Small cleanups. (White space).
[smatch.git] / smatch_implied.c
blob5a8dac1ef2478b3f1198acb465287065adfe318a
1 /*
2 * sparse/smatch_implied.c
4 * Copyright (C) 2008 Dan Carpenter.
6 * Licensed under the Open Software License version 1.1
8 */
11 * Imagine we have this code:
12 * foo = 0;
13 * if (bar)
14 * foo = 1;
15 * // <-- point #1
16 * else
17 * frob();
18 * // <-- point #2
19 * if (foo == 1) // <-- point #3
20 * bar->baz; // <-- point #4
22 * Currently (Oct 2008) in smatch when we merge bar states
23 * null and nonnull, at point #2, the state becomes undefined.
24 * As a result we get an error at point #3.
26 * The idea behind "implied state pools" is to fix that.
28 * The implied pools get created in merge_slist(). Whatever
29 * is unique to one slist being merged gets put into a pool.
31 * If we set a state that removes it from all pools.
33 * When we come to an if statement where "foo" has some pools
34 * associated we take all the pools where "foo == 1" and keep
35 * all the states that are consistent across those pools.
37 * The point of doing this is to turn an undefined state into
38 * a defined state. This hopefully gets rid of some false positives.
39 * What it doesn't do is find new errors that were
40 * missed before.
42 * There are quite a few implementation details I haven't figured
43 * out. How do you create implied state pools inside a
44 * complex condition? How do you determine what is implied
45 * from a complex condition? The initial patch is extremely rudimentary...
48 #include "smatch.h"
49 #include "smatch_slist.h"
52 * This function gets all the states which are implied by a non zero value.
53 * So for example for the code:
54 * if (c) {
55 * We would want to know what was implied by c is non zero.
56 */
58 static struct state_list *get_non_zero_filtered(struct sm_state *sm_state)
60 struct state_list *list;
61 struct smatch_state *s;
62 struct state_list *ret = NULL;
64 FOR_EACH_PTR(sm_state->pools, list) {
65 s = get_state_slist(list, sm_state->name, sm_state->owner,
66 sm_state->sym);
67 if (s == &undefined) {
68 del_slist(&ret);
69 return NULL;
71 if (s->data && *(int *)s->data != 0) {
72 printf("debug %s is %d\n", s->name, *(int *)s->data);
74 if (!ret)
75 ret = clone_slist(list);
76 else
77 filter(&ret, list);
79 } END_FOR_EACH_PTR(list);
80 return ret;
85 * This condition hook is very connected to smatch_extra.c.
86 * It's registered there.
89 void __implied_states_hook(struct expression *expr)
91 struct symbol *sym;
92 char *name;
93 struct sm_state *state;
94 struct state_list *implied_states;
96 if (expr->type != EXPR_COMPARE)
97 return;
99 name = get_variable_from_expr(expr, &sym);
100 state = __get_sm_state(name, SMATCH_EXTRA, sym);
101 if (!state)
102 return;
103 if (!state->pools) {
104 printf("no pools for %s\n", state->name);
105 return;
107 implied_states = get_non_zero_filtered(state);
108 if (debug_states) {
109 printf("Setting the following implied states\n");
110 __print_slist(implied_states);
112 __overwrite_cur_slist(implied_states);
113 free_string(name);