09e9260e997284bb5e9705423626fb700619c50b
2 * smatch/smatch_comparison.c
4 * Copyright (C) 2012 Oracle.
6 * Licensed under the Open Software License version 1.1
11 * The point here is to store the relationships between two variables.
13 * To do that we create a state with the two variables in alphabetical order:
14 * ->name = "x vs y" and the state would be "<". On the false path the state
17 * Part of the trick of it is that if x or y is modified then we need to reset
18 * the state. We need to keep a list of all the states which depend on x and
19 * all the states which depend on y. The link_id code handles this.
21 * Future work: If we know that x is greater than y and y is greater than z
22 * then we know that x is greater than z.
26 #include "smatch_extra.h"
27 #include "smatch_slist.h"
29 static int compare_id
;
39 ALLOCATOR(compare_data
, "compare data");
41 int var_sym_eq(const char *a
, struct symbol
*a_sym
, const char *b
, struct symbol
*b_sym
)
45 if (strcmp(a
, b
) == 0)
50 static struct smatch_state
*alloc_compare_state(
51 const char *var1
, struct symbol
*sym1
,
53 const char *var2
, struct symbol
*sym2
)
55 struct smatch_state
*state
;
56 struct compare_data
*data
;
58 state
= __alloc_smatch_state(0);
59 state
->name
= alloc_sname(show_special(comparison
));
60 data
= __alloc_compare_data(0);
61 data
->var1
= alloc_sname(var1
);
63 data
->comparison
= comparison
;
64 data
->var2
= alloc_sname(var2
);
70 static int state_to_comparison(struct smatch_state
*state
)
72 if (!state
|| !state
->data
)
74 return ((struct compare_data
*)state
->data
)->comparison
;
78 * flip_op() reverses the op left and right. So "x >= y" becomes "y <= x".
80 static int flip_op(int op
)
87 case SPECIAL_UNSIGNED_LT
:
88 return SPECIAL_UNSIGNED_GT
;
91 case SPECIAL_UNSIGNED_LTE
:
92 return SPECIAL_UNSIGNED_GTE
;
95 case SPECIAL_NOTEQUAL
:
96 return SPECIAL_NOTEQUAL
;
99 case SPECIAL_UNSIGNED_GTE
:
100 return SPECIAL_UNSIGNED_LTE
;
103 case SPECIAL_UNSIGNED_GT
:
104 return SPECIAL_UNSIGNED_LT
;
106 sm_msg("internal smatch bug. unhandled comparison %d", op
);
111 static int falsify_op(int op
)
118 case SPECIAL_UNSIGNED_LT
:
119 return SPECIAL_UNSIGNED_GTE
;
122 case SPECIAL_UNSIGNED_LTE
:
123 return SPECIAL_UNSIGNED_GT
;
125 return SPECIAL_NOTEQUAL
;
126 case SPECIAL_NOTEQUAL
:
127 return SPECIAL_EQUAL
;
130 case SPECIAL_UNSIGNED_GTE
:
131 return SPECIAL_UNSIGNED_LT
;
134 case SPECIAL_UNSIGNED_GT
:
135 return SPECIAL_UNSIGNED_LTE
;
137 sm_msg("internal smatch bug. unhandled comparison %d", op
);
142 static int rl_comparison(struct range_list
*left_rl
, struct range_list
*right_rl
)
144 sval_t left_min
, left_max
, right_min
, right_max
;
146 if (!left_rl
|| !right_rl
)
149 left_min
= rl_min(left_rl
);
150 left_max
= rl_max(left_rl
);
151 right_min
= rl_min(right_rl
);
152 right_max
= rl_max(right_rl
);
154 if (left_min
.value
== left_max
.value
&&
155 right_min
.value
== right_max
.value
&&
156 left_min
.value
== right_min
.value
)
157 return SPECIAL_EQUAL
;
159 if (sval_cmp(left_max
, right_min
) < 0)
161 if (sval_cmp(left_max
, right_min
) == 0)
163 if (sval_cmp(left_min
, right_max
) > 0)
165 if (sval_cmp(left_min
, right_max
) == 0)
171 static struct range_list
*get_orig_rl(struct symbol
*sym
)
173 struct smatch_state
*state
;
175 if (!sym
|| !sym
->ident
)
177 state
= get_orig_estate(sym
->ident
->name
, sym
);
178 return estate_rl(state
);
181 static struct smatch_state
*unmatched_comparison(struct sm_state
*sm
)
183 struct compare_data
*data
= sm
->state
->data
;
184 struct range_list
*left_rl
, *right_rl
;
190 if (strstr(data
->var1
, " orig"))
191 left_rl
= get_orig_rl(data
->sym1
);
192 else if (!get_implied_rl_var_sym(data
->var1
, data
->sym1
, &left_rl
))
194 if (strstr(data
->var2
, " orig"))
195 right_rl
= get_orig_rl(data
->sym2
);
196 else if (!get_implied_rl_var_sym(data
->var2
, data
->sym2
, &right_rl
))
199 op
= rl_comparison(left_rl
, right_rl
);
201 return alloc_compare_state(data
->var1
, data
->sym1
, op
, data
->var2
, data
->sym2
);
206 /* remove_unsigned_from_comparison() is obviously a hack. */
207 static int remove_unsigned_from_comparison(int op
)
210 case SPECIAL_UNSIGNED_LT
:
212 case SPECIAL_UNSIGNED_LTE
:
214 case SPECIAL_UNSIGNED_GTE
:
216 case SPECIAL_UNSIGNED_GT
:
224 * This is for when you merge states "a < b" and "a == b", the result is that
225 * we can say for sure, "a <= b" after the merge.
227 static int merge_comparisons(int one
, int two
)
231 one
= remove_unsigned_from_comparison(one
);
232 two
= remove_unsigned_from_comparison(two
);
279 return SPECIAL_NOTEQUAL
;
290 * This is for if you have "a < b" and "b <= c". Or in other words,
291 * "a < b <= c". You would call this like get_combined_comparison('<', '<=').
292 * The return comparison would be '<'.
294 * This function is different from merge_comparisons(), for example:
295 * merge_comparison('<', '==') returns '<='
296 * get_combined_comparison('<', '==') returns '<'
298 static int combine_comparisons(int left_compare
, int right_compare
)
302 left_compare
= remove_unsigned_from_comparison(left_compare
);
303 right_compare
= remove_unsigned_from_comparison(right_compare
);
307 switch (left_compare
) {
316 return right_compare
;
325 switch (right_compare
) {
357 static struct smatch_state
*merge_compare_states(struct smatch_state
*s1
, struct smatch_state
*s2
)
359 struct compare_data
*data
= s1
->data
;
362 op
= merge_comparisons(state_to_comparison(s1
), state_to_comparison(s2
));
364 return alloc_compare_state(data
->var1
, data
->sym1
, op
, data
->var2
, data
->sym2
);
368 struct smatch_state
*alloc_link_state(struct string_list
*links
)
370 struct smatch_state
*state
;
371 static char buf
[256];
375 state
= __alloc_smatch_state(0);
378 FOR_EACH_PTR(links
, tmp
) {
380 snprintf(buf
, sizeof(buf
), "%s", tmp
);
382 snprintf(buf
, sizeof(buf
), "%s, %s", buf
, tmp
);
383 } END_FOR_EACH_PTR(tmp
);
385 state
->name
= alloc_sname(buf
);
390 static void save_start_states(struct statement
*stmt
)
392 struct symbol
*param
;
394 char state_name
[128];
395 struct smatch_state
*state
;
396 struct string_list
*links
;
399 FOR_EACH_PTR(cur_func_sym
->ctype
.base_type
->arguments
, param
) {
402 snprintf(orig
, sizeof(orig
), "%s orig", param
->ident
->name
);
403 snprintf(state_name
, sizeof(state_name
), "%s vs %s", param
->ident
->name
, orig
);
404 state
= alloc_compare_state(param
->ident
->name
, param
, SPECIAL_EQUAL
, alloc_sname(orig
), param
);
405 set_state(compare_id
, state_name
, NULL
, state
);
407 link
= alloc_sname(state_name
);
409 insert_string(&links
, link
);
410 state
= alloc_link_state(links
);
411 set_state(link_id
, param
->ident
->name
, param
, state
);
412 } END_FOR_EACH_PTR(param
);
415 static struct smatch_state
*merge_links(struct smatch_state
*s1
, struct smatch_state
*s2
)
417 struct smatch_state
*ret
;
418 struct string_list
*links
;
420 links
= combine_string_lists(s1
->data
, s2
->data
);
421 ret
= alloc_link_state(links
);
425 static void save_link_var_sym(const char *var
, struct symbol
*sym
, const char *link
)
427 struct smatch_state
*old_state
, *new_state
;
428 struct string_list
*links
;
431 old_state
= get_state(link_id
, var
, sym
);
433 links
= clone_str_list(old_state
->data
);
437 new = alloc_sname(link
);
438 insert_string(&links
, new);
440 new_state
= alloc_link_state(links
);
441 set_state(link_id
, var
, sym
, new_state
);
444 static void match_inc(struct sm_state
*sm
)
446 struct string_list
*links
;
447 struct smatch_state
*state
;
450 links
= sm
->state
->data
;
452 FOR_EACH_PTR(links
, tmp
) {
453 state
= get_state(compare_id
, tmp
, NULL
);
455 switch (state_to_comparison(state
)) {
458 case SPECIAL_UNSIGNED_GTE
:
460 case SPECIAL_UNSIGNED_GT
: {
461 struct compare_data
*data
= state
->data
;
462 struct smatch_state
*new;
464 new = alloc_compare_state(data
->var1
, data
->sym1
, '>', data
->var2
, data
->sym2
);
465 set_state(compare_id
, tmp
, NULL
, new);
469 set_state(compare_id
, tmp
, NULL
, &undefined
);
471 } END_FOR_EACH_PTR(tmp
);
474 static void match_dec(struct sm_state
*sm
)
476 struct string_list
*links
;
477 struct smatch_state
*state
;
480 links
= sm
->state
->data
;
482 FOR_EACH_PTR(links
, tmp
) {
483 state
= get_state(compare_id
, tmp
, NULL
);
485 switch (state_to_comparison(state
)) {
488 case SPECIAL_UNSIGNED_LTE
:
490 case SPECIAL_UNSIGNED_LT
: {
491 struct compare_data
*data
= state
->data
;
492 struct smatch_state
*new;
494 new = alloc_compare_state(data
->var1
, data
->sym1
, '<', data
->var2
, data
->sym2
);
495 set_state(compare_id
, tmp
, NULL
, new);
499 set_state(compare_id
, tmp
, NULL
, &undefined
);
501 } END_FOR_EACH_PTR(tmp
);
504 static int match_inc_dec(struct sm_state
*sm
, struct expression
*mod_expr
)
508 if (mod_expr
->type
!= EXPR_PREOP
&& mod_expr
->type
!= EXPR_POSTOP
)
511 if (mod_expr
->op
== SPECIAL_INCREMENT
) {
515 if (mod_expr
->op
== SPECIAL_DECREMENT
) {
522 static void match_modify(struct sm_state
*sm
, struct expression
*mod_expr
)
524 struct string_list
*links
;
527 if (match_inc_dec(sm
, mod_expr
))
530 links
= sm
->state
->data
;
532 FOR_EACH_PTR(links
, tmp
) {
533 set_state(compare_id
, tmp
, NULL
, &undefined
);
534 } END_FOR_EACH_PTR(tmp
);
535 set_state(link_id
, sm
->name
, sm
->sym
, &undefined
);
538 static char *chunk_to_var_sym(struct expression
*expr
, struct symbol
**sym
)
540 char *name
, *left_name
, *right_name
;
544 expr
= strip_expr(expr
);
548 name
= expr_to_var_sym(expr
, &tmp
);
557 if (expr
->type
!= EXPR_BINOP
)
559 if (expr
->op
!= '-' && expr
->op
!= '+')
562 left_name
= expr_to_var(expr
->left
);
565 right_name
= expr_to_var(expr
->right
);
567 free_string(left_name
);
570 snprintf(buf
, sizeof(buf
), "%s %s %s", left_name
, show_special(expr
->op
), right_name
);
571 free_string(left_name
);
572 free_string(right_name
);
573 return alloc_string(buf
);
576 static char *chunk_to_var(struct expression
*expr
)
578 return chunk_to_var_sym(expr
, NULL
);
581 static void save_link(struct expression
*expr
, char *link
)
586 expr
= strip_expr(expr
);
587 if (expr
->type
== EXPR_BINOP
) {
590 chunk
= chunk_to_var(expr
);
594 save_link(expr
->left
, link
);
595 save_link(expr
->right
, link
);
596 save_link_var_sym(chunk
, NULL
, link
);
600 var
= expr_to_var_sym(expr
, &sym
);
604 save_link_var_sym(var
, sym
, link
);
611 static void update_tf_links(struct state_list
*pre_slist
,
612 const char *left_var
, struct symbol
*left_sym
,
614 const char *mid_var
, struct symbol
*mid_sym
,
615 struct string_list
*links
)
617 struct smatch_state
*state
;
618 struct smatch_state
*true_state
, *false_state
;
619 struct compare_data
*data
;
620 const char *right_var
;
621 struct symbol
*right_sym
;
622 int right_comparison
;
624 int false_comparison
;
626 char state_name
[256];
628 FOR_EACH_PTR(links
, tmp
) {
629 state
= get_state_slist(pre_slist
, compare_id
, tmp
, NULL
);
630 if (!state
|| !state
->data
)
633 right_comparison
= data
->comparison
;
634 right_var
= data
->var2
;
635 right_sym
= data
->sym2
;
636 if (var_sym_eq(mid_var
, mid_sym
, right_var
, right_sym
)) {
637 right_var
= data
->var1
;
638 right_sym
= data
->sym1
;
639 right_comparison
= flip_op(right_comparison
);
641 true_comparison
= combine_comparisons(left_comparison
, right_comparison
);
642 false_comparison
= combine_comparisons(falsify_op(left_comparison
), right_comparison
);
644 if (strcmp(left_var
, right_var
) > 0) {
645 struct symbol
*tmp_sym
= left_sym
;
646 const char *tmp_var
= left_var
;
648 left_var
= right_var
;
649 left_sym
= right_sym
;
652 true_comparison
= flip_op(true_comparison
);
653 false_comparison
= flip_op(false_comparison
);
656 if (!true_comparison
&& !false_comparison
)
660 true_state
= alloc_compare_state(left_var
, left_sym
, true_comparison
, right_var
, right_sym
);
663 if (false_comparison
)
664 false_state
= alloc_compare_state(left_var
, left_sym
, false_comparison
, right_var
, right_sym
);
668 snprintf(state_name
, sizeof(state_name
), "%s vs %s", left_var
, right_var
);
669 set_true_false_states(compare_id
, state_name
, NULL
, true_state
, false_state
);
670 save_link_var_sym(left_var
, left_sym
, state_name
);
671 save_link_var_sym(right_var
, right_sym
, state_name
);
672 } END_FOR_EACH_PTR(tmp
);
675 static void update_tf_data(struct state_list
*pre_slist
, struct compare_data
*tdata
)
677 struct smatch_state
*state
;
679 state
= get_state_slist(pre_slist
, link_id
, tdata
->var2
, tdata
->sym2
);
681 update_tf_links(pre_slist
, tdata
->var1
, tdata
->sym1
, tdata
->comparison
, tdata
->var2
, tdata
->sym2
, state
->data
);
683 state
= get_state_slist(pre_slist
, link_id
, tdata
->var1
, tdata
->sym1
);
685 update_tf_links(pre_slist
, tdata
->var2
, tdata
->sym2
, flip_op(tdata
->comparison
), tdata
->var1
, tdata
->sym1
, state
->data
);
688 static void match_compare(struct expression
*expr
)
692 struct symbol
*left_sym
, *right_sym
;
694 struct smatch_state
*true_state
, *false_state
;
695 char state_name
[256];
696 struct state_list
*pre_slist
;
698 if (expr
->type
!= EXPR_COMPARE
)
700 left
= chunk_to_var_sym(expr
->left
, &left_sym
);
703 right
= chunk_to_var_sym(expr
->right
, &right_sym
);
707 if (strcmp(left
, right
) > 0) {
708 struct symbol
*tmp_sym
= left_sym
;
709 char *tmp_name
= left
;
712 left_sym
= right_sym
;
715 op
= flip_op(expr
->op
);
719 false_op
= falsify_op(op
);
720 snprintf(state_name
, sizeof(state_name
), "%s vs %s", left
, right
);
721 true_state
= alloc_compare_state(left
, left_sym
, op
, right
, right_sym
);
722 false_state
= alloc_compare_state(left
, left_sym
, false_op
, right
, right_sym
);
724 pre_slist
= clone_slist(__get_cur_slist());
725 update_tf_data(pre_slist
, true_state
->data
);
726 free_slist(&pre_slist
);
728 set_true_false_states(compare_id
, state_name
, NULL
, true_state
, false_state
);
729 save_link(expr
->left
, state_name
);
730 save_link(expr
->right
, state_name
);
736 static void add_comparison_var_sym(const char *left_name
, struct symbol
*left_sym
, int comparison
, const char *right_name
, struct symbol
*right_sym
)
738 struct smatch_state
*state
;
739 char state_name
[256];
741 if (strcmp(left_name
, right_name
) > 0) {
742 struct symbol
*tmp_sym
= left_sym
;
743 const char *tmp_name
= left_name
;
745 left_name
= right_name
;
746 left_sym
= right_sym
;
747 right_name
= tmp_name
;
749 comparison
= flip_op(comparison
);
751 snprintf(state_name
, sizeof(state_name
), "%s vs %s", left_name
, right_name
);
752 state
= alloc_compare_state(left_name
, left_sym
, comparison
, right_name
, right_sym
);
754 set_state(compare_id
, state_name
, NULL
, state
);
755 save_link_var_sym(left_name
, left_sym
, state_name
);
756 save_link_var_sym(right_name
, right_sym
, state_name
);
759 static void add_comparison(struct expression
*left
, int comparison
, struct expression
*right
)
761 char *left_name
= NULL
;
762 char *right_name
= NULL
;
763 struct symbol
*left_sym
, *right_sym
;
765 left_name
= chunk_to_var_sym(left
, &left_sym
);
768 right_name
= chunk_to_var_sym(right
, &right_sym
);
772 add_comparison_var_sym(left_name
, left_sym
, comparison
, right_name
, right_sym
);
775 free_string(left_name
);
776 free_string(right_name
);
779 static void match_assign_add(struct expression
*expr
)
781 struct expression
*right
;
782 struct expression
*r_left
, *r_right
;
783 sval_t left_tmp
, right_tmp
;
785 right
= strip_expr(expr
->right
);
786 r_left
= strip_expr(right
->left
);
787 r_right
= strip_expr(right
->right
);
789 get_absolute_min(r_left
, &left_tmp
);
790 get_absolute_min(r_right
, &right_tmp
);
792 if (left_tmp
.value
> 0)
793 add_comparison(expr
->left
, '>', r_right
);
794 else if (left_tmp
.value
== 0)
795 add_comparison(expr
->left
, SPECIAL_GTE
, r_right
);
797 if (right_tmp
.value
> 0)
798 add_comparison(expr
->left
, '>', r_left
);
799 else if (right_tmp
.value
== 0)
800 add_comparison(expr
->left
, SPECIAL_GTE
, r_left
);
803 static void match_assign_sub(struct expression
*expr
)
805 struct expression
*right
;
806 struct expression
*r_left
, *r_right
;
810 right
= strip_expr(expr
->right
);
811 r_left
= strip_expr(right
->left
);
812 r_right
= strip_expr(right
->right
);
814 if (get_absolute_min(r_right
, &min
) && sval_is_negative(min
))
817 comparison
= get_comparison(r_left
, r_right
);
819 switch (comparison
) {
822 if (implied_not_equal(r_right
, 0))
823 add_comparison(expr
->left
, '>', r_left
);
825 add_comparison(expr
->left
, SPECIAL_GTE
, r_left
);
830 static void match_assign_divide(struct expression
*expr
)
832 struct expression
*right
;
833 struct expression
*r_left
, *r_right
;
836 right
= strip_expr(expr
->right
);
837 r_left
= strip_expr(right
->left
);
838 r_right
= strip_expr(right
->right
);
839 if (!get_implied_min(r_right
, &min
) || min
.value
<= 1)
842 add_comparison(expr
->left
, '<', r_left
);
845 static void match_binop_assign(struct expression
*expr
)
847 struct expression
*right
;
849 right
= strip_expr(expr
->right
);
850 if (right
->op
== '+')
851 match_assign_add(expr
);
852 if (right
->op
== '-')
853 match_assign_sub(expr
);
854 if (right
->op
== '/')
855 match_assign_divide(expr
);
858 static void copy_comparisons(struct expression
*left
, struct expression
*right
)
860 struct string_list
*links
;
861 struct smatch_state
*state
;
862 struct compare_data
*data
;
863 struct symbol
*left_sym
, *right_sym
;
864 char *left_var
= NULL
;
865 char *right_var
= NULL
;
871 left_var
= chunk_to_var_sym(left
, &left_sym
);
874 right_var
= chunk_to_var_sym(right
, &right_sym
);
878 state
= get_state(link_id
, right_var
, right_sym
);
883 FOR_EACH_PTR(links
, tmp
) {
884 state
= get_state(compare_id
, tmp
, NULL
);
885 if (!state
|| !state
->data
)
888 comparison
= data
->comparison
;
891 if (var_sym_eq(var
, sym
, right_var
, right_sym
)) {
894 comparison
= flip_op(comparison
);
896 add_comparison_var_sym(left_var
, left_sym
, comparison
, var
, sym
);
897 } END_FOR_EACH_PTR(tmp
);
900 free_string(right_var
);
903 static void match_assign(struct expression
*expr
)
905 struct expression
*right
;
910 copy_comparisons(expr
->left
, expr
->right
);
911 add_comparison(expr
->left
, SPECIAL_EQUAL
, expr
->right
);
913 right
= strip_expr(expr
->right
);
914 if (right
->type
== EXPR_BINOP
)
915 match_binop_assign(expr
);
918 static int get_comparison_strings(char *one
, char *two
)
921 struct smatch_state
*state
;
925 if (strcmp(one
, two
) > 0) {
933 snprintf(buf
, sizeof(buf
), "%s vs %s", one
, two
);
934 state
= get_state(compare_id
, buf
, NULL
);
936 ret
= state_to_comparison(state
);
944 int get_comparison(struct expression
*a
, struct expression
*b
)
950 one
= chunk_to_var(a
);
953 two
= chunk_to_var(b
);
957 ret
= get_comparison_strings(one
, two
);
964 void __add_comparison_info(struct expression
*expr
, struct expression
*call
, const char *range
)
966 struct expression
*arg
;
968 const char *c
= range
;
970 if (!str_to_comparison_arg(c
, call
, &comparison
, &arg
))
972 add_comparison(expr
, comparison
, arg
);
975 static char *range_comparison_to_param_helper(struct expression
*expr
, char starts_with
)
977 struct symbol
*param
;
980 char *ret_str
= NULL
;
984 var
= chunk_to_var(expr
);
989 FOR_EACH_PTR(cur_func_sym
->ctype
.base_type
->arguments
, param
) {
993 snprintf(buf
, sizeof(buf
), "%s orig", param
->ident
->name
);
994 compare
= get_comparison_strings(var
, buf
);
997 if (show_special(compare
)[0] != starts_with
)
999 snprintf(buf
, sizeof(buf
), "[%sp%d]", show_special(compare
), i
);
1000 ret_str
= alloc_sname(buf
);
1002 } END_FOR_EACH_PTR(param
);
1009 char *expr_equal_to_param(struct expression
*expr
)
1011 return range_comparison_to_param_helper(expr
, '=');
1014 char *expr_lte_to_param(struct expression
*expr
)
1016 return range_comparison_to_param_helper(expr
, '<');
1019 static void free_data(struct symbol
*sym
)
1023 clear_compare_data_alloc();
1026 void register_comparison(int id
)
1029 add_hook(&match_compare
, CONDITION_HOOK
);
1030 add_hook(&match_assign
, ASSIGNMENT_HOOK
);
1031 add_hook(&save_start_states
, AFTER_DEF_HOOK
);
1032 add_unmatched_state_hook(compare_id
, unmatched_comparison
);
1033 add_merge_hook(compare_id
, &merge_compare_states
);
1034 add_hook(&free_data
, AFTER_FUNC_HOOK
);
1037 void register_comparison_links(int id
)
1040 add_merge_hook(link_id
, &merge_links
);
1041 add_modification_hook(link_id
, &match_modify
);