-
Notifications
You must be signed in to change notification settings - Fork 860
Use indirect call effects in LinearExecutionWalker #8738
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|
@@ -80,7 +80,12 @@ struct LinearExecutionWalker : public PostWalker<SubType, VisitorType> { | |||||||||||||||||||||||||
| static void scan(SubType* self, Expression** currp) { | ||||||||||||||||||||||||||
| Expression* curr = *currp; | ||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||
| auto handleCall = [&](bool mayThrow, bool isReturn) { | ||||||||||||||||||||||||||
| auto handleCall = [&](bool isReturn, const EffectAnalyzer* effects) { | ||||||||||||||||||||||||||
| bool refutesThrowEffect = effects && !effects->throws_; | ||||||||||||||||||||||||||
| bool mayThrow = !self->getModule() || | ||||||||||||||||||||||||||
| self->getModule()->features.hasExceptionHandling(); | ||||||||||||||||||||||||||
| mayThrow = mayThrow && !refutesThrowEffect; | ||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||
| if (!self->connectAdjacentBlocks) { | ||||||||||||||||||||||||||
| // Control is nonlinear if we return or throw. Traps don't need to be | ||||||||||||||||||||||||||
| // taken into account since they don't break control flow in a way | ||||||||||||||||||||||||||
|
|
@@ -156,40 +161,54 @@ struct LinearExecutionWalker : public PostWalker<SubType, VisitorType> { | |||||||||||||||||||||||||
| case Expression::Id::CallId: { | ||||||||||||||||||||||||||
| auto* call = curr->cast<Call>(); | ||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||
| bool mayThrow = !self->getModule() || | ||||||||||||||||||||||||||
| self->getModule()->features.hasExceptionHandling(); | ||||||||||||||||||||||||||
| if (mayThrow && self->getModule()) { | ||||||||||||||||||||||||||
| auto* effects = | ||||||||||||||||||||||||||
| self->getModule()->getFunction(call->target)->effects.get(); | ||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||
| if (effects && !effects->throws_) { | ||||||||||||||||||||||||||
| mayThrow = false; | ||||||||||||||||||||||||||
| const EffectAnalyzer* effects = nullptr; | ||||||||||||||||||||||||||
| if (self->getModule()) { | ||||||||||||||||||||||||||
| auto* func = self->getModule()->getFunctionOrNull(call->target); | ||||||||||||||||||||||||||
| // TODO: `func` might not exist here because of #8753. Fix this | ||||||||||||||||||||||||||
| // and remove the null check. | ||||||||||||||||||||||||||
| if (func) { | ||||||||||||||||||||||||||
| effects = func->effects.get(); | ||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||
| handleCall(mayThrow, call->isReturn); | ||||||||||||||||||||||||||
| handleCall(call->isReturn, effects); | ||||||||||||||||||||||||||
| break; | ||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||
| case Expression::Id::CallRefId: { | ||||||||||||||||||||||||||
| auto* callRef = curr->cast<CallRef>(); | ||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||
| // TODO: Effect analysis for indirect calls isn't implemented yet. | ||||||||||||||||||||||||||
| // Assume any indirect call may throw for now. | ||||||||||||||||||||||||||
| bool mayThrow = !self->getModule() || | ||||||||||||||||||||||||||
| self->getModule()->features.hasExceptionHandling(); | ||||||||||||||||||||||||||
| const EffectAnalyzer* effects = [&]() -> const EffectAnalyzer* { | ||||||||||||||||||||||||||
| if (!self->getModule()) { | ||||||||||||||||||||||||||
| return nullptr; | ||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||
| if (!callRef->target->type.isRef()) { | ||||||||||||||||||||||||||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Might as well filter out
Suggested change
Member
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I hadn't thought of that, but I think we don't want to do that because that means that we'd fail to lookup effects for calls to these types and be overly conservative as a result. We want the lookup to succeed and see empty effects which is what happens today: binaryen/src/passes/GlobalEffects.cpp Lines 176 to 178 in 84ace4a
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I would expect these to get a
Member
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. The map will contain entries for those types with a binaryen/src/passes/GlobalEffects.cpp Lines 317 to 323 in 505dae4
indirectCallEffects having to replicate this logic.
Will add a test including an indirect call to (unreachable) to hit this code path. |
||||||||||||||||||||||||||
| return nullptr; | ||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||
| handleCall(mayThrow, callRef->isReturn); | ||||||||||||||||||||||||||
| auto* effectsPtr = | ||||||||||||||||||||||||||
| find_or_null(self->getModule()->indirectCallEffects, | ||||||||||||||||||||||||||
| callRef->target->type.getHeapType()); | ||||||||||||||||||||||||||
| if (!effectsPtr) { | ||||||||||||||||||||||||||
| return nullptr; | ||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||
| return effectsPtr->get(); | ||||||||||||||||||||||||||
| }(); | ||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||
| handleCall(callRef->isReturn, effects); | ||||||||||||||||||||||||||
| break; | ||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||
| case Expression::Id::CallIndirectId: { | ||||||||||||||||||||||||||
| auto* callIndirect = curr->cast<CallIndirect>(); | ||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||
| // TODO: Effect analysis for indirect calls isn't implemented yet. | ||||||||||||||||||||||||||
| // Assume any indirect call may throw for now. | ||||||||||||||||||||||||||
| bool mayThrow = !self->getModule() || | ||||||||||||||||||||||||||
| self->getModule()->features.hasExceptionHandling(); | ||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||
| handleCall(mayThrow, callIndirect->isReturn); | ||||||||||||||||||||||||||
| const EffectAnalyzer* effects = nullptr; | ||||||||||||||||||||||||||
| if (self->getModule()) { | ||||||||||||||||||||||||||
| if (const auto& effectsPtr = | ||||||||||||||||||||||||||
| find_or_null(self->getModule()->indirectCallEffects, | ||||||||||||||||||||||||||
| callIndirect->heapType)) { | ||||||||||||||||||||||||||
| effects = effectsPtr->get(); | ||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||
| handleCall(callIndirect->isReturn, effects); | ||||||||||||||||||||||||||
| break; | ||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||
| case Expression::Id::TryId: { | ||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -56,10 +56,11 @@ | |
| ) | ||
|
|
||
| (module | ||
| ;; CHECK: (type $throw-type (func (result f64))) | ||
|
|
||
| ;; CHECK: (type $const-type (func (result f32))) | ||
| (type $const-type (func (result f32))) | ||
|
|
||
| ;; CHECK: (type $throw-type (func (result f64))) | ||
| (type $throw-type (func (result f64))) | ||
|
|
||
| ;; CHECK: (global $g (mut i32) (i32.const 0)) | ||
|
|
@@ -68,7 +69,7 @@ | |
| ;; CHECK: (table $t 2 2 funcref) | ||
| (table $t 2 2 funcref) | ||
|
|
||
| ;; CHECK: (tag $t (type $2)) | ||
| ;; CHECK: (tag $t (type $3)) | ||
| (tag $t) | ||
|
|
||
| ;; CHECK: (func $const (type $const-type) (result f32) | ||
|
|
@@ -90,32 +91,48 @@ | |
| ) | ||
| (elem declare $throws) | ||
|
|
||
| ;; CHECK: (func $read-g (type $3) (param $ref (ref null $const-type)) (result i32) | ||
| ;; CHECK: (func $read-g-with-nop-call-ref (type $4) (param $ref (ref null $const-type)) (result i32) | ||
| ;; CHECK-NEXT: (local $x i32) | ||
| ;; CHECK-NEXT: (local.set $x | ||
| ;; CHECK-NEXT: (global.get $g) | ||
| ;; CHECK-NEXT: ) | ||
| ;; CHECK-NEXT: (nop) | ||
| ;; CHECK-NEXT: (drop | ||
| ;; CHECK-NEXT: (call_ref $const-type | ||
| ;; CHECK-NEXT: (local.get $ref) | ||
| ;; CHECK-NEXT: ) | ||
| ;; CHECK-NEXT: ) | ||
| ;; CHECK-NEXT: (local.get $x) | ||
| ;; CHECK-NEXT: (global.get $g) | ||
| ;; CHECK-NEXT: ) | ||
| (func $read-g (param $ref (ref null $const-type)) (result i32) | ||
| (func $read-g-with-nop-call-ref (param $ref (ref null $const-type)) (result i32) | ||
| (local $x i32) | ||
| (local.set $x (global.get $g)) | ||
|
|
||
| ;; With more precise effect analysis for indirect calls, we can determine | ||
| ;; that the only possible target for this ref is $const in a closed world, | ||
| ;; which wouldn't block our optimizations. | ||
| ;; TODO: Add effects analysis for indirect calls. | ||
| ;; With --closed-world enabled, we can tell that this can only possibly call | ||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I think --closed-world isn't even necessary for this, since this module has no imports or exports. There's no way for an outside function reference to sneak in.
Member
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Good point, is it worth doing any indirect call analysis in the open world case? We could aggregate type effects unconditionally, and if we see a function ref that's imported or exported then invalidate the effects for that type and all subtypes. But any exported table of funcref would be enough to stop all analysis, and I know that many users use --closed-world anyway? In practice, we only do indirect call analysis if --closed-world is enabled, so I think the comment is appropriate. It's still true that --closed-world is enough to determine that $const is the only possible callee here.
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I think we should do indirect call analysis in open world, too. It just needs to respect the public/private type classification it gets from
Member
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I'll leave this alone since I think the comment is still accurate for now based on #8754. In the future we can change GlobalEffects to look at public/private for types instead of --closed-world at which point we can change this. |
||
| ;; $const, which doesn't block our optimizations. | ||
| (drop (call_ref $const-type (local.get $ref))) | ||
|
|
||
| (local.get $x) | ||
| ) | ||
|
|
||
| ;; CHECK: (func $read-g-with-throw-in-between (type $4) (param $ref (ref $throw-type)) (result i32) | ||
| ;; CHECK: (func $read-g-with-nop-call-indirect (type $5) (result i32) | ||
| ;; CHECK-NEXT: (local $x i32) | ||
| ;; CHECK-NEXT: (nop) | ||
| ;; CHECK-NEXT: (drop | ||
| ;; CHECK-NEXT: (call_indirect $t (type $const-type) | ||
| ;; CHECK-NEXT: (i32.const 0) | ||
| ;; CHECK-NEXT: ) | ||
| ;; CHECK-NEXT: ) | ||
| ;; CHECK-NEXT: (global.get $g) | ||
| ;; CHECK-NEXT: ) | ||
| (func $read-g-with-nop-call-indirect (result i32) | ||
| (local $x i32) | ||
| (local.set $x (global.get $g)) | ||
|
|
||
| ;; Similar to above with call_indirect instead of call_ref. | ||
| (drop (call_indirect (type $const-type) (i32.const 0))) | ||
|
|
||
| (local.get $x) | ||
| ) | ||
|
|
||
| ;; CHECK: (func $read-g-with-effectful-call-ref (type $2) (param $ref (ref $throw-type)) (result i32) | ||
| ;; CHECK-NEXT: (local $x i32) | ||
| ;; CHECK-NEXT: (local.set $x | ||
| ;; CHECK-NEXT: (global.get $g) | ||
|
|
@@ -127,7 +144,7 @@ | |
| ;; CHECK-NEXT: ) | ||
| ;; CHECK-NEXT: (local.get $x) | ||
| ;; CHECK-NEXT: ) | ||
| (func $read-g-with-throw-in-between (param $ref (ref $throw-type)) (result i32) | ||
| (func $read-g-with-effectful-call-ref (param $ref (ref $throw-type)) (result i32) | ||
| (local $x i32) | ||
| (local.set $x (global.get $g)) | ||
|
|
||
|
|
@@ -138,25 +155,25 @@ | |
| (local.get $x) | ||
| ) | ||
|
|
||
| ;; CHECK: (func $read-g-with-call-indirect-in-between (type $5) (result i32) | ||
| ;; CHECK: (func $read-g-with-effectful-call-indirect (type $2) (param $ref (ref $throw-type)) (result i32) | ||
| ;; CHECK-NEXT: (local $x i32) | ||
| ;; CHECK-NEXT: (local.set $x | ||
| ;; CHECK-NEXT: (global.get $g) | ||
| ;; CHECK-NEXT: ) | ||
| ;; CHECK-NEXT: (drop | ||
| ;; CHECK-NEXT: (call_indirect $t (type $const-type) | ||
| ;; CHECK-NEXT: (call_indirect $t (type $throw-type) | ||
| ;; CHECK-NEXT: (i32.const 0) | ||
| ;; CHECK-NEXT: ) | ||
| ;; CHECK-NEXT: ) | ||
| ;; CHECK-NEXT: (local.get $x) | ||
| ;; CHECK-NEXT: ) | ||
| (func $read-g-with-call-indirect-in-between (result i32) | ||
| (func $read-g-with-effectful-call-indirect (param $ref (ref $throw-type)) (result i32) | ||
| (local $x i32) | ||
| (local.set $x (global.get $g)) | ||
|
|
||
| ;; Similar to above with call_indirect instead of call_ref. | ||
| ;; TODO: Add effects analysis for indirect calls. | ||
| (drop (call_indirect (type $const-type) (i32.const 0))) | ||
| ;; Similar to above, except here we can tell that the indirect call may | ||
| ;; throw so optimization is halted. | ||
| (drop (call_indirect (type $throw-type) (i32.const 0))) | ||
|
|
||
| (local.get $x) | ||
| ) | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I would expect us to be able to assume that the target function exists, given that it would be invalid for it not to exist.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I thought so too, but when we run with --asyncify it causes us to fail when trying to lookup __asyncify_get_call_index. Maybe it's a problem with when the function is generated?
The repro is from test/lit/passes/asyncify_optimize-level=1.wast. The earlier code assumed that call targets exist but looks like it never hit an error before by luck.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
if (true || func)😆 what is going on there?It looks like Asyncify is temporarily adding calls to "intrinsics" that it later replaces with real code sequences. I think it should be fixed to add its "intrinsics" as actual function imports to avoid running other passes on invalid IR. But maybe that can be done as a follow-up. I'd be happy with a TODO here pointing to the problem.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I just quickly added that as an equivalent to your snippet to test out!
Sounds good, will add a todo here and follow up.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Filed #8753 and added a TODO.