2 * sparse/smatch_extra.c
4 * Copyright (C) 2008 Dan Carpenter.
6 * Licensed under the Open Software License version 1.1
11 * smatch_extra.c is supposed to track the value of every variable.
21 #include "smatch_slist.h"
22 #include "smatch_extra.h"
26 static struct symbol
*cur_func
;
28 struct data_range whole_range
= {
33 static struct data_info
*alloc_dinfo(void)
35 struct data_info
*ret
;
37 ret
= __alloc_data_info(0);
39 ret
->type
= DATA_RANGE
;
40 ret
->value_ranges
= NULL
;
44 static struct data_info
*alloc_dinfo_range(long long min
, long long max
)
46 struct data_info
*ret
;
49 add_range(&ret
->value_ranges
, min
, max
);
53 static struct data_info
*alloc_dinfo_range_list(struct range_list
*rl
)
55 struct data_info
*ret
;
58 ret
->value_ranges
= rl
;
62 static struct data_info
*clone_dinfo(struct data_info
*dinfo
)
64 struct data_info
*ret
;
67 ret
->equiv
= clone_tracker_list(dinfo
->equiv
);
68 ret
->value_ranges
= clone_range_list(dinfo
->value_ranges
);
72 static struct smatch_state
*clone_extra_state(struct smatch_state
*state
)
74 struct smatch_state
*ret
;
76 ret
= __alloc_smatch_state(0);
77 ret
->name
= state
->name
;
78 ret
->data
= clone_dinfo(get_dinfo(state
));
82 static struct smatch_state
*alloc_extra_state_empty(void)
84 struct smatch_state
*state
;
85 struct data_info
*dinfo
;
87 dinfo
= alloc_dinfo();
88 state
= __alloc_smatch_state(0);
94 static struct smatch_state
*alloc_extra_state_no_name(int val
)
96 struct smatch_state
*state
;
98 state
= __alloc_smatch_state(0);
99 state
->data
= (void *)alloc_dinfo_range(val
, val
);
103 /* We do this because ->value_ranges is a list */
104 struct smatch_state
*extra_undefined(void)
106 struct data_info
*dinfo
;
107 static struct smatch_state
*ret
;
108 static struct symbol
*prev_func
;
110 if (prev_func
== cur_func
)
112 prev_func
= cur_func
;
114 dinfo
= alloc_dinfo_range(whole_range
.min
, whole_range
.max
);
115 ret
= __alloc_smatch_state(0);
116 ret
->name
= "unknown";
121 struct smatch_state
*alloc_extra_state(long long val
)
123 struct smatch_state
*state
;
125 state
= alloc_extra_state_no_name(val
);
126 state
->name
= show_ranges(get_dinfo(state
)->value_ranges
);
130 struct smatch_state
*alloc_extra_state_range(long long min
, long long max
)
132 struct smatch_state
*state
;
134 if (min
== whole_range
.min
&& max
== whole_range
.max
)
135 return extra_undefined();
136 state
= __alloc_smatch_state(0);
137 state
->data
= (void *)alloc_dinfo_range(min
, max
);
138 state
->name
= show_ranges(get_dinfo(state
)->value_ranges
);
142 struct smatch_state
*alloc_extra_state_range_list(struct range_list
*rl
)
144 struct smatch_state
*state
;
146 state
= __alloc_smatch_state(0);
147 state
->data
= (void *)alloc_dinfo_range_list(rl
);
148 state
->name
= show_ranges(get_dinfo(state
)->value_ranges
);
152 static void add_equiv(struct smatch_state
*state
, const char *name
, struct symbol
*sym
)
154 struct data_info
*dinfo
;
156 dinfo
= get_dinfo(state
);
157 add_tracker(&dinfo
->equiv
, SMATCH_EXTRA
, name
, sym
);
160 static void del_equiv(struct smatch_state
*state
, const char *name
, struct symbol
*sym
)
162 struct data_info
*dinfo
;
164 dinfo
= get_dinfo(state
);
165 del_tracker(&dinfo
->equiv
, SMATCH_EXTRA
, name
, sym
);
168 static void remove_from_equiv(const char *name
, struct symbol
*sym
)
170 struct sm_state
*orig_sm
;
171 struct tracker
*tracker
;
172 struct smatch_state
*state
;
173 struct tracker_list
*to_update
;
175 orig_sm
= get_sm_state(SMATCH_EXTRA
, name
, sym
);
176 if (!orig_sm
|| !get_dinfo(orig_sm
->state
)->equiv
)
179 state
= clone_extra_state(orig_sm
->state
);
180 del_equiv(state
, name
, sym
);
181 to_update
= get_dinfo(state
)->equiv
;
182 if (ptr_list_size((struct ptr_list
*)get_dinfo(state
)->equiv
) == 1)
183 get_dinfo(state
)->equiv
= NULL
;
185 FOR_EACH_PTR(to_update
, tracker
) {
186 struct sm_state
*new_sm
;
188 new_sm
= clone_sm(orig_sm
);
189 new_sm
->name
= tracker
->name
;
190 new_sm
->sym
= tracker
->sym
;
191 new_sm
->state
= state
;
193 } END_FOR_EACH_PTR(tracker
);
196 static void remove_from_equiv_expr(struct expression
*expr
)
201 name
= get_variable_from_expr(expr
, &sym
);
204 remove_from_equiv(name
, sym
);
209 struct sm_state
*set_extra_mod(const char *name
, struct symbol
*sym
, struct smatch_state
*state
)
211 remove_from_equiv(name
, sym
);
212 return set_state(SMATCH_EXTRA
, name
, sym
, state
);
215 struct sm_state
*set_extra_expr_mod(struct expression
*expr
, struct smatch_state
*state
)
217 remove_from_equiv_expr(expr
);
218 return set_state_expr(SMATCH_EXTRA
, expr
, state
);
222 * This is for return_implies_state() hooks which modify a SMATCH_EXTRA state
224 void set_extra_expr_nomod(struct expression
*expr
, struct smatch_state
*state
)
226 struct tracker
*tracker
;
227 struct smatch_state
*orig_state
;
229 orig_state
= get_state_expr(SMATCH_EXTRA
, expr
);
231 if (!orig_state
|| !get_dinfo(orig_state
)->equiv
) {
232 set_state_expr(SMATCH_EXTRA
, expr
, state
);
236 FOR_EACH_PTR(get_dinfo(orig_state
)->equiv
, tracker
) {
237 set_state(tracker
->owner
, tracker
->name
, tracker
->sym
, state
);
238 add_equiv(state
, tracker
->name
, tracker
->sym
);
239 } END_FOR_EACH_PTR(tracker
);
242 void set_extra_true_false(const char *name
, struct symbol
*sym
,
243 struct smatch_state
*true_state
,
244 struct smatch_state
*false_state
)
246 struct tracker
*tracker
;
247 struct smatch_state
*orig_state
;
249 orig_state
= get_state(SMATCH_EXTRA
, name
, sym
);
251 if (!orig_state
|| !get_dinfo(orig_state
)->equiv
) {
252 set_true_false_states(SMATCH_EXTRA
, name
, sym
, true_state
, false_state
);
256 FOR_EACH_PTR(get_dinfo(orig_state
)->equiv
, tracker
) {
257 set_true_false_states(tracker
->owner
, tracker
->name
, tracker
->sym
,
258 true_state
, false_state
);
260 add_equiv(true_state
, tracker
->name
, tracker
->sym
);
262 add_equiv(false_state
, tracker
->name
, tracker
->sym
);
263 } END_FOR_EACH_PTR(tracker
);
266 struct data_info
*get_dinfo(struct smatch_state
*state
)
270 return (struct data_info
*)state
->data
;
274 struct smatch_state
*filter_range(struct smatch_state
*orig
,
275 long long filter_min
, long long filter_max
)
277 struct smatch_state
*ret
;
278 struct data_info
*orig_info
;
279 struct data_info
*ret_info
;
282 orig
= extra_undefined();
283 orig_info
= get_dinfo(orig
);
284 ret
= alloc_extra_state_empty();
285 ret_info
= get_dinfo(ret
);
286 ret_info
->value_ranges
= remove_range(orig_info
->value_ranges
, filter_min
, filter_max
);
287 ret
->name
= show_ranges(ret_info
->value_ranges
);
291 struct smatch_state
*add_filter(struct smatch_state
*orig
, long long num
)
293 return filter_range(orig
, num
, num
);
296 static struct smatch_state
*merge_func(const char *name
, struct symbol
*sym
,
297 struct smatch_state
*s1
,
298 struct smatch_state
*s2
)
300 struct data_info
*info1
= get_dinfo(s1
);
301 struct data_info
*info2
= get_dinfo(s2
);
302 struct data_info
*ret_info
;
303 struct smatch_state
*tmp
;
304 struct range_list
*value_ranges
;
305 struct tracker
*tracker
;
307 value_ranges
= range_list_union(info1
->value_ranges
, info2
->value_ranges
);
308 tmp
= alloc_extra_state_empty();
309 ret_info
= get_dinfo(tmp
);
310 ret_info
->value_ranges
= value_ranges
;
311 tmp
->name
= show_ranges(ret_info
->value_ranges
);
312 FOR_EACH_PTR(info1
->equiv
, tracker
) {
313 if (in_tracker_list(info2
->equiv
, tracker
->owner
, tracker
->name
, tracker
->sym
))
314 add_equiv(tmp
, tracker
->name
, tracker
->sym
);
315 } END_FOR_EACH_PTR(tracker
);
319 static struct sm_state
*handle_canonical_while_count_down(struct statement
*loop
)
321 struct expression
*iter_var
;
322 struct expression
*condition
;
326 condition
= strip_expr(loop
->iterator_pre_condition
);
329 if (condition
->type
!= EXPR_PREOP
&& condition
->type
!= EXPR_POSTOP
)
331 if (condition
->op
!= SPECIAL_DECREMENT
)
334 iter_var
= condition
->unop
;
335 sm
= get_sm_state_expr(SMATCH_EXTRA
, iter_var
);
338 if (get_dinfo_min(get_dinfo(sm
->state
)) < 0)
340 start
= get_dinfo_max(get_dinfo(sm
->state
));
343 if (start
!= whole_range
.max
)
346 if (condition
->type
== EXPR_PREOP
)
347 set_extra_expr_mod(iter_var
, alloc_extra_state_range(1, start
));
348 if (condition
->type
== EXPR_POSTOP
)
349 set_extra_expr_mod(iter_var
, alloc_extra_state_range(0, start
));
350 return get_sm_state_expr(SMATCH_EXTRA
, iter_var
);
353 static struct sm_state
*handle_canonical_for_loops(struct statement
*loop
)
355 struct expression
*iter_expr
;
356 struct expression
*iter_var
;
357 struct expression
*condition
;
362 if (!loop
->iterator_post_statement
)
364 if (loop
->iterator_post_statement
->type
!= STMT_EXPRESSION
)
366 iter_expr
= loop
->iterator_post_statement
->expression
;
367 if (!loop
->iterator_pre_condition
)
369 if (loop
->iterator_pre_condition
->type
!= EXPR_COMPARE
)
371 condition
= loop
->iterator_pre_condition
;
374 if (iter_expr
->op
!= SPECIAL_INCREMENT
)
376 iter_var
= iter_expr
->unop
;
377 sm
= get_sm_state_expr(SMATCH_EXTRA
, iter_var
);
380 if (!get_single_value_from_dinfo(get_dinfo(sm
->state
), &start
))
382 if (!get_implied_value(condition
->right
, &end
))
383 end
= whole_range
.max
;
384 if (get_sm_state_expr(SMATCH_EXTRA
, condition
->left
) != sm
)
387 switch (condition
->op
) {
388 case SPECIAL_NOTEQUAL
:
390 if (end
!= whole_range
.max
)
400 set_extra_expr_mod(iter_var
, alloc_extra_state_range(start
, end
));
401 return get_sm_state_expr(SMATCH_EXTRA
, iter_var
);
404 struct sm_state
*__extra_handle_canonical_loops(struct statement
*loop
, struct state_list
**slist
)
406 struct sm_state
*ret
;
408 __push_fake_cur_slist();;
409 if (!loop
->iterator_post_statement
)
410 ret
= handle_canonical_while_count_down(loop
);
412 ret
= handle_canonical_for_loops(loop
);
413 *slist
= __pop_fake_cur_slist();
417 int __iterator_unchanged(struct sm_state
*sm
)
421 if (get_sm_state(my_id
, sm
->name
, sm
->sym
) == sm
)
426 static void while_count_down_after(struct sm_state
*sm
, struct expression
*condition
)
428 long long after_value
;
430 /* paranoid checking. prolly not needed */
431 condition
= strip_expr(condition
);
434 if (condition
->type
!= EXPR_PREOP
&& condition
->type
!= EXPR_POSTOP
)
436 if (condition
->op
!= SPECIAL_DECREMENT
)
438 after_value
= get_dinfo_min(get_dinfo(sm
->state
));
440 set_extra_mod(sm
->name
, sm
->sym
, alloc_extra_state(after_value
));
443 void __extra_pre_loop_hook_after(struct sm_state
*sm
,
444 struct statement
*iterator
,
445 struct expression
*condition
)
447 struct expression
*iter_expr
;
452 struct smatch_state
*state
;
453 struct data_info
*dinfo
;
457 while_count_down_after(sm
, condition
);
461 iter_expr
= iterator
->expression
;
463 if (condition
->type
!= EXPR_COMPARE
)
465 if (!get_value(condition
->left
, &value
)) {
466 if (!get_value(condition
->right
, &value
))
471 name
= get_variable_from_expr(condition
->left
, &sym
);
473 name
= get_variable_from_expr(condition
->right
, &sym
);
476 if (sym
!= sm
->sym
|| strcmp(name
, sm
->name
))
478 state
= get_state(my_id
, name
, sym
);
479 dinfo
= get_dinfo(state
);
480 min
= get_dinfo_min(dinfo
);
481 max
= get_dinfo_max(dinfo
);
482 if (iter_expr
->op
== SPECIAL_INCREMENT
&& min
!= whole_range
.min
&& max
== whole_range
.max
) {
483 set_extra_mod(name
, sym
, alloc_extra_state(min
));
484 } else if (min
== whole_range
.min
&& max
!= whole_range
.max
) {
485 set_extra_mod(name
, sym
, alloc_extra_state(max
));
492 static struct smatch_state
*unmatched_state(struct sm_state
*sm
)
494 return extra_undefined();
497 static void match_function_call(struct expression
*expr
)
499 struct expression
*tmp
;
504 FOR_EACH_PTR(expr
->args
, tmp
) {
505 if (tmp
->type
== EXPR_PREOP
&& tmp
->op
== '&') {
506 name
= get_variable_from_expr(tmp
->unop
, &sym
);
508 set_extra_mod(name
, sym
, extra_undefined());
513 } END_FOR_EACH_PTR(tmp
);
516 static void set_equiv(struct sm_state
*right_sm
, struct expression
*left
)
518 struct smatch_state
*state
;
519 struct data_info
*dinfo
;
520 struct tracker
*tracker
;
524 name
= get_variable_from_expr(left
, &sym
);
528 remove_from_equiv(name
, sym
);
530 state
= clone_extra_state(right_sm
->state
);
531 dinfo
= get_dinfo(state
);
533 add_equiv(state
, right_sm
->name
, right_sm
->sym
);
534 add_equiv(state
, name
, sym
);
536 FOR_EACH_PTR(dinfo
->equiv
, tracker
) {
537 struct sm_state
*new_sm
;
539 new_sm
= clone_sm(right_sm
);
540 new_sm
->name
= tracker
->name
;
541 new_sm
->sym
= tracker
->sym
;
542 new_sm
->state
= state
;
544 } END_FOR_EACH_PTR(tracker
);
549 static void match_assign(struct expression
*expr
)
551 struct expression
*left
;
552 struct expression
*right
;
553 struct sm_state
*right_sm
;
558 long long min
= whole_range
.min
;
559 long long max
= whole_range
.max
;
561 struct range_list
*rl
= NULL
;
563 left
= strip_expr(expr
->left
);
564 name
= get_variable_from_expr(left
, &sym
);
567 right
= strip_expr(expr
->right
);
568 while (right
->type
== EXPR_ASSIGNMENT
&& right
->op
== '=')
569 right
= strip_expr(right
->left
);
571 right_sm
= get_sm_state_expr(SMATCH_EXTRA
, right
);
572 if (expr
->op
== '=' && right_sm
) {
573 set_equiv(right_sm
, left
);
577 known
= get_implied_range_list(right
, &rl
);
578 if (expr
->op
== '=') {
580 set_extra_mod(name
, sym
, alloc_extra_state_range_list(rl
));
582 set_extra_mod(name
, sym
, extra_undefined());
586 known
= get_implied_value(right
, &value
);
587 if (expr
->op
== SPECIAL_ADD_ASSIGN
) {
588 if (get_implied_min(left
, &tmp
)) {
594 if (!inside_loop() && known
&& get_implied_max(left
, &tmp
))
597 if (expr
->op
== SPECIAL_SUB_ASSIGN
) {
598 if (get_implied_max(left
, &tmp
)) {
604 if (!inside_loop() && known
&& get_implied_min(left
, &tmp
))
607 set_extra_mod(name
, sym
, alloc_extra_state_range(min
, max
));
612 static void unop_expr(struct expression
*expr
)
616 long long min
= whole_range
.min
;
617 long long max
= whole_range
.max
;
627 name
= get_variable_from_expr(expr
->unop
, &sym
);
630 if (expr
->op
== SPECIAL_INCREMENT
) {
631 if (get_implied_min(expr
->unop
, &val
))
633 if (!inside_loop() && get_implied_max(expr
->unop
, &val
))
636 if (expr
->op
== SPECIAL_DECREMENT
) {
637 if (get_implied_max(expr
->unop
, &val
))
639 if (!inside_loop() && get_implied_min(expr
->unop
, &val
))
642 set_extra_mod(name
, sym
, alloc_extra_state_range(min
, max
));
647 static void delete_state_tracker(struct tracker
*t
)
649 remove_from_equiv(t
->name
, t
->sym
);
650 delete_state(t
->owner
, t
->name
, t
->sym
);
653 static void scoped_state_extra(const char *name
, struct symbol
*sym
)
657 t
= alloc_tracker(SMATCH_EXTRA
, name
, sym
);
658 add_scope_hook((scope_hook
*)&delete_state_tracker
, t
);
661 static void match_declarations(struct symbol
*sym
)
666 name
= sym
->ident
->name
;
667 if (!sym
->initializer
) {
668 set_state(SMATCH_EXTRA
, name
, sym
, extra_undefined());
669 scoped_state_extra(name
, sym
);
674 static void match_function_def(struct symbol
*sym
)
679 FOR_EACH_PTR(sym
->ctype
.base_type
->arguments
, arg
) {
683 set_state(my_id
, arg
->ident
->name
, arg
, extra_undefined());
684 } END_FOR_EACH_PTR(arg
);
687 static int last_stmt_val(struct statement
*stmt
, long long *val
)
689 struct expression
*expr
;
694 stmt
= last_ptr_list((struct ptr_list
*)stmt
->stmts
);
695 if (stmt
->type
!= STMT_EXPRESSION
)
697 expr
= stmt
->expression
;
698 return get_value(expr
, val
);
701 static void match_comparison(struct expression
*expr
)
706 struct smatch_state
*true_state
;
707 struct smatch_state
*false_state
;
708 struct smatch_state
*orig
;
710 int comparison
= expr
->op
;
711 struct expression
*varies
= expr
->right
;
713 if (!get_value(expr
->left
, &fixed
)) {
714 if (!get_value(expr
->right
, &fixed
))
716 varies
= strip_expr(expr
->left
);
719 if (varies
->op
== SPECIAL_INCREMENT
|| varies
->op
== SPECIAL_DECREMENT
)
720 varies
= varies
->unop
;
721 if (varies
->type
== EXPR_CALL
) {
722 function_comparison(comparison
, varies
, fixed
, left
);
726 name
= get_variable_from_expr(varies
, &sym
);
730 orig
= get_state(my_id
, name
, sym
);
732 orig
= extra_undefined();
734 switch (comparison
) {
736 case SPECIAL_UNSIGNED_LT
:
738 true_state
= filter_range(orig
, fixed
, whole_range
.max
);
739 false_state
= filter_range(orig
, whole_range
.min
, fixed
- 1);
741 true_state
= filter_range(orig
, whole_range
.min
, fixed
);
742 false_state
= filter_range(orig
, fixed
+ 1, whole_range
.max
);
745 case SPECIAL_UNSIGNED_LTE
:
748 true_state
= filter_range(orig
, fixed
+ 1, whole_range
.max
);
749 false_state
= filter_range(orig
, whole_range
.min
, fixed
);
751 true_state
= filter_range(orig
, whole_range
.min
, fixed
- 1);
752 false_state
= filter_range(orig
, fixed
, whole_range
.max
);
756 if (possibly_true(SPECIAL_EQUAL
, get_dinfo(orig
), fixed
, fixed
))
757 true_state
= alloc_extra_state(fixed
);
759 true_state
= alloc_extra_state_empty();
760 false_state
= filter_range(orig
, fixed
, fixed
);
762 case SPECIAL_UNSIGNED_GTE
:
765 true_state
= filter_range(orig
, whole_range
.min
, fixed
- 1);
766 false_state
= filter_range(orig
, fixed
, whole_range
.max
);
768 true_state
= filter_range(orig
, fixed
+ 1, whole_range
.max
);
769 false_state
= filter_range(orig
, whole_range
.min
, fixed
);
773 case SPECIAL_UNSIGNED_GT
:
775 true_state
= filter_range(orig
, whole_range
.min
, fixed
);
776 false_state
= filter_range(orig
, fixed
+ 1, whole_range
.max
);
778 true_state
= filter_range(orig
, fixed
, whole_range
.max
);
779 false_state
= filter_range(orig
, whole_range
.min
, fixed
- 1);
782 case SPECIAL_NOTEQUAL
:
783 true_state
= filter_range(orig
, fixed
, fixed
);
784 if (possibly_true(SPECIAL_EQUAL
, get_dinfo(orig
), fixed
, fixed
))
785 false_state
= alloc_extra_state(fixed
);
787 false_state
= alloc_extra_state_empty();
790 sm_msg("unhandled comparison %d\n", comparison
);
793 set_extra_true_false(name
, sym
, true_state
, false_state
);
798 /* this is actually hooked from smatch_implied.c... it's hacky, yes */
799 void __extra_match_condition(struct expression
*expr
)
803 struct smatch_state
*pre_state
;
804 struct smatch_state
*true_state
;
805 struct smatch_state
*false_state
;
807 expr
= strip_expr(expr
);
808 switch (expr
->type
) {
810 function_comparison(SPECIAL_NOTEQUAL
, expr
, 0, 1);
815 name
= get_variable_from_expr(expr
, &sym
);
818 pre_state
= get_state(my_id
, name
, sym
);
819 true_state
= add_filter(pre_state
, 0);
820 if (possibly_true(SPECIAL_EQUAL
, get_dinfo(pre_state
), 0, 0))
821 false_state
= alloc_extra_state(0);
823 false_state
= alloc_extra_state_empty();
824 set_extra_true_false(name
, sym
, true_state
, false_state
);
828 match_comparison(expr
);
830 case EXPR_ASSIGNMENT
:
831 __extra_match_condition(expr
->left
);
836 /* returns 1 if it is not possible for expr to be value, otherwise returns 0 */
837 int implied_not_equal(struct expression
*expr
, long long val
)
841 struct smatch_state
*state
;
844 name
= get_variable_from_expr(expr
, &sym
);
847 state
= get_state(my_id
, name
, sym
);
848 if (!state
|| !state
->data
)
850 ret
= !possibly_false(SPECIAL_NOTEQUAL
, get_dinfo(state
), val
, 1);
856 int known_condition_true(struct expression
*expr
)
859 struct statement
*stmt
;
864 if (get_value(expr
, &tmp
) && tmp
)
867 expr
= strip_expr(expr
);
868 switch (expr
->type
) {
870 if (expr
->op
== '!') {
871 if (known_condition_false(expr
->unop
))
875 stmt
= get_expression_statement(expr
);
876 if (last_stmt_val(stmt
, &tmp
) && tmp
== 1)
885 int known_condition_false(struct expression
*expr
)
888 struct statement
*stmt
;
896 switch (expr
->type
) {
898 if (expr
->op
== '!') {
899 if (known_condition_true(expr
->unop
))
903 stmt
= get_expression_statement(expr
);
904 if (last_stmt_val(stmt
, &tmp
) && tmp
== 0)
913 struct range_list
*get_range_list(struct expression
*expr
)
917 struct range_list
*ret
= NULL
;
918 struct smatch_state
*state
;
920 state
= get_state_expr(SMATCH_EXTRA
, expr
);
922 return clone_range_list(get_dinfo(state
)->value_ranges
);
923 if (!get_absolute_min(expr
, &min
))
925 if (!get_absolute_max(expr
, &max
))
927 add_range(&ret
, min
, max
);
931 static int do_comparison(struct expression
*expr
)
933 struct range_list
*left_ranges
;
934 struct range_list
*right_ranges
;
935 int poss_true
, poss_false
;
937 left_ranges
= get_range_list(expr
->left
);
938 right_ranges
= get_range_list(expr
->right
);
940 poss_true
= possibly_true_range_lists(left_ranges
, expr
->op
, right_ranges
);
941 poss_false
= possibly_false_range_lists(left_ranges
, expr
->op
, right_ranges
);
943 free_range_list(&left_ranges
);
944 free_range_list(&right_ranges
);
946 if (!poss_true
&& !poss_false
)
948 if (poss_true
&& !poss_false
)
950 if (!poss_true
&& poss_false
)
955 int implied_condition_true(struct expression
*expr
)
957 struct statement
*stmt
;
964 if (get_implied_value(expr
, &tmp
) && tmp
)
967 if (expr
->type
== EXPR_POSTOP
)
968 return implied_condition_true(expr
->unop
);
970 if (expr
->type
== EXPR_PREOP
&& expr
->op
== SPECIAL_DECREMENT
)
971 return implied_not_equal(expr
->unop
, 1);
972 if (expr
->type
== EXPR_PREOP
&& expr
->op
== SPECIAL_INCREMENT
)
973 return implied_not_equal(expr
->unop
, -1);
975 expr
= strip_expr(expr
);
976 switch (expr
->type
) {
978 if (do_comparison(expr
) == 1)
982 if (expr
->op
== '!') {
983 if (implied_condition_false(expr
->unop
))
987 stmt
= get_expression_statement(expr
);
988 if (last_stmt_val(stmt
, &val
) && val
== 1)
992 if (implied_not_equal(expr
, 0) == 1)
999 int implied_condition_false(struct expression
*expr
)
1001 struct statement
*stmt
;
1002 struct expression
*tmp
;
1011 switch (expr
->type
) {
1013 if (do_comparison(expr
) == 2)
1016 if (expr
->op
== '!') {
1017 if (implied_condition_true(expr
->unop
))
1021 stmt
= get_expression_statement(expr
);
1022 if (last_stmt_val(stmt
, &val
) && val
== 0)
1024 tmp
= strip_expr(expr
);
1026 return implied_condition_false(tmp
);
1029 if (get_implied_value(expr
, &val
) && val
== 0)
1036 int get_implied_range_list(struct expression
*expr
, struct range_list
**rl
)
1039 struct smatch_state
*state
;
1041 expr
= strip_expr(expr
);
1043 state
= get_state_expr(my_id
, expr
);
1045 *rl
= clone_range_list(get_dinfo(state
)->value_ranges
);
1049 if (get_implied_value(expr
, &val
)) {
1051 add_range(rl
, val
, val
);
1055 if (expr
->type
== EXPR_BINOP
&& expr
->op
== '%') {
1056 if (!get_implied_value(expr
->right
, &val
))
1059 add_range(rl
, 0, val
- 1);
1066 int is_whole_range(struct smatch_state
*state
)
1068 struct data_info
*dinfo
;
1069 struct data_range
*drange
;
1073 dinfo
= get_dinfo(state
);
1074 drange
= first_ptr_list((struct ptr_list
*)dinfo
->value_ranges
);
1075 if (drange
->min
== whole_range
.min
&& drange
->max
== whole_range
.max
)
1080 void register_smatch_extra(int id
)
1083 add_merge_hook(my_id
, &merge_func
);
1084 add_unmatched_state_hook(my_id
, &unmatched_state
);
1085 add_hook(&unop_expr
, OP_HOOK
);
1086 add_hook(&match_function_def
, FUNC_DEF_HOOK
);
1087 add_hook(&match_function_call
, FUNCTION_CALL_HOOK
);
1088 add_hook(&match_assign
, ASSIGNMENT_HOOK
);
1089 add_hook(&match_declarations
, DECLARATION_HOOK
);