core: make the valid pointer range 4096-7777777777
[smatch.git] / smatch_type_val.c
blobb3765db512e8b8f1fa9f5637f9068d09d80ebb64
1 /*
2 * Copyright (C) 2013 Oracle.
4 * This program is free software; you can redistribute it and/or
5 * modify it under the terms of the GNU General Public License
6 * as published by the Free Software Foundation; either version 2
7 * of the License, or (at your option) any later version.
9 * This program is distributed in the hope that it will be useful,
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 * GNU General Public License for more details.
14 * You should have received a copy of the GNU General Public License
15 * along with this program; if not, see http://www.gnu.org/copyleft/gpl.txt
19 * The plan here is to save all the possible values store to a given struct
20 * member.
22 * We will load all the values in to the function_type_val table first then
23 * run a script on that and load all the resulting values into the type_val
24 * table.
26 * So in this file we want to take the union of everything assigned to the
27 * struct member and insert it into the function_type_val at the end.
29 * You would think that we could use smatch_modification_hooks.c or
30 * extra_modification_hook() here to get the information here but in the end we
31 * need to code everything again a third time.
35 #include "smatch.h"
36 #include "smatch_slist.h"
37 #include "smatch_extra.h"
39 static int my_id;
41 struct stree_stack *fn_type_val_stack;
42 struct stree *fn_type_val;
43 struct stree *global_type_val;
45 static char *db_vals;
46 static int get_vals(void *unused, int argc, char **argv, char **azColName)
48 db_vals = alloc_string(argv[0]);
49 return 0;
52 static void match_inline_start(struct expression *expr)
54 push_stree(&fn_type_val_stack, fn_type_val);
55 fn_type_val = NULL;
58 static void match_inline_end(struct expression *expr)
60 free_stree(&fn_type_val);
61 fn_type_val = pop_stree(&fn_type_val_stack);
64 int get_db_type_rl(struct expression *expr, struct range_list **rl)
66 char *member;
67 struct range_list *tmp;
69 member = get_member_name(expr);
70 if (!member)
71 return 0;
73 db_vals = NULL;
74 run_sql(get_vals, NULL,
75 "select value from type_value where type = '%s';", member);
76 free_string(member);
77 if (!db_vals)
78 return 0;
79 str_to_rl(&llong_ctype, db_vals, &tmp);
80 tmp = cast_rl(get_type(expr), tmp);
81 if (is_whole_rl(tmp))
82 return 0;
83 *rl = tmp;
84 free_string(db_vals);
86 return 1;
89 static void add_type_val(char *member, struct range_list *rl)
91 struct smatch_state *old, *add, *new;
93 member = alloc_string(member);
94 old = get_state_stree(fn_type_val, my_id, member, NULL);
95 add = alloc_estate_rl(rl);
96 if (old)
97 new = merge_estates(old, add);
98 else
99 new = add;
100 set_state_stree(&fn_type_val, my_id, member, NULL, new);
103 static void add_fake_type_val(char *member, struct range_list *rl)
105 struct smatch_state *old, *add, *new;
107 member = alloc_string(member);
108 old = get_state_stree(fn_type_val, my_id, member, NULL);
109 if (old && strcmp(old->name, "min-max") == 0)
110 return;
111 add = alloc_estate_rl(rl);
112 if (old) {
113 new = merge_estates(old, add);
114 } else {
115 new = add;
116 new->name = alloc_string("min-max");
118 set_state_stree(&fn_type_val, my_id, member, NULL, new);
121 static void add_global_type_val(char *member, struct range_list *rl)
123 struct smatch_state *old, *add, *new;
125 member = alloc_string(member);
126 old = get_state_stree(global_type_val, my_id, member, NULL);
127 add = alloc_estate_rl(rl);
128 if (old)
129 new = merge_estates(old, add);
130 else
131 new = add;
132 new = clone_estate_perm(new);
133 set_state_stree_perm(&global_type_val, my_id, member, NULL, new);
136 static void match_assign_value(struct expression *expr)
138 char *member, *right_member;
139 struct range_list *rl;
140 struct symbol *type;
142 type = get_type(expr->left);
143 if (type && type->type == SYM_STRUCT)
144 return;
146 member = get_member_name(expr->left);
147 if (!member)
148 return;
150 /* if we're saying foo->mtu = bar->mtu then that doesn't add information */
151 right_member = get_member_name(expr->right);
152 if (right_member && strcmp(right_member, member) == 0)
153 goto free;
155 if (is_fake_call(expr->right)) {
156 add_fake_type_val(member, alloc_whole_rl(get_type(expr->left)));
157 goto free;
160 if (expr->op != '=') {
161 add_type_val(member, alloc_whole_rl(get_type(expr->left)));
162 goto free;
164 get_absolute_rl(expr->right, &rl);
165 rl = cast_rl(type, rl);
166 add_type_val(member, rl);
167 free:
168 free_string(right_member);
169 free_string(member);
173 * If we too: int *p = &my_struct->member then abandon all hope of tracking
174 * my_struct->member.
176 static void match_assign_pointer(struct expression *expr)
178 struct expression *right;
179 char *member;
180 struct range_list *rl;
181 struct symbol *type;
183 right = strip_expr(expr->right);
184 if (right->type != EXPR_PREOP || right->op != '&')
185 return;
186 right = strip_expr(right->unop);
188 member = get_member_name(right);
189 if (!member)
190 return;
191 type = get_type(right);
192 rl = alloc_whole_rl(type);
193 add_type_val(member, rl);
194 free_string(member);
197 static void match_global_assign(struct expression *expr)
199 char *member;
200 struct range_list *rl;
202 member = get_member_name(expr->left);
203 if (!member)
204 return;
205 get_absolute_rl(expr->right, &rl);
206 add_global_type_val(member, rl);
207 free_string(member);
210 static void unop_expr(struct expression *expr)
212 struct range_list *rl;
213 char *member;
215 if (expr->op != SPECIAL_DECREMENT && expr->op != SPECIAL_INCREMENT)
216 return;
218 expr = strip_expr(expr->unop);
219 member = get_member_name(expr);
220 if (!member)
221 return;
222 rl = alloc_whole_rl(get_type(expr));
223 add_type_val(member, rl);
224 free_string(member);
227 static void asm_expr(struct statement *stmt)
229 struct expression *expr;
230 struct range_list *rl;
231 char *member;
232 int state = 0;
234 FOR_EACH_PTR(stmt->asm_outputs, expr) {
235 switch (state) {
236 case 0: /* identifier */
237 case 1: /* constraint */
238 state++;
239 continue;
240 case 2: /* expression */
241 state = 0;
242 member = get_member_name(expr);
243 if (!member)
244 continue;
245 rl = alloc_whole_rl(get_type(expr));
246 add_type_val(member, rl);
247 free_string(member);
248 continue;
250 } END_FOR_EACH_PTR(expr);
253 static void db_param_add(struct expression *expr, int param, char *key, char *value)
255 struct expression *arg;
256 struct symbol *type;
257 struct range_list *rl;
258 char *member;
260 if (strcmp(key, "*$$") != 0)
261 return;
263 while (expr->type == EXPR_ASSIGNMENT)
264 expr = strip_expr(expr->right);
265 if (expr->type != EXPR_CALL)
266 return;
268 arg = get_argument_from_call_expr(expr->args, param);
269 arg = strip_expr(arg);
270 if (!arg)
271 return;
272 type = get_member_type_from_key(arg, key);
273 if (arg->type != EXPR_PREOP || arg->op != '&')
274 return;
275 arg = strip_expr(arg->unop);
277 member = get_member_name(arg);
278 if (!member)
279 return;
280 call_results_to_rl(expr, type, value, &rl);
281 add_type_val(member, rl);
282 free_string(member);
285 static void match_end_func_info(struct symbol *sym)
287 struct sm_state *sm;
289 FOR_EACH_SM(fn_type_val, sm) {
290 sql_insert_function_type_value(sm->name, sm->state->name);
291 } END_FOR_EACH_SM(sm);
293 free_stree(&fn_type_val);
296 static void match_end_file(struct symbol_list *sym_list)
298 struct sm_state *sm;
300 FOR_EACH_SM(global_type_val, sm) {
301 sql_insert_function_type_value(sm->name, sm->state->name);
302 } END_FOR_EACH_SM(sm);
305 void register_type_val(int id)
307 if (!option_info)
308 return;
310 my_id = id;
312 add_hook(&match_assign_value, ASSIGNMENT_HOOK);
313 add_hook(&match_assign_pointer, ASSIGNMENT_HOOK);
314 add_hook(&unop_expr, OP_HOOK);
315 add_hook(&asm_expr, ASM_HOOK);
316 select_return_states_hook(ADDED_VALUE, &db_param_add);
318 add_hook(&match_inline_start, INLINE_FN_START);
319 add_hook(&match_inline_end, INLINE_FN_END);
321 add_hook(&match_end_func_info, END_FUNC_HOOK);
323 add_hook(&match_global_assign, GLOBAL_ASSIGNMENT_HOOK);
324 add_hook(&match_end_file, END_FILE_HOOK);