
时间:2023-01-08 17:05:21


The following critical loop of a piece of numerical software, written in C++, basically compares two objects by one of their members:


for(int j=n;--j>0;)

a and b are of class ASD:


struct ASD  {
    float e;

I was investigating the effect of putting this comparison in a lightweight member function:


bool test(const ASD& y)const {
    return e<y.e;

and using it like this:


for(int j=n;--j>0;)

The compiler is inlining this function, but the problem is, that the assembly code will be different and cause >10% of runtime overhead. I have to question:



  1. Why is the compiler prodrucing different assembly code?


  2. Why is the produced assembly slower?


EDIT: The second question has been answered by implementing @KamyarSouri's suggestion (j%16). The assembly code now looks almost identical (see http://pastebin.com/diff.php?i=yqXedtPm). The only differences are the lines 18, 33, 48:


000646F9  movzx       edx,dl 


  • The test code: http://pastebin.com/03s3Kvry
  • 测试代码:http://pastebin.com/03s3Kvry
  • The assembly output on MSVC10 with /Ox /Ob2 /Ot /arch:SSE2:
  • MSVC10上的汇编输出是/Ox /Ob2 /Ot /arch:SSE2:编译器内联版本:http://pastebin.com/yqXedtPm手动内联版本:http://pastebin.com/pYSXL77f Difference http://pastebin.com/diff.php?

This chart shows the FLOP/s (up to a scaling factor) for 50 testruns of my code.



The gnuplot script to generate the plot: http://pastebin.com/8amNqya7


Compiler Options:


/Zi /W3 /WX- /MP /Ox /Ob2 /Oi /Ot /Oy /GL /D "WIN32" /D "NDEBUG" /D "_CONSOLE" /D "_UNICODE" /D "UNICODE" /Gm- /EHsc /MT /GS- /Gy /arch:SSE2 /fp:precise /Zc:wchar_t /Zc:forScope /Gd /analyze-

/Zi /W3 /WX- /MP /Ox /Ob2 /Oi /Ot /Oy /GL /D“WIN32”/D“NDEBUG”/D“_CONSOLE”/D“_UNICODE”/D“UNICODE”/D“UNICODE”/Gm /EHsc /MT /GS- /Gy /arch:SSE2 /fp:精确/Zc

Linker Options: /INCREMENTAL:NO "kernel32.lib" "user32.lib" "gdi32.lib" "winspool.lib" "comdlg32.lib" "advapi32.lib" "shell32.lib" "ole32.lib" "oleaut32.lib" "uuid.lib" "odbc32.lib" "odbccp32.lib" /ALLOWISOLATION /MANIFESTUAC:"level='asInvoker' uiAccess='false'" /SUBSYSTEM:CONSOLE /OPT:REF /OPT:ICF /LTCG /TLBID:1 /DYNAMICBASE /NXCOMPAT /MACHINE:X86 /ERRORREPORT:QUEUE

链接器选项:kernel32 /增量:不”。*”“user32。*”“gdi32。*”“winspool。*”“comdlg32。*”“advapi32。*”“shell32。*”“ole32。*”“oleaut32。*”“uuid。*”“odbc32。*”“odbccp32。"level='asInvoker' uiAccess='false' > /子系统:控制台/OPT:REF /OPT:ICF /LTCG /TLBID:1 /DYNAMICBASE /NXCOMPAT /MACHINE:X86 /ERRORREPORT:QUEUE

2 个解决方案



Short Answer:

Your asd array is declared as this:


int *asd=new int[16];

Therefore, use int as the return type rather than bool.
Alternatively, change the array type to bool.


In any case, make the return type of the test function match the type of the array.


Skip to bottom for more details.


Long Answer:

In the manually inlined version, the "core" of one iteration looks like this:


xor         eax,eax  

mov         edx,ecx  
and         edx,0Fh  
mov         dword ptr [ebp+edx*4],eax  
mov         eax,dword ptr [esp+1Ch]  
movss       xmm0,dword ptr [eax]  
movss       xmm1,dword ptr [edi]  
cvtps2pd    xmm0,xmm0  
cvtps2pd    xmm1,xmm1  
comisd      xmm1,xmm0  

The compiler inlined version is completely identical except for the first instruction.


Where instead of:


xor         eax,eax

it has:


xor         eax,eax  
movzx       edx,al

Okay, so it's one extra instruction. They both do the same - zeroing a register. This is the only difference that I see...


The movzx instruction has a single-cycle latency and 0.33 cycle reciprocal throughput on all the newer architectures. So I can't imagine how this could make a 10% difference.


In both cases, the result of the zeroing is used only 3 instructions later. So it's very possible that this could be on the critical path of execution.


While I'm not an Intel engineer, here's my guess:


Most modern processors deal with zeroing operations (such as xor eax,eax) via register renaming to a bank of zero registers. It completely bypasses the execution units. However, it's possible that this special handling could cause a pipeline bubble when the (partial) register is accessed via movzx edi,al.

大多数现代处理器通过将寄存器重命名为一个零寄存器组来处理归零操作(如xor eax、eax)。它完全绕过执行单元。然而,当(部分)寄存器通过movzx edi被访问时,这种特殊处理可能会导致管道泡沫。

Furthermore, there's also a false dependency on eax in the compiler inlined version:


movzx       edx,al  
mov         eax,ecx  //  False dependency on "eax".

Whether or not the out-of-order execution is able to resolve this is beyond me.


Okay, this is basically turning into a question of reverse-engineering the MSVC compiler...

Here I'll to explain why that extra movzx is generated as well as why it stays.


The key here is the bool return value. Apparently, bool datatypes are probably as stored 8-bit values inside the MSVC internal-representation. Therefore when you implicitly convert from bool to int here:


asd[j%16] = a.test(b);
^^^^^^^^^   ^^^^^^^^^
 type int   type bool

there is an 8-bit -> 32-bit integer promotion. This is the reason why MSVC generates the movzx instruction.

有一个8位> 32位整数提升。这就是MSVC生成movzx指令的原因。

When the inlining is done manually, the compiler has enough information to optimize out this conversion and keeps everything as a 32-bit datatype IR.


However, when the code is put into it's own function with a bool return value, the compiler is not able to optimize out the 8-bit intermediate datatype. Therefore, the movzx stays.


When you make both datatypes the same (either int or bool), no conversion is needed. Hence the problem is avoided altogether.




lea esp,[esp] occupies 7 bytes of i-cache and it's inside the loop. A few other clues make it look like the compiler isn't sure if this is a release build or a debug build.

lea esp [esp]占用i-cache的7字节,它在循环中。其他一些线索使编译器看起来不确定这是一个发布版本还是一个调试版本。



The lea esp,[esp] isn't in the loop. The position among the surrounding instructions misled me. Now it looks like it intentionally wasted 7 bytes, followed by another wasted 2 bytes, in order to start the actual loop at a 16-byte boundary. Which means that this actually speeds things up, as observed by Johennes Gerer.

lea esp (esp)不在这个圈子里。周围指示的位置误导了我。现在看起来它故意浪费了7个字节,然后又浪费了2个字节,以便在16字节的边界上启动实际的循环。这意味着这实际上加速了事情的发展,正如约翰内斯·杰勒观察到的那样。

The compiler still seems to be uncertain whether this is a debug or release build though.


Another edit:


The pastebin diff is different from the pastebin diff that I saw earlier. This answer could be deleted now, but it already has comments so I'll leave it.

pastebin diff不同于我之前看到的pastebin diff。这个答案现在可以删除了,但是它已经有注释了,所以我就不写了。



Short Answer:

Your asd array is declared as this:


int *asd=new int[16];

Therefore, use int as the return type rather than bool.
Alternatively, change the array type to bool.


In any case, make the return type of the test function match the type of the array.


Skip to bottom for more details.


Long Answer:

In the manually inlined version, the "core" of one iteration looks like this:


xor         eax,eax  

mov         edx,ecx  
and         edx,0Fh  
mov         dword ptr [ebp+edx*4],eax  
mov         eax,dword ptr [esp+1Ch]  
movss       xmm0,dword ptr [eax]  
movss       xmm1,dword ptr [edi]  
cvtps2pd    xmm0,xmm0  
cvtps2pd    xmm1,xmm1  
comisd      xmm1,xmm0  

The compiler inlined version is completely identical except for the first instruction.


Where instead of:


xor         eax,eax

it has:


xor         eax,eax  
movzx       edx,al

Okay, so it's one extra instruction. They both do the same - zeroing a register. This is the only difference that I see...


The movzx instruction has a single-cycle latency and 0.33 cycle reciprocal throughput on all the newer architectures. So I can't imagine how this could make a 10% difference.


In both cases, the result of the zeroing is used only 3 instructions later. So it's very possible that this could be on the critical path of execution.


While I'm not an Intel engineer, here's my guess:


Most modern processors deal with zeroing operations (such as xor eax,eax) via register renaming to a bank of zero registers. It completely bypasses the execution units. However, it's possible that this special handling could cause a pipeline bubble when the (partial) register is accessed via movzx edi,al.

大多数现代处理器通过将寄存器重命名为一个零寄存器组来处理归零操作(如xor eax、eax)。它完全绕过执行单元。然而,当(部分)寄存器通过movzx edi被访问时,这种特殊处理可能会导致管道泡沫。

Furthermore, there's also a false dependency on eax in the compiler inlined version:


movzx       edx,al  
mov         eax,ecx  //  False dependency on "eax".

Whether or not the out-of-order execution is able to resolve this is beyond me.


Okay, this is basically turning into a question of reverse-engineering the MSVC compiler...

Here I'll to explain why that extra movzx is generated as well as why it stays.


The key here is the bool return value. Apparently, bool datatypes are probably as stored 8-bit values inside the MSVC internal-representation. Therefore when you implicitly convert from bool to int here:


asd[j%16] = a.test(b);
^^^^^^^^^   ^^^^^^^^^
 type int   type bool

there is an 8-bit -> 32-bit integer promotion. This is the reason why MSVC generates the movzx instruction.

有一个8位> 32位整数提升。这就是MSVC生成movzx指令的原因。

When the inlining is done manually, the compiler has enough information to optimize out this conversion and keeps everything as a 32-bit datatype IR.


However, when the code is put into it's own function with a bool return value, the compiler is not able to optimize out the 8-bit intermediate datatype. Therefore, the movzx stays.


When you make both datatypes the same (either int or bool), no conversion is needed. Hence the problem is avoided altogether.




lea esp,[esp] occupies 7 bytes of i-cache and it's inside the loop. A few other clues make it look like the compiler isn't sure if this is a release build or a debug build.

lea esp [esp]占用i-cache的7字节,它在循环中。其他一些线索使编译器看起来不确定这是一个发布版本还是一个调试版本。



The lea esp,[esp] isn't in the loop. The position among the surrounding instructions misled me. Now it looks like it intentionally wasted 7 bytes, followed by another wasted 2 bytes, in order to start the actual loop at a 16-byte boundary. Which means that this actually speeds things up, as observed by Johennes Gerer.

lea esp (esp)不在这个圈子里。周围指示的位置误导了我。现在看起来它故意浪费了7个字节,然后又浪费了2个字节,以便在16字节的边界上启动实际的循环。这意味着这实际上加速了事情的发展,正如约翰内斯·杰勒观察到的那样。

The compiler still seems to be uncertain whether this is a debug or release build though.


Another edit:


The pastebin diff is different from the pastebin diff that I saw earlier. This answer could be deleted now, but it already has comments so I'll leave it.

pastebin diff不同于我之前看到的pastebin diff。这个答案现在可以删除了,但是它已经有注释了,所以我就不写了。