1 /*
   2  * Copyright (c) 1998, 2026, Oracle and/or its affiliates. All rights reserved.
   3  * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
   4  *
   5  * This code is free software; you can redistribute it and/or modify it
   6  * under the terms of the GNU General Public License version 2 only, as
   7  * published by the Free Software Foundation.
   8  *
   9  * This code is distributed in the hope that it will be useful, but WITHOUT
  10  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
  11  * FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License
  12  * version 2 for more details (a copy is included in the LICENSE file that
  13  * accompanied this code).
  14  *
  15  * You should have received a copy of the GNU General Public License version
  16  * 2 along with this work; if not, write to the Free Software Foundation,
  17  * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
  18  *
  19  * Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
  20  * or visit www.oracle.com if you need additional information or have any
  21  * questions.
  22  *
  23  */
  24 
  25 #include "ci/ciInlineKlass.hpp"
  26 #include "ci/ciMethodData.hpp"
  27 #include "ci/ciSymbols.hpp"
  28 #include "classfile/vmSymbols.hpp"
  29 #include "compiler/compileLog.hpp"
  30 #include "interpreter/linkResolver.hpp"
  31 #include "jvm_io.h"
  32 #include "memory/resourceArea.hpp"
  33 #include "memory/universe.hpp"
  34 #include "oops/oop.inline.hpp"
  35 #include "opto/addnode.hpp"
  36 #include "opto/castnode.hpp"
  37 #include "opto/convertnode.hpp"
  38 #include "opto/divnode.hpp"
  39 #include "opto/idealGraphPrinter.hpp"
  40 #include "opto/idealKit.hpp"
  41 #include "opto/inlinetypenode.hpp"
  42 #include "opto/matcher.hpp"
  43 #include "opto/memnode.hpp"
  44 #include "opto/mulnode.hpp"
  45 #include "opto/opaquenode.hpp"
  46 #include "opto/parse.hpp"
  47 #include "opto/runtime.hpp"
  48 #include "opto/subtypenode.hpp"
  49 #include "runtime/arguments.hpp"
  50 #include "runtime/deoptimization.hpp"
  51 #include "runtime/globals.hpp"
  52 #include "runtime/sharedRuntime.hpp"
  53 
  54 #ifndef PRODUCT
  55 extern uint explicit_null_checks_inserted,
  56             explicit_null_checks_elided;
  57 #endif
  58 
  59 Node* Parse::record_profile_for_speculation_at_array_load(Node* ld) {
  60   // Feed unused profile data to type speculation
  61   if (UseTypeSpeculation && UseArrayLoadStoreProfile) {
  62     ciKlass* array_type = nullptr;
  63     ciKlass* element_type = nullptr;
  64     ProfilePtrKind element_ptr = ProfileMaybeNull;
  65     bool flat_array = true;
  66     bool null_free_array = true;
  67     method()->array_access_profiled_type(bci(), array_type, element_type, element_ptr, flat_array, null_free_array);
  68     if (element_type != nullptr || element_ptr != ProfileMaybeNull) {
  69       ld = record_profile_for_speculation(ld, element_type, element_ptr);
  70     }
  71   }
  72   return ld;
  73 }
  74 
  75 
  76 //---------------------------------array_load----------------------------------
  77 void Parse::array_load(BasicType bt) {
  78   const Type* elemtype = Type::TOP;
  79   Node* adr = array_addressing(bt, 0, elemtype);
  80   if (stopped())  return;     // guaranteed null or range check
  81 
  82   Node* array_index = pop();
  83   Node* array = pop();
  84 
  85   // Handle inline type arrays
  86   const TypeOopPtr* element_ptr = elemtype->make_oopptr();
  87   const TypeAryPtr* array_type = _gvn.type(array)->is_aryptr();
  88 
  89   if (!array_type->is_not_flat()) {
  90     // Cannot statically determine if array is a flat array, emit runtime check
  91     assert(UseArrayFlattening && is_reference_type(bt) && element_ptr->can_be_inline_type() &&
  92            (!element_ptr->is_inlinetypeptr() || element_ptr->inline_klass()->maybe_flat_in_array()), "array can't be flat");
  93     IdealKit ideal(this);
  94     IdealVariable res(ideal);
  95     ideal.declarations_done();
  96     ideal.if_then(flat_array_test(array, /* flat = */ false)); {
  97       // Non-flat array
  98       sync_kit(ideal);
  99       if (!array_type->is_flat()) {
 100         assert(array_type->is_flat() || control()->in(0)->as_If()->is_flat_array_check(&_gvn), "Should be found");
 101         const TypeAryPtr* adr_type = TypeAryPtr::get_array_body_type(bt);
 102         DecoratorSet decorator_set = IN_HEAP | IS_ARRAY | C2_CONTROL_DEPENDENT_LOAD;
 103         if (needs_range_check(array_type->size(), array_index)) {
 104           // We've emitted a RangeCheck but now insert an additional check between the range check and the actual load.
 105           // We cannot pin the load to two separate nodes. Instead, we pin it conservatively here such that it cannot
 106           // possibly float above the range check at any point.
 107           decorator_set |= C2_UNKNOWN_CONTROL_LOAD;
 108         }
 109         Node* ld = access_load_at(array, adr, adr_type, element_ptr, bt, decorator_set);
 110         if (element_ptr->is_inlinetypeptr()) {
 111           ld = InlineTypeNode::make_from_oop(this, ld, element_ptr->inline_klass());
 112         }
 113         ideal.set(res, ld);
 114       }
 115       ideal.sync_kit(this);
 116     } ideal.else_(); {
 117       // Flat array
 118       sync_kit(ideal);
 119       if (!array_type->is_not_flat()) {
 120         if (element_ptr->is_inlinetypeptr()) {
 121           ciInlineKlass* vk = element_ptr->inline_klass();
 122           Node* flat_array = cast_to_flat_array(array, vk);
 123           Node* vt = InlineTypeNode::make_from_flat_array(this, vk, flat_array, array_index);
 124           ideal.set(res, vt);
 125         } else {
 126           // Element type is unknown, and thus we cannot statically determine the exact flat array layout. Emit a
 127           // runtime call to correctly load the inline type element from the flat array.
 128           Node* inline_type = load_from_unknown_flat_array(array, array_index, element_ptr);
 129           bool is_null_free = array_type->is_null_free() ||
 130                               (!UseNullableAtomicValueFlattening && !UseNullableNonAtomicValueFlattening);
 131           if (is_null_free) {
 132             inline_type = cast_not_null(inline_type);
 133           }
 134           ideal.set(res, inline_type);
 135         }
 136       }
 137       ideal.sync_kit(this);
 138     } ideal.end_if();
 139     sync_kit(ideal);
 140     Node* ld = _gvn.transform(ideal.value(res));
 141     ld = record_profile_for_speculation_at_array_load(ld);
 142     push_node(bt, ld);
 143     return;
 144   }
 145 
 146   if (elemtype == TypeInt::BOOL) {
 147     bt = T_BOOLEAN;
 148   }
 149   const TypeAryPtr* adr_type = TypeAryPtr::get_array_body_type(bt);
 150   Node* ld = access_load_at(array, adr, adr_type, elemtype, bt,
 151                             IN_HEAP | IS_ARRAY | C2_CONTROL_DEPENDENT_LOAD);
 152   ld = record_profile_for_speculation_at_array_load(ld);
 153   // Loading an inline type from a non-flat array
 154   if (element_ptr != nullptr && element_ptr->is_inlinetypeptr()) {
 155     assert(!array_type->is_null_free() || !element_ptr->maybe_null(), "inline type array elements should never be null");
 156     ld = InlineTypeNode::make_from_oop(this, ld, element_ptr->inline_klass());
 157   }
 158   push_node(bt, ld);
 159 }
 160 
 161 Node* Parse::load_from_unknown_flat_array(Node* array, Node* array_index, const TypeOopPtr* element_ptr) {
 162   // Below membars keep this access to an unknown flat array correctly
 163   // ordered with other unknown and known flat array accesses.
 164   insert_mem_bar_volatile(Op_MemBarCPUOrder, C->get_alias_index(TypeAryPtr::INLINES));
 165 
 166   Node* call = nullptr;
 167   {
 168     // Re-execute flat array load if runtime call triggers deoptimization
 169     PreserveReexecuteState preexecs(this);
 170     jvms()->set_bci(_bci);
 171     jvms()->set_should_reexecute(true);
 172     inc_sp(2);
 173     kill_dead_locals();
 174     call = make_runtime_call(RC_NO_LEAF | RC_NO_IO,
 175                              OptoRuntime::load_unknown_inline_Type(),
 176                              OptoRuntime::load_unknown_inline_Java(),
 177                              nullptr, TypeRawPtr::BOTTOM,
 178                              array, array_index);
 179   }
 180   make_slow_call_ex(call, env()->Throwable_klass(), false);
 181   Node* buffer = _gvn.transform(new ProjNode(call, TypeFunc::Parms));
 182 
 183   insert_mem_bar_volatile(Op_MemBarCPUOrder, C->get_alias_index(TypeAryPtr::INLINES));
 184 
 185   // Keep track of the information that the inline type is in flat arrays
 186   const Type* unknown_value = element_ptr->is_instptr()->cast_to_flat_in_array();
 187   return _gvn.transform(new CheckCastPPNode(control(), buffer, unknown_value));
 188 }
 189 
 190 //--------------------------------array_store----------------------------------
 191 void Parse::array_store(BasicType bt) {
 192   const Type* elemtype = Type::TOP;
 193   Node* adr = array_addressing(bt, type2size[bt], elemtype);
 194   if (stopped())  return;     // guaranteed null or range check
 195   Node* stored_value_casted = nullptr;
 196   if (bt == T_OBJECT) {
 197     stored_value_casted = array_store_check(adr, elemtype);
 198     if (stopped()) {
 199       return;
 200     }
 201   }
 202   Node* const stored_value = pop_node(bt); // Value to store
 203   Node* const array_index = pop();         // Index in the array
 204   Node* array = pop();                     // The array itself
 205 
 206   const TypeAryPtr* array_type = _gvn.type(array)->is_aryptr();
 207   const TypeAryPtr* adr_type = TypeAryPtr::get_array_body_type(bt);
 208 
 209   if (elemtype == TypeInt::BOOL) {
 210     bt = T_BOOLEAN;
 211   } else if (bt == T_OBJECT) {
 212     elemtype = elemtype->make_oopptr();
 213     const Type* stored_value_casted_type = _gvn.type(stored_value_casted);
 214     // Based on the value to be stored, try to determine if the array is not null-free and/or not flat.
 215     // This is only legal for non-null stores because the array_store_check always passes for null, even
 216     // if the array is null-free. Null stores are handled in GraphKit::inline_array_null_guard().
 217     bool not_inline = !stored_value_casted_type->maybe_null() && !stored_value_casted_type->is_oopptr()->can_be_inline_type();
 218     bool not_null_free = not_inline;
 219     bool not_flat = not_inline || ( stored_value_casted_type->is_inlinetypeptr() &&
 220                                    !stored_value_casted_type->inline_klass()->maybe_flat_in_array());
 221     if (!array_type->is_not_null_free() && not_null_free) {
 222       // Storing a non-inline type, mark array as not null-free.
 223       array_type = array_type->cast_to_not_null_free();
 224       Node* cast = _gvn.transform(new CheckCastPPNode(control(), array, array_type));
 225       replace_in_map(array, cast);
 226       array = cast;
 227     }
 228     if (!array_type->is_not_flat() && not_flat) {
 229       // Storing to a non-flat array, mark array as not flat.
 230       array_type = array_type->cast_to_not_flat();
 231       Node* cast = _gvn.transform(new CheckCastPPNode(control(), array, array_type));
 232       replace_in_map(array, cast);
 233       array = cast;
 234     }
 235 
 236     if (array_type->is_null_free() && elemtype->is_inlinetypeptr() && elemtype->inline_klass()->is_empty()) {
 237       // Array of null-free empty inline type, there is only 1 state for the elements
 238       assert(!stored_value_casted_type->maybe_null(), "should be guaranteed by array store check");
 239       return;
 240     }
 241 
 242     if (!array_type->is_not_flat()) {
 243       // Array might be a flat array, emit runtime checks (for null, a simple inline_array_null_guard is sufficient).
 244       assert(UseArrayFlattening && !not_flat && elemtype->is_oopptr()->can_be_inline_type() &&
 245              (!array_type->klass_is_exact() || array_type->is_flat()), "array can't be a flat array");
 246       // TODO 8350865 Depending on the available layouts, we can avoid this check in below flat/not-flat branches. Also the safe_for_replace arg is now always true.
 247       array = inline_array_null_guard(array, stored_value_casted, 3, true);
 248       IdealKit ideal(this);
 249       ideal.if_then(flat_array_test(array, /* flat = */ false)); {
 250         // Non-flat array
 251         if (!array_type->is_flat()) {
 252           sync_kit(ideal);
 253           assert(array_type->is_flat() || ideal.ctrl()->in(0)->as_If()->is_flat_array_check(&_gvn), "Should be found");
 254           inc_sp(3);
 255           access_store_at(array, adr, adr_type, stored_value_casted, elemtype, bt, MO_UNORDERED | IN_HEAP | IS_ARRAY, false);
 256           dec_sp(3);
 257           ideal.sync_kit(this);
 258         }
 259       } ideal.else_(); {
 260         // Flat array
 261         sync_kit(ideal);
 262         if (!array_type->is_not_flat()) {
 263           // Try to determine the inline klass type of the stored value
 264           ciInlineKlass* vk = nullptr;
 265           if (stored_value_casted_type->is_inlinetypeptr()) {
 266             vk = stored_value_casted_type->inline_klass();
 267           } else if (elemtype->is_inlinetypeptr()) {
 268             vk = elemtype->inline_klass();
 269           }
 270 
 271           if (vk != nullptr) {
 272             // Element type is known, cast and store to flat array layout.
 273             Node* flat_array = cast_to_flat_array(array, vk);
 274 
 275             // Re-execute flat array store if buffering triggers deoptimization
 276             PreserveReexecuteState preexecs(this);
 277             jvms()->set_should_reexecute(true);
 278             inc_sp(3);
 279 
 280             if (!stored_value_casted->is_InlineType()) {
 281               assert(_gvn.type(stored_value_casted) == TypePtr::NULL_PTR, "Unexpected value");
 282               stored_value_casted = InlineTypeNode::make_null(_gvn, vk);
 283             }
 284 
 285             stored_value_casted->as_InlineType()->store_flat_array(this, flat_array, array_index);
 286           } else {
 287             // Element type is unknown, emit a runtime call since the flat array layout is not statically known.
 288             store_to_unknown_flat_array(array, array_index, stored_value_casted);
 289           }
 290         }
 291         ideal.sync_kit(this);
 292       }
 293       ideal.end_if();
 294       sync_kit(ideal);
 295       return;
 296     } else if (!array_type->is_not_null_free()) {
 297       // Array is not flat but may be null free
 298       assert(elemtype->is_oopptr()->can_be_inline_type(), "array can't be null-free");
 299       array = inline_array_null_guard(array, stored_value_casted, 3, true);
 300     }
 301   }
 302   inc_sp(3);
 303   access_store_at(array, adr, adr_type, stored_value, elemtype, bt, MO_UNORDERED | IN_HEAP | IS_ARRAY);
 304   dec_sp(3);
 305 }
 306 
 307 // Emit a runtime call to store to a flat array whose element type is either unknown (i.e. we do not know the flat
 308 // array layout) or not exact (could have different flat array layouts at runtime).
 309 void Parse::store_to_unknown_flat_array(Node* array, Node* const idx, Node* non_null_stored_value) {
 310   // Below membars keep this access to an unknown flat array correctly
 311   // ordered with other unknown and known flat array accesses.
 312   insert_mem_bar_volatile(Op_MemBarCPUOrder, C->get_alias_index(TypeAryPtr::INLINES));
 313 
 314   Node* call = nullptr;
 315   {
 316     // Re-execute flat array store if runtime call triggers deoptimization
 317     PreserveReexecuteState preexecs(this);
 318     jvms()->set_bci(_bci);
 319     jvms()->set_should_reexecute(true);
 320     inc_sp(3);
 321     kill_dead_locals();
 322     call = make_runtime_call(RC_NO_LEAF | RC_NO_IO,
 323                       OptoRuntime::store_unknown_inline_Type(),
 324                       OptoRuntime::store_unknown_inline_Java(),
 325                       nullptr, TypeRawPtr::BOTTOM,
 326                       non_null_stored_value, array, idx);
 327   }
 328   make_slow_call_ex(call, env()->Throwable_klass(), false);
 329 
 330   insert_mem_bar_volatile(Op_MemBarCPUOrder, C->get_alias_index(TypeAryPtr::INLINES));
 331 }
 332 
 333 //------------------------------array_addressing-------------------------------
 334 // Pull array and index from the stack.  Compute pointer-to-element.
 335 Node* Parse::array_addressing(BasicType type, int vals, const Type*& elemtype) {
 336   Node *idx   = peek(0+vals);   // Get from stack without popping
 337   Node *ary   = peek(1+vals);   // in case of exception
 338 
 339   // Null check the array base, with correct stack contents
 340   ary = null_check(ary, T_ARRAY);
 341   // Compile-time detect of null-exception?
 342   if (stopped())  return top();
 343 
 344   const TypeAryPtr* arytype  = _gvn.type(ary)->is_aryptr();
 345   const TypeInt*    sizetype = arytype->size();
 346   elemtype = arytype->elem();
 347 
 348   if (UseUniqueSubclasses) {
 349     const Type* el = elemtype->make_ptr();
 350     if (el && el->isa_instptr()) {
 351       const TypeInstPtr* toop = el->is_instptr();
 352       if (toop->instance_klass()->unique_concrete_subklass()) {
 353         // If we load from "AbstractClass[]" we must see "ConcreteSubClass".
 354         const Type* subklass = Type::get_const_type(toop->instance_klass());
 355         elemtype = subklass->join_speculative(el);
 356       }
 357     }
 358   }
 359 
 360   if (!arytype->is_loaded()) {
 361     // Only fails for some -Xcomp runs
 362     // The class is unloaded.  We have to run this bytecode in the interpreter.
 363     ciKlass* klass = arytype->unloaded_klass();
 364 
 365     uncommon_trap(Deoptimization::Reason_unloaded,
 366                   Deoptimization::Action_reinterpret,
 367                   klass, "!loaded array");
 368     return top();
 369   }
 370 
 371   ary = create_speculative_inline_type_array_checks(ary, arytype, elemtype);
 372 
 373   if (needs_range_check(sizetype, idx)) {
 374     create_range_check(idx, ary, sizetype);
 375   } else if (C->log() != nullptr) {
 376     C->log()->elem("observe that='!need_range_check'");
 377   }
 378 
 379   // Check for always knowing you are throwing a range-check exception
 380   if (stopped())  return top();
 381 
 382   // Make array address computation control dependent to prevent it
 383   // from floating above the range check during loop optimizations.
 384   Node* ptr = array_element_address(ary, idx, type, sizetype, control());
 385   assert(ptr != top(), "top should go hand-in-hand with stopped");
 386 
 387   return ptr;
 388 }
 389 
 390 // Check if we need a range check for an array access. This is the case if the index is either negative or if it could
 391 // be greater or equal the smallest possible array size (i.e. out-of-bounds).
 392 bool Parse::needs_range_check(const TypeInt* size_type, const Node* index) const {
 393   const TypeInt* index_type = _gvn.type(index)->is_int();
 394   return index_type->_hi >= size_type->_lo || index_type->_lo < 0;
 395 }
 396 
 397 void Parse::create_range_check(Node* idx, Node* ary, const TypeInt* sizetype) {
 398   Node* tst;
 399   if (sizetype->_hi <= 0) {
 400     // The greatest array bound is negative, so we can conclude that we're
 401     // compiling unreachable code, but the unsigned compare trick used below
 402     // only works with non-negative lengths.  Instead, hack "tst" to be zero so
 403     // the uncommon_trap path will always be taken.
 404     tst = _gvn.intcon(0);
 405   } else {
 406     // Range is constant in array-oop, so we can use the original state of mem
 407     Node* len = load_array_length(ary);
 408 
 409     // Test length vs index (standard trick using unsigned compare)
 410     Node* chk = _gvn.transform(new CmpUNode(idx, len) );
 411     BoolTest::mask btest = BoolTest::lt;
 412     tst = _gvn.transform(new BoolNode(chk, btest) );
 413   }
 414   RangeCheckNode* rc = new RangeCheckNode(control(), tst, PROB_MAX, COUNT_UNKNOWN);
 415   _gvn.set_type(rc, rc->Value(&_gvn));
 416   if (!tst->is_Con()) {
 417     record_for_igvn(rc);
 418   }
 419   set_control(_gvn.transform(new IfTrueNode(rc)));
 420   // Branch to failure if out of bounds
 421   {
 422     PreserveJVMState pjvms(this);
 423     set_control(_gvn.transform(new IfFalseNode(rc)));
 424     if (C->allow_range_check_smearing()) {
 425       // Do not use builtin_throw, since range checks are sometimes
 426       // made more stringent by an optimistic transformation.
 427       // This creates "tentative" range checks at this point,
 428       // which are not guaranteed to throw exceptions.
 429       // See IfNode::Ideal, is_range_check, adjust_check.
 430       uncommon_trap(Deoptimization::Reason_range_check,
 431                     Deoptimization::Action_make_not_entrant,
 432                     nullptr, "range_check");
 433     } else {
 434       // If we have already recompiled with the range-check-widening
 435       // heroic optimization turned off, then we must really be throwing
 436       // range check exceptions.
 437       builtin_throw(Deoptimization::Reason_range_check);
 438     }
 439   }
 440 }
 441 
 442 // For inline type arrays, we can use the profiling information for array accesses to speculate on the type, flatness,
 443 // and null-freeness. We can either prepare the speculative type for later uses or emit explicit speculative checks with
 444 // traps now. In the latter case, the speculative type guarantees can avoid additional runtime checks later (e.g.
 445 // non-null-free implies non-flat which allows us to remove flatness checks). This makes the graph simpler.
 446 Node* Parse::create_speculative_inline_type_array_checks(Node* array, const TypeAryPtr* array_type,
 447                                                          const Type*& element_type) {
 448   if (!array_type->is_flat() && !array_type->is_not_flat()) {
 449     // For arrays that might be flat, speculate that the array has the exact type reported in the profile data such that
 450     // we can rely on a fixed memory layout (i.e. either a flat layout or not).
 451     array = cast_to_speculative_array_type(array, array_type, element_type);
 452   } else if (UseTypeSpeculation && UseArrayLoadStoreProfile) {
 453     // Array is known to be either flat or not flat. If possible, update the speculative type by using the profile data
 454     // at this bci.
 455     array = cast_to_profiled_array_type(array);
 456   }
 457 
 458   // Even though the type does not tell us whether we have an inline type array or not, we can still check the profile data
 459   // whether we have a non-null-free or non-flat array. Speculating on a non-null-free array doesn't help aaload but could
 460   // be profitable for a subsequent aastore.
 461   if (!array_type->is_null_free() && !array_type->is_not_null_free()) {
 462     array = speculate_non_null_free_array(array, array_type);
 463   }
 464   if (!array_type->is_flat() && !array_type->is_not_flat()) {
 465     array = speculate_non_flat_array(array, array_type);
 466   }
 467   return array;
 468 }
 469 
 470 // Speculate that the array has the exact type reported in the profile data. We emit a trap when this turns out to be
 471 // wrong. On the fast path, we add a CheckCastPP to use the exact type.
 472 Node* Parse::cast_to_speculative_array_type(Node* const array, const TypeAryPtr*& array_type, const Type*& element_type) {
 473   Deoptimization::DeoptReason reason = Deoptimization::Reason_speculate_class_check;
 474   ciKlass* speculative_array_type = array_type->speculative_type();
 475   if (too_many_traps_or_recompiles(reason) || speculative_array_type == nullptr) {
 476     // No speculative type, check profile data at this bci
 477     speculative_array_type = nullptr;
 478     reason = Deoptimization::Reason_class_check;
 479     if (UseArrayLoadStoreProfile && !too_many_traps_or_recompiles(reason)) {
 480       ciKlass* profiled_element_type = nullptr;
 481       ProfilePtrKind element_ptr = ProfileMaybeNull;
 482       bool flat_array = true;
 483       bool null_free_array = true;
 484       method()->array_access_profiled_type(bci(), speculative_array_type, profiled_element_type, element_ptr, flat_array,
 485                                            null_free_array);
 486     }
 487   }
 488   if (speculative_array_type != nullptr) {
 489     // Speculate that this array has the exact type reported by profile data
 490     Node* casted_array = nullptr;
 491     DEBUG_ONLY(Node* old_control = control();)
 492     Node* slow_ctl = type_check_receiver(array, speculative_array_type, 1.0, &casted_array);
 493     if (stopped()) {
 494       // The check always fails and therefore profile information is incorrect. Don't use it.
 495       assert(old_control == slow_ctl, "type check should have been removed");
 496       set_control(slow_ctl);
 497     } else if (!slow_ctl->is_top()) {
 498       { PreserveJVMState pjvms(this);
 499         set_control(slow_ctl);
 500         uncommon_trap_exact(reason, Deoptimization::Action_maybe_recompile);
 501       }
 502       replace_in_map(array, casted_array);
 503       array_type = _gvn.type(casted_array)->is_aryptr();
 504       element_type = array_type->elem();
 505       return casted_array;
 506     }
 507   }
 508   return array;
 509 }
 510 
 511 // Create a CheckCastPP when the speculative type can improve the current type.
 512 Node* Parse::cast_to_profiled_array_type(Node* const array) {
 513   ciKlass* array_type = nullptr;
 514   ciKlass* element_type = nullptr;
 515   ProfilePtrKind element_ptr = ProfileMaybeNull;
 516   bool flat_array = true;
 517   bool null_free_array = true;
 518   method()->array_access_profiled_type(bci(), array_type, element_type, element_ptr, flat_array, null_free_array);
 519   if (array_type != nullptr) {
 520     return record_profile_for_speculation(array, array_type, ProfileMaybeNull);
 521   }
 522   return array;
 523 }
 524 
 525 // Speculate that the array is non-null-free. We emit a trap when this turns out to be
 526 // wrong. On the fast path, we add a CheckCastPP to use the non-null-free type.
 527 Node* Parse::speculate_non_null_free_array(Node* const array, const TypeAryPtr*& array_type) {
 528   bool null_free_array = true;
 529   Deoptimization::DeoptReason reason = Deoptimization::Reason_none;
 530   if (array_type->speculative() != nullptr &&
 531       array_type->speculative()->is_aryptr()->is_not_null_free() &&
 532       !too_many_traps_or_recompiles(Deoptimization::Reason_speculate_class_check)) {
 533     null_free_array = false;
 534     reason = Deoptimization::Reason_speculate_class_check;
 535   } else if (UseArrayLoadStoreProfile && !too_many_traps_or_recompiles(Deoptimization::Reason_class_check)) {
 536     ciKlass* profiled_array_type = nullptr;
 537     ciKlass* profiled_element_type = nullptr;
 538     ProfilePtrKind element_ptr = ProfileMaybeNull;
 539     bool flat_array = true;
 540     method()->array_access_profiled_type(bci(), profiled_array_type, profiled_element_type, element_ptr, flat_array,
 541                                          null_free_array);
 542     reason = Deoptimization::Reason_class_check;
 543   }
 544   if (!null_free_array) {
 545     { // Deoptimize if null-free array
 546       BuildCutout unless(this, null_free_array_test(array, /* null_free = */ false), PROB_MAX);
 547       uncommon_trap_exact(reason, Deoptimization::Action_maybe_recompile);
 548     }
 549     assert(!stopped(), "null-free array should have been caught earlier");
 550     Node* casted_array = _gvn.transform(new CheckCastPPNode(control(), array, array_type->cast_to_not_null_free()));
 551     replace_in_map(array, casted_array);
 552     array_type = _gvn.type(casted_array)->is_aryptr();
 553     return casted_array;
 554   }
 555   return array;
 556 }
 557 
 558 // Speculate that the array is non-flat. We emit a trap when this turns out to be wrong.
 559 // On the fast path, we add a CheckCastPP to use the non-flat type.
 560 Node* Parse::speculate_non_flat_array(Node* const array, const TypeAryPtr* const array_type) {
 561   bool flat_array = true;
 562   Deoptimization::DeoptReason reason = Deoptimization::Reason_none;
 563   if (array_type->speculative() != nullptr &&
 564       array_type->speculative()->is_aryptr()->is_not_flat() &&
 565       !too_many_traps_or_recompiles(Deoptimization::Reason_speculate_class_check)) {
 566     flat_array = false;
 567     reason = Deoptimization::Reason_speculate_class_check;
 568   } else if (UseArrayLoadStoreProfile && !too_many_traps_or_recompiles(reason)) {
 569     ciKlass* profiled_array_type = nullptr;
 570     ciKlass* profiled_element_type = nullptr;
 571     ProfilePtrKind element_ptr = ProfileMaybeNull;
 572     bool null_free_array = true;
 573     method()->array_access_profiled_type(bci(), profiled_array_type, profiled_element_type, element_ptr, flat_array,
 574                                          null_free_array);
 575     reason = Deoptimization::Reason_class_check;
 576   }
 577   if (!flat_array) {
 578     { // Deoptimize if flat array
 579       BuildCutout unless(this, flat_array_test(array, /* flat = */ false), PROB_MAX);
 580       uncommon_trap_exact(reason, Deoptimization::Action_maybe_recompile);
 581     }
 582     assert(!stopped(), "flat array should have been caught earlier");
 583     Node* casted_array = _gvn.transform(new CheckCastPPNode(control(), array, array_type->cast_to_not_flat()));
 584     replace_in_map(array, casted_array);
 585     return casted_array;
 586   }
 587   return array;
 588 }
 589 
 590 // returns IfNode
 591 IfNode* Parse::jump_if_fork_int(Node* a, Node* b, BoolTest::mask mask, float prob, float cnt) {
 592   Node   *cmp = _gvn.transform(new CmpINode(a, b)); // two cases: shiftcount > 32 and shiftcount <= 32
 593   Node   *tst = _gvn.transform(new BoolNode(cmp, mask));
 594   IfNode *iff = create_and_map_if(control(), tst, prob, cnt);
 595   return iff;
 596 }
 597 
 598 
 599 // sentinel value for the target bci to mark never taken branches
 600 // (according to profiling)
 601 static const int never_reached = INT_MAX;
 602 
 603 //------------------------------helper for tableswitch-------------------------
 604 void Parse::jump_if_true_fork(IfNode *iff, int dest_bci_if_true, bool unc) {
 605   // True branch, use existing map info
 606   { PreserveJVMState pjvms(this);
 607     Node *iftrue  = _gvn.transform( new IfTrueNode (iff) );
 608     set_control( iftrue );
 609     if (unc) {
 610       repush_if_args();
 611       uncommon_trap(Deoptimization::Reason_unstable_if,
 612                     Deoptimization::Action_reinterpret,
 613                     nullptr,
 614                     "taken always");
 615     } else {
 616       assert(dest_bci_if_true != never_reached, "inconsistent dest");
 617       merge_new_path(dest_bci_if_true);
 618     }
 619   }
 620 
 621   // False branch
 622   Node *iffalse = _gvn.transform( new IfFalseNode(iff) );
 623   set_control( iffalse );
 624 }
 625 
 626 void Parse::jump_if_false_fork(IfNode *iff, int dest_bci_if_true, bool unc) {
 627   // True branch, use existing map info
 628   { PreserveJVMState pjvms(this);
 629     Node *iffalse  = _gvn.transform( new IfFalseNode (iff) );
 630     set_control( iffalse );
 631     if (unc) {
 632       repush_if_args();
 633       uncommon_trap(Deoptimization::Reason_unstable_if,
 634                     Deoptimization::Action_reinterpret,
 635                     nullptr,
 636                     "taken never");
 637     } else {
 638       assert(dest_bci_if_true != never_reached, "inconsistent dest");
 639       merge_new_path(dest_bci_if_true);
 640     }
 641   }
 642 
 643   // False branch
 644   Node *iftrue = _gvn.transform( new IfTrueNode(iff) );
 645   set_control( iftrue );
 646 }
 647 
 648 void Parse::jump_if_always_fork(int dest_bci, bool unc) {
 649   // False branch, use existing map and control()
 650   if (unc) {
 651     repush_if_args();
 652     uncommon_trap(Deoptimization::Reason_unstable_if,
 653                   Deoptimization::Action_reinterpret,
 654                   nullptr,
 655                   "taken never");
 656   } else {
 657     assert(dest_bci != never_reached, "inconsistent dest");
 658     merge_new_path(dest_bci);
 659   }
 660 }
 661 
 662 
 663 extern "C" {
 664   static int jint_cmp(const void *i, const void *j) {
 665     int a = *(jint *)i;
 666     int b = *(jint *)j;
 667     return a > b ? 1 : a < b ? -1 : 0;
 668   }
 669 }
 670 
 671 
 672 class SwitchRange : public StackObj {
 673   // a range of integers coupled with a bci destination
 674   jint _lo;                     // inclusive lower limit
 675   jint _hi;                     // inclusive upper limit
 676   int _dest;
 677   float _cnt;                   // how many times this range was hit according to profiling
 678 
 679 public:
 680   jint lo() const              { return _lo;   }
 681   jint hi() const              { return _hi;   }
 682   int  dest() const            { return _dest; }
 683   bool is_singleton() const    { return _lo == _hi; }
 684   float cnt() const            { return _cnt; }
 685 
 686   void setRange(jint lo, jint hi, int dest, float cnt) {
 687     assert(lo <= hi, "must be a non-empty range");
 688     _lo = lo, _hi = hi; _dest = dest; _cnt = cnt;
 689     assert(_cnt >= 0, "");
 690   }
 691   bool adjoinRange(jint lo, jint hi, int dest, float cnt, bool trim_ranges) {
 692     assert(lo <= hi, "must be a non-empty range");
 693     if (lo == _hi+1) {
 694       // see merge_ranges() comment below
 695       if (trim_ranges) {
 696         if (cnt == 0) {
 697           if (_cnt != 0) {
 698             return false;
 699           }
 700           if (dest != _dest) {
 701             _dest = never_reached;
 702           }
 703         } else {
 704           if (_cnt == 0) {
 705             return false;
 706           }
 707           if (dest != _dest) {
 708             return false;
 709           }
 710         }
 711       } else {
 712         if (dest != _dest) {
 713           return false;
 714         }
 715       }
 716       _hi = hi;
 717       _cnt += cnt;
 718       return true;
 719     }
 720     return false;
 721   }
 722 
 723   void set (jint value, int dest, float cnt) {
 724     setRange(value, value, dest, cnt);
 725   }
 726   bool adjoin(jint value, int dest, float cnt, bool trim_ranges) {
 727     return adjoinRange(value, value, dest, cnt, trim_ranges);
 728   }
 729   bool adjoin(SwitchRange& other) {
 730     return adjoinRange(other._lo, other._hi, other._dest, other._cnt, false);
 731   }
 732 
 733   void print() {
 734     if (is_singleton())
 735       tty->print(" {%d}=>%d (cnt=%f)", lo(), dest(), cnt());
 736     else if (lo() == min_jint)
 737       tty->print(" {..%d}=>%d (cnt=%f)", hi(), dest(), cnt());
 738     else if (hi() == max_jint)
 739       tty->print(" {%d..}=>%d (cnt=%f)", lo(), dest(), cnt());
 740     else
 741       tty->print(" {%d..%d}=>%d (cnt=%f)", lo(), hi(), dest(), cnt());
 742   }
 743 };
 744 
 745 // We try to minimize the number of ranges and the size of the taken
 746 // ones using profiling data. When ranges are created,
 747 // SwitchRange::adjoinRange() only allows 2 adjoining ranges to merge
 748 // if both were never hit or both were hit to build longer unreached
 749 // ranges. Here, we now merge adjoining ranges with the same
 750 // destination and finally set destination of unreached ranges to the
 751 // special value never_reached because it can help minimize the number
 752 // of tests that are necessary.
 753 //
 754 // For instance:
 755 // [0, 1] to target1 sometimes taken
 756 // [1, 2] to target1 never taken
 757 // [2, 3] to target2 never taken
 758 // would lead to:
 759 // [0, 1] to target1 sometimes taken
 760 // [1, 3] never taken
 761 //
 762 // (first 2 ranges to target1 are not merged)
 763 static void merge_ranges(SwitchRange* ranges, int& rp) {
 764   if (rp == 0) {
 765     return;
 766   }
 767   int shift = 0;
 768   for (int j = 0; j < rp; j++) {
 769     SwitchRange& r1 = ranges[j-shift];
 770     SwitchRange& r2 = ranges[j+1];
 771     if (r1.adjoin(r2)) {
 772       shift++;
 773     } else if (shift > 0) {
 774       ranges[j+1-shift] = r2;
 775     }
 776   }
 777   rp -= shift;
 778   for (int j = 0; j <= rp; j++) {
 779     SwitchRange& r = ranges[j];
 780     if (r.cnt() == 0 && r.dest() != never_reached) {
 781       r.setRange(r.lo(), r.hi(), never_reached, r.cnt());
 782     }
 783   }
 784 }
 785 
 786 //-------------------------------do_tableswitch--------------------------------
 787 void Parse::do_tableswitch() {
 788   // Get information about tableswitch
 789   int default_dest = iter().get_dest_table(0);
 790   jint lo_index    = iter().get_int_table(1);
 791   jint hi_index    = iter().get_int_table(2);
 792   int len          = hi_index - lo_index + 1;
 793 
 794   if (len < 1) {
 795     // If this is a backward branch, add safepoint
 796     maybe_add_safepoint(default_dest);
 797     pop(); // the effect of the instruction execution on the operand stack
 798     merge(default_dest);
 799     return;
 800   }
 801 
 802   ciMethodData* methodData = method()->method_data();
 803   ciMultiBranchData* profile = nullptr;
 804   if (methodData->is_mature() && UseSwitchProfiling) {
 805     ciProfileData* data = methodData->bci_to_data(bci());
 806     if (data != nullptr && data->is_MultiBranchData()) {
 807       profile = (ciMultiBranchData*)data;
 808     }
 809   }
 810   bool trim_ranges = !C->too_many_traps(method(), bci(), Deoptimization::Reason_unstable_if);
 811 
 812   // generate decision tree, using trichotomy when possible
 813   int rnum = len+2;
 814   bool makes_backward_branch = (default_dest <= bci());
 815   SwitchRange* ranges = NEW_RESOURCE_ARRAY(SwitchRange, rnum);
 816   int rp = -1;
 817   if (lo_index != min_jint) {
 818     float cnt = 1.0F;
 819     if (profile != nullptr) {
 820       cnt = (float)profile->default_count() / (hi_index != max_jint ? 2.0F : 1.0F);
 821     }
 822     ranges[++rp].setRange(min_jint, lo_index-1, default_dest, cnt);
 823   }
 824   for (int j = 0; j < len; j++) {
 825     jint match_int = lo_index+j;
 826     int  dest      = iter().get_dest_table(j+3);
 827     makes_backward_branch |= (dest <= bci());
 828     float cnt = 1.0F;
 829     if (profile != nullptr) {
 830       cnt = (float)profile->count_at(j);
 831     }
 832     if (rp < 0 || !ranges[rp].adjoin(match_int, dest, cnt, trim_ranges)) {
 833       ranges[++rp].set(match_int, dest, cnt);
 834     }
 835   }
 836   jint highest = lo_index+(len-1);
 837   assert(ranges[rp].hi() == highest, "");
 838   if (highest != max_jint) {
 839     float cnt = 1.0F;
 840     if (profile != nullptr) {
 841       cnt = (float)profile->default_count() / (lo_index != min_jint ? 2.0F : 1.0F);
 842     }
 843     if (!ranges[rp].adjoinRange(highest+1, max_jint, default_dest, cnt, trim_ranges)) {
 844       ranges[++rp].setRange(highest+1, max_jint, default_dest, cnt);
 845     }
 846   }
 847   assert(rp < len+2, "not too many ranges");
 848 
 849   if (trim_ranges) {
 850     merge_ranges(ranges, rp);
 851   }
 852 
 853   // Safepoint in case if backward branch observed
 854   if (makes_backward_branch) {
 855     add_safepoint();
 856   }
 857 
 858   Node* lookup = pop(); // lookup value
 859   jump_switch_ranges(lookup, &ranges[0], &ranges[rp]);
 860 }
 861 
 862 
 863 //------------------------------do_lookupswitch--------------------------------
 864 void Parse::do_lookupswitch() {
 865   // Get information about lookupswitch
 866   int default_dest = iter().get_dest_table(0);
 867   jint len          = iter().get_int_table(1);
 868 
 869   if (len < 1) {    // If this is a backward branch, add safepoint
 870     maybe_add_safepoint(default_dest);
 871     pop(); // the effect of the instruction execution on the operand stack
 872     merge(default_dest);
 873     return;
 874   }
 875 
 876   ciMethodData* methodData = method()->method_data();
 877   ciMultiBranchData* profile = nullptr;
 878   if (methodData->is_mature() && UseSwitchProfiling) {
 879     ciProfileData* data = methodData->bci_to_data(bci());
 880     if (data != nullptr && data->is_MultiBranchData()) {
 881       profile = (ciMultiBranchData*)data;
 882     }
 883   }
 884   bool trim_ranges = !C->too_many_traps(method(), bci(), Deoptimization::Reason_unstable_if);
 885 
 886   // generate decision tree, using trichotomy when possible
 887   jint* table = NEW_RESOURCE_ARRAY(jint, len*3);
 888   {
 889     for (int j = 0; j < len; j++) {
 890       table[3*j+0] = iter().get_int_table(2+2*j);
 891       table[3*j+1] = iter().get_dest_table(2+2*j+1);
 892       // Handle overflow when converting from uint to jint
 893       table[3*j+2] = (profile == nullptr) ? 1 : (jint)MIN2<uint>((uint)max_jint, profile->count_at(j));
 894     }
 895     qsort(table, len, 3*sizeof(table[0]), jint_cmp);
 896   }
 897 
 898   float default_cnt = 1.0F;
 899   if (profile != nullptr) {
 900     juint defaults = max_juint - len;
 901     default_cnt = (float)profile->default_count()/(float)defaults;
 902   }
 903 
 904   int rnum = len*2+1;
 905   bool makes_backward_branch = (default_dest <= bci());
 906   SwitchRange* ranges = NEW_RESOURCE_ARRAY(SwitchRange, rnum);
 907   int rp = -1;
 908   for (int j = 0; j < len; j++) {
 909     jint match_int   = table[3*j+0];
 910     jint  dest        = table[3*j+1];
 911     jint  cnt         = table[3*j+2];
 912     jint  next_lo     = rp < 0 ? min_jint : ranges[rp].hi()+1;
 913     makes_backward_branch |= (dest <= bci());
 914     float c = default_cnt * ((float)match_int - (float)next_lo);
 915     if (match_int != next_lo && (rp < 0 || !ranges[rp].adjoinRange(next_lo, match_int-1, default_dest, c, trim_ranges))) {
 916       assert(default_dest != never_reached, "sentinel value for dead destinations");
 917       ranges[++rp].setRange(next_lo, match_int-1, default_dest, c);
 918     }
 919     if (rp < 0 || !ranges[rp].adjoin(match_int, dest, (float)cnt, trim_ranges)) {
 920       assert(dest != never_reached, "sentinel value for dead destinations");
 921       ranges[++rp].set(match_int, dest,  (float)cnt);
 922     }
 923   }
 924   jint highest = table[3*(len-1)];
 925   assert(ranges[rp].hi() == highest, "");
 926   if (highest != max_jint &&
 927       !ranges[rp].adjoinRange(highest+1, max_jint, default_dest, default_cnt * ((float)max_jint - (float)highest), trim_ranges)) {
 928     ranges[++rp].setRange(highest+1, max_jint, default_dest, default_cnt * ((float)max_jint - (float)highest));
 929   }
 930   assert(rp < rnum, "not too many ranges");
 931 
 932   if (trim_ranges) {
 933     merge_ranges(ranges, rp);
 934   }
 935 
 936   // Safepoint in case backward branch observed
 937   if (makes_backward_branch) {
 938     add_safepoint();
 939   }
 940 
 941   Node *lookup = pop(); // lookup value
 942   jump_switch_ranges(lookup, &ranges[0], &ranges[rp]);
 943 }
 944 
 945 static float if_prob(float taken_cnt, float total_cnt) {
 946   assert(taken_cnt <= total_cnt, "");
 947   if (total_cnt == 0) {
 948     return PROB_FAIR;
 949   }
 950   float p = taken_cnt / total_cnt;
 951   return clamp(p, PROB_MIN, PROB_MAX);
 952 }
 953 
 954 static float if_cnt(float cnt) {
 955   if (cnt == 0) {
 956     return COUNT_UNKNOWN;
 957   }
 958   return cnt;
 959 }
 960 
 961 static float sum_of_cnts(SwitchRange *lo, SwitchRange *hi) {
 962   float total_cnt = 0;
 963   for (SwitchRange* sr = lo; sr <= hi; sr++) {
 964     total_cnt += sr->cnt();
 965   }
 966   return total_cnt;
 967 }
 968 
 969 class SwitchRanges : public ResourceObj {
 970 public:
 971   SwitchRange* _lo;
 972   SwitchRange* _hi;
 973   SwitchRange* _mid;
 974   float _cost;
 975 
 976   enum {
 977     Start,
 978     LeftDone,
 979     RightDone,
 980     Done
 981   } _state;
 982 
 983   SwitchRanges(SwitchRange *lo, SwitchRange *hi)
 984     : _lo(lo), _hi(hi), _mid(nullptr),
 985       _cost(0), _state(Start) {
 986   }
 987 
 988   SwitchRanges()
 989     : _lo(nullptr), _hi(nullptr), _mid(nullptr),
 990       _cost(0), _state(Start) {}
 991 };
 992 
 993 // Estimate cost of performing a binary search on lo..hi
 994 static float compute_tree_cost(SwitchRange *lo, SwitchRange *hi, float total_cnt) {
 995   GrowableArray<SwitchRanges> tree;
 996   SwitchRanges root(lo, hi);
 997   tree.push(root);
 998 
 999   float cost = 0;
1000   do {
1001     SwitchRanges& r = *tree.adr_at(tree.length()-1);
1002     if (r._hi != r._lo) {
1003       if (r._mid == nullptr) {
1004         float r_cnt = sum_of_cnts(r._lo, r._hi);
1005 
1006         if (r_cnt == 0) {
1007           tree.pop();
1008           cost = 0;
1009           continue;
1010         }
1011 
1012         SwitchRange* mid = nullptr;
1013         mid = r._lo;
1014         for (float cnt = 0; ; ) {
1015           assert(mid <= r._hi, "out of bounds");
1016           cnt += mid->cnt();
1017           if (cnt > r_cnt / 2) {
1018             break;
1019           }
1020           mid++;
1021         }
1022         assert(mid <= r._hi, "out of bounds");
1023         r._mid = mid;
1024         r._cost = r_cnt / total_cnt;
1025       }
1026       r._cost += cost;
1027       if (r._state < SwitchRanges::LeftDone && r._mid > r._lo) {
1028         cost = 0;
1029         r._state = SwitchRanges::LeftDone;
1030         tree.push(SwitchRanges(r._lo, r._mid-1));
1031       } else if (r._state < SwitchRanges::RightDone) {
1032         cost = 0;
1033         r._state = SwitchRanges::RightDone;
1034         tree.push(SwitchRanges(r._mid == r._lo ? r._mid+1 : r._mid, r._hi));
1035       } else {
1036         tree.pop();
1037         cost = r._cost;
1038       }
1039     } else {
1040       tree.pop();
1041       cost = r._cost;
1042     }
1043   } while (tree.length() > 0);
1044 
1045 
1046   return cost;
1047 }
1048 
1049 // It sometimes pays off to test most common ranges before the binary search
1050 void Parse::linear_search_switch_ranges(Node* key_val, SwitchRange*& lo, SwitchRange*& hi) {
1051   uint nr = hi - lo + 1;
1052   float total_cnt = sum_of_cnts(lo, hi);
1053 
1054   float min = compute_tree_cost(lo, hi, total_cnt);
1055   float extra = 1;
1056   float sub = 0;
1057 
1058   SwitchRange* array1 = lo;
1059   SwitchRange* array2 = NEW_RESOURCE_ARRAY(SwitchRange, nr);
1060 
1061   SwitchRange* ranges = nullptr;
1062 
1063   while (nr >= 2) {
1064     assert(lo == array1 || lo == array2, "one the 2 already allocated arrays");
1065     ranges = (lo == array1) ? array2 : array1;
1066 
1067     // Find highest frequency range
1068     SwitchRange* candidate = lo;
1069     for (SwitchRange* sr = lo+1; sr <= hi; sr++) {
1070       if (sr->cnt() > candidate->cnt()) {
1071         candidate = sr;
1072       }
1073     }
1074     SwitchRange most_freq = *candidate;
1075     if (most_freq.cnt() == 0) {
1076       break;
1077     }
1078 
1079     // Copy remaining ranges into another array
1080     int shift = 0;
1081     for (uint i = 0; i < nr; i++) {
1082       SwitchRange* sr = &lo[i];
1083       if (sr != candidate) {
1084         ranges[i-shift] = *sr;
1085       } else {
1086         shift++;
1087         if (i > 0 && i < nr-1) {
1088           SwitchRange prev = lo[i-1];
1089           prev.setRange(prev.lo(), sr->hi(), prev.dest(), prev.cnt());
1090           if (prev.adjoin(lo[i+1])) {
1091             shift++;
1092             i++;
1093           }
1094           ranges[i-shift] = prev;
1095         }
1096       }
1097     }
1098     nr -= shift;
1099 
1100     // Evaluate cost of testing the most common range and performing a
1101     // binary search on the other ranges
1102     float cost = extra + compute_tree_cost(&ranges[0], &ranges[nr-1], total_cnt);
1103     if (cost >= min) {
1104       break;
1105     }
1106     // swap arrays
1107     lo = &ranges[0];
1108     hi = &ranges[nr-1];
1109 
1110     // It pays off: emit the test for the most common range
1111     assert(most_freq.cnt() > 0, "must be taken");
1112     Node* val = _gvn.transform(new SubINode(key_val, _gvn.intcon(most_freq.lo())));
1113     Node* cmp = _gvn.transform(new CmpUNode(val, _gvn.intcon(java_subtract(most_freq.hi(), most_freq.lo()))));
1114     Node* tst = _gvn.transform(new BoolNode(cmp, BoolTest::le));
1115     IfNode* iff = create_and_map_if(control(), tst, if_prob(most_freq.cnt(), total_cnt), if_cnt(most_freq.cnt()));
1116     jump_if_true_fork(iff, most_freq.dest(), false);
1117 
1118     sub += most_freq.cnt() / total_cnt;
1119     extra += 1 - sub;
1120     min = cost;
1121   }
1122 }
1123 
1124 //----------------------------create_jump_tables-------------------------------
1125 bool Parse::create_jump_tables(Node* key_val, SwitchRange* lo, SwitchRange* hi) {
1126   // Are jumptables enabled
1127   if (!UseJumpTables)  return false;
1128 
1129   // Are jumptables supported
1130   if (!Matcher::has_match_rule(Op_Jump))  return false;
1131 
1132   bool trim_ranges = !C->too_many_traps(method(), bci(), Deoptimization::Reason_unstable_if);
1133 
1134   // Decide if a guard is needed to lop off big ranges at either (or
1135   // both) end(s) of the input set. We'll call this the default target
1136   // even though we can't be sure that it is the true "default".
1137 
1138   bool needs_guard = false;
1139   int default_dest;
1140   int64_t total_outlier_size = 0;
1141   int64_t hi_size = ((int64_t)hi->hi()) - ((int64_t)hi->lo()) + 1;
1142   int64_t lo_size = ((int64_t)lo->hi()) - ((int64_t)lo->lo()) + 1;
1143 
1144   if (lo->dest() == hi->dest()) {
1145     total_outlier_size = hi_size + lo_size;
1146     default_dest = lo->dest();
1147   } else if (lo_size > hi_size) {
1148     total_outlier_size = lo_size;
1149     default_dest = lo->dest();
1150   } else {
1151     total_outlier_size = hi_size;
1152     default_dest = hi->dest();
1153   }
1154 
1155   float total = sum_of_cnts(lo, hi);
1156   float cost = compute_tree_cost(lo, hi, total);
1157 
1158   // If a guard test will eliminate very sparse end ranges, then
1159   // it is worth the cost of an extra jump.
1160   float trimmed_cnt = 0;
1161   if (total_outlier_size > (MaxJumpTableSparseness * 4)) {
1162     needs_guard = true;
1163     if (default_dest == lo->dest()) {
1164       trimmed_cnt += lo->cnt();
1165       lo++;
1166     }
1167     if (default_dest == hi->dest()) {
1168       trimmed_cnt += hi->cnt();
1169       hi--;
1170     }
1171   }
1172 
1173   // Find the total number of cases and ranges
1174   int64_t num_cases = ((int64_t)hi->hi()) - ((int64_t)lo->lo()) + 1;
1175   int num_range = hi - lo + 1;
1176 
1177   // Don't create table if: too large, too small, or too sparse.
1178   if (num_cases > MaxJumpTableSize)
1179     return false;
1180   if (UseSwitchProfiling) {
1181     // MinJumpTableSize is set so with a well balanced binary tree,
1182     // when the number of ranges is MinJumpTableSize, it's cheaper to
1183     // go through a JumpNode that a tree of IfNodes. Average cost of a
1184     // tree of IfNodes with MinJumpTableSize is
1185     // log2f(MinJumpTableSize) comparisons. So if the cost computed
1186     // from profile data is less than log2f(MinJumpTableSize) then
1187     // going with the binary search is cheaper.
1188     if (cost < log2f(MinJumpTableSize)) {
1189       return false;
1190     }
1191   } else {
1192     if (num_cases < MinJumpTableSize)
1193       return false;
1194   }
1195   if (num_cases > (MaxJumpTableSparseness * num_range))
1196     return false;
1197 
1198   // Normalize table lookups to zero
1199   int lowval = lo->lo();
1200   key_val = _gvn.transform( new SubINode(key_val, _gvn.intcon(lowval)) );
1201 
1202   // Generate a guard to protect against input keyvals that aren't
1203   // in the switch domain.
1204   if (needs_guard) {
1205     Node*   size = _gvn.intcon(num_cases);
1206     Node*   cmp = _gvn.transform(new CmpUNode(key_val, size));
1207     Node*   tst = _gvn.transform(new BoolNode(cmp, BoolTest::ge));
1208     IfNode* iff = create_and_map_if(control(), tst, if_prob(trimmed_cnt, total), if_cnt(trimmed_cnt));
1209     jump_if_true_fork(iff, default_dest, trim_ranges && trimmed_cnt == 0);
1210 
1211     total -= trimmed_cnt;
1212   }
1213 
1214   // Create an ideal node JumpTable that has projections
1215   // of all possible ranges for a switch statement
1216   // The key_val input must be converted to a pointer offset and scaled.
1217   // Compare Parse::array_addressing above.
1218 
1219   // Clean the 32-bit int into a real 64-bit offset.
1220   // Otherwise, the jint value 0 might turn into an offset of 0x0800000000.
1221   // Make I2L conversion control dependent to prevent it from
1222   // floating above the range check during loop optimizations.
1223   // Do not use a narrow int type here to prevent the data path from dying
1224   // while the control path is not removed. This can happen if the type of key_val
1225   // is later known to be out of bounds of [0, num_cases] and therefore a narrow cast
1226   // would be replaced by TOP while C2 is not able to fold the corresponding range checks.
1227   // Set _carry_dependency for the cast to avoid being removed by IGVN.
1228 #ifdef _LP64
1229   key_val = C->constrained_convI2L(&_gvn, key_val, TypeInt::INT, control(), true /* carry_dependency */);
1230 #endif
1231 
1232   // Shift the value by wordsize so we have an index into the table, rather
1233   // than a switch value
1234   Node *shiftWord = _gvn.MakeConX(wordSize);
1235   key_val = _gvn.transform( new MulXNode( key_val, shiftWord));
1236 
1237   // Create the JumpNode
1238   Arena* arena = C->comp_arena();
1239   float* probs = (float*)arena->Amalloc(sizeof(float)*num_cases);
1240   int i = 0;
1241   if (total == 0) {
1242     for (SwitchRange* r = lo; r <= hi; r++) {
1243       for (int64_t j = r->lo(); j <= r->hi(); j++, i++) {
1244         probs[i] = 1.0F / num_cases;
1245       }
1246     }
1247   } else {
1248     for (SwitchRange* r = lo; r <= hi; r++) {
1249       float prob = r->cnt()/total;
1250       for (int64_t j = r->lo(); j <= r->hi(); j++, i++) {
1251         probs[i] = prob / (r->hi() - r->lo() + 1);
1252       }
1253     }
1254   }
1255 
1256   ciMethodData* methodData = method()->method_data();
1257   ciMultiBranchData* profile = nullptr;
1258   if (methodData->is_mature()) {
1259     ciProfileData* data = methodData->bci_to_data(bci());
1260     if (data != nullptr && data->is_MultiBranchData()) {
1261       profile = (ciMultiBranchData*)data;
1262     }
1263   }
1264 
1265   Node* jtn = _gvn.transform(new JumpNode(control(), key_val, num_cases, probs, profile == nullptr ? COUNT_UNKNOWN : total));
1266 
1267   // These are the switch destinations hanging off the jumpnode
1268   i = 0;
1269   for (SwitchRange* r = lo; r <= hi; r++) {
1270     for (int64_t j = r->lo(); j <= r->hi(); j++, i++) {
1271       Node* input = _gvn.transform(new JumpProjNode(jtn, i, r->dest(), (int)(j - lowval)));
1272       {
1273         PreserveJVMState pjvms(this);
1274         set_control(input);
1275         jump_if_always_fork(r->dest(), trim_ranges && r->cnt() == 0);
1276       }
1277     }
1278   }
1279   assert(i == num_cases, "miscount of cases");
1280   stop_and_kill_map();  // no more uses for this JVMS
1281   return true;
1282 }
1283 
1284 //----------------------------jump_switch_ranges-------------------------------
1285 void Parse::jump_switch_ranges(Node* key_val, SwitchRange *lo, SwitchRange *hi, int switch_depth) {
1286   Block* switch_block = block();
1287   bool trim_ranges = !C->too_many_traps(method(), bci(), Deoptimization::Reason_unstable_if);
1288 
1289   if (switch_depth == 0) {
1290     // Do special processing for the top-level call.
1291     assert(lo->lo() == min_jint, "initial range must exhaust Type::INT");
1292     assert(hi->hi() == max_jint, "initial range must exhaust Type::INT");
1293 
1294     // Decrement pred-numbers for the unique set of nodes.
1295 #ifdef ASSERT
1296     if (!trim_ranges) {
1297       // Ensure that the block's successors are a (duplicate-free) set.
1298       int successors_counted = 0;  // block occurrences in [hi..lo]
1299       int unique_successors = switch_block->num_successors();
1300       for (int i = 0; i < unique_successors; i++) {
1301         Block* target = switch_block->successor_at(i);
1302 
1303         // Check that the set of successors is the same in both places.
1304         int successors_found = 0;
1305         for (SwitchRange* p = lo; p <= hi; p++) {
1306           if (p->dest() == target->start())  successors_found++;
1307         }
1308         assert(successors_found > 0, "successor must be known");
1309         successors_counted += successors_found;
1310       }
1311       assert(successors_counted == (hi-lo)+1, "no unexpected successors");
1312     }
1313 #endif
1314 
1315     // Maybe prune the inputs, based on the type of key_val.
1316     jint min_val = min_jint;
1317     jint max_val = max_jint;
1318     const TypeInt* ti = key_val->bottom_type()->isa_int();
1319     if (ti != nullptr) {
1320       min_val = ti->_lo;
1321       max_val = ti->_hi;
1322       assert(min_val <= max_val, "invalid int type");
1323     }
1324     while (lo->hi() < min_val) {
1325       lo++;
1326     }
1327     if (lo->lo() < min_val)  {
1328       lo->setRange(min_val, lo->hi(), lo->dest(), lo->cnt());
1329     }
1330     while (hi->lo() > max_val) {
1331       hi--;
1332     }
1333     if (hi->hi() > max_val) {
1334       hi->setRange(hi->lo(), max_val, hi->dest(), hi->cnt());
1335     }
1336 
1337     linear_search_switch_ranges(key_val, lo, hi);
1338   }
1339 
1340 #ifndef PRODUCT
1341   if (switch_depth == 0) {
1342     _max_switch_depth = 0;
1343     _est_switch_depth = log2i_graceful((hi - lo + 1) - 1) + 1;
1344   }
1345   SwitchRange* orig_lo = lo;
1346   SwitchRange* orig_hi = hi;
1347 #endif
1348 
1349   // The lower-range processing is done iteratively to avoid O(N) stack depth
1350   // when the profiling-based pivot repeatedly selects mid==lo (JDK-8366138).
1351   // The upper-range processing remains recursive but is only reached for
1352   // balanced splits, bounding its depth to O(log N).
1353   // Termination: every iteration either exits or strictly decreases hi-lo:
1354   //   lo == mid && mid < hi, increments lo
1355   //   lo < mid <= hi, sets hi = mid - 1.
1356   for (int depth = switch_depth;; depth++) {
1357 #ifndef PRODUCT
1358     _max_switch_depth = MAX2(depth, _max_switch_depth);
1359 #endif
1360 
1361     assert(lo <= hi, "must be a non-empty set of ranges");
1362     if (lo == hi) {
1363       jump_if_always_fork(lo->dest(), trim_ranges && lo->cnt() == 0);
1364       break;
1365     }
1366 
1367     assert(lo->hi() == (lo+1)->lo()-1, "contiguous ranges");
1368     assert(hi->lo() == (hi-1)->hi()+1, "contiguous ranges");
1369 
1370     if (create_jump_tables(key_val, lo, hi)) return;
1371 
1372     SwitchRange* mid = nullptr;
1373     float total_cnt = sum_of_cnts(lo, hi);
1374 
1375     int nr = hi - lo + 1;
1376     // With total_cnt==0 the profiling pivot degenerates to mid==lo
1377     // (0 >= 0/2), producing a linear chain of If nodes instead of a
1378     // balanced tree. A balanced tree is strictly better here: all paths
1379     // are cold, so a balanced split gives fewer comparisons at runtime
1380     // and avoids pathological memory usage in the optimizer.
1381     if (UseSwitchProfiling && total_cnt > 0) {
1382       // Don't keep the binary search tree balanced: pick up mid point
1383       // that split frequencies in half.
1384       float cnt = 0;
1385       for (SwitchRange* sr = lo; sr <= hi; sr++) {
1386         cnt += sr->cnt();
1387         if (cnt >= total_cnt / 2) {
1388           mid = sr;
1389           break;
1390         }
1391       }
1392     } else {
1393       mid = lo + nr/2;
1394 
1395       // if there is an easy choice, pivot at a singleton:
1396       if (nr > 3 && !mid->is_singleton() && (mid-1)->is_singleton())  mid--;
1397 
1398       assert(lo < mid && mid <= hi, "good pivot choice");
1399       assert(nr != 2 || mid == hi,   "should pick higher of 2");
1400       assert(nr != 3 || mid == hi-1, "should pick middle of 3");
1401     }
1402     assert(mid != nullptr, "mid must be set");
1403 
1404     Node *test_val = _gvn.intcon(mid == lo ? mid->hi() : mid->lo());
1405 
1406     if (mid->is_singleton()) {
1407       IfNode *iff_ne = jump_if_fork_int(key_val, test_val, BoolTest::ne, 1-if_prob(mid->cnt(), total_cnt), if_cnt(mid->cnt()));
1408       jump_if_false_fork(iff_ne, mid->dest(), trim_ranges && mid->cnt() == 0);
1409 
1410       // Special Case:  If there are exactly three ranges, and the high
1411       // and low range each go to the same place, omit the "gt" test,
1412       // since it will not discriminate anything.
1413       bool eq_test_only = (hi == lo+2 && hi->dest() == lo->dest() && mid == hi-1) || mid == lo;
1414 
1415       // if there is a higher range, test for it and process it:
1416       if (mid < hi && !eq_test_only) {
1417         // two comparisons of same values--should enable 1 test for 2 branches
1418         // Use BoolTest::lt instead of BoolTest::gt
1419         float cnt = sum_of_cnts(lo, mid-1);
1420         IfNode *iff_lt  = jump_if_fork_int(key_val, test_val, BoolTest::lt, if_prob(cnt, total_cnt), if_cnt(cnt));
1421         Node   *iftrue  = _gvn.transform( new IfTrueNode(iff_lt) );
1422         Node   *iffalse = _gvn.transform( new IfFalseNode(iff_lt) );
1423         { PreserveJVMState pjvms(this);
1424           set_control(iffalse);
1425           jump_switch_ranges(key_val, mid+1, hi, depth+1);
1426         }
1427         set_control(iftrue);
1428       }
1429 
1430     } else {
1431       // mid is a range, not a singleton, so treat mid..hi as a unit
1432       float cnt = sum_of_cnts(mid == lo ? mid+1 : mid, hi);
1433       IfNode *iff_ge = jump_if_fork_int(key_val, test_val, mid == lo ? BoolTest::gt : BoolTest::ge, if_prob(cnt, total_cnt), if_cnt(cnt));
1434 
1435       // if there is a higher range, test for it and process it:
1436       if (mid == hi) {
1437         jump_if_true_fork(iff_ge, mid->dest(), trim_ranges && cnt == 0);
1438       } else {
1439         Node *iftrue  = _gvn.transform( new IfTrueNode(iff_ge) );
1440         Node *iffalse = _gvn.transform( new IfFalseNode(iff_ge) );
1441         { PreserveJVMState pjvms(this);
1442           set_control(iftrue);
1443           jump_switch_ranges(key_val, mid == lo ? mid+1 : mid, hi, depth+1);
1444         }
1445         set_control(iffalse);
1446       }
1447     }
1448 
1449     // Process the lower range: iterate instead of recursing.
1450     if (mid == lo) {
1451       if (mid->is_singleton()) {
1452         lo++;
1453       } else {
1454         jump_if_always_fork(lo->dest(), trim_ranges && lo->cnt() == 0);
1455         break;
1456       }
1457     } else {
1458       hi = mid - 1;
1459     }
1460   }
1461 
1462   // Decrease pred_count for each successor after all is done.
1463   if (switch_depth == 0) {
1464     int unique_successors = switch_block->num_successors();
1465     for (int i = 0; i < unique_successors; i++) {
1466       Block* target = switch_block->successor_at(i);
1467       // Throw away the pre-allocated path for each unique successor.
1468       target->next_path_num();
1469     }
1470   }
1471 
1472 #ifndef PRODUCT
1473   if (TraceOptoParse && Verbose && WizardMode && switch_depth == 0) {
1474     SwitchRange* r;
1475     int nsing = 0;
1476     for (r = orig_lo; r <= orig_hi; r++) {
1477       if( r->is_singleton() )  nsing++;
1478     }
1479     tty->print(">>> ");
1480     _method->print_short_name();
1481     tty->print_cr(" switch decision tree");
1482     tty->print_cr("    %d ranges (%d singletons), max_depth=%d, est_depth=%d",
1483                   (int) (orig_hi-orig_lo+1), nsing, _max_switch_depth, _est_switch_depth);
1484     if (_max_switch_depth > _est_switch_depth) {
1485       tty->print_cr("******** BAD SWITCH DEPTH ********");
1486     }
1487     tty->print("   ");
1488     for (r = orig_lo; r <= orig_hi; r++) {
1489       r->print();
1490     }
1491     tty->cr();
1492   }
1493 #endif
1494 }
1495 
1496 Node* Parse::floating_point_mod(Node* a, Node* b, BasicType type) {
1497   assert(type == BasicType::T_FLOAT || type == BasicType::T_DOUBLE, "only float and double are floating points");
1498   CallLeafPureNode* mod = type == BasicType::T_DOUBLE ? static_cast<CallLeafPureNode*>(new ModDNode(C, a, b)) : new ModFNode(C, a, b);
1499 
1500   set_predefined_input_for_runtime_call(mod);
1501   mod = _gvn.transform(mod)->as_CallLeafPure();
1502   set_predefined_output_for_runtime_call(mod);
1503   Node* result = _gvn.transform(new ProjNode(mod, TypeFunc::Parms + 0));
1504   record_for_igvn(mod);
1505   return result;
1506 }
1507 
1508 void Parse::l2f() {
1509   Node* f2 = pop();
1510   Node* f1 = pop();
1511   Node* c = make_runtime_call(RC_LEAF, OptoRuntime::l2f_Type(),
1512                               CAST_FROM_FN_PTR(address, SharedRuntime::l2f),
1513                               "l2f", nullptr, //no memory effects
1514                               f1, f2);
1515   Node* res = _gvn.transform(new ProjNode(c, TypeFunc::Parms + 0));
1516 
1517   push(res);
1518 }
1519 
1520 // Handle jsr and jsr_w bytecode
1521 void Parse::do_jsr() {
1522   assert(bc() == Bytecodes::_jsr || bc() == Bytecodes::_jsr_w, "wrong bytecode");
1523 
1524   // Store information about current state, tagged with new _jsr_bci
1525   int return_bci = iter().next_bci();
1526   int jsr_bci    = (bc() == Bytecodes::_jsr) ? iter().get_dest() : iter().get_far_dest();
1527 
1528   // The way we do things now, there is only one successor block
1529   // for the jsr, because the target code is cloned by ciTypeFlow.
1530   Block* target = successor_for_bci(jsr_bci);
1531 
1532   // What got pushed?
1533   const Type* ret_addr = target->peek();
1534   assert(ret_addr->singleton(), "must be a constant (cloned jsr body)");
1535 
1536   // Effect on jsr on stack
1537   push(_gvn.makecon(ret_addr));
1538 
1539   // Flow to the jsr.
1540   merge(jsr_bci);
1541 }
1542 
1543 // Handle ret bytecode
1544 void Parse::do_ret() {
1545   // Find to whom we return.
1546   assert(block()->num_successors() == 1, "a ret can only go one place now");
1547   Block* target = block()->successor_at(0);
1548   assert(!target->is_ready(), "our arrival must be expected");
1549   int pnum = target->next_path_num();
1550   merge_common(target, pnum);
1551 }
1552 
1553 static bool has_injected_profile(BoolTest::mask btest, Node* test, int& taken, int& not_taken) {
1554   if (btest != BoolTest::eq && btest != BoolTest::ne) {
1555     // Only ::eq and ::ne are supported for profile injection.
1556     return false;
1557   }
1558   if (test->is_Cmp() &&
1559       test->in(1)->Opcode() == Op_ProfileBoolean) {
1560     ProfileBooleanNode* profile = (ProfileBooleanNode*)test->in(1);
1561     int false_cnt = profile->false_count();
1562     int  true_cnt = profile->true_count();
1563 
1564     // Counts matching depends on the actual test operation (::eq or ::ne).
1565     // No need to scale the counts because profile injection was designed
1566     // to feed exact counts into VM.
1567     taken     = (btest == BoolTest::eq) ? false_cnt :  true_cnt;
1568     not_taken = (btest == BoolTest::eq) ?  true_cnt : false_cnt;
1569 
1570     profile->consume();
1571     return true;
1572   }
1573   return false;
1574 }
1575 
1576 // Give up if too few (or too many, in which case the sum will overflow) counts to be meaningful.
1577 // We also check that individual counters are positive first, otherwise the sum can become positive.
1578 // (check for saturation, integer overflow, and immature counts)
1579 static bool counters_are_meaningful(int counter1, int counter2, int min) {
1580   // check for saturation, including "uint" values too big to fit in "int"
1581   if (counter1 < 0 || counter2 < 0) {
1582     return false;
1583   }
1584   // check for integer overflow of the sum
1585   int64_t sum = (int64_t)counter1 + (int64_t)counter2;
1586   STATIC_ASSERT(sizeof(counter1) < sizeof(sum));
1587   if (sum > INT_MAX) {
1588     return false;
1589   }
1590   // check if mature
1591   return (counter1 + counter2) >= min;
1592 }
1593 
1594 //--------------------------dynamic_branch_prediction--------------------------
1595 // Try to gather dynamic branch prediction behavior.  Return a probability
1596 // of the branch being taken and set the "cnt" field.  Returns a -1.0
1597 // if we need to use static prediction for some reason.
1598 float Parse::dynamic_branch_prediction(float &cnt, BoolTest::mask btest, Node* test) {
1599   ResourceMark rm;
1600 
1601   cnt  = COUNT_UNKNOWN;
1602 
1603   int     taken = 0;
1604   int not_taken = 0;
1605 
1606   bool use_mdo = !has_injected_profile(btest, test, taken, not_taken);
1607 
1608   if (use_mdo) {
1609     // Use MethodData information if it is available
1610     // FIXME: free the ProfileData structure
1611     ciMethodData* methodData = method()->method_data();
1612     if (!methodData->is_mature())  return PROB_UNKNOWN;
1613     ciProfileData* data = methodData->bci_to_data(bci());
1614     if (data == nullptr) {
1615       return PROB_UNKNOWN;
1616     }
1617     if (!data->is_JumpData())  return PROB_UNKNOWN;
1618 
1619     // get taken and not taken values
1620     // NOTE: saturated UINT_MAX values become negative,
1621     // as do counts above INT_MAX.
1622     taken = data->as_JumpData()->taken();
1623     not_taken = 0;
1624     if (data->is_BranchData()) {
1625       not_taken = data->as_BranchData()->not_taken();
1626     }
1627 
1628     // scale the counts to be commensurate with invocation counts:
1629     // NOTE: overflow for positive values is clamped at INT_MAX
1630     taken = method()->scale_count(taken);
1631     not_taken = method()->scale_count(not_taken);
1632   }
1633   // At this point, saturation or overflow is indicated by INT_MAX
1634   // or a negative value.
1635 
1636   // Give up if too few (or too many, in which case the sum will overflow) counts to be meaningful.
1637   // We also check that individual counters are positive first, otherwise the sum can become positive.
1638   if (!counters_are_meaningful(taken, not_taken, 40)) {
1639     if (C->log() != nullptr) {
1640       C->log()->elem("branch target_bci='%d' taken='%d' not_taken='%d'", iter().get_dest(), taken, not_taken);
1641     }
1642     return PROB_UNKNOWN;
1643   }
1644 
1645   // Compute frequency that we arrive here
1646   float sum = taken + not_taken;
1647   // Adjust, if this block is a cloned private block but the
1648   // Jump counts are shared.  Taken the private counts for
1649   // just this path instead of the shared counts.
1650   if( block()->count() > 0 )
1651     sum = block()->count();
1652   cnt = sum / FreqCountInvocations;
1653 
1654   // Pin probability to sane limits
1655   float prob;
1656   if( !taken )
1657     prob = (0+PROB_MIN) / 2;
1658   else if( !not_taken )
1659     prob = (1+PROB_MAX) / 2;
1660   else {                         // Compute probability of true path
1661     prob = (float)taken / (float)(taken + not_taken);
1662     if (prob > PROB_MAX)  prob = PROB_MAX;
1663     if (prob < PROB_MIN)   prob = PROB_MIN;
1664   }
1665 
1666   assert((cnt > 0.0f) && (prob > 0.0f),
1667          "Bad frequency assignment in if cnt=%g prob=%g taken=%d not_taken=%d", cnt, prob, taken, not_taken);
1668 
1669   if (C->log() != nullptr) {
1670     const char* prob_str = nullptr;
1671     if (prob >= PROB_MAX)  prob_str = (prob == PROB_MAX) ? "max" : "always";
1672     if (prob <= PROB_MIN)  prob_str = (prob == PROB_MIN) ? "min" : "never";
1673     char prob_str_buf[30];
1674     if (prob_str == nullptr) {
1675       jio_snprintf(prob_str_buf, sizeof(prob_str_buf), "%20.2f", prob);
1676       prob_str = prob_str_buf;
1677     }
1678     C->log()->elem("branch target_bci='%d' taken='%d' not_taken='%d' cnt='%f' prob='%s'",
1679                    iter().get_dest(), taken, not_taken, cnt, prob_str);
1680   }
1681   return prob;
1682 }
1683 
1684 //-----------------------------branch_prediction-------------------------------
1685 float Parse::branch_prediction(float& cnt,
1686                                BoolTest::mask btest,
1687                                int target_bci,
1688                                Node* test) {
1689   float prob = dynamic_branch_prediction(cnt, btest, test);
1690   // If prob is unknown, switch to static prediction
1691   if (prob != PROB_UNKNOWN)  return prob;
1692 
1693   prob = PROB_FAIR;                   // Set default value
1694   if (btest == BoolTest::eq)          // Exactly equal test?
1695     prob = PROB_STATIC_INFREQUENT;    // Assume its relatively infrequent
1696   else if (btest == BoolTest::ne)
1697     prob = PROB_STATIC_FREQUENT;      // Assume its relatively frequent
1698 
1699   // If this is a conditional test guarding a backwards branch,
1700   // assume its a loop-back edge.  Make it a likely taken branch.
1701   if (target_bci < bci()) {
1702     if (is_osr_parse()) {    // Could be a hot OSR'd loop; force deopt
1703       // Since it's an OSR, we probably have profile data, but since
1704       // branch_prediction returned PROB_UNKNOWN, the counts are too small.
1705       // Let's make a special check here for completely zero counts.
1706       ciMethodData* methodData = method()->method_data();
1707       if (!methodData->is_empty()) {
1708         ciProfileData* data = methodData->bci_to_data(bci());
1709         // Only stop for truly zero counts, which mean an unknown part
1710         // of the OSR-ed method, and we want to deopt to gather more stats.
1711         // If you have ANY counts, then this loop is simply 'cold' relative
1712         // to the OSR loop.
1713         if (data == nullptr ||
1714             (data->as_BranchData()->taken() +  data->as_BranchData()->not_taken() == 0)) {
1715           // This is the only way to return PROB_UNKNOWN:
1716           return PROB_UNKNOWN;
1717         }
1718       }
1719     }
1720     prob = PROB_STATIC_FREQUENT;     // Likely to take backwards branch
1721   }
1722 
1723   assert(prob != PROB_UNKNOWN, "must have some guess at this point");
1724   return prob;
1725 }
1726 
1727 // The magic constants are chosen so as to match the output of
1728 // branch_prediction() when the profile reports a zero taken count.
1729 // It is important to distinguish zero counts unambiguously, because
1730 // some branches (e.g., _213_javac.Assembler.eliminate) validly produce
1731 // very small but nonzero probabilities, which if confused with zero
1732 // counts would keep the program recompiling indefinitely.
1733 bool Parse::seems_never_taken(float prob) const {
1734   return prob < PROB_MIN;
1735 }
1736 
1737 //-------------------------------repush_if_args--------------------------------
1738 // Push arguments of an "if" bytecode back onto the stack by adjusting _sp.
1739 inline int Parse::repush_if_args() {
1740   if (PrintOpto && WizardMode) {
1741     tty->print("defending against excessive implicit null exceptions on %s @%d in ",
1742                Bytecodes::name(iter().cur_bc()), iter().cur_bci());
1743     method()->print_name(); tty->cr();
1744   }
1745   int bc_depth = - Bytecodes::depth(iter().cur_bc());
1746   assert(bc_depth == 1 || bc_depth == 2, "only two kinds of branches");
1747   DEBUG_ONLY(sync_jvms());   // argument(n) requires a synced jvms
1748   assert(argument(0) != nullptr, "must exist");
1749   assert(bc_depth == 1 || argument(1) != nullptr, "two must exist");
1750   inc_sp(bc_depth);
1751   return bc_depth;
1752 }
1753 
1754 // Used by StressUnstableIfTraps
1755 static volatile int _trap_stress_counter = 0;
1756 
1757 void Parse::increment_trap_stress_counter(Node*& counter, Node*& incr_store) {
1758   Node* counter_addr = makecon(TypeRawPtr::make((address)&_trap_stress_counter));
1759   counter = make_load(control(), counter_addr, TypeInt::INT, T_INT, MemNode::unordered);
1760   counter = _gvn.transform(new AddINode(counter, intcon(1)));
1761   incr_store = store_to_memory(control(), counter_addr, counter, T_INT, MemNode::unordered);
1762 }
1763 
1764 //----------------------------------do_ifnull----------------------------------
1765 void Parse::do_ifnull(BoolTest::mask btest, Node *c) {
1766   int target_bci = iter().get_dest();
1767 
1768   Node* counter = nullptr;
1769   Node* incr_store = nullptr;
1770   bool do_stress_trap = StressUnstableIfTraps && ((C->random() % 2) == 0);
1771   if (do_stress_trap) {
1772     increment_trap_stress_counter(counter, incr_store);
1773   }
1774 
1775   Block* branch_block = successor_for_bci(target_bci);
1776   Block* next_block   = successor_for_bci(iter().next_bci());
1777 
1778   float cnt;
1779   float prob = branch_prediction(cnt, btest, target_bci, c);
1780   if (prob == PROB_UNKNOWN) {
1781     // (An earlier version of do_ifnull omitted this trap for OSR methods.)
1782     if (PrintOpto && Verbose) {
1783       tty->print_cr("Never-taken edge stops compilation at bci %d", bci());
1784     }
1785     repush_if_args(); // to gather stats on loop
1786     uncommon_trap(Deoptimization::Reason_unreached,
1787                   Deoptimization::Action_reinterpret,
1788                   nullptr, "cold");
1789     if (C->eliminate_boxing()) {
1790       // Mark the successor blocks as parsed
1791       branch_block->next_path_num();
1792       next_block->next_path_num();
1793     }
1794     return;
1795   }
1796 
1797   NOT_PRODUCT(explicit_null_checks_inserted++);
1798 
1799   // Generate real control flow
1800   Node   *tst = _gvn.transform( new BoolNode( c, btest ) );
1801 
1802   // Sanity check the probability value
1803   assert(prob > 0.0f,"Bad probability in Parser");
1804  // Need xform to put node in hash table
1805   IfNode *iff = create_and_xform_if( control(), tst, prob, cnt );
1806   assert(iff->_prob > 0.0f,"Optimizer made bad probability in parser");
1807   // True branch
1808   { PreserveJVMState pjvms(this);
1809     Node* iftrue  = _gvn.transform( new IfTrueNode (iff) );
1810     set_control(iftrue);
1811 
1812     if (stopped()) {            // Path is dead?
1813       NOT_PRODUCT(explicit_null_checks_elided++);
1814       if (C->eliminate_boxing()) {
1815         // Mark the successor block as parsed
1816         branch_block->next_path_num();
1817       }
1818     } else {                    // Path is live.
1819       adjust_map_after_if(btest, c, prob, branch_block);
1820       if (!stopped()) {
1821         merge(target_bci);
1822       }
1823     }
1824   }
1825 
1826   // False branch
1827   Node* iffalse = _gvn.transform( new IfFalseNode(iff) );
1828   set_control(iffalse);
1829 
1830   if (stopped()) {              // Path is dead?
1831     NOT_PRODUCT(explicit_null_checks_elided++);
1832     if (C->eliminate_boxing()) {
1833       // Mark the successor block as parsed
1834       next_block->next_path_num();
1835     }
1836   } else  {                     // Path is live.
1837     adjust_map_after_if(BoolTest(btest).negate(), c, 1.0-prob, next_block);
1838   }
1839 
1840   if (do_stress_trap) {
1841     stress_trap(iff, counter, incr_store);
1842   }
1843 }
1844 
1845 //------------------------------------do_if------------------------------------
1846 void Parse::do_if(BoolTest::mask btest, Node* c, bool can_trap, bool new_path, Node** ctrl_taken, Node** mem_taken, Node** io_taken) {
1847   int target_bci = iter().get_dest();
1848 
1849   Block* branch_block = successor_for_bci(target_bci);
1850   Block* next_block   = successor_for_bci(iter().next_bci());
1851 
1852   float cnt;
1853   float prob = branch_prediction(cnt, btest, target_bci, c);
1854   float untaken_prob = 1.0 - prob;
1855 
1856   if (prob == PROB_UNKNOWN) {
1857     if (PrintOpto && Verbose) {
1858       tty->print_cr("Never-taken edge stops compilation at bci %d", bci());
1859     }
1860     repush_if_args(); // to gather stats on loop
1861     uncommon_trap(Deoptimization::Reason_unreached,
1862                   Deoptimization::Action_reinterpret,
1863                   nullptr, "cold");
1864     if (C->eliminate_boxing()) {
1865       // Mark the successor blocks as parsed
1866       branch_block->next_path_num();
1867       next_block->next_path_num();
1868     }
1869     return;
1870   }
1871 
1872   Node* counter = nullptr;
1873   Node* incr_store = nullptr;
1874   bool do_stress_trap = StressUnstableIfTraps && ((C->random() % 2) == 0);
1875   if (do_stress_trap) {
1876     increment_trap_stress_counter(counter, incr_store);
1877   }
1878 
1879   // Sanity check the probability value
1880   assert(0.0f < prob && prob < 1.0f,"Bad probability in Parser");
1881 
1882   bool taken_if_true = true;
1883   // Convert BoolTest to canonical form:
1884   if (!BoolTest(btest).is_canonical()) {
1885     btest         = BoolTest(btest).negate();
1886     taken_if_true = false;
1887     // prob is NOT updated here; it remains the probability of the taken
1888     // path (as opposed to the prob of the path guarded by an 'IfTrueNode').
1889   }
1890   assert(btest != BoolTest::eq, "!= is the only canonical exact test");
1891 
1892   Node* tst0 = new BoolNode(c, btest);
1893   Node* tst = _gvn.transform(tst0);
1894   BoolTest::mask taken_btest   = BoolTest::illegal;
1895   BoolTest::mask untaken_btest = BoolTest::illegal;
1896 
1897   if (tst->is_Bool()) {
1898     // Refresh c from the transformed bool node, since it may be
1899     // simpler than the original c.  Also re-canonicalize btest.
1900     // This wins when (Bool ne (Conv2B p) 0) => (Bool ne (CmpP p null)).
1901     // That can arise from statements like: if (x instanceof C) ...
1902     if (tst != tst0) {
1903       // Canonicalize one more time since transform can change it.
1904       btest = tst->as_Bool()->_test._test;
1905       if (!BoolTest(btest).is_canonical()) {
1906         // Reverse edges one more time...
1907         tst   = _gvn.transform( tst->as_Bool()->negate(&_gvn) );
1908         btest = tst->as_Bool()->_test._test;
1909         assert(BoolTest(btest).is_canonical(), "sanity");
1910         taken_if_true = !taken_if_true;
1911       }
1912       c = tst->in(1);
1913     }
1914     BoolTest::mask neg_btest = BoolTest(btest).negate();
1915     taken_btest   = taken_if_true ?     btest : neg_btest;
1916     untaken_btest = taken_if_true ? neg_btest :     btest;
1917   }
1918 
1919   // Generate real control flow
1920   float true_prob = (taken_if_true ? prob : untaken_prob);
1921   IfNode* iff = create_and_map_if(control(), tst, true_prob, cnt);
1922   assert(iff->_prob > 0.0f,"Optimizer made bad probability in parser");
1923   Node* taken_branch   = new IfTrueNode(iff);
1924   Node* untaken_branch = new IfFalseNode(iff);
1925   if (!taken_if_true) {  // Finish conversion to canonical form
1926     Node* tmp      = taken_branch;
1927     taken_branch   = untaken_branch;
1928     untaken_branch = tmp;
1929   }
1930 
1931   // Branch is taken:
1932   { PreserveJVMState pjvms(this);
1933     taken_branch = _gvn.transform(taken_branch);
1934     set_control(taken_branch);
1935 
1936     if (stopped()) {
1937       if (C->eliminate_boxing() && !new_path) {
1938         // Mark the successor block as parsed (if we haven't created a new path)
1939         branch_block->next_path_num();
1940       }
1941     } else {
1942       adjust_map_after_if(taken_btest, c, prob, branch_block, can_trap);
1943       if (!stopped()) {
1944         if (new_path) {
1945           // Merge by using a new path
1946           merge_new_path(target_bci);
1947         } else if (ctrl_taken != nullptr) {
1948           // Don't merge but save taken branch to be wired by caller
1949           *ctrl_taken = control();
1950           if (mem_taken != nullptr) {
1951             *mem_taken = reset_memory();
1952           }
1953           if (io_taken != nullptr) {
1954             *io_taken = i_o();
1955           }
1956         } else {
1957           merge(target_bci);
1958         }
1959       }
1960     }
1961   }
1962 
1963   untaken_branch = _gvn.transform(untaken_branch);
1964   set_control(untaken_branch);
1965 
1966   // Branch not taken.
1967   if (stopped() && ctrl_taken == nullptr) {
1968     if (C->eliminate_boxing()) {
1969       // Mark the successor block as parsed (if caller does not re-wire control flow)
1970       next_block->next_path_num();
1971     }
1972   } else {
1973     adjust_map_after_if(untaken_btest, c, untaken_prob, next_block, can_trap);
1974   }
1975 
1976   if (do_stress_trap) {
1977     stress_trap(iff, counter, incr_store);
1978   }
1979 }
1980 
1981 
1982 static ProfilePtrKind speculative_ptr_kind(const TypeOopPtr* t) {
1983   if (t->speculative() == nullptr) {
1984     return ProfileUnknownNull;
1985   }
1986   if (t->speculative_always_null()) {
1987     return ProfileAlwaysNull;
1988   }
1989   if (t->speculative_maybe_null()) {
1990     return ProfileMaybeNull;
1991   }
1992   return ProfileNeverNull;
1993 }
1994 
1995 void Parse::acmp_always_null_input(Node* input, const TypeOopPtr* tinput, BoolTest::mask btest, Node* eq_region) {
1996   if (btest == BoolTest::ne) {
1997     {
1998       PreserveJVMState pjvms(this);
1999       inc_sp(2);
2000       null_check_common(input, T_OBJECT, true, nullptr,
2001                         !too_many_traps_or_recompiles(Deoptimization::Reason_speculate_null_check) &&
2002                         speculative_ptr_kind(tinput) == ProfileAlwaysNull);
2003       dec_sp(2);
2004       int target_bci = iter().get_dest();
2005       merge(target_bci);
2006     }
2007     record_for_igvn(eq_region);
2008     set_control(_gvn.transform(eq_region));
2009   } else {
2010     inc_sp(2);
2011     null_check_common(input, T_OBJECT, true, nullptr,
2012                       !too_many_traps_or_recompiles(Deoptimization::Reason_speculate_null_check) &&
2013                       speculative_ptr_kind(tinput) == ProfileAlwaysNull);
2014     dec_sp(2);
2015   }
2016 }
2017 
2018 Node* Parse::acmp_null_check(Node* input, const TypeOopPtr* tinput, ProfilePtrKind input_ptr, Node*& null_ctl) {
2019   inc_sp(2);
2020   null_ctl = top();
2021   Node* cast = null_check_oop(input, &null_ctl,
2022                               input_ptr == ProfileNeverNull || (input_ptr == ProfileUnknownNull && !too_many_traps_or_recompiles(Deoptimization::Reason_null_check)),
2023                               false,
2024                               speculative_ptr_kind(tinput) == ProfileNeverNull &&
2025                               !too_many_traps_or_recompiles(Deoptimization::Reason_speculate_null_check));
2026   dec_sp(2);
2027   return cast;
2028 }
2029 
2030 void Parse::acmp_type_check_or_trap(Node** non_null_input, ciKlass* input_type, Deoptimization::DeoptReason reason) {
2031   Node* slow_ctl = type_check_receiver(*non_null_input, input_type, 1.0, non_null_input);
2032   {
2033     PreserveJVMState pjvms(this);
2034     inc_sp(2);
2035     set_control(slow_ctl);
2036     uncommon_trap_exact(reason, Deoptimization::Action_maybe_recompile);
2037   }
2038 }
2039 
2040 void Parse::acmp_type_check(Node* input, const TypeOopPtr* tinput, ProfilePtrKind input_ptr, ciKlass* input_type, BoolTest::mask btest, Node* eq_region) {
2041   Node* null_ctl;
2042   Node* cast = acmp_null_check(input, tinput, input_ptr, null_ctl);
2043 
2044   if (input_type != nullptr) {
2045     Deoptimization::DeoptReason reason;
2046     if (tinput->speculative_type() != nullptr && !too_many_traps_or_recompiles(Deoptimization::Reason_speculate_class_check)) {
2047       reason = Deoptimization::Reason_speculate_class_check;
2048     } else {
2049       reason = Deoptimization::Reason_class_check;
2050     }
2051     acmp_type_check_or_trap(&cast, input_type, reason);
2052   } else {
2053     // No specific type, check for inline type
2054     BuildCutout unless(this, inline_type_test(cast, /* is_inline = */ false), PROB_MAX);
2055     inc_sp(2);
2056     uncommon_trap_exact(Deoptimization::Reason_class_check, Deoptimization::Action_maybe_recompile);
2057   }
2058 
2059   Node* ne_region = new RegionNode(2);
2060   ne_region->add_req(null_ctl);
2061   ne_region->add_req(control());
2062 
2063   record_for_igvn(ne_region);
2064   set_control(_gvn.transform(ne_region));
2065   if (btest == BoolTest::ne) {
2066     {
2067       PreserveJVMState pjvms(this);
2068       if (null_ctl == top()) {
2069         replace_in_map(input, cast);
2070       }
2071       int target_bci = iter().get_dest();
2072       merge(target_bci);
2073     }
2074     record_for_igvn(eq_region);
2075     set_control(_gvn.transform(eq_region));
2076   } else {
2077     if (null_ctl == top()) {
2078       replace_in_map(input, cast);
2079     }
2080     set_control(_gvn.transform(ne_region));
2081   }
2082 }
2083 
2084 void Parse::do_acmp(BoolTest::mask btest, Node* left, Node* right) {
2085   ciKlass* left_type = nullptr;
2086   ciKlass* right_type = nullptr;
2087   ProfilePtrKind left_ptr = ProfileUnknownNull;
2088   ProfilePtrKind right_ptr = ProfileUnknownNull;
2089   bool left_inline_type = true;
2090   bool right_inline_type = true;
2091 
2092   // Leverage profiling at acmp
2093   if (UseACmpProfile) {
2094     method()->acmp_profiled_type(bci(), left_type, right_type, left_ptr, right_ptr, left_inline_type, right_inline_type);
2095     if (too_many_traps_or_recompiles(Deoptimization::Reason_class_check)) {
2096       left_type = nullptr;
2097       right_type = nullptr;
2098       left_inline_type = true;
2099       right_inline_type = true;
2100     }
2101     if (too_many_traps_or_recompiles(Deoptimization::Reason_null_check)) {
2102       left_ptr = ProfileUnknownNull;
2103       right_ptr = ProfileUnknownNull;
2104     }
2105   }
2106 
2107   if (UseTypeSpeculation) {
2108     record_profile_for_speculation(left, left_type, left_ptr);
2109     record_profile_for_speculation(right, right_type, right_ptr);
2110   }
2111 
2112   if (!Arguments::is_valhalla_enabled()) {
2113     Node* cmp = CmpP(left, right);
2114     cmp = optimize_cmp_with_klass(cmp);
2115     do_if(btest, cmp);
2116     return;
2117   }
2118 
2119   // Check for equality before potentially allocating
2120   if (left == right) {
2121     do_if(btest, makecon(TypeInt::CC_EQ));
2122     return;
2123   }
2124 
2125   // Allocate inline type operands and re-execute on deoptimization
2126   if (left->is_InlineType()) {
2127     PreserveReexecuteState preexecs(this);
2128     inc_sp(2);
2129     jvms()->set_should_reexecute(true);
2130     left = left->as_InlineType()->buffer(this);
2131   }
2132   if (right->is_InlineType()) {
2133     PreserveReexecuteState preexecs(this);
2134     inc_sp(2);
2135     jvms()->set_should_reexecute(true);
2136     right = right->as_InlineType()->buffer(this);
2137   }
2138 
2139   // First, do a normal pointer comparison
2140   const TypeOopPtr* tleft = _gvn.type(left)->isa_oopptr();
2141   const TypeOopPtr* tright = _gvn.type(right)->isa_oopptr();
2142   Node* cmp = CmpP(left, right);
2143   record_for_igvn(cmp);
2144   cmp = optimize_cmp_with_klass(cmp);
2145   if (tleft == nullptr || !tleft->can_be_inline_type() ||
2146       tright == nullptr || !tright->can_be_inline_type()) {
2147     // This is sufficient, if one of the operands can't be an inline type
2148     do_if(btest, cmp);
2149     return;
2150   }
2151 
2152   // Don't add traps to unstable if branches because additional checks are required to
2153   // decide if the operands are equal/substitutable and we therefore shouldn't prune
2154   // branches for one if based on the profiling of the acmp branches.
2155   // Also, OptimizeUnstableIf would set an incorrect re-rexecution state because it
2156   // assumes that there is a 1-1 mapping between the if and the acmp branches and that
2157   // hitting a trap means that we will take the corresponding acmp branch on re-execution.
2158   const bool can_trap = true;
2159 
2160   Node* eq_region = nullptr;
2161   if (btest == BoolTest::eq) {
2162     do_if(btest, cmp, !can_trap, true);
2163     if (stopped()) {
2164       // Pointers are equal, operands must be equal
2165       return;
2166     }
2167   } else {
2168     assert(btest == BoolTest::ne, "only eq or ne");
2169     Node* is_not_equal = nullptr;
2170     eq_region = new RegionNode(4);
2171     {
2172       PreserveJVMState pjvms(this);
2173       // Pointers are not equal, but more checks are needed to determine if the operands are (not) substitutable
2174       do_if(btest, cmp, !can_trap, false, &is_not_equal);
2175       if (!stopped()) {
2176         eq_region->init_req(1, control());
2177       }
2178     }
2179     if (is_not_equal == nullptr || is_not_equal->is_top()) {
2180       record_for_igvn(eq_region);
2181       set_control(_gvn.transform(eq_region));
2182       return;
2183     }
2184     set_control(is_not_equal);
2185   }
2186 
2187   // Prefer speculative types if available
2188   if (!too_many_traps_or_recompiles(Deoptimization::Reason_speculate_class_check)) {
2189     if (tleft->speculative_type() != nullptr) {
2190       left_type = tleft->speculative_type();
2191     }
2192     if (tright->speculative_type() != nullptr) {
2193       right_type = tright->speculative_type();
2194     }
2195   }
2196 
2197   if (speculative_ptr_kind(tleft) != ProfileMaybeNull && speculative_ptr_kind(tleft) != ProfileUnknownNull) {
2198     ProfilePtrKind speculative_left_ptr = speculative_ptr_kind(tleft);
2199     if (speculative_left_ptr == ProfileAlwaysNull && !too_many_traps_or_recompiles(Deoptimization::Reason_speculate_null_assert)) {
2200       left_ptr = speculative_left_ptr;
2201     } else if (speculative_left_ptr == ProfileNeverNull && !too_many_traps_or_recompiles(Deoptimization::Reason_speculate_null_check)) {
2202       left_ptr = speculative_left_ptr;
2203     }
2204   }
2205   if (speculative_ptr_kind(tright) != ProfileMaybeNull && speculative_ptr_kind(tright) != ProfileUnknownNull) {
2206     ProfilePtrKind speculative_right_ptr = speculative_ptr_kind(tright);
2207     if (speculative_right_ptr == ProfileAlwaysNull && !too_many_traps_or_recompiles(Deoptimization::Reason_speculate_null_assert)) {
2208       right_ptr = speculative_right_ptr;
2209     } else if (speculative_right_ptr == ProfileNeverNull && !too_many_traps_or_recompiles(Deoptimization::Reason_speculate_null_check)) {
2210       right_ptr = speculative_right_ptr;
2211     }
2212   }
2213 
2214   if (left_ptr == ProfileAlwaysNull) {
2215     // Comparison with null. Assert the input is indeed null and we're done.
2216     acmp_always_null_input(left, tleft, btest, eq_region);
2217     return;
2218   }
2219   if (right_ptr == ProfileAlwaysNull) {
2220     // Comparison with null. Assert the input is indeed null and we're done.
2221     acmp_always_null_input(right, tright, btest, eq_region);
2222     return;
2223   }
2224   if (left_type != nullptr && !left_type->is_inlinetype()) {
2225     // Comparison with an object of known type
2226     acmp_type_check(left, tleft, left_ptr, left_type, btest, eq_region);
2227     return;
2228   }
2229   if (right_type != nullptr && !right_type->is_inlinetype()) {
2230     // Comparison with an object of known type
2231     acmp_type_check(right, tright, right_ptr, right_type, btest, eq_region);
2232     return;
2233   }
2234   if (!left_inline_type) {
2235     // Comparison with an object known not to be an inline type
2236     acmp_type_check(left, tleft, left_ptr, nullptr, btest, eq_region);
2237     return;
2238   }
2239   if (!right_inline_type) {
2240     // Comparison with an object known not to be an inline type
2241     acmp_type_check(right, tright, right_ptr, nullptr, btest, eq_region);
2242     return;
2243   }
2244 
2245   // Pointers are not equal, check if first operand is non-null
2246   Node* ne_region = new RegionNode(7);
2247   Node* null_ctl = nullptr;
2248   Node* not_null_left = nullptr;
2249   Node* not_null_right = acmp_null_check(right, tright, right_ptr, null_ctl);
2250   ne_region->init_req(1, null_ctl);
2251 
2252   Node* kls_right = nullptr;
2253   if (!stopped()) {
2254     // First operand is non-null, check if it is the speculative inline type if possible
2255     // (which later allows isSubstitutable to be intrinsified), or any inline type if no
2256     // speculation is available.
2257     if (right_type != nullptr && right_type->is_inlinetype()) {
2258       acmp_type_check_or_trap(&not_null_right, right_type, Deoptimization::Reason_speculate_class_check);
2259     } else {
2260       Node* is_value = inline_type_test(not_null_right);
2261       IfNode* is_value_iff = create_and_map_if(control(), is_value, PROB_FAIR, COUNT_UNKNOWN);
2262       Node* not_value = _gvn.transform(new IfFalseNode(is_value_iff));
2263       ne_region->init_req(2, not_value);
2264       set_control(_gvn.transform(new IfTrueNode(is_value_iff)));
2265     }
2266 
2267     // The first operand is an inline type, check if the second operand is non-null
2268     not_null_left = acmp_null_check(left, tleft, left_ptr, null_ctl);
2269     ne_region->init_req(3, null_ctl);
2270     if (!stopped()) {
2271       // Check if lhs operand is of a specific speculative inline type (see above).
2272       // If not, we don't need to enforce that the lhs is a value object since we know
2273       // it already for the rhs, and must enforce that they have the same type.
2274       if (left_type != nullptr && left_type->is_inlinetype()) {
2275         acmp_type_check_or_trap(&not_null_left, left_type, Deoptimization::Reason_speculate_class_check);
2276       }
2277       if (!stopped()) {
2278         // Check if both operands are of the same class.
2279         Node* kls_left = load_object_klass(not_null_left);
2280         kls_right = load_object_klass(not_null_right);
2281         Node* kls_cmp = CmpP(kls_left, kls_right);
2282         Node* kls_bol = _gvn.transform(new BoolNode(kls_cmp, BoolTest::ne));
2283         IfNode* kls_iff = create_and_map_if(control(), kls_bol, PROB_FAIR, COUNT_UNKNOWN);
2284         Node* kls_ne = _gvn.transform(new IfTrueNode(kls_iff));
2285         set_control(_gvn.transform(new IfFalseNode(kls_iff)));
2286         ne_region->init_req(4, kls_ne);
2287       }
2288     }
2289   }
2290 
2291   if (stopped()) {
2292     record_for_igvn(ne_region);
2293     set_control(_gvn.transform(ne_region));
2294     if (btest == BoolTest::ne) {
2295       {
2296         PreserveJVMState pjvms(this);
2297         int target_bci = iter().get_dest();
2298         merge(target_bci);
2299       }
2300       record_for_igvn(eq_region);
2301       set_control(_gvn.transform(eq_region));
2302     }
2303     return;
2304   }
2305   assert(kls_right != nullptr, "");
2306 
2307   IfNode* mask_iff = nullptr;
2308   // If any operand has a precisely known type, isSubstitutable will be intrinsified, so we don't need the fast path
2309   if (UseAcmpFastPath && !_gvn.type(not_null_left)->is_inlinetypeptr() && !_gvn.type(not_null_right)->is_inlinetypeptr()) {
2310     /* Here, we are generating the fast path (the slow path being the call to isSubstitutable)
2311      * See the declarations of _fast_acmp_offset and _fast_acmp_mask in InlineKlass::Members
2312      * for details about the fast path logic, and the meaning of these values.
2313      */
2314     Node* members_addr = off_heap_plus_addr(kls_right, in_bytes(InlineKlass::adr_members_offset()));
2315     Node* members = make_load(control(), members_addr, TypeRawPtr::BOTTOM, T_ADDRESS, MemNode::unordered);
2316     Node* offset_addr = off_heap_plus_addr(members, in_bytes(InlineKlass::fast_acmp_offset_offset()));
2317     Node* offset = make_load(control(), offset_addr, TypeInt::INT, T_INT, MemNode::unordered);
2318 
2319     Node* offset_cmp = CmpI(offset, zerocon(T_INT));
2320     Node* offset_bol = _gvn.transform(new BoolNode(offset_cmp, BoolTest::lt));
2321     mask_iff = create_and_map_if(control(), offset_bol, PROB_FAIR, COUNT_UNKNOWN);
2322     Node* slow_path_ctl = _gvn.transform(new IfTrueNode(mask_iff));
2323     Node* fast_path_ctl = _gvn.transform(new IfFalseNode(mask_iff));
2324     set_control(slow_path_ctl);
2325 
2326     {
2327       PreserveJVMState jvms(this);
2328       set_control(fast_path_ctl);
2329 
2330       Node* offset_l = ConvI2L(offset);
2331       Node* fast_acmp_mask_addr = off_heap_plus_addr(members, in_bytes(InlineKlass::fast_acmp_mask_offset()));
2332       Node* fast_acmp_mask = make_load(control(), fast_acmp_mask_addr, TypeLong::LONG, T_LONG, MemNode::unordered);
2333 
2334       // *(left + offset) & mask == *(right + offset) & mask
2335       Node* left_payload_addr = basic_plus_adr(not_null_left, offset_l);
2336       Node* left_payload = make_load(control(), left_payload_addr, TypeLong::LONG, T_LONG, MemNode::unordered, LoadNNode::DependsOnlyOnTest, false, true, true, true);
2337       Node* left_masked = _gvn.transform(new AndLNode(left_payload, fast_acmp_mask));
2338 
2339       Node* right_payload_addr = basic_plus_adr(not_null_right, offset_l);
2340       Node* right_payload = make_load(control(), right_payload_addr, TypeLong::LONG, T_LONG, MemNode::unordered, LoadNNode::DependsOnlyOnTest, false, true, true, true);
2341       Node* right_masked = _gvn.transform(new AndLNode(right_payload, fast_acmp_mask));
2342 
2343       Node* masked_cmp = CmpL(left_masked, right_masked);
2344 
2345       Node* ctl = C->top();
2346       if (btest == BoolTest::eq) {
2347         PreserveJVMState pjvms(this);
2348         do_if(btest, masked_cmp, !can_trap, true, nullptr);
2349         if (!stopped()) {
2350           ctl = control();
2351         }
2352       } else {
2353         assert(btest == BoolTest::ne, "only eq or ne");
2354         PreserveJVMState pjvms(this);
2355         do_if(btest, masked_cmp, !can_trap, false, &ctl);
2356         if (!stopped()) {
2357           eq_region->init_req(3, control());
2358         }
2359       }
2360       ne_region->init_req(6, ctl);
2361     }
2362   }
2363 
2364   // Both operands are values types of the same class, we need to perform a
2365   // substitutability test. Delegate to ValueObjectMethods::isSubstitutable().
2366   Node* ne_io_phi = PhiNode::make(ne_region, i_o());
2367   Node* mem = reset_memory();
2368   Node* ne_mem_phi = PhiNode::make(ne_region, mem);
2369 
2370   Node* eq_io_phi = nullptr;
2371   Node* eq_mem_phi = nullptr;
2372   if (eq_region != nullptr) {
2373     eq_io_phi = PhiNode::make(eq_region, i_o());
2374     eq_mem_phi = PhiNode::make(eq_region, mem);
2375   }
2376 
2377   set_all_memory(mem);
2378 
2379   kill_dead_locals();
2380   ciSymbol* subst_method_name = ciSymbols::isSubstitutable_name();
2381   ciMethod* subst_method = ciEnv::current()->ValueObjectMethods_klass()->find_method(subst_method_name, ciSymbols::object_object_boolean_signature());
2382   CallStaticJavaNode* call = new CallStaticJavaNode(C, TypeFunc::make(subst_method), SharedRuntime::get_resolve_static_call_stub(), subst_method);
2383   call->set_override_symbolic_info(true);
2384   call->init_req(TypeFunc::Parms, not_null_left);
2385   call->init_req(TypeFunc::Parms+1, not_null_right);
2386   inc_sp(2);
2387   set_edges_for_java_call(call, false, false);
2388   Node* ret = set_results_for_java_call(call, false, true);
2389   dec_sp(2);
2390 
2391   assert(acmp_fast_path_if_from_substitutable_call(&_gvn, call) == mask_iff, "");
2392 
2393   // Test the return value of ValueObjectMethods::isSubstitutable()
2394   // This is the last check, do_if can emit traps now.
2395   Node* subst_cmp = _gvn.transform(new CmpINode(ret, intcon(1)));
2396   Node* ctl = C->top();
2397   Node* mem_taken = nullptr;
2398   Node* io_taken = nullptr;
2399   if (btest == BoolTest::eq) {
2400     PreserveJVMState pjvms(this);
2401     do_if(btest, subst_cmp, can_trap, false, nullptr, &mem_taken, &io_taken);
2402     if (!stopped()) {
2403       ctl = control();
2404       mem_taken = reset_memory();
2405       io_taken = i_o();
2406     }
2407   } else {
2408     assert(btest == BoolTest::ne, "only eq or ne");
2409     PreserveJVMState pjvms(this);
2410     do_if(btest, subst_cmp, can_trap, false, &ctl, &mem_taken, &io_taken);
2411     if (!stopped()) {
2412       eq_region->init_req(2, control());
2413       eq_io_phi->init_req(2, i_o());
2414       eq_mem_phi->init_req(2, reset_memory());
2415     }
2416   }
2417   ne_region->init_req(5, ctl);
2418   ne_io_phi->init_req(5, io_taken);
2419   ne_mem_phi->init_req(5, mem_taken);
2420 
2421   record_for_igvn(ne_region);
2422   set_control(_gvn.transform(ne_region));
2423   set_i_o(_gvn.transform(ne_io_phi));
2424   set_all_memory(_gvn.transform(ne_mem_phi));
2425 
2426   if (btest == BoolTest::ne) {
2427     {
2428       PreserveJVMState pjvms(this);
2429       int target_bci = iter().get_dest();
2430       merge(target_bci);
2431     }
2432 
2433     record_for_igvn(eq_region);
2434     set_control(_gvn.transform(eq_region));
2435     set_i_o(_gvn.transform(eq_io_phi));
2436     set_all_memory(_gvn.transform(eq_mem_phi));
2437   }
2438 }
2439 
2440 /* Detects whether a call to isSubstitutable is under an IfNode guarding the fast path for acmp.
2441  * If so, returns the IfNode branching between the call and the fast path. Returns null otherwise.
2442  *
2443  * The fast path is a LOT easier to generate at parsing time, but can be later proven useless if further
2444  * optimization narrows down the type of operands and allows intrinsification of the substitutability
2445  * check. In this case, the fast path might still apply, but it comes with various downsides, such as
2446  * mismatch access that may hinder optimizations, or buffering requirement. So, when intrinsifying the call,
2447  * we try to remove the fast path.
2448  *
2449  * This test isn't so bad. Loading the fast acmp offset is pretty unique to the fast acmp path.
2450  *
2451  * Clearly, this is only a step before a proper solution for acmp, such as a macro node.
2452  */
2453 IfNode* Parse::acmp_fast_path_if_from_substitutable_call(PhaseGVN* phase, CallStaticJavaNode* call) {
2454   auto is_con_offset = [](Node* node, ByteSize n) -> bool {
2455     if (!node->is_Con()) return false;
2456     TypeNode* con = node->as_Type();
2457     assert(con->type()->is_intptr_t(), "");
2458     return con->type()->is_intptr_t()->is_con(in_bytes(n));
2459   };
2460 
2461   assert(call->in(TypeFunc::Control) != nullptr, "");
2462   if (!call->in(TypeFunc::Control)->is_IfProj()) return nullptr;
2463   IfProjNode* if_proj = call->in(TypeFunc::Control)->as_IfProj();
2464   if (if_proj->_con != 1) return nullptr;
2465 
2466   assert(if_proj->in(0) != nullptr, "");
2467   assert(if_proj->in(0)->is_If(), "");
2468   IfNode* iff = if_proj->in(0)->as_If();
2469 
2470   assert(iff->in(1) != nullptr, "");
2471   if (!iff->in(1)->is_Bool()) return nullptr;
2472   BoolNode* lt = iff->in(1)->as_Bool();
2473   if (lt->_test._test != BoolTest::lt) return nullptr;
2474 
2475   assert(lt->in(1) != nullptr, "");
2476   if (lt->in(1)->Opcode() != Op_CmpI) return nullptr;
2477   CmpNode* cmp_i = lt->in(1)->as_Cmp();
2478 
2479   assert(cmp_i->in(1) != nullptr, "");
2480   assert(cmp_i->in(2) != nullptr, "");
2481 
2482   if (cmp_i->in(1)->Opcode() != Op_LoadI) return nullptr;
2483   LoadNode* load_offset = cmp_i->in(1)->as_Load();
2484   if (!cmp_i->in(2)->is_ConI()) return nullptr;
2485   ConINode* zero_i = cmp_i->in(2)->as_ConI();
2486   assert(zero_i->type()->is_int() != nullptr, "");
2487   if (!zero_i->type()->is_int()->is_con(0)) return nullptr;
2488 
2489   assert(load_offset->in(2) != nullptr, "");
2490   if (!load_offset->in(2)->is_AddP()) return nullptr;
2491   AddPNode* offset_addr_add = load_offset->in(2)->as_AddP();
2492 
2493   assert(offset_addr_add->in(AddPNode::Base) != nullptr, "");
2494   assert(offset_addr_add->in(AddPNode::Address) != nullptr, "");
2495   assert(offset_addr_add->in(AddPNode::Offset) != nullptr, "");
2496   if (!offset_addr_add->in(AddPNode::Base)->is_top()) return nullptr;
2497   if (offset_addr_add->in(AddPNode::Address)->Opcode() != Op_LoadP) return nullptr;
2498   LoadNode* load_members = offset_addr_add->in(AddPNode::Address)->as_Load();
2499   if (!is_con_offset(offset_addr_add->in(AddPNode::Offset), InlineKlass::fast_acmp_offset_offset())) return nullptr;
2500 
2501   assert(load_members->in(2) != nullptr, "");
2502   if (!load_members->in(2)->is_AddP()) return nullptr;
2503   AddPNode* members_addr_add = load_members->in(2)->as_AddP();
2504 
2505   assert(members_addr_add->in(AddPNode::Base) != nullptr, "");
2506   assert(members_addr_add->in(AddPNode::Address) != nullptr, "");
2507   assert(members_addr_add->in(AddPNode::Offset) != nullptr, "");
2508   if (!members_addr_add->in(AddPNode::Base)->is_top()) return nullptr;
2509   if (!phase->type(members_addr_add->in(AddPNode::Address))->isa_instklassptr()) return nullptr;
2510   if (!is_con_offset(members_addr_add->in(AddPNode::Offset), InlineKlass::adr_members_offset())) return nullptr;
2511 
2512   return iff;
2513 }
2514 
2515 // Force unstable if traps to be taken randomly to trigger intermittent bugs such as incorrect debug information.
2516 // Add another if before the unstable if that checks a "random" condition at runtime (a simple shared counter) and
2517 // then either takes the trap or executes the original, unstable if.
2518 void Parse::stress_trap(IfNode* orig_iff, Node* counter, Node* incr_store) {
2519   // Search for an unstable if trap
2520   CallStaticJavaNode* trap = nullptr;
2521   assert(orig_iff->Opcode() == Op_If && orig_iff->outcnt() == 2, "malformed if");
2522   ProjNode* trap_proj = orig_iff->uncommon_trap_proj(trap, Deoptimization::Reason_unstable_if);
2523   if (trap == nullptr || !trap->jvms()->should_reexecute()) {
2524     // No suitable trap found. Remove unused counter load and increment.
2525     C->gvn_replace_by(incr_store, incr_store->in(MemNode::Memory));
2526     return;
2527   }
2528 
2529   // Remove trap from optimization list since we add another path to the trap.
2530   bool success = C->remove_unstable_if_trap(trap, true);
2531   assert(success, "Trap already modified");
2532 
2533   // Add a check before the original if that will trap with a certain frequency and execute the original if otherwise
2534   int freq_log = (C->random() % 31) + 1; // Random logarithmic frequency in [1, 31]
2535   Node* mask = intcon(right_n_bits(freq_log));
2536   counter = _gvn.transform(new AndINode(counter, mask));
2537   Node* cmp = _gvn.transform(new CmpINode(counter, intcon(0)));
2538   Node* bol = _gvn.transform(new BoolNode(cmp, BoolTest::mask::eq));
2539   IfNode* iff = _gvn.transform(new IfNode(orig_iff->in(0), bol, orig_iff->_prob, orig_iff->_fcnt))->as_If();
2540   Node* if_true = _gvn.transform(new IfTrueNode(iff));
2541   Node* if_false = _gvn.transform(new IfFalseNode(iff));
2542   assert(!if_true->is_top() && !if_false->is_top(), "trap always / never taken");
2543 
2544   // Trap
2545   assert(trap_proj->outcnt() == 1, "some other nodes are dependent on the trap projection");
2546 
2547   Node* trap_region = new RegionNode(3);
2548   trap_region->set_req(1, trap_proj);
2549   trap_region->set_req(2, if_true);
2550   trap->set_req(0, _gvn.transform(trap_region));
2551 
2552   // Don't trap, execute original if
2553   orig_iff->set_req(0, if_false);
2554 }
2555 
2556 bool Parse::path_is_suitable_for_uncommon_trap(float prob) const {
2557   // Randomly skip emitting an uncommon trap
2558   if (StressUnstableIfTraps && ((C->random() % 2) == 0)) {
2559     return false;
2560   }
2561   // Don't want to speculate on uncommon traps when running with -Xcomp
2562   if (!UseInterpreter) {
2563     return false;
2564   }
2565   return seems_never_taken(prob) &&
2566          !C->too_many_traps(method(), bci(), Deoptimization::Reason_unstable_if);
2567 }
2568 
2569 void Parse::maybe_add_predicate_after_if(Block* path) {
2570   if (path->is_SEL_head() && path->preds_parsed() == 0) {
2571     // Add predicates at bci of if dominating the loop so traps can be
2572     // recorded on the if's profile data
2573     int bc_depth = repush_if_args();
2574     add_parse_predicates();
2575     dec_sp(bc_depth);
2576     path->set_has_predicates();
2577   }
2578 }
2579 
2580 
2581 //----------------------------adjust_map_after_if------------------------------
2582 // Adjust the JVM state to reflect the result of taking this path.
2583 // Basically, it means inspecting the CmpNode controlling this
2584 // branch, seeing how it constrains a tested value, and then
2585 // deciding if it's worth our while to encode this constraint
2586 // as graph nodes in the current abstract interpretation map.
2587 void Parse::adjust_map_after_if(BoolTest::mask btest, Node* c, float prob, Block* path, bool can_trap) {
2588   if (!c->is_Cmp()) {
2589     maybe_add_predicate_after_if(path);
2590     return;
2591   }
2592 
2593   if (stopped() || btest == BoolTest::illegal) {
2594     return;                             // nothing to do
2595   }
2596 
2597   bool is_fallthrough = (path == successor_for_bci(iter().next_bci()));
2598 
2599   if (can_trap && path_is_suitable_for_uncommon_trap(prob)) {
2600     repush_if_args();
2601     Node* call = uncommon_trap(Deoptimization::Reason_unstable_if,
2602                   Deoptimization::Action_reinterpret,
2603                   nullptr,
2604                   (is_fallthrough ? "taken always" : "taken never"));
2605 
2606     if (call != nullptr) {
2607       C->record_unstable_if_trap(new UnstableIfTrap(call->as_CallStaticJava(), path));
2608     }
2609     return;
2610   }
2611 
2612   if (c->is_FlatArrayCheck()) {
2613     maybe_add_predicate_after_if(path);
2614     return;
2615   }
2616 
2617   Node* val = c->in(1);
2618   Node* con = c->in(2);
2619   const Type* tcon = _gvn.type(con);
2620   const Type* tval = _gvn.type(val);
2621   bool have_con = tcon->singleton();
2622   if (tval->singleton()) {
2623     if (!have_con) {
2624       // Swap, so constant is in con.
2625       con  = val;
2626       tcon = tval;
2627       val  = c->in(2);
2628       tval = _gvn.type(val);
2629       btest = BoolTest(btest).commute();
2630       have_con = true;
2631     } else {
2632       // Do we have two constants?  Then leave well enough alone.
2633       have_con = false;
2634     }
2635   }
2636   if (!have_con) {                        // remaining adjustments need a con
2637     maybe_add_predicate_after_if(path);
2638     return;
2639   }
2640 
2641   sharpen_type_after_if(btest, con, tcon, val, tval);
2642   maybe_add_predicate_after_if(path);
2643 }
2644 
2645 
2646 static Node* extract_obj_from_klass_load(PhaseGVN* gvn, Node* n) {
2647   Node* ldk;
2648   if (n->is_DecodeNKlass()) {
2649     if (n->in(1)->Opcode() != Op_LoadNKlass) {
2650       return nullptr;
2651     } else {
2652       ldk = n->in(1);
2653     }
2654   } else if (n->Opcode() != Op_LoadKlass) {
2655     return nullptr;
2656   } else {
2657     ldk = n;
2658   }
2659   assert(ldk != nullptr && ldk->is_Load(), "should have found a LoadKlass or LoadNKlass node");
2660 
2661   Node* adr = ldk->in(MemNode::Address);
2662   intptr_t off = 0;
2663   Node* obj = AddPNode::Ideal_base_and_offset(adr, gvn, off);
2664   if (obj == nullptr || off != oopDesc::klass_offset_in_bytes()) // loading oopDesc::_klass?
2665     return nullptr;
2666   const TypePtr* tp = gvn->type(obj)->is_ptr();
2667   if (tp == nullptr || !(tp->isa_instptr() || tp->isa_aryptr())) // is obj a Java object ptr?
2668     return nullptr;
2669 
2670   return obj;
2671 }
2672 
2673 // Matches exact and inexact type check IR shapes during parsing.
2674 // On successful match, returns type checked object node and its type after successful check
2675 // as out parameters.
2676 static bool match_type_check(PhaseGVN& gvn,
2677                              BoolTest::mask btest,
2678                              Node* con, const Type* tcon,
2679                              Node* val, const Type* tval,
2680                              Node** obj, const TypeOopPtr** cast_type) { // out-parameters
2681   // Look for opportunities to sharpen the type of a node whose klass is compared with a constant klass.
2682   // The constant klass being tested against can come from many bytecode instructions (implicitly or explicitly),
2683   // and also from profile data used by speculative casts.
2684   if (btest == BoolTest::eq && tcon->isa_klassptr()) {
2685     // Found:
2686     //   Bool(CmpP(LoadKlass(obj._klass), ConP(Foo.klass)), [eq])
2687     // or the narrowOop equivalent.
2688     (*obj) = extract_obj_from_klass_load(&gvn, val);
2689     // Some klass comparisons are not directly in the form
2690     // Bool(CmpP(LoadKlass(obj._klass), ConP(Foo.klass)), [eq]),
2691     // e.g. Bool(CmpP(CastPP(LoadKlass(...)), ConP(klass)), [eq]).
2692     // These patterns with nullable klasses arise from example from
2693     // load_array_klass_from_mirror.
2694     if (*obj == nullptr) { return false; }
2695     (*cast_type) = tcon->isa_klassptr()->as_instance_type();
2696     return true; // found
2697   }
2698 
2699   // Match an instanceof check.
2700   // During parsing its IR shape is not canonicalized yet.
2701   //
2702   //             obj superklass
2703   //              |    |
2704   //           SubTypeCheck
2705   //                |
2706   //               Bool [eq] / [ne]
2707   //                |
2708   //                If
2709   //               / \
2710   //              T   F
2711   //               \ /
2712   //              Region
2713   //                 \  ConI ConI
2714   //                  \  |  /
2715   //          val ->    Phi  ConI  <- con
2716   //                     \  /
2717   //                     CmpI
2718   //                      |
2719   //                    Bool [btest]
2720   //                      |
2721   //
2722   if (tval->isa_int() && val->is_Phi() && val->in(0)->as_Region()->is_diamond()) {
2723     RegionNode* diamond = val->in(0)->as_Region();
2724     IfNode* if1 = diamond->in(1)->in(0)->as_If();
2725     BoolNode* b1 = if1->in(1)->isa_Bool();
2726     if (b1 != nullptr && b1->in(1)->isa_SubTypeCheck()) {
2727       assert(b1->_test._test == BoolTest::eq ||
2728              b1->_test._test == BoolTest::ne, "%d", b1->_test._test);
2729 
2730       ProjNode* success_proj = if1->proj_out(b1->_test._test == BoolTest::eq ? 1 : 0);
2731       int idx = diamond->find_edge(success_proj);
2732       assert(idx == 1 || idx == 2, "");
2733       Node* vcon = val->in(idx);
2734 
2735       if ((btest == BoolTest::eq && vcon == con) || (btest == BoolTest::ne && vcon != con)) {
2736         assert(val->find_edge(con) > 0, "mismatch");
2737         SubTypeCheckNode* sub = b1->in(1)->as_SubTypeCheck();
2738         Node* obj_or_subklass = sub->in(SubTypeCheckNode::ObjOrSubKlass);
2739         Node* superklass = sub->in(SubTypeCheckNode::SuperKlass);
2740 
2741         if (gvn.type(obj_or_subklass)->isa_oopptr()) {
2742           const TypeKlassPtr* klass_ptr_type = gvn.type(superklass)->is_klassptr();
2743           const TypeKlassPtr* improved_klass_ptr_type = klass_ptr_type->try_improve();
2744 
2745           (*obj) = obj_or_subklass;
2746           (*cast_type) = improved_klass_ptr_type->cast_to_exactness(false)->as_instance_type();
2747           return true; // found
2748         }
2749       }
2750     }
2751   }
2752   return false; // not found
2753 }
2754 
2755 void Parse::sharpen_type_after_if(BoolTest::mask btest,
2756                                   Node* con, const Type* tcon,
2757                                   Node* val, const Type* tval) {
2758   Node* obj = nullptr;
2759   const TypeOopPtr* cast_type = nullptr;
2760   // Insert a cast node with a narrowed type after a successful type check.
2761   if (match_type_check(_gvn, btest, con, tcon, val, tval,
2762                        &obj, &cast_type)) {
2763     assert(obj != nullptr && cast_type != nullptr, "missing type check info");
2764     const Type* obj_type = _gvn.type(obj);
2765     const Type* tboth = obj_type->filter_speculative(cast_type);
2766     assert(tboth->higher_equal(obj_type) && tboth->higher_equal(cast_type), "sanity");
2767     if (tboth == Type::TOP && KillPathsReachableByDeadTypeNode) {
2768       // Let dead type node cleaning logic prune effectively dead path for us.
2769       // CheckCastPP::Value() == TOP and it will trigger the cleanup during GVN.
2770       // Don't materialize the cast when cleanup is disabled, because
2771       // it kills data and control leaving IR in broken state.
2772       tboth = cast_type;
2773     }
2774     if (tboth != Type::TOP && tboth != obj_type) {
2775       int obj_in_map = map()->find_edge(obj);
2776       if (obj_in_map >= 0 &&
2777           (jvms()->is_loc(obj_in_map) || jvms()->is_stk(obj_in_map))) {
2778         TypeNode* ccast = new CheckCastPPNode(control(), obj, tboth);
2779         // Delay transform() call to allow recovery of pre-cast value at the control merge.
2780         _gvn.set_type_bottom(ccast);
2781         record_for_igvn(ccast);
2782         if (tboth->is_inlinetypeptr()) {
2783           ccast = InlineTypeNode::make_from_oop(this, ccast, tboth->isa_oopptr()->exact_klass(true)->as_inline_klass());
2784         }
2785         // Here's the payoff.
2786         replace_in_map(obj, ccast);
2787       }
2788     }
2789   }
2790 
2791   int val_in_map = map()->find_edge(val);
2792   if (val_in_map < 0)  return;          // replace_in_map would be useless
2793   {
2794     JVMState* jvms = this->jvms();
2795     if (!(jvms->is_loc(val_in_map) ||
2796           jvms->is_stk(val_in_map)))
2797       return;                           // again, it would be useless
2798   }
2799 
2800   // Check for a comparison to a constant, and "know" that the compared
2801   // value is constrained on this path.
2802   assert(tcon->singleton(), "");
2803   ConstraintCastNode* ccast = nullptr;
2804   Node* cast = nullptr;
2805 
2806   switch (btest) {
2807   case BoolTest::eq:                    // Constant test?
2808     {
2809       const Type* tboth = tcon->join_speculative(tval);
2810       if (tboth == tval)  break;        // Nothing to gain.
2811       if (tcon->isa_int()) {
2812         ccast = new CastIINode(control(), val, tboth);
2813       } else if (tcon == TypePtr::NULL_PTR) {
2814         // Cast to null, but keep the pointer identity temporarily live.
2815         ccast = new CastPPNode(control(), val, tboth);
2816       } else {
2817         const TypeF* tf = tcon->isa_float_constant();
2818         const TypeD* td = tcon->isa_double_constant();
2819         // Exclude tests vs float/double 0 as these could be
2820         // either +0 or -0.  Just because you are equal to +0
2821         // doesn't mean you ARE +0!
2822         // Note, following code also replaces Long and Oop values.
2823         if ((!tf || tf->_f != 0.0) &&
2824             (!td || td->_d != 0.0))
2825           cast = con;                   // Replace non-constant val by con.
2826       }
2827     }
2828     break;
2829 
2830   case BoolTest::ne:
2831     if (tcon == TypePtr::NULL_PTR) {
2832       cast = cast_not_null(val, false);
2833     }
2834     break;
2835 
2836   default:
2837     // (At this point we could record int range types with CastII.)
2838     break;
2839   }
2840 
2841   if (ccast != nullptr) {
2842     const Type* tcc = ccast->as_Type()->type();
2843     assert(tcc != tval && tcc->higher_equal(tval), "must improve");
2844     // Delay transform() call to allow recovery of pre-cast value
2845     // at the control merge.
2846     _gvn.set_type_bottom(ccast);
2847     record_for_igvn(ccast);
2848     cast = ccast;
2849   }
2850 
2851   if (cast != nullptr) {                   // Here's the payoff.
2852     replace_in_map(val, cast);
2853   }
2854 }
2855 
2856 /**
2857  * Use speculative type to optimize CmpP node: if comparison is
2858  * against the low level class, cast the object to the speculative
2859  * type if any. CmpP should then go away.
2860  *
2861  * @param c  expected CmpP node
2862  * @return   result of CmpP on object casted to speculative type
2863  *
2864  */
2865 Node* Parse::optimize_cmp_with_klass(Node* c) {
2866   // If this is transformed by the _gvn to a comparison with the low
2867   // level klass then we may be able to use speculation
2868   if (c->Opcode() == Op_CmpP &&
2869       (c->in(1)->Opcode() == Op_LoadKlass || c->in(1)->Opcode() == Op_DecodeNKlass) &&
2870       c->in(2)->is_Con()) {
2871     Node* load_klass = nullptr;
2872     Node* decode = nullptr;
2873     if (c->in(1)->Opcode() == Op_DecodeNKlass) {
2874       decode = c->in(1);
2875       load_klass = c->in(1)->in(1);
2876     } else {
2877       load_klass = c->in(1);
2878     }
2879     if (load_klass->in(2)->is_AddP()) {
2880       Node* addp = load_klass->in(2);
2881       Node* obj = addp->in(AddPNode::Address);
2882       const TypeOopPtr* obj_type = _gvn.type(obj)->is_oopptr();
2883       if (obj_type->speculative_type_not_null() != nullptr) {
2884         ciKlass* k = obj_type->speculative_type();
2885         inc_sp(2);
2886         obj = maybe_cast_profiled_obj(obj, k);
2887         dec_sp(2);
2888         if (obj->is_InlineType()) {
2889           assert(obj->as_InlineType()->is_allocated(&_gvn), "must be allocated");
2890           obj = obj->as_InlineType()->get_oop();
2891         }
2892         // Make the CmpP use the casted obj
2893         addp = basic_plus_adr(obj, addp->in(AddPNode::Offset));
2894         load_klass = load_klass->clone();
2895         load_klass->set_req(2, addp);
2896         load_klass = _gvn.transform(load_klass);
2897         if (decode != nullptr) {
2898           decode = decode->clone();
2899           decode->set_req(1, load_klass);
2900           load_klass = _gvn.transform(decode);
2901         }
2902         c = c->clone();
2903         c->set_req(1, load_klass);
2904         c = _gvn.transform(c);
2905       }
2906     }
2907   }
2908   return c;
2909 }
2910 
2911 //------------------------------do_one_bytecode--------------------------------
2912 // Parse this bytecode, and alter the Parsers JVM->Node mapping
2913 void Parse::do_one_bytecode() {
2914   Node *a, *b, *c, *d;          // Handy temps
2915   BoolTest::mask btest;
2916   int i;
2917 
2918   assert(!has_exceptions(), "bytecode entry state must be clear of throws");
2919 
2920   if (C->check_node_count(NodeLimitFudgeFactor * 5,
2921                           "out of nodes parsing method")) {
2922     return;
2923   }
2924 
2925 #ifdef ASSERT
2926   // for setting breakpoints
2927   if (TraceOptoParse) {
2928     tty->print(" @");
2929     dump_bci(bci());
2930     tty->print(" %s", Bytecodes::name(bc()));
2931     tty->cr();
2932   }
2933 #endif
2934 
2935   switch (bc()) {
2936   case Bytecodes::_nop:
2937     // do nothing
2938     break;
2939   case Bytecodes::_lconst_0:
2940     push_pair(longcon(0));
2941     break;
2942 
2943   case Bytecodes::_lconst_1:
2944     push_pair(longcon(1));
2945     break;
2946 
2947   case Bytecodes::_fconst_0:
2948     push(zerocon(T_FLOAT));
2949     break;
2950 
2951   case Bytecodes::_fconst_1:
2952     push(makecon(TypeF::ONE));
2953     break;
2954 
2955   case Bytecodes::_fconst_2:
2956     push(makecon(TypeF::make(2.0f)));
2957     break;
2958 
2959   case Bytecodes::_dconst_0:
2960     push_pair(zerocon(T_DOUBLE));
2961     break;
2962 
2963   case Bytecodes::_dconst_1:
2964     push_pair(makecon(TypeD::ONE));
2965     break;
2966 
2967   case Bytecodes::_iconst_m1:push(intcon(-1)); break;
2968   case Bytecodes::_iconst_0: push(intcon( 0)); break;
2969   case Bytecodes::_iconst_1: push(intcon( 1)); break;
2970   case Bytecodes::_iconst_2: push(intcon( 2)); break;
2971   case Bytecodes::_iconst_3: push(intcon( 3)); break;
2972   case Bytecodes::_iconst_4: push(intcon( 4)); break;
2973   case Bytecodes::_iconst_5: push(intcon( 5)); break;
2974   case Bytecodes::_bipush:   push(intcon(iter().get_constant_u1())); break;
2975   case Bytecodes::_sipush:   push(intcon(iter().get_constant_u2())); break;
2976   case Bytecodes::_aconst_null: push(null());  break;
2977 
2978   case Bytecodes::_ldc:
2979   case Bytecodes::_ldc_w:
2980   case Bytecodes::_ldc2_w: {
2981     // ciTypeFlow should trap if the ldc is in error state or if the constant is not loaded
2982     assert(!iter().is_in_error(), "ldc is in error state");
2983     ciConstant constant = iter().get_constant();
2984     assert(constant.is_loaded(), "constant is not loaded");
2985     const Type* con_type = Type::make_from_constant(constant);
2986     if (con_type != nullptr) {
2987       push_node(con_type->basic_type(), makecon(con_type));
2988     }
2989     break;
2990   }
2991 
2992   case Bytecodes::_aload_0:
2993     push( local(0) );
2994     break;
2995   case Bytecodes::_aload_1:
2996     push( local(1) );
2997     break;
2998   case Bytecodes::_aload_2:
2999     push( local(2) );
3000     break;
3001   case Bytecodes::_aload_3:
3002     push( local(3) );
3003     break;
3004   case Bytecodes::_aload:
3005     push( local(iter().get_index()) );
3006     break;
3007 
3008   case Bytecodes::_fload_0:
3009   case Bytecodes::_iload_0:
3010     push( local(0) );
3011     break;
3012   case Bytecodes::_fload_1:
3013   case Bytecodes::_iload_1:
3014     push( local(1) );
3015     break;
3016   case Bytecodes::_fload_2:
3017   case Bytecodes::_iload_2:
3018     push( local(2) );
3019     break;
3020   case Bytecodes::_fload_3:
3021   case Bytecodes::_iload_3:
3022     push( local(3) );
3023     break;
3024   case Bytecodes::_fload:
3025   case Bytecodes::_iload:
3026     push( local(iter().get_index()) );
3027     break;
3028   case Bytecodes::_lload_0:
3029     push_pair_local( 0 );
3030     break;
3031   case Bytecodes::_lload_1:
3032     push_pair_local( 1 );
3033     break;
3034   case Bytecodes::_lload_2:
3035     push_pair_local( 2 );
3036     break;
3037   case Bytecodes::_lload_3:
3038     push_pair_local( 3 );
3039     break;
3040   case Bytecodes::_lload:
3041     push_pair_local( iter().get_index() );
3042     break;
3043 
3044   case Bytecodes::_dload_0:
3045     push_pair_local(0);
3046     break;
3047   case Bytecodes::_dload_1:
3048     push_pair_local(1);
3049     break;
3050   case Bytecodes::_dload_2:
3051     push_pair_local(2);
3052     break;
3053   case Bytecodes::_dload_3:
3054     push_pair_local(3);
3055     break;
3056   case Bytecodes::_dload:
3057     push_pair_local(iter().get_index());
3058     break;
3059   case Bytecodes::_fstore_0:
3060   case Bytecodes::_istore_0:
3061   case Bytecodes::_astore_0:
3062     set_local( 0, pop() );
3063     break;
3064   case Bytecodes::_fstore_1:
3065   case Bytecodes::_istore_1:
3066   case Bytecodes::_astore_1:
3067     set_local( 1, pop() );
3068     break;
3069   case Bytecodes::_fstore_2:
3070   case Bytecodes::_istore_2:
3071   case Bytecodes::_astore_2:
3072     set_local( 2, pop() );
3073     break;
3074   case Bytecodes::_fstore_3:
3075   case Bytecodes::_istore_3:
3076   case Bytecodes::_astore_3:
3077     set_local( 3, pop() );
3078     break;
3079   case Bytecodes::_fstore:
3080   case Bytecodes::_istore:
3081   case Bytecodes::_astore:
3082     set_local( iter().get_index(), pop() );
3083     break;
3084   // long stores
3085   case Bytecodes::_lstore_0:
3086     set_pair_local( 0, pop_pair() );
3087     break;
3088   case Bytecodes::_lstore_1:
3089     set_pair_local( 1, pop_pair() );
3090     break;
3091   case Bytecodes::_lstore_2:
3092     set_pair_local( 2, pop_pair() );
3093     break;
3094   case Bytecodes::_lstore_3:
3095     set_pair_local( 3, pop_pair() );
3096     break;
3097   case Bytecodes::_lstore:
3098     set_pair_local( iter().get_index(), pop_pair() );
3099     break;
3100 
3101   // double stores
3102   case Bytecodes::_dstore_0:
3103     set_pair_local( 0, pop_pair() );
3104     break;
3105   case Bytecodes::_dstore_1:
3106     set_pair_local( 1, pop_pair() );
3107     break;
3108   case Bytecodes::_dstore_2:
3109     set_pair_local( 2, pop_pair() );
3110     break;
3111   case Bytecodes::_dstore_3:
3112     set_pair_local( 3, pop_pair() );
3113     break;
3114   case Bytecodes::_dstore:
3115     set_pair_local( iter().get_index(), pop_pair() );
3116     break;
3117 
3118   case Bytecodes::_pop:  dec_sp(1);   break;
3119   case Bytecodes::_pop2: dec_sp(2);   break;
3120   case Bytecodes::_swap:
3121     a = pop();
3122     b = pop();
3123     push(a);
3124     push(b);
3125     break;
3126   case Bytecodes::_dup:
3127     a = pop();
3128     push(a);
3129     push(a);
3130     break;
3131   case Bytecodes::_dup_x1:
3132     a = pop();
3133     b = pop();
3134     push( a );
3135     push( b );
3136     push( a );
3137     break;
3138   case Bytecodes::_dup_x2:
3139     a = pop();
3140     b = pop();
3141     c = pop();
3142     push( a );
3143     push( c );
3144     push( b );
3145     push( a );
3146     break;
3147   case Bytecodes::_dup2:
3148     a = pop();
3149     b = pop();
3150     push( b );
3151     push( a );
3152     push( b );
3153     push( a );
3154     break;
3155 
3156   case Bytecodes::_dup2_x1:
3157     // before: .. c, b, a
3158     // after:  .. b, a, c, b, a
3159     // not tested
3160     a = pop();
3161     b = pop();
3162     c = pop();
3163     push( b );
3164     push( a );
3165     push( c );
3166     push( b );
3167     push( a );
3168     break;
3169   case Bytecodes::_dup2_x2:
3170     // before: .. d, c, b, a
3171     // after:  .. b, a, d, c, b, a
3172     // not tested
3173     a = pop();
3174     b = pop();
3175     c = pop();
3176     d = pop();
3177     push( b );
3178     push( a );
3179     push( d );
3180     push( c );
3181     push( b );
3182     push( a );
3183     break;
3184 
3185   case Bytecodes::_arraylength: {
3186     // Must do null-check with value on expression stack
3187     Node *ary = null_check(peek(), T_ARRAY);
3188     // Compile-time detect of null-exception?
3189     if (stopped())  return;
3190     a = pop();
3191     push(load_array_length(a));
3192     break;
3193   }
3194 
3195   case Bytecodes::_baload:  array_load(T_BYTE);    break;
3196   case Bytecodes::_caload:  array_load(T_CHAR);    break;
3197   case Bytecodes::_iaload:  array_load(T_INT);     break;
3198   case Bytecodes::_saload:  array_load(T_SHORT);   break;
3199   case Bytecodes::_faload:  array_load(T_FLOAT);   break;
3200   case Bytecodes::_aaload:  array_load(T_OBJECT);  break;
3201   case Bytecodes::_laload:  array_load(T_LONG);    break;
3202   case Bytecodes::_daload:  array_load(T_DOUBLE);  break;
3203   case Bytecodes::_bastore: array_store(T_BYTE);   break;
3204   case Bytecodes::_castore: array_store(T_CHAR);   break;
3205   case Bytecodes::_iastore: array_store(T_INT);    break;
3206   case Bytecodes::_sastore: array_store(T_SHORT);  break;
3207   case Bytecodes::_fastore: array_store(T_FLOAT);  break;
3208   case Bytecodes::_aastore: array_store(T_OBJECT); break;
3209   case Bytecodes::_lastore: array_store(T_LONG);   break;
3210   case Bytecodes::_dastore: array_store(T_DOUBLE); break;
3211 
3212   case Bytecodes::_getfield:
3213     do_getfield();
3214     break;
3215 
3216   case Bytecodes::_getstatic:
3217     do_getstatic();
3218     break;
3219 
3220   case Bytecodes::_putfield:
3221     do_putfield();
3222     break;
3223 
3224   case Bytecodes::_putstatic:
3225     do_putstatic();
3226     break;
3227 
3228   case Bytecodes::_irem:
3229     // Must keep both values on the expression-stack during null-check
3230     zero_check_int(peek());
3231     // Compile-time detect of null-exception?
3232     if (stopped())  return;
3233     b = pop();
3234     a = pop();
3235     push(_gvn.transform(new ModINode(control(), a, b)));
3236     break;
3237   case Bytecodes::_idiv:
3238     // Must keep both values on the expression-stack during null-check
3239     zero_check_int(peek());
3240     // Compile-time detect of null-exception?
3241     if (stopped())  return;
3242     b = pop();
3243     a = pop();
3244     push( _gvn.transform( new DivINode(control(),a,b) ) );
3245     break;
3246   case Bytecodes::_imul:
3247     b = pop(); a = pop();
3248     push( _gvn.transform( new MulINode(a,b) ) );
3249     break;
3250   case Bytecodes::_iadd:
3251     b = pop(); a = pop();
3252     push( _gvn.transform( new AddINode(a,b) ) );
3253     break;
3254   case Bytecodes::_ineg:
3255     a = pop();
3256     push( _gvn.transform( new SubINode(_gvn.intcon(0),a)) );
3257     break;
3258   case Bytecodes::_isub:
3259     b = pop(); a = pop();
3260     push( _gvn.transform( new SubINode(a,b) ) );
3261     break;
3262   case Bytecodes::_iand:
3263     b = pop(); a = pop();
3264     push( _gvn.transform( new AndINode(a,b) ) );
3265     break;
3266   case Bytecodes::_ior:
3267     b = pop(); a = pop();
3268     push( _gvn.transform( new OrINode(a,b) ) );
3269     break;
3270   case Bytecodes::_ixor:
3271     b = pop(); a = pop();
3272     push( _gvn.transform( new XorINode(a,b) ) );
3273     break;
3274   case Bytecodes::_ishl:
3275     b = pop(); a = pop();
3276     push( _gvn.transform( new LShiftINode(a,b) ) );
3277     break;
3278   case Bytecodes::_ishr:
3279     b = pop(); a = pop();
3280     push( _gvn.transform( new RShiftINode(a,b) ) );
3281     break;
3282   case Bytecodes::_iushr:
3283     b = pop(); a = pop();
3284     push( _gvn.transform( new URShiftINode(a,b) ) );
3285     break;
3286 
3287   case Bytecodes::_fneg:
3288     a = pop();
3289     b = _gvn.transform(new NegFNode (a));
3290     push(b);
3291     break;
3292 
3293   case Bytecodes::_fsub:
3294     b = pop();
3295     a = pop();
3296     c = _gvn.transform( new SubFNode(a,b) );
3297     push(c);
3298     break;
3299 
3300   case Bytecodes::_fadd:
3301     b = pop();
3302     a = pop();
3303     c = _gvn.transform( new AddFNode(a,b) );
3304     push(c);
3305     break;
3306 
3307   case Bytecodes::_fmul:
3308     b = pop();
3309     a = pop();
3310     c = _gvn.transform( new MulFNode(a,b) );
3311     push(c);
3312     break;
3313 
3314   case Bytecodes::_fdiv:
3315     b = pop();
3316     a = pop();
3317     c = _gvn.transform( new DivFNode(nullptr,a,b) );
3318     push(c);
3319     break;
3320 
3321   case Bytecodes::_frem:
3322     // Generate a ModF node.
3323     b = pop();
3324     a = pop();
3325     push(floating_point_mod(a, b, BasicType::T_FLOAT));
3326     break;
3327 
3328   case Bytecodes::_fcmpl:
3329     b = pop();
3330     a = pop();
3331     c = _gvn.transform( new CmpF3Node( a, b));
3332     push(c);
3333     break;
3334   case Bytecodes::_fcmpg:
3335     b = pop();
3336     a = pop();
3337 
3338     // Same as fcmpl but need to flip the unordered case.  Swap the inputs,
3339     // which negates the result sign except for unordered.  Flip the unordered
3340     // as well by using CmpF3 which implements unordered-lesser instead of
3341     // unordered-greater semantics.  Finally, commute the result bits.  Result
3342     // is same as using a CmpF3Greater except we did it with CmpF3 alone.
3343     c = _gvn.transform( new CmpF3Node( b, a));
3344     c = _gvn.transform( new SubINode(_gvn.intcon(0),c) );
3345     push(c);
3346     break;
3347 
3348   case Bytecodes::_f2i:
3349     a = pop();
3350     push(_gvn.transform(new ConvF2INode(a)));
3351     break;
3352 
3353   case Bytecodes::_d2i:
3354     a = pop_pair();
3355     b = _gvn.transform(new ConvD2INode(a));
3356     push( b );
3357     break;
3358 
3359   case Bytecodes::_f2d:
3360     a = pop();
3361     b = _gvn.transform( new ConvF2DNode(a));
3362     push_pair( b );
3363     break;
3364 
3365   case Bytecodes::_d2f:
3366     a = pop_pair();
3367     b = _gvn.transform( new ConvD2FNode(a));
3368     push( b );
3369     break;
3370 
3371   case Bytecodes::_l2f:
3372     if (Matcher::convL2FSupported()) {
3373       a = pop_pair();
3374       b = _gvn.transform( new ConvL2FNode(a));
3375       push(b);
3376     } else {
3377       l2f();
3378     }
3379     break;
3380 
3381   case Bytecodes::_l2d:
3382     a = pop_pair();
3383     b = _gvn.transform( new ConvL2DNode(a));
3384     push_pair(b);
3385     break;
3386 
3387   case Bytecodes::_f2l:
3388     a = pop();
3389     b = _gvn.transform( new ConvF2LNode(a));
3390     push_pair(b);
3391     break;
3392 
3393   case Bytecodes::_d2l:
3394     a = pop_pair();
3395     b = _gvn.transform( new ConvD2LNode(a));
3396     push_pair(b);
3397     break;
3398 
3399   case Bytecodes::_dsub:
3400     b = pop_pair();
3401     a = pop_pair();
3402     c = _gvn.transform( new SubDNode(a,b) );
3403     push_pair(c);
3404     break;
3405 
3406   case Bytecodes::_dadd:
3407     b = pop_pair();
3408     a = pop_pair();
3409     c = _gvn.transform( new AddDNode(a,b) );
3410     push_pair(c);
3411     break;
3412 
3413   case Bytecodes::_dmul:
3414     b = pop_pair();
3415     a = pop_pair();
3416     c = _gvn.transform( new MulDNode(a,b) );
3417     push_pair(c);
3418     break;
3419 
3420   case Bytecodes::_ddiv:
3421     b = pop_pair();
3422     a = pop_pair();
3423     c = _gvn.transform( new DivDNode(nullptr,a,b) );
3424     push_pair(c);
3425     break;
3426 
3427   case Bytecodes::_dneg:
3428     a = pop_pair();
3429     b = _gvn.transform(new NegDNode (a));
3430     push_pair(b);
3431     break;
3432 
3433   case Bytecodes::_drem:
3434     // Generate a ModD node.
3435     b = pop_pair();
3436     a = pop_pair();
3437     push_pair(floating_point_mod(a, b, BasicType::T_DOUBLE));
3438     break;
3439 
3440   case Bytecodes::_dcmpl:
3441     b = pop_pair();
3442     a = pop_pair();
3443     c = _gvn.transform( new CmpD3Node( a, b));
3444     push(c);
3445     break;
3446 
3447   case Bytecodes::_dcmpg:
3448     b = pop_pair();
3449     a = pop_pair();
3450     // Same as dcmpl but need to flip the unordered case.
3451     // Commute the inputs, which negates the result sign except for unordered.
3452     // Flip the unordered as well by using CmpD3 which implements
3453     // unordered-lesser instead of unordered-greater semantics.
3454     // Finally, negate the result bits.  Result is same as using a
3455     // CmpD3Greater except we did it with CmpD3 alone.
3456     c = _gvn.transform( new CmpD3Node( b, a));
3457     c = _gvn.transform( new SubINode(_gvn.intcon(0),c) );
3458     push(c);
3459     break;
3460 
3461 
3462     // Note for longs -> lo word is on TOS, hi word is on TOS - 1
3463   case Bytecodes::_land:
3464     b = pop_pair();
3465     a = pop_pair();
3466     c = _gvn.transform( new AndLNode(a,b) );
3467     push_pair(c);
3468     break;
3469   case Bytecodes::_lor:
3470     b = pop_pair();
3471     a = pop_pair();
3472     c = _gvn.transform( new OrLNode(a,b) );
3473     push_pair(c);
3474     break;
3475   case Bytecodes::_lxor:
3476     b = pop_pair();
3477     a = pop_pair();
3478     c = _gvn.transform( new XorLNode(a,b) );
3479     push_pair(c);
3480     break;
3481 
3482   case Bytecodes::_lshl:
3483     b = pop();                  // the shift count
3484     a = pop_pair();             // value to be shifted
3485     c = _gvn.transform( new LShiftLNode(a,b) );
3486     push_pair(c);
3487     break;
3488   case Bytecodes::_lshr:
3489     b = pop();                  // the shift count
3490     a = pop_pair();             // value to be shifted
3491     c = _gvn.transform( new RShiftLNode(a,b) );
3492     push_pair(c);
3493     break;
3494   case Bytecodes::_lushr:
3495     b = pop();                  // the shift count
3496     a = pop_pair();             // value to be shifted
3497     c = _gvn.transform( new URShiftLNode(a,b) );
3498     push_pair(c);
3499     break;
3500   case Bytecodes::_lmul:
3501     b = pop_pair();
3502     a = pop_pair();
3503     c = _gvn.transform( new MulLNode(a,b) );
3504     push_pair(c);
3505     break;
3506 
3507   case Bytecodes::_lrem:
3508     // Must keep both values on the expression-stack during null-check
3509     assert(peek(0) == top(), "long word order");
3510     zero_check_long(peek(1));
3511     // Compile-time detect of null-exception?
3512     if (stopped())  return;
3513     b = pop_pair();
3514     a = pop_pair();
3515     c = _gvn.transform( new ModLNode(control(),a,b) );
3516     push_pair(c);
3517     break;
3518 
3519   case Bytecodes::_ldiv:
3520     // Must keep both values on the expression-stack during null-check
3521     assert(peek(0) == top(), "long word order");
3522     zero_check_long(peek(1));
3523     // Compile-time detect of null-exception?
3524     if (stopped())  return;
3525     b = pop_pair();
3526     a = pop_pair();
3527     c = _gvn.transform( new DivLNode(control(),a,b) );
3528     push_pair(c);
3529     break;
3530 
3531   case Bytecodes::_ladd:
3532     b = pop_pair();
3533     a = pop_pair();
3534     c = _gvn.transform( new AddLNode(a,b) );
3535     push_pair(c);
3536     break;
3537   case Bytecodes::_lsub:
3538     b = pop_pair();
3539     a = pop_pair();
3540     c = _gvn.transform( new SubLNode(a,b) );
3541     push_pair(c);
3542     break;
3543   case Bytecodes::_lcmp:
3544     // Safepoints are now inserted _before_ branches.  The long-compare
3545     // bytecode painfully produces a 3-way value (-1,0,+1) which requires a
3546     // slew of control flow.  These are usually followed by a CmpI vs zero and
3547     // a branch; this pattern then optimizes to the obvious long-compare and
3548     // branch.  However, if the branch is backwards there's a Safepoint
3549     // inserted.  The inserted Safepoint captures the JVM state at the
3550     // pre-branch point, i.e. it captures the 3-way value.  Thus if a
3551     // long-compare is used to control a loop the debug info will force
3552     // computation of the 3-way value, even though the generated code uses a
3553     // long-compare and branch.  We try to rectify the situation by inserting
3554     // a SafePoint here and have it dominate and kill the safepoint added at a
3555     // following backwards branch.  At this point the JVM state merely holds 2
3556     // longs but not the 3-way value.
3557     switch (iter().next_bc()) {
3558       case Bytecodes::_ifgt:
3559       case Bytecodes::_iflt:
3560       case Bytecodes::_ifge:
3561       case Bytecodes::_ifle:
3562       case Bytecodes::_ifne:
3563       case Bytecodes::_ifeq:
3564         // If this is a backwards branch in the bytecodes, add Safepoint
3565         maybe_add_safepoint(iter().next_get_dest());
3566       default:
3567         break;
3568     }
3569     b = pop_pair();
3570     a = pop_pair();
3571     c = _gvn.transform( new CmpL3Node( a, b ));
3572     push(c);
3573     break;
3574 
3575   case Bytecodes::_lneg:
3576     a = pop_pair();
3577     b = _gvn.transform( new SubLNode(longcon(0),a));
3578     push_pair(b);
3579     break;
3580   case Bytecodes::_l2i:
3581     a = pop_pair();
3582     push( _gvn.transform( new ConvL2INode(a)));
3583     break;
3584   case Bytecodes::_i2l:
3585     a = pop();
3586     b = _gvn.transform( new ConvI2LNode(a));
3587     push_pair(b);
3588     break;
3589   case Bytecodes::_i2b:
3590     // Sign extend
3591     a = pop();
3592     a = Compile::narrow_value(T_BYTE, a, nullptr, &_gvn, true);
3593     push(a);
3594     break;
3595   case Bytecodes::_i2s:
3596     a = pop();
3597     a = Compile::narrow_value(T_SHORT, a, nullptr, &_gvn, true);
3598     push(a);
3599     break;
3600   case Bytecodes::_i2c:
3601     a = pop();
3602     a = Compile::narrow_value(T_CHAR, a, nullptr, &_gvn, true);
3603     push(a);
3604     break;
3605 
3606   case Bytecodes::_i2f:
3607     a = pop();
3608     b = _gvn.transform( new ConvI2FNode(a) ) ;
3609     push(b);
3610     break;
3611 
3612   case Bytecodes::_i2d:
3613     a = pop();
3614     b = _gvn.transform( new ConvI2DNode(a));
3615     push_pair(b);
3616     break;
3617 
3618   case Bytecodes::_iinc:        // Increment local
3619     i = iter().get_index();     // Get local index
3620     set_local( i, _gvn.transform( new AddINode( _gvn.intcon(iter().get_iinc_con()), local(i) ) ) );
3621     break;
3622 
3623   // Exit points of synchronized methods must have an unlock node
3624   case Bytecodes::_return:
3625     return_current(nullptr);
3626     break;
3627 
3628   case Bytecodes::_ireturn:
3629   case Bytecodes::_areturn:
3630   case Bytecodes::_freturn:
3631     return_current(pop());
3632     break;
3633   case Bytecodes::_lreturn:
3634   case Bytecodes::_dreturn:
3635     return_current(pop_pair());
3636     break;
3637 
3638   case Bytecodes::_athrow:
3639     // null exception oop throws null pointer exception
3640     null_check(peek());
3641     if (stopped())  return;
3642     // Hook the thrown exception directly to subsequent handlers.
3643     if (BailoutToInterpreterForThrows) {
3644       // Keep method interpreted from now on.
3645       uncommon_trap(Deoptimization::Reason_unhandled,
3646                     Deoptimization::Action_make_not_compilable);
3647       return;
3648     }
3649     if (env()->jvmti_can_post_on_exceptions()) {
3650       // check if we must post exception events, take uncommon trap if so (with must_throw = false)
3651       uncommon_trap_if_should_post_on_exceptions(Deoptimization::Reason_unhandled, false);
3652     }
3653     // Here if either can_post_on_exceptions or should_post_on_exceptions is false
3654     add_exception_state(make_exception_state(peek()));
3655     break;
3656 
3657   case Bytecodes::_goto:   // fall through
3658   case Bytecodes::_goto_w: {
3659     int target_bci = (bc() == Bytecodes::_goto) ? iter().get_dest() : iter().get_far_dest();
3660 
3661     // If this is a backwards branch in the bytecodes, add Safepoint
3662     maybe_add_safepoint(target_bci);
3663 
3664     // Merge the current control into the target basic block
3665     merge(target_bci);
3666 
3667     // See if we can get some profile data and hand it off to the next block
3668     Block *target_block = block()->successor_for_bci(target_bci);
3669     if (target_block->pred_count() != 1)  break;
3670     ciMethodData* methodData = method()->method_data();
3671     if (!methodData->is_mature())  break;
3672     ciProfileData* data = methodData->bci_to_data(bci());
3673     assert(data != nullptr && data->is_JumpData(), "need JumpData for taken branch");
3674     int taken = ((ciJumpData*)data)->taken();
3675     taken = method()->scale_count(taken);
3676     target_block->set_count(taken);
3677     break;
3678   }
3679 
3680   case Bytecodes::_ifnull:    btest = BoolTest::eq; goto handle_if_null;
3681   case Bytecodes::_ifnonnull: btest = BoolTest::ne; goto handle_if_null;
3682   handle_if_null:
3683     // If this is a backwards branch in the bytecodes, add Safepoint
3684     maybe_add_safepoint(iter().get_dest());
3685     a = null();
3686     b = pop();
3687     if (b->is_InlineType()) {
3688       // Null checking a scalarized but nullable inline type. Check the null marker
3689       // input instead of the oop input to avoid keeping buffer allocations alive
3690       c = _gvn.transform(new CmpINode(b->as_InlineType()->get_null_marker(), zerocon(T_INT)));
3691     } else {
3692       if (!_gvn.type(b)->speculative_maybe_null() &&
3693           !too_many_traps(Deoptimization::Reason_speculate_null_check)) {
3694         inc_sp(1);
3695         Node* null_ctl = top();
3696         b = null_check_oop(b, &null_ctl, true, true, true);
3697         assert(null_ctl->is_top(), "no null control here");
3698         dec_sp(1);
3699       } else if (_gvn.type(b)->speculative_always_null() &&
3700                  !too_many_traps(Deoptimization::Reason_speculate_null_assert)) {
3701         inc_sp(1);
3702         b = null_assert(b);
3703         dec_sp(1);
3704       }
3705       c = _gvn.transform( new CmpPNode(b, a) );
3706     }
3707     do_ifnull(btest, c);
3708     break;
3709 
3710   case Bytecodes::_if_acmpeq: btest = BoolTest::eq; goto handle_if_acmp;
3711   case Bytecodes::_if_acmpne: btest = BoolTest::ne; goto handle_if_acmp;
3712   handle_if_acmp:
3713     // If this is a backwards branch in the bytecodes, add Safepoint
3714     maybe_add_safepoint(iter().get_dest());
3715     a = pop();
3716     b = pop();
3717     do_acmp(btest, b, a);
3718     break;
3719 
3720   case Bytecodes::_ifeq: btest = BoolTest::eq; goto handle_ifxx;
3721   case Bytecodes::_ifne: btest = BoolTest::ne; goto handle_ifxx;
3722   case Bytecodes::_iflt: btest = BoolTest::lt; goto handle_ifxx;
3723   case Bytecodes::_ifle: btest = BoolTest::le; goto handle_ifxx;
3724   case Bytecodes::_ifgt: btest = BoolTest::gt; goto handle_ifxx;
3725   case Bytecodes::_ifge: btest = BoolTest::ge; goto handle_ifxx;
3726   handle_ifxx:
3727     // If this is a backwards branch in the bytecodes, add Safepoint
3728     maybe_add_safepoint(iter().get_dest());
3729     a = _gvn.intcon(0);
3730     b = pop();
3731     c = _gvn.transform( new CmpINode(b, a) );
3732     do_if(btest, c);
3733     break;
3734 
3735   case Bytecodes::_if_icmpeq: btest = BoolTest::eq; goto handle_if_icmp;
3736   case Bytecodes::_if_icmpne: btest = BoolTest::ne; goto handle_if_icmp;
3737   case Bytecodes::_if_icmplt: btest = BoolTest::lt; goto handle_if_icmp;
3738   case Bytecodes::_if_icmple: btest = BoolTest::le; goto handle_if_icmp;
3739   case Bytecodes::_if_icmpgt: btest = BoolTest::gt; goto handle_if_icmp;
3740   case Bytecodes::_if_icmpge: btest = BoolTest::ge; goto handle_if_icmp;
3741   handle_if_icmp:
3742     // If this is a backwards branch in the bytecodes, add Safepoint
3743     maybe_add_safepoint(iter().get_dest());
3744     a = pop();
3745     b = pop();
3746     c = _gvn.transform( new CmpINode( b, a ) );
3747     do_if(btest, c);
3748     break;
3749 
3750   case Bytecodes::_tableswitch:
3751     do_tableswitch();
3752     break;
3753 
3754   case Bytecodes::_lookupswitch:
3755     do_lookupswitch();
3756     break;
3757 
3758   case Bytecodes::_invokestatic:
3759   case Bytecodes::_invokedynamic:
3760   case Bytecodes::_invokespecial:
3761   case Bytecodes::_invokevirtual:
3762   case Bytecodes::_invokeinterface:
3763     do_call();
3764     break;
3765   case Bytecodes::_checkcast:
3766     do_checkcast();
3767     break;
3768   case Bytecodes::_instanceof:
3769     do_instanceof();
3770     break;
3771   case Bytecodes::_anewarray:
3772     do_newarray();
3773     break;
3774   case Bytecodes::_newarray:
3775     do_newarray((BasicType)iter().get_index());
3776     break;
3777   case Bytecodes::_multianewarray:
3778     do_multianewarray();
3779     break;
3780   case Bytecodes::_new:
3781     do_new();
3782     break;
3783 
3784   case Bytecodes::_jsr:
3785   case Bytecodes::_jsr_w:
3786     do_jsr();
3787     break;
3788 
3789   case Bytecodes::_ret:
3790     do_ret();
3791     break;
3792 
3793 
3794   case Bytecodes::_monitorenter:
3795     do_monitor_enter();
3796     break;
3797 
3798   case Bytecodes::_monitorexit:
3799     do_monitor_exit();
3800     break;
3801 
3802   case Bytecodes::_breakpoint:
3803     // Breakpoint set concurrently to compile
3804     // %%% use an uncommon trap?
3805     C->record_failure("breakpoint in method");
3806     return;
3807 
3808   default:
3809 #ifndef PRODUCT
3810     map()->dump(99);
3811 #endif
3812     tty->print("\nUnhandled bytecode %s\n", Bytecodes::name(bc()) );
3813     ShouldNotReachHere();
3814   }
3815 
3816 #ifndef PRODUCT
3817   if (failing()) { return; }
3818   constexpr int perBytecode = 6;
3819   if (C->should_print_igv(perBytecode)) {
3820     IdealGraphPrinter* printer = C->igv_printer();
3821     char buffer[256];
3822     jio_snprintf(buffer, sizeof(buffer), "Bytecode %d: %s", bci(), Bytecodes::name(bc()));
3823     bool old = printer->traverse_outs();
3824     printer->set_traverse_outs(true);
3825     printer->set_parse(this);
3826     printer->print_graph(buffer);
3827     printer->set_traverse_outs(old);
3828     printer->set_parse(nullptr);
3829   }
3830 #endif
3831 }