2 * Copyright (C) 2010 Dan Carpenter.
4 * This program is free software; you can redistribute it and/or
5 * modify it under the terms of the GNU General Public License
6 * as published by the Free Software Foundation; either version 2
7 * of the License, or (at your option) any later version.
9 * This program is distributed in the hope that it will be useful,
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 * GNU General Public License for more details.
14 * You should have received a copy of the GNU General Public License
15 * along with this program; if not, see http://www.gnu.org/copyleft/gpl.txt
19 * check_memory() is getting too big and messy.
25 #include "smatch_slist.h"
26 #include "smatch_extra.h"
33 static void ok_to_use(struct sm_state
*sm
, struct expression
*mod_expr
)
36 set_state(my_id
, sm
->name
, sm
->sym
, &ok
);
39 static void pre_merge_hook(struct sm_state
*sm
)
41 if (is_impossible_path())
42 set_state(my_id
, sm
->name
, sm
->sym
, &ok
);
45 static int is_freed(struct expression
*expr
)
49 sm
= get_sm_state_expr(my_id
, expr
);
50 if (sm
&& slist_has_state(sm
->possible
, &freed
))
55 static void match_symbol(struct expression
*expr
)
57 struct expression
*parent
;
60 if (is_impossible_path())
63 parent
= expr_get_parent_expr(expr
);
64 while (parent
&& parent
->type
== EXPR_PREOP
&& parent
->op
== '(')
65 parent
= expr_get_parent_expr(parent
);
66 if (parent
&& parent
->type
== EXPR_PREOP
&& parent
->op
== '&')
71 name
= expr_to_var(expr
);
72 sm_msg("warn: '%s' was already freed.", name
);
76 static void match_dereferences(struct expression
*expr
)
80 if (expr
->type
!= EXPR_PREOP
)
83 if (is_impossible_path())
86 expr
= strip_expr(expr
->unop
);
89 name
= expr_to_var(expr
);
90 sm_msg("error: dereferencing freed memory '%s'", name
);
91 set_state_expr(my_id
, expr
, &ok
);
95 static int ignored_params
[16];
97 static void set_ignored_params(struct expression
*call
)
99 struct expression
*arg
;
103 memset(&ignored_params
, 0, sizeof(ignored_params
));
106 FOR_EACH_PTR(call
->args
, arg
) {
108 if (arg
->type
!= EXPR_STRING
)
111 } END_FOR_EACH_PTR(arg
);
117 p
= arg
->string
->data
;
118 while ((p
= strchr(p
, '%'))) {
119 if (i
>= ARRAY_SIZE(ignored_params
))
131 ignored_params
[i
] = 1;
136 static int is_free_func(struct expression
*fn
)
141 name
= expr_to_str(fn
);
144 if (strstr(name
, "free"))
151 static void match_call(struct expression
*expr
)
153 struct expression
*arg
;
157 if (is_impossible_path())
160 set_ignored_params(expr
);
163 FOR_EACH_PTR(expr
->args
, arg
) {
165 if (!is_pointer(arg
))
169 if (ignored_params
[i
])
172 name
= expr_to_var(arg
);
173 if (is_free_func(expr
->fn
))
174 sm_msg("error: double free of '%s'", name
);
176 sm_msg("warn: passing freed memory '%s'", name
);
177 set_state_expr(my_id
, arg
, &ok
);
179 } END_FOR_EACH_PTR(arg
);
182 static void match_return(struct expression
*expr
)
186 if (is_impossible_path())
194 name
= expr_to_var(expr
);
195 sm_msg("warn: returning freed memory '%s'", name
);
196 set_state_expr(my_id
, expr
, &ok
);
200 static void match_free(const char *fn
, struct expression
*expr
, void *param
)
202 struct expression
*arg
;
204 if (is_impossible_path())
207 arg
= get_argument_from_call_expr(expr
->args
, PTR_INT(param
));
211 char *name
= expr_to_var(arg
);
213 sm_msg("error: double free of '%s'", name
);
216 set_state_expr(my_id
, arg
, &freed
);
219 static void set_param_freed(struct expression
*call
, struct expression
*arg
, char *key
, char *unused
)
224 name
= get_variable_from_key(arg
, key
, &sym
);
228 set_state(my_id
, name
, sym
, &freed
);
233 int parent_is_free_var_sym(const char *name
, struct symbol
*sym
)
238 struct smatch_state
*state
;
240 if (option_project
== PROJ_KERNEL
)
241 return parent_is_free_var_sym_strict(name
, sym
);
243 strncpy(buf
, name
, sizeof(buf
) - 1);
244 buf
[sizeof(buf
) - 1] = '\0';
247 while ((*start
== '&'))
250 while ((end
= strrchr(start
, '-'))) {
252 state
= __get_state(my_id
, start
, sym
);
259 int parent_is_free(struct expression
*expr
)
265 expr
= strip_expr(expr
);
266 var
= expr_to_var_sym(expr
, &sym
);
269 ret
= parent_is_free_var_sym(var
, sym
);
275 void check_free(int id
)
279 if (option_project
== PROJ_KERNEL
) {
280 /* The kernel use check_free_strict.c */
284 add_function_hook("free", &match_free
, INT_PTR(0));
287 add_hook(&match_symbol
, SYM_HOOK
);
288 add_hook(&match_dereferences
, DEREF_HOOK
);
289 add_hook(&match_call
, FUNCTION_CALL_HOOK
);
290 add_hook(&match_return
, RETURN_HOOK
);
292 add_modification_hook(my_id
, &ok_to_use
);
293 select_return_implies_hook(PARAM_FREED
, &set_param_freed
);
294 add_pre_merge_hook(my_id
, &pre_merge_hook
);