
990        building.through(block, second);
991        let (reach, allocation) = building.allocate(2, 4);
992
993        let narrow = Local { size: 4, align: 4 };
994        let wide = Local { size: 16, align: 16 };
995        let plan = Slots::share(&building.func, Some(&reach), &allocation, &[narrow, wide], &[]);
996        assert_eq!(plan.cells(), [Cell { size: 16, align: 16 }]);
997        assert_eq!(plan.local(0), plan.local(1));
998    }
999
1000    #[test]
1001    fn a_local_nothing_on_the_address_list_names_shares_with_nothing() {
1002        let (mut building, block) = Building::new();
1003        let addr = building.local(block, 0);
1004        building.through(block, addr);
1005        let (reach, allocation) = building.allocate(2, 4);
1006
1007        // A list with nothing on it for a local is this pass having no account of it rather than
1008        // a local nothing touches, so it keeps bytes of its own.
1009        assert!(!reach.shares(1));
1010        let plan = Slots::share(&building.func, Some(&reach), &allocation, &[WORD, WORD], &[]);
1011        assert_eq!(plan.cells().len(), 2);
1012    }
1013
1014    #[test]
1015    fn the_frame_with_nothing_sharing_gives_every_local_and_every_slot_a_run_of_its_own() {
1016        let plan = Slots::apart(&[WORD, Local { size: 4, align: 4 }], &[8, 16]);
1017
1018        assert_eq!(plan.cells().len(), 4);
1019        assert_eq!(plan.saved(), 0);
1020        assert_eq!((plan.local(0), plan.local(1)), (Some(0), Some(1)));
1021        assert_eq!((plan.slot(0), plan.slot(1)), (Some(2), Some(3)));
1022        assert_eq!(plan.cells()[3], Cell { size: 16, align: 16 });
1023    }
1024
1025    #[test]
1026    fn a_frame_whose_locals_share_is_smaller_and_puts_them_at_the_same_offset() {
1027        let (mut building, block) = Building::new();
1028        let first = building.local(block, 0);
1029        building.through(block, first);
1030        let second = building.local(block, 1);
1031        building.through(block, second);
1032        let (reach, allocation) = building.allocate(2, 4);
1033
1034        // Not a leaf, so the frame is taken rather than kept in the red zone and its size is a
1035        // number rather than nothing, and big enough that the convention's alignment does not
1036        // round the difference away.
1037        let locals = [Local { size: 64, align: 8 }; 2];
1038        let base = Layout { leaf: false, locals: &locals, ..Layout::new(&SYSV, REGS) };
1039        let apart = Frame::of(&building.func, &allocation, &base);
1040        let plan = Slots::share(&building.func, Some(&reach), &allocation, &locals, &[]);
1041        let layout = Layout { share: Some(&plan), ..base };
1042        let together = Frame::of(&building.func, &allocation, &layout);
1043
1044        assert_ne!(apart.local(0), apart.local(1));
1045        assert_eq!(together.local(0), together.local(1));
1046        // Sixty four bytes of frame gone, and eight more in each of them for the word that lands
1047        // the stack pointer back where a call wants it.
1048        assert_eq!((apart.size(), together.size()), (136, 72));
1049    }
1050
1051    #[test]
1052    fn a_run_of_bytes_that_ends_part_way_through_its_alignment_costs_the_frame_nothing() {
1053        let (mut building, block) = Building::new();
1054        let addr = building.local(block, 0);
1055        building.through(block, addr);
1056        let (_, allocation) = building.allocate(1, 4);
1057
1058        // Twenty four bytes asking for sixteen is what a cell shared by a wide thing and a strict
1059        // one looks like, and it ends eight bytes into an alignment. Which way round the two are
1060        // given is not allowed to matter, because the order they are placed in is this pass's
1061        // business and the order they were declared in is not.
1062        let ragged = Local { size: 24, align: 16 };
1063        let whole = Local { size: 32, align: 16 };
1064        let size = |locals: &[Local]| {
1065            let layout = Layout { leaf: false, locals, ..Layout::new(&SYSV, REGS) };
1066            Frame::of(&building.func, &allocation, &layout).size()
1067        };
1068
1069        assert_eq!(size(&[ragged, whole]), size(&[whole, ragged]));
1070        // The two of them end to end with no hole between, which with the return address on top
1071        // of it is already where a call wants the stack pointer, so nothing is added for that.
1072        assert_eq!(size(&[ragged, whole]), 56);
1073    }
1074
1075    #[test]
1076    fn a_build_whose_locals_keep_their_own_bytes_still_shares_the_spill_slots() {
1077        let (mut building, block) = Building::new();
1078        let first = building.local(block, 0);
1079        building.through(block, first);
1080        let second = building.local(block, 1);
1081        building.through(block, second);
1082        // Two stretches of three values with two registers to hand out, one after the other, so
1083        // what goes to the stack in the first is finished with before the second starts.
1084        for _ in 0..2 {
1085            let values: Vec<Reg> = (0..3).map(|_| building.value(block)).collect();
1086            for &reg in &values {
1087                building.held(block, reg);
1088            }
1089        }
1090        let (_, allocation) = building.allocate(2, 2);
1091
1092        let widths = vec![8; allocation.assignment.spilled()];
1093        let plan = Slots::share(&building.func, None, &allocation, &[WORD, WORD], &widths);
1094        assert_ne!(plan.local(0), plan.local(1), "a variable somebody can ask for keeps its bytes");
1095        assert_eq!(plan.slot(0), plan.slot(1), "and two spilled values that never meet share");
1096    }
1097
1098    /// A spill slot wanting bytes over one stretch of the line.
1099    fn slot(number: usize, start: Point, end: Point) -> Want {
1100        Want { what: What::Slot(number), size: 8, align: 8, area: Some(vec![Range { start, end }]) }
1101    }
1102
1103    #[test]
1104    fn what_is_left_when_the_budget_runs_out_gets_bytes_of_its_own() {
1105        // Three that are never both wanted, which is one run of bytes for the three of them when
1106        // there is anything to spend on finding that out.
1107        let three = || vec![slot(0, 0, 10), slot(1, 20, 30), slot(2, 40, 50)];
1108        assert_eq!(fit(three(), 0, 3, BUDGET).cells().len(), 1);
1109        // One comparison puts the second beside the first and leaves nothing for the third.
1110        assert_eq!(fit(three(), 0, 3, 1).cells().len(), 2);
1111        assert_eq!(fit(three(), 0, 3, 0).cells().len(), 3);
1112    }
1113}