2 * sparse/smatch_extra.c
4 * Copyright (C) 2008 Dan Carpenter.
6 * Licensed under the Open Software License version 1.1
11 * smatch_extra.c is supposed to track the value of every variable.
21 #include "smatch_slist.h"
22 #include "smatch_extra.h"
26 static struct symbol
*cur_func
;
28 struct data_range whole_range
= {
33 static struct data_info
*alloc_dinfo(void)
35 struct data_info
*ret
;
37 ret
= __alloc_data_info(0);
39 ret
->type
= DATA_RANGE
;
40 ret
->value_ranges
= NULL
;
44 static struct data_info
*alloc_dinfo_range(long long min
, long long max
)
46 struct data_info
*ret
;
49 add_range(&ret
->value_ranges
, min
, max
);
53 static struct data_info
*alloc_dinfo_range_list(struct range_list
*rl
)
55 struct data_info
*ret
;
58 ret
->value_ranges
= rl
;
62 static struct smatch_state
*alloc_extra_state_empty(void)
64 struct smatch_state
*state
;
65 struct data_info
*dinfo
;
67 dinfo
= alloc_dinfo();
68 state
= __alloc_smatch_state(0);
73 static struct smatch_state
*alloc_extra_state_no_name(int val
)
75 struct smatch_state
*state
;
77 state
= __alloc_smatch_state(0);
78 state
->data
= (void *)alloc_dinfo_range(val
, val
);
82 /* We do this because ->value_ranges is a list */
83 struct smatch_state
*extra_undefined(void)
85 struct data_info
*dinfo
;
86 static struct smatch_state
*ret
;
87 static struct symbol
*prev_func
;
89 if (prev_func
== cur_func
)
93 dinfo
= alloc_dinfo_range(whole_range
.min
, whole_range
.max
);
94 ret
= __alloc_smatch_state(0);
95 ret
->name
= "unknown";
100 struct smatch_state
*alloc_extra_state(long long val
)
102 struct smatch_state
*state
;
104 state
= alloc_extra_state_no_name(val
);
105 state
->name
= show_ranges(get_dinfo(state
)->value_ranges
);
109 struct smatch_state
*alloc_extra_state_range(long long min
, long long max
)
111 struct smatch_state
*state
;
113 if (min
== whole_range
.min
&& max
== whole_range
.max
)
114 return extra_undefined();
115 state
= __alloc_smatch_state(0);
116 state
->data
= (void *)alloc_dinfo_range(min
, max
);
117 state
->name
= show_ranges(get_dinfo(state
)->value_ranges
);
121 struct smatch_state
*alloc_extra_state_range_list(struct range_list
*rl
)
123 struct smatch_state
*state
;
125 state
= __alloc_smatch_state(0);
126 state
->data
= (void *)alloc_dinfo_range_list(rl
);
127 state
->name
= show_ranges(get_dinfo(state
)->value_ranges
);
131 struct data_info
*get_dinfo(struct smatch_state
*state
)
135 return (struct data_info
*)state
->data
;
139 struct smatch_state
*filter_range(struct smatch_state
*orig
,
140 long long filter_min
, long long filter_max
)
142 struct smatch_state
*ret
;
143 struct data_info
*orig_info
;
144 struct data_info
*ret_info
;
147 orig
= extra_undefined();
148 orig_info
= get_dinfo(orig
);
149 ret
= alloc_extra_state_empty();
150 ret_info
= get_dinfo(ret
);
151 ret_info
->value_ranges
= remove_range(orig_info
->value_ranges
, filter_min
, filter_max
);
152 ret
->name
= show_ranges(ret_info
->value_ranges
);
156 struct smatch_state
*add_filter(struct smatch_state
*orig
, long long num
)
158 return filter_range(orig
, num
, num
);
161 static struct smatch_state
*merge_func(const char *name
, struct symbol
*sym
,
162 struct smatch_state
*s1
,
163 struct smatch_state
*s2
)
165 struct data_info
*info1
= get_dinfo(s1
);
166 struct data_info
*info2
= get_dinfo(s2
);
167 struct data_info
*ret_info
;
168 struct smatch_state
*tmp
;
169 struct range_list
*value_ranges
;
171 value_ranges
= range_list_union(info1
->value_ranges
, info2
->value_ranges
);
172 tmp
= alloc_extra_state_empty();
173 ret_info
= get_dinfo(tmp
);
174 ret_info
->value_ranges
= value_ranges
;
175 tmp
->name
= show_ranges(ret_info
->value_ranges
);
179 static struct sm_state
*handle_canonical_while_count_down(struct statement
*loop
)
181 struct expression
*iter_var
;
182 struct expression
*condition
;
186 condition
= strip_expr(loop
->iterator_pre_condition
);
189 if (condition
->type
!= EXPR_PREOP
&& condition
->type
!= EXPR_POSTOP
)
191 if (condition
->op
!= SPECIAL_DECREMENT
)
194 iter_var
= condition
->unop
;
195 sm
= get_sm_state_expr(SMATCH_EXTRA
, iter_var
);
198 if (get_dinfo_min(get_dinfo(sm
->state
)) < 0)
200 start
= get_dinfo_max(get_dinfo(sm
->state
));
203 if (start
!= whole_range
.max
)
206 if (condition
->type
== EXPR_PREOP
)
207 set_state_expr(SMATCH_EXTRA
, iter_var
, alloc_extra_state_range(1, start
));
208 if (condition
->type
== EXPR_POSTOP
)
209 set_state_expr(SMATCH_EXTRA
, iter_var
, alloc_extra_state_range(0, start
));
210 return get_sm_state_expr(SMATCH_EXTRA
, iter_var
);
213 static struct sm_state
*handle_canonical_for_loops(struct statement
*loop
)
215 struct expression
*iter_expr
;
216 struct expression
*iter_var
;
217 struct expression
*condition
;
222 if (!loop
->iterator_post_statement
)
224 if (loop
->iterator_post_statement
->type
!= STMT_EXPRESSION
)
226 iter_expr
= loop
->iterator_post_statement
->expression
;
227 if (!loop
->iterator_pre_condition
)
229 if (loop
->iterator_pre_condition
->type
!= EXPR_COMPARE
)
231 condition
= loop
->iterator_pre_condition
;
234 if (iter_expr
->op
!= SPECIAL_INCREMENT
)
236 iter_var
= iter_expr
->unop
;
237 sm
= get_sm_state_expr(SMATCH_EXTRA
, iter_var
);
240 if (!get_single_value_from_dinfo(get_dinfo(sm
->state
), &start
))
242 if (!get_implied_value(condition
->right
, &end
))
243 end
= whole_range
.max
;
244 if (get_sm_state_expr(SMATCH_EXTRA
, condition
->left
) != sm
)
247 switch (condition
->op
) {
248 case SPECIAL_NOTEQUAL
:
250 if (end
!= whole_range
.max
)
260 set_state_expr(SMATCH_EXTRA
, iter_var
, alloc_extra_state_range(start
, end
));
261 return get_sm_state_expr(SMATCH_EXTRA
, iter_var
);
264 struct sm_state
*__extra_handle_canonical_loops(struct statement
*loop
, struct state_list
**slist
)
266 struct sm_state
*ret
;
269 if (!loop
->iterator_post_statement
)
270 ret
= handle_canonical_while_count_down(loop
);
272 ret
= handle_canonical_for_loops(loop
);
273 *slist
= __fake_cur_slist
;
274 __fake_cur_slist
= NULL
;
279 int __iterator_unchanged(struct sm_state
*sm
)
283 if (get_sm_state(my_id
, sm
->name
, sm
->sym
) == sm
)
288 static void while_count_down_after(struct sm_state
*sm
, struct expression
*condition
)
290 long long after_value
;
292 /* paranoid checking. prolly not needed */
293 condition
= strip_expr(condition
);
296 if (condition
->type
!= EXPR_PREOP
&& condition
->type
!= EXPR_POSTOP
)
298 if (condition
->op
!= SPECIAL_DECREMENT
)
300 after_value
= get_dinfo_min(get_dinfo(sm
->state
));
302 set_state(SMATCH_EXTRA
, sm
->name
, sm
->sym
, alloc_extra_state(after_value
));
305 void __extra_pre_loop_hook_after(struct sm_state
*sm
,
306 struct statement
*iterator
,
307 struct expression
*condition
)
309 struct expression
*iter_expr
;
314 struct smatch_state
*state
;
315 struct data_info
*dinfo
;
319 while_count_down_after(sm
, condition
);
323 iter_expr
= iterator
->expression
;
325 if (condition
->type
!= EXPR_COMPARE
)
327 if (!get_value(condition
->left
, &value
)) {
328 if (!get_value(condition
->right
, &value
))
333 name
= get_variable_from_expr(condition
->left
, &sym
);
335 name
= get_variable_from_expr(condition
->right
, &sym
);
338 if (sym
!= sm
->sym
|| strcmp(name
, sm
->name
))
340 state
= get_state(my_id
, name
, sym
);
341 dinfo
= get_dinfo(state
);
342 min
= get_dinfo_min(dinfo
);
343 max
= get_dinfo_max(dinfo
);
344 if (iter_expr
->op
== SPECIAL_INCREMENT
&& min
!= whole_range
.min
&& max
== whole_range
.max
) {
345 set_state(my_id
, name
, sym
, alloc_extra_state(min
));
346 } else if (min
== whole_range
.min
&& max
!= whole_range
.max
) {
347 set_state(my_id
, name
, sym
, alloc_extra_state(max
));
354 static struct smatch_state
*unmatched_state(struct sm_state
*sm
)
356 return extra_undefined();
359 static void match_function_call(struct expression
*expr
)
361 struct expression
*tmp
;
366 FOR_EACH_PTR(expr
->args
, tmp
) {
367 if (tmp
->type
== EXPR_PREOP
&& tmp
->op
== '&') {
368 name
= get_variable_from_expr(tmp
->unop
, &sym
);
370 set_state(my_id
, name
, sym
, extra_undefined());
375 } END_FOR_EACH_PTR(tmp
);
378 static void match_assign(struct expression
*expr
)
380 struct expression
*left
;
381 struct expression
*right
;
386 long long min
= whole_range
.min
;
387 long long max
= whole_range
.max
;
389 struct range_list
*rl
= NULL
;
391 left
= strip_expr(expr
->left
);
392 name
= get_variable_from_expr(left
, &sym
);
395 right
= strip_expr(expr
->right
);
396 while (right
->type
== EXPR_ASSIGNMENT
&& right
->op
== '=')
397 right
= strip_expr(right
->left
);
399 known
= get_implied_range_list(right
, &rl
);
400 if (expr
->op
== '=') {
402 set_state(my_id
, name
, sym
, alloc_extra_state_range_list(rl
));
404 set_state(my_id
, name
, sym
, extra_undefined());
408 known
= get_implied_value(right
, &value
);
409 if (expr
->op
== SPECIAL_ADD_ASSIGN
) {
410 if (get_implied_min(left
, &tmp
)) {
418 if (expr
->op
== SPECIAL_SUB_ASSIGN
) {
419 if (get_implied_max(left
, &tmp
)) {
427 set_state(my_id
, name
, sym
, alloc_extra_state_range(min
, max
));
432 static void unop_expr(struct expression
*expr
)
436 long long min
= whole_range
.min
;
437 long long max
= whole_range
.max
;
447 name
= get_variable_from_expr(expr
->unop
, &sym
);
450 if (expr
->op
== SPECIAL_INCREMENT
) {
451 if (get_implied_min(expr
->unop
, &val
))
454 if (expr
->op
== SPECIAL_DECREMENT
) {
455 if (get_implied_max(expr
->unop
, &val
))
458 set_state(my_id
, name
, sym
, alloc_extra_state_range(min
, max
));
463 static void match_declarations(struct symbol
*sym
)
469 name
= sym
->ident
->name
;
470 if (sym
->initializer
) {
471 if (get_value(sym
->initializer
, &val
))
472 set_state(my_id
, name
, sym
, alloc_extra_state(val
));
474 set_state(my_id
, name
, sym
, extra_undefined());
475 scoped_state(my_id
, name
, sym
);
477 set_state(my_id
, name
, sym
, extra_undefined());
478 scoped_state(my_id
, name
, sym
);
483 static void match_function_def(struct symbol
*sym
)
488 FOR_EACH_PTR(sym
->ctype
.base_type
->arguments
, arg
) {
492 set_state(my_id
, arg
->ident
->name
, arg
, extra_undefined());
493 } END_FOR_EACH_PTR(arg
);
500 static int get_implied_value_helper(struct expression
*expr
, long long *val
, int what
)
502 struct smatch_state
*state
;
506 if (get_value(expr
, val
))
509 name
= get_variable_from_expr(expr
, &sym
);
512 state
= get_state(my_id
, name
, sym
);
514 if (!state
|| !state
->data
)
516 if (what
== VAL_SINGLE
)
517 return get_single_value_from_dinfo(get_dinfo(state
), val
);
518 if (what
== VAL_MAX
) {
519 *val
= get_dinfo_max(get_dinfo(state
));
520 if (*val
== whole_range
.max
) /* this means just guessing */
524 *val
= get_dinfo_min(get_dinfo(state
));
525 if (*val
== whole_range
.min
)
530 int get_implied_single_val(struct expression
*expr
, long long *val
)
532 return get_implied_value_helper(expr
, val
, VAL_SINGLE
);
535 int get_implied_max(struct expression
*expr
, long long *val
)
537 return get_implied_value_helper(expr
, val
, VAL_MAX
);
540 int get_implied_min(struct expression
*expr
, long long *val
)
542 return get_implied_value_helper(expr
, val
, VAL_MIN
);
545 int get_implied_single_fuzzy_max(struct expression
*expr
, long long *max
)
548 struct sm_state
*tmp
;
550 if (get_implied_max(expr
, max
))
553 sm
= get_sm_state_expr(SMATCH_EXTRA
, expr
);
557 *max
= whole_range
.min
;
558 FOR_EACH_PTR(sm
->possible
, tmp
) {
561 new_min
= get_dinfo_min(get_dinfo(tmp
->state
));
564 } END_FOR_EACH_PTR(tmp
);
566 if (*max
> whole_range
.min
)
571 int get_implied_single_fuzzy_min(struct expression
*expr
, long long *min
)
574 struct sm_state
*tmp
;
576 if (get_implied_min(expr
, min
))
579 sm
= get_sm_state_expr(SMATCH_EXTRA
, expr
);
583 *min
= whole_range
.max
;
584 FOR_EACH_PTR(sm
->possible
, tmp
) {
587 new_max
= get_dinfo_max(get_dinfo(tmp
->state
));
590 } END_FOR_EACH_PTR(tmp
);
592 if (*min
< whole_range
.max
)
597 static int last_stmt_val(struct statement
*stmt
, long long *val
)
599 struct expression
*expr
;
604 stmt
= last_ptr_list((struct ptr_list
*)stmt
->stmts
);
605 if (stmt
->type
!= STMT_EXPRESSION
)
607 expr
= stmt
->expression
;
608 return get_value(expr
, val
);
611 static void match_comparison(struct expression
*expr
)
616 struct smatch_state
*true_state
;
617 struct smatch_state
*false_state
;
618 struct smatch_state
*orig
;
620 int comparison
= expr
->op
;
621 struct expression
*varies
= expr
->right
;
623 if (!get_value(expr
->left
, &fixed
)) {
624 if (!get_value(expr
->right
, &fixed
))
626 varies
= strip_expr(expr
->left
);
629 if (varies
->op
== SPECIAL_INCREMENT
|| varies
->op
== SPECIAL_DECREMENT
)
630 varies
= varies
->unop
;
631 if (varies
->type
== EXPR_CALL
) {
632 function_comparison(comparison
, varies
, fixed
, left
);
636 name
= get_variable_from_expr(varies
, &sym
);
640 orig
= get_state(my_id
, name
, sym
);
642 orig
= extra_undefined();
644 switch (comparison
) {
646 case SPECIAL_UNSIGNED_LT
:
648 true_state
= filter_range(orig
, fixed
, whole_range
.max
);
649 false_state
= filter_range(orig
, whole_range
.min
, fixed
- 1);
651 true_state
= filter_range(orig
, whole_range
.min
, fixed
);
652 false_state
= filter_range(orig
, fixed
+ 1, whole_range
.max
);
655 case SPECIAL_UNSIGNED_LTE
:
658 true_state
= filter_range(orig
, fixed
+ 1, whole_range
.max
);
659 false_state
= filter_range(orig
, whole_range
.min
, fixed
);
661 true_state
= filter_range(orig
, whole_range
.min
, fixed
- 1);
662 false_state
= filter_range(orig
, fixed
, whole_range
.max
);
666 // todo. print a warning here for impossible conditions.
667 true_state
= alloc_extra_state(fixed
);
668 false_state
= filter_range(orig
, fixed
, fixed
);
670 case SPECIAL_UNSIGNED_GTE
:
673 true_state
= filter_range(orig
, whole_range
.min
, fixed
- 1);
674 false_state
= filter_range(orig
, fixed
, whole_range
.max
);
676 true_state
= filter_range(orig
, fixed
+ 1, whole_range
.max
);
677 false_state
= filter_range(orig
, whole_range
.min
, fixed
);
681 case SPECIAL_UNSIGNED_GT
:
683 true_state
= filter_range(orig
, whole_range
.min
, fixed
);
684 false_state
= filter_range(orig
, fixed
+ 1, whole_range
.max
);
686 true_state
= filter_range(orig
, fixed
, whole_range
.max
);
687 false_state
= filter_range(orig
, whole_range
.min
, fixed
- 1);
690 case SPECIAL_NOTEQUAL
:
691 true_state
= filter_range(orig
, fixed
, fixed
);
692 false_state
= alloc_extra_state(fixed
);
695 sm_msg("unhandled comparison %d\n", comparison
);
698 set_true_false_states(my_id
, name
, sym
, true_state
, false_state
);
703 /* this is actually hooked from smatch_implied.c... it's hacky, yes */
704 void __extra_match_condition(struct expression
*expr
)
708 struct smatch_state
*pre_state
;
709 struct smatch_state
*true_state
;
710 struct smatch_state
*false_state
;
712 expr
= strip_expr(expr
);
713 switch (expr
->type
) {
715 function_comparison(SPECIAL_NOTEQUAL
, expr
, 0, 1);
720 name
= get_variable_from_expr(expr
, &sym
);
723 pre_state
= get_state(my_id
, name
, sym
);
724 true_state
= add_filter(pre_state
, 0);
725 if (possibly_true(SPECIAL_EQUAL
, get_dinfo(pre_state
), 0, 0))
726 false_state
= alloc_extra_state(0);
729 set_true_false_states(my_id
, name
, sym
, true_state
, false_state
);
733 match_comparison(expr
);
735 case EXPR_ASSIGNMENT
:
736 __extra_match_condition(expr
->left
);
741 /* returns 1 if it is not possible for expr to be value, otherwise returns 0 */
742 int implied_not_equal(struct expression
*expr
, long long val
)
746 struct smatch_state
*state
;
749 name
= get_variable_from_expr(expr
, &sym
);
752 state
= get_state(my_id
, name
, sym
);
753 if (!state
|| !state
->data
)
755 ret
= !possibly_false(SPECIAL_NOTEQUAL
, get_dinfo(state
), val
, 1);
761 int known_condition_true(struct expression
*expr
)
768 if (get_value(expr
, &tmp
) && tmp
)
771 expr
= strip_expr(expr
);
772 switch (expr
->type
) {
774 if (expr
->op
== '!') {
775 if (known_condition_false(expr
->unop
))
786 int known_condition_false(struct expression
*expr
)
794 switch (expr
->type
) {
796 if (expr
->op
== '!') {
797 if (known_condition_true(expr
->unop
))
808 static int do_comparison_range(struct expression
*expr
)
812 struct smatch_state
*state
;
815 int poss_true
, poss_false
;
817 if (!get_value(expr
->left
, &value
)) {
818 if (!get_value(expr
->right
, &value
))
823 name
= get_variable_from_expr(expr
->left
, &sym
);
825 name
= get_variable_from_expr(expr
->right
, &sym
);
828 state
= get_state(SMATCH_EXTRA
, name
, sym
);
831 poss_true
= possibly_true(expr
->op
, get_dinfo(state
), value
, left
);
832 poss_false
= possibly_false(expr
->op
, get_dinfo(state
), value
, left
);
833 if (!poss_true
&& !poss_false
)
835 if (poss_true
&& !poss_false
)
837 if (!poss_true
&& poss_false
)
839 if (poss_true
&& poss_false
)
846 int implied_condition_true(struct expression
*expr
)
848 struct statement
*stmt
;
855 if (get_implied_value(expr
, &tmp
) && tmp
)
858 if (expr
->type
== EXPR_POSTOP
)
859 return implied_condition_true(expr
->unop
);
861 if (expr
->type
== EXPR_PREOP
&& expr
->op
== SPECIAL_DECREMENT
)
862 return implied_not_equal(expr
->unop
, 1);
863 if (expr
->type
== EXPR_PREOP
&& expr
->op
== SPECIAL_INCREMENT
)
864 return implied_not_equal(expr
->unop
, -1);
866 expr
= strip_expr(expr
);
867 switch (expr
->type
) {
869 if (do_comparison_range(expr
) == 1)
873 if (expr
->op
== '!') {
874 if (implied_condition_false(expr
->unop
))
878 stmt
= get_block_thing(expr
);
879 if (last_stmt_val(stmt
, &val
) && val
== 1)
883 if (implied_not_equal(expr
, 0) == 1)
890 int implied_condition_false(struct expression
*expr
)
892 struct statement
*stmt
;
893 struct expression
*tmp
;
902 switch (expr
->type
) {
904 if (do_comparison_range(expr
) == 2)
907 if (expr
->op
== '!') {
908 if (implied_condition_true(expr
->unop
))
912 stmt
= get_block_thing(expr
);
913 if (last_stmt_val(stmt
, &val
) && val
== 0)
915 tmp
= strip_expr(expr
);
917 return implied_condition_false(tmp
);
920 if (get_implied_value(expr
, &val
) && val
== 0)
927 int get_implied_range_list(struct expression
*expr
, struct range_list
**rl
)
930 struct smatch_state
*state
;
932 expr
= strip_expr(expr
);
934 state
= get_state_expr(my_id
, expr
);
936 *rl
= clone_range_list(get_dinfo(state
)->value_ranges
);
940 if (get_implied_value(expr
, &val
)) {
942 add_range(rl
, val
, val
);
946 if (expr
->type
== EXPR_BINOP
&& expr
->op
== '%') {
947 if (!get_implied_value(expr
->right
, &val
))
950 add_range(rl
, 0, val
- 1);
957 int is_whole_range(struct smatch_state
*state
)
959 struct data_info
*dinfo
;
960 struct data_range
*drange
;
964 dinfo
= get_dinfo(state
);
965 drange
= first_ptr_list((struct ptr_list
*)dinfo
->value_ranges
);
966 if (drange
->min
== whole_range
.min
&& drange
->max
== whole_range
.max
)
971 void register_smatch_extra(int id
)
974 add_merge_hook(my_id
, &merge_func
);
975 add_unmatched_state_hook(my_id
, &unmatched_state
);
976 add_hook(&unop_expr
, OP_HOOK
);
977 add_hook(&match_function_def
, FUNC_DEF_HOOK
);
978 add_hook(&match_function_call
, FUNCTION_CALL_HOOK
);
979 add_hook(&match_assign
, ASSIGNMENT_HOOK
);
980 add_hook(&match_declarations
, DECLARATION_HOOK
);