math: handle foo = !2;
[smatch.git] / smatch_db.c
blob1ffc222ac2cd51c9fec69b5cbcbdc69272e438d8
1 /*
2 * smatch/smatch_db.c
4 * Copyright (C) 2010 Dan Carpenter.
6 * Licensed under the Open Software License version 1.1
8 */
10 #include <string.h>
11 #include <errno.h>
12 #include <sqlite3.h>
13 #include "smatch.h"
14 #include "smatch_slist.h"
15 #include "smatch_extra.h"
17 static sqlite3 *db;
19 struct def_callback {
20 int hook_type;
21 void (*callback)(const char *name, struct symbol *sym, char *key, char *value);
23 ALLOCATOR(def_callback, "definition db hook callbacks");
24 DECLARE_PTR_LIST(callback_list, struct def_callback);
25 static struct callback_list *callbacks;
27 struct member_info_callback {
28 int owner;
29 void (*callback)(char *fn, int param, char *printed_name, struct smatch_state *state);
31 ALLOCATOR(member_info_callback, "caller_info callbacks");
32 DECLARE_PTR_LIST(member_info_cb_list, struct member_info_callback);
33 static struct member_info_cb_list *member_callbacks;
35 void sql_exec(int (*callback)(void*, int, char**, char**), const char *sql)
37 char *err = NULL;
38 int rc;
40 if (option_no_db || !db)
41 return;
43 rc = sqlite3_exec(db, sql, callback, 0, &err);
44 if (rc != SQLITE_OK) {
45 fprintf(stderr, "SQL error #2: %s\n", err);
46 exit(1);
50 void add_definition_db_callback(void (*callback)(const char *name, struct symbol *sym, char *key, char *value), int type)
52 struct def_callback *def_callback = __alloc_def_callback(0);
54 def_callback->hook_type = type;
55 def_callback->callback = callback;
56 add_ptr_list(&callbacks, def_callback);
59 void add_member_info_callback(int owner, void (*callback)(char *fn, int param, char *printed_name, struct smatch_state *state))
61 struct member_info_callback *member_callback = __alloc_member_info_callback(0);
63 member_callback->owner = owner;
64 member_callback->callback = callback;
65 add_ptr_list(&member_callbacks, member_callback);
68 static struct range_list *return_range_list;
69 static int db_return_callback(void *unused, int argc, char **argv, char **azColName)
71 struct range_list *rl = NULL;
73 if (argc != 1)
74 return 0;
76 get_value_ranges(argv[0], &rl);
77 return_range_list = range_list_union(return_range_list, rl);
79 return 0;
82 struct range_list *db_return_vals(struct expression *expr)
84 struct symbol *sym;
85 static char sql_filter[1024];
87 if (expr->type != EXPR_CALL)
88 return NULL;
89 if (expr->fn->type != EXPR_SYMBOL)
90 return NULL;
91 sym = expr->fn->symbol;
92 if (!sym)
93 return NULL;
95 if (sym->ctype.modifiers & MOD_STATIC) {
96 snprintf(sql_filter, 1024, "file = '%s' and function = '%s';",
97 get_filename(), sym->ident->name);
98 } else {
99 snprintf(sql_filter, 1024, "function = '%s';", sym->ident->name);
102 return_range_list = NULL;
103 run_sql(db_return_callback, "select value from return_info where %s",
104 sql_filter);
105 return return_range_list;
108 static void match_call_hack(struct expression *expr)
110 char *name;
113 * we just want to record something in the database so that if we have
114 * two calls like: frob(4); frob(some_unkown); then on the recieving
115 * side we know that sometimes frob is called with unknown parameters.
118 name = get_fnptr_name(expr->fn);
119 if (!name)
120 return;
121 if (ptr_list_empty(expr->args))
122 return;
123 sm_msg("info: passes param_value '%s' -1 '$$' min-max", name);
124 free_string(name);
127 static void print_struct_members(char *fn, struct expression *expr, int param, struct state_list *slist,
128 void (*callback)(char *fn, int param, char *printed_name, struct smatch_state *state))
130 struct sm_state *sm;
131 char *name;
132 struct symbol *sym;
133 int len;
134 char printed_name[256];
135 int is_address = 0;
137 expr = strip_expr(expr);
138 if (expr->type == EXPR_PREOP && expr->op == '&') {
139 expr = strip_expr(expr->unop);
140 is_address = 1;
143 name = get_variable_from_expr(expr, &sym);
144 if (!name || !sym)
145 goto free;
147 len = strlen(name);
148 FOR_EACH_PTR(slist, sm) {
149 if (sm->sym != sym)
150 continue;
151 if (strncmp(name, sm->name, len) || sm->name[len] == '\0')
152 continue;
153 if (is_address)
154 snprintf(printed_name, sizeof(printed_name), "$$->%s", sm->name + len + 1);
155 else
156 snprintf(printed_name, sizeof(printed_name), "$$%s", sm->name + len);
157 callback(fn, param, printed_name, sm->state);
158 } END_FOR_EACH_PTR(sm);
159 free:
160 free_string(name);
163 static void match_call_info(struct expression *expr)
165 struct member_info_callback *cb;
166 struct expression *arg;
167 struct state_list *slist;
168 char *name;
169 int i;
171 name = get_fnptr_name(expr->fn);
172 if (!name)
173 return;
175 FOR_EACH_PTR(member_callbacks, cb) {
176 slist = get_all_states(cb->owner);
177 i = 0;
178 FOR_EACH_PTR(expr->args, arg) {
179 print_struct_members(name, arg, i, slist, cb->callback);
180 i++;
181 } END_FOR_EACH_PTR(arg);
182 } END_FOR_EACH_PTR(cb);
184 free_string(name);
185 free_slist(&slist);
188 static int get_param(int param, char **name, struct symbol **sym)
190 struct symbol *arg;
191 int i;
193 i = 0;
194 FOR_EACH_PTR(cur_func_sym->ctype.base_type->arguments, arg) {
196 * this is a temporary hack to work around a bug (I think in sparse?)
197 * 2.6.37-rc1:fs/reiserfs/journal.o
198 * If there is a function definition without parameter name found
199 * after a function implementation then it causes a crash.
200 * int foo() {}
201 * int bar(char *);
203 if (arg->ident->name < (char *)100)
204 continue;
205 if (i == param && arg->ident->name) {
206 *name = arg->ident->name;
207 *sym = arg;
208 return TRUE;
210 i++;
211 } END_FOR_EACH_PTR(arg);
213 return FALSE;
216 static struct state_list *final_states;
217 static int prev_func_id = -1;
218 static int db_callback(void *unused, int argc, char **argv, char **azColName)
220 int func_id;
221 long type;
222 long param;
223 char *name;
224 struct symbol *sym;
225 struct def_callback *def_callback;
227 if (argc != 5)
228 return 0;
230 func_id = atoi(argv[0]);
231 errno = 0;
232 type = strtol(argv[1], NULL, 10);
233 param = strtol(argv[2], NULL, 10);
234 if (errno)
235 return 0;
237 if (prev_func_id == -1)
238 prev_func_id = func_id;
239 if (func_id != prev_func_id) {
240 merge_slist(&final_states, __pop_fake_cur_slist());
241 __push_fake_cur_slist();
242 __unnullify_path();
243 prev_func_id = func_id;
246 if (param == -1 || !get_param(param, &name, &sym))
247 return 0;
249 FOR_EACH_PTR(callbacks, def_callback) {
250 if (def_callback->hook_type == type)
251 def_callback->callback(name, sym, argv[3], argv[4]);
252 } END_FOR_EACH_PTR(def_callback);
254 return 0;
257 static void get_direct_callers(struct symbol *sym)
259 char sql_filter[1024];
261 if (sym->ctype.modifiers & MOD_STATIC) {
262 snprintf(sql_filter, 1024,
263 "file = '%s' and function = '%s' order by function_id;",
264 get_filename(), sym->ident->name);
265 } else {
266 snprintf(sql_filter, 1024,
267 "function = '%s' order by function_id;",
268 sym->ident->name);
271 run_sql(db_callback, "select function_id, type, parameter, key, value from caller_info"
272 " where %s", sql_filter);
275 static char *ptr_name;
276 static int get_ptr_name(void *unused, int argc, char **argv, char **azColName)
278 if (!ptr_name)
279 ptr_name = alloc_string(argv[0]);
280 return 0;
283 static void get_function_pointer_callers(struct symbol *sym)
285 ptr_name = NULL;
286 run_sql(get_ptr_name, "select ptr from function_ptr where function = '%s'",
287 sym->ident->name);
288 if (!ptr_name)
289 return;
291 run_sql(db_callback, "select function_id, type, parameter, key, value from caller_info"
292 " where function = '%s' order by function_id", ptr_name);
295 static void match_data_from_db(struct symbol *sym)
297 struct sm_state *sm;
299 if (!sym || !sym->ident || !sym->ident->name)
300 return;
302 __push_fake_cur_slist();
303 __unnullify_path();
304 prev_func_id = -1;
306 get_direct_callers(sym);
307 get_function_pointer_callers(sym);
309 merge_slist(&final_states, __pop_fake_cur_slist());
311 FOR_EACH_PTR(final_states, sm) {
312 __set_sm(sm);
313 } END_FOR_EACH_PTR(sm);
315 free_slist(&final_states);
318 static void match_function_assign(struct expression *expr)
320 struct expression *right = expr->right;
321 struct symbol *sym;
322 char *fn_name;
323 char *ptr_name;
325 if (right->type == EXPR_PREOP && right->op == '&')
326 right = right->unop;
327 if (right->type != EXPR_SYMBOL)
328 return;
329 sym = get_type(right);
330 if (!sym || sym->type != SYM_FN)
331 return;
333 fn_name = get_variable_from_expr(right, NULL);
334 ptr_name = get_fnptr_name(expr->left);
335 if (!fn_name || !ptr_name)
336 goto free;
338 sm_msg("info: sets_fn_ptr '%s' '%s'", ptr_name, fn_name);
340 free:
341 free_string(fn_name);
342 free_string(ptr_name);
345 static void print_initializer_list(struct expression_list *expr_list,
346 struct symbol *struct_type)
348 struct expression *expr;
349 struct symbol *base_type;
351 FOR_EACH_PTR(expr_list, expr) {
352 if (expr->type == EXPR_INDEX && expr->idx_expression && expr->idx_expression->type == EXPR_INITIALIZER) {
353 print_initializer_list(expr->idx_expression->expr_list, struct_type);
354 continue;
356 if (expr->type != EXPR_IDENTIFIER)
357 continue;
358 if (!expr->expr_ident)
359 continue;
360 if (!expr->ident_expression || !expr->ident_expression->symbol_name)
361 continue;
362 base_type = get_type(expr->ident_expression);
363 if (!base_type || base_type->type != SYM_FN)
364 continue;
365 sm_msg("info: sets_fn_ptr '(struct %s)->%s' '%s'", struct_type->ident->name,
366 expr->expr_ident->name,
367 expr->ident_expression->symbol_name->name);
368 } END_FOR_EACH_PTR(expr);
372 static void global_variable(struct symbol *sym)
374 struct symbol *struct_type;
376 if (!sym->ident)
377 return;
378 if (!sym->initializer || sym->initializer->type != EXPR_INITIALIZER)
379 return;
380 struct_type = get_base_type(sym);
381 if (!struct_type)
382 return;
383 if (struct_type->type == SYM_ARRAY) {
384 struct_type = get_base_type(struct_type);
385 if (!struct_type)
386 return;
388 if (struct_type->type != SYM_STRUCT || !struct_type->ident)
389 return;
390 print_initializer_list(sym->initializer->expr_list, struct_type);
393 void open_smatch_db(void)
395 #ifdef SQLITE_OPEN_READONLY
396 int rc;
398 if (option_no_db)
399 return;
401 rc = sqlite3_open_v2("smatch_db.sqlite", &db, SQLITE_OPEN_READONLY, NULL);
402 if (rc != SQLITE_OK) {
403 option_no_db = 1;
404 return;
406 return;
407 #else
408 option_no_db = 1;
409 return;
410 #endif
413 void register_definition_db_callbacks(int id)
415 if (option_info) {
416 add_hook(&match_call_info, FUNCTION_CALL_HOOK);
417 add_hook(&match_call_hack, FUNCTION_CALL_HOOK);
418 add_hook(&match_function_assign, ASSIGNMENT_HOOK);
419 add_hook(&global_variable, BASE_HOOK);
420 add_hook(&global_variable, DECLARATION_HOOK);
423 if (option_no_db)
424 return;
426 add_hook(&match_data_from_db, FUNC_DEF_HOOK);