If the pointer is initialized to non-null then set the state appropriately.
[smatch.git] / smatch_flow.c
blobbed37f2ded7c443da56a7d8fa721cbeb79a4db7a
1 /*
2 * sparse/smatch_flow.c
4 * Copyright (C) 2006,2008 Dan Carpenter.
6 * Licensed under the Open Software License version 1.1
8 */
10 #include <stdio.h>
11 #include "token.h"
12 #include "smatch.h"
14 int __smatch_lineno = 0;
16 static char *filename;
17 static char *cur_func;
18 static int line_func_start;
20 char *get_filename() { return filename; }
21 char *get_function() { return cur_func; }
22 int get_lineno() { return __smatch_lineno; }
23 int get_func_pos() { return __smatch_lineno - line_func_start; }
25 static void split_statements(struct statement *stmt);
26 static void split_symlist(struct symbol_list *sym_list);
27 static void split_expr_list(struct expression_list *expr_list);
29 void __split_expr(struct expression *expr)
31 if (!expr)
32 return;
34 // printf("%d Debug expr_type %d\n", get_lineno(), expr->type);
36 __smatch_lineno = expr->pos.line;
37 __pass_to_client(expr, EXPR_HOOK);
39 switch (expr->type) {
40 case EXPR_PREOP:
41 case EXPR_POSTOP:
42 __pass_to_client(expr, OP_HOOK);
43 if (expr->op == '*')
44 __pass_to_client(expr, DEREF_HOOK);
45 __split_expr(expr->unop);
46 return;
47 case EXPR_STATEMENT:
48 split_statements(expr->statement);
49 return;
50 case EXPR_BINOP:
51 case EXPR_COMMA:
52 case EXPR_COMPARE:
53 case EXPR_LOGICAL:
54 case EXPR_ASSIGNMENT:
55 if (expr->type == EXPR_ASSIGNMENT)
56 __pass_to_client(expr, ASSIGNMENT_HOOK);
57 __split_expr(expr->left);
58 __split_expr(expr->right);
59 if (expr->type == EXPR_ASSIGNMENT)
60 __pass_to_client(expr, ASSIGNMENT_AFTER_HOOK);
61 return;
62 case EXPR_DEREF:
63 __pass_to_client(expr, DEREF_HOOK);
64 __split_expr(expr->deref);
65 return;
66 case EXPR_SLICE:
67 __split_expr(expr->base);
68 return;
69 case EXPR_CAST:
70 __split_expr(expr->cast_expression);
71 return;
72 case EXPR_SIZEOF:
73 /* there isn't anything to pass a client from inside a sizeof() */
74 return;
75 case EXPR_CONDITIONAL:
76 case EXPR_SELECT:
77 __split_whole_condition(expr->conditional);
78 __split_expr(expr->cond_true);
79 __push_true_states();
80 __use_false_states();
81 __split_expr(expr->cond_false);
82 __merge_true_states();
83 __pop_false_only_stack();
84 return;
85 case EXPR_CALL:
86 __pass_to_client(expr, FUNCTION_CALL_HOOK);
87 __split_expr(expr->fn);
88 split_expr_list(expr->args);
89 __pass_to_client(expr, FUNCTION_CALL_AFTER_HOOK);
90 #ifdef KERNEL
91 if (expr->fn->type == EXPR_SYMBOL &&
92 !strcmp(expr->fn->symbol_name->name, "panic"))
93 nullify_path();
94 #endif
95 return;
96 case EXPR_INITIALIZER:
97 split_expr_list(expr->expr_list);
98 return;
99 case EXPR_IDENTIFIER:
100 __split_expr(expr->ident_expression);
101 return;
102 case EXPR_INDEX:
103 __split_expr(expr->idx_expression);
104 return;
105 case EXPR_POS:
106 __split_expr(expr->init_expr);
107 return;
108 default:
109 return;
113 static int is_forever_loop(struct statement *stmt)
116 struct expression *expr;
118 expr = stmt->iterator_pre_condition;
119 if (!expr)
120 expr = stmt->iterator_post_condition;
121 if (!expr) {
122 /* this is a for(;;) loop... */
123 return 1;
126 if (expr->type == EXPR_VALUE && expr->value == 1) {
127 return 1;
130 return 0;
134 * Pre Loops are while and for loops.
137 static void handle_pre_loop(struct statement *stmt)
139 int once_through; /* we go through the loop at least once */
141 split_statements(stmt->iterator_pre_statement);
143 once_through = known_condition_true(stmt->iterator_pre_condition);
145 __push_continues();
146 __push_breaks();
148 __split_whole_condition(stmt->iterator_pre_condition);
150 split_statements(stmt->iterator_statement);
151 split_statements(stmt->iterator_post_statement);
152 if (is_forever_loop(stmt)) {
153 __pop_false_only_stack();
154 __pop_continues();
155 __pop_false_states();
156 if (!__break_called()) {
157 set_null_path();
159 __use_breaks();
160 } else if (once_through) {
161 __merge_continues();
162 __pop_false_states();
163 __use_false_only_stack();
164 __merge_breaks();
165 } else {
166 __merge_continues();
167 __merge_false_states();
168 __use_false_only_stack();
169 __merge_breaks();
174 * Post loops are do {} while();
176 static void handle_post_loop(struct statement *stmt)
178 __push_continues();
179 __push_breaks();
180 split_statements(stmt->iterator_statement);
182 __split_whole_condition(stmt->iterator_post_condition);
183 __use_false_states();
185 if (is_forever_loop(stmt)) {
186 __pop_continues();
187 __use_breaks();
189 } else {
190 set_null_path();
191 __merge_continues();
192 __merge_breaks();
194 __pop_false_only_stack();
197 static void split_statements(struct statement *stmt)
199 if (!stmt)
200 return;
202 __smatch_lineno = stmt->pos.line;
203 __pass_to_client(stmt, STMT_HOOK);
205 switch (stmt->type) {
206 case STMT_DECLARATION:
207 __pass_declarations_to_client(stmt->declaration);
208 split_symlist(stmt->declaration);
209 return;
210 case STMT_RETURN:
211 __pass_to_client(stmt, RETURN_HOOK);
212 __split_expr(stmt->ret_value);
213 //set_null_path();
214 nullify_path();
215 return;
216 case STMT_EXPRESSION:
217 __split_expr(stmt->expression);
218 return;
219 case STMT_COMPOUND: {
220 struct statement *s;
221 FOR_EACH_PTR(stmt->stmts, s) {
222 split_statements(s);
223 } END_FOR_EACH_PTR(s);
224 return;
226 case STMT_IF:
227 __split_whole_condition(stmt->if_conditional);
228 split_statements(stmt->if_true);
229 __push_true_states();
230 __use_false_states();
231 split_statements(stmt->if_false);
232 __merge_true_states();
233 __pop_false_only_stack();
234 return;
235 case STMT_ITERATOR:
236 if (stmt->iterator_pre_condition)
237 handle_pre_loop(stmt);
238 else if (stmt->iterator_post_condition)
239 handle_post_loop(stmt);
240 else {
241 // these are for(;;) type loops.
242 handle_pre_loop(stmt);
244 return;
245 case STMT_SWITCH:
246 __split_expr(stmt->switch_expression);
247 __save_switch_states();
248 __push_default();
249 __push_breaks();
250 //set_null_path();
251 nullify_path();
252 split_statements(stmt->switch_statement);
253 if (!__pop_default())
254 __merge_switches();
255 __pop_switches();
256 __merge_breaks();
257 return;
258 case STMT_CASE:
259 __merge_switches();
260 if (!stmt->case_expression)
261 __set_default();
262 __split_expr(stmt->case_expression);
263 __split_expr(stmt->case_to);
264 split_statements(stmt->case_statement);
265 return;
266 case STMT_LABEL:
267 if (stmt->label &&
268 stmt->label->type == SYM_LABEL &&
269 stmt->label->ident) {
270 __merge_gotos(stmt->label->ident->name);
272 split_statements(stmt->label_statement);
273 return;
274 case STMT_GOTO:
275 __split_expr(stmt->goto_expression);
276 if (stmt->goto_label && stmt->goto_label->type == SYM_NODE) {
277 if (!strcmp(stmt->goto_label->ident->name, "break")) {
278 __process_breaks();
279 } else if (!strcmp(stmt->goto_label->ident->name,
280 "continue")) {
281 __process_continues();
283 } else if (stmt->goto_label &&
284 stmt->goto_label->type == SYM_LABEL &&
285 stmt->goto_label->ident) {
286 __save_gotos(stmt->goto_label->ident->name);
288 //set_null_path();
289 nullify_path();
290 return;
291 case STMT_NONE:
292 return;
293 case STMT_ASM:
294 __split_expr(stmt->asm_string);
295 //__split_expr(stmt->asm_outputs);
296 //__split_expr(stmt->asm_inputs);
297 //__split_expr(stmt->asm_clobbers);
298 return;
299 case STMT_CONTEXT:
300 return;
301 case STMT_RANGE:
302 __split_expr(stmt->range_expression);
303 __split_expr(stmt->range_low);
304 __split_expr(stmt->range_high);
305 return;
309 static void split_expr_list(struct expression_list *expr_list)
311 struct expression *expr;
312 FOR_EACH_PTR(expr_list, expr) {
313 __split_expr(expr);
314 } END_FOR_EACH_PTR(expr);
318 static void split_sym(struct symbol *sym)
320 if (!sym)
321 return;
322 if (!(sym->namespace & NS_SYMBOL))
323 return;
325 __pass_to_client(sym, SYM_HOOK);
326 split_statements(sym->stmt);
327 __split_expr(sym->array_size);
328 split_symlist(sym->arguments);
329 split_symlist(sym->symbol_list);
330 split_statements(sym->inline_stmt);
331 split_symlist(sym->inline_symbol_list);
332 __split_expr(sym->initializer);
335 static void split_symlist(struct symbol_list *sym_list)
337 struct symbol *sym;
339 FOR_EACH_PTR(sym_list, sym) {
340 split_sym(sym);
341 } END_FOR_EACH_PTR(sym);
344 static void split_functions(struct symbol_list *sym_list)
346 struct symbol *sym;
348 FOR_EACH_PTR(sym_list, sym) {
349 struct symbol *base_type;
350 base_type = get_base_type(sym);
351 if (sym->type == SYM_NODE && base_type->type == SYM_FN) {
352 if (base_type->stmt)
353 line_func_start = base_type->stmt->pos.line;
354 if (sym->ident)
355 cur_func = sym->ident->name;
356 __smatch_lineno = sym->pos.line;
357 SM_DEBUG("new function: %s\n", cur_func);
358 __pass_to_client(sym, FUNC_DEF_HOOK);
359 __unnullify_path();
360 split_statements(base_type->stmt);
361 __pass_to_client(sym, END_FUNC_HOOK);
362 cur_func = NULL;
363 line_func_start = 0;
364 clear_all_states();
366 } else {
367 __pass_to_client(sym, BASE_HOOK);
369 } END_FOR_EACH_PTR(sym);
372 void smatch (int argc, char **argv)
375 struct string_list *filelist = NULL;
376 struct symbol_list *sym_list;
378 if (argc < 2) {
379 printf("Usage: smatch <filename.c>\n");
380 exit(1);
382 sparse_initialize(argc, argv, &filelist);
383 FOR_EACH_PTR_NOTAG(filelist, filename) {
384 sym_list = __sparse(filename);
385 split_functions(sym_list);
386 } END_FOR_EACH_PTR_NOTAG(filename);