2 * sparse/smatch_extra.c
4 * Copyright (C) 2008 Dan Carpenter.
6 * Licensed under the Open Software License version 1.1
11 * smatch_extra.c is supposed to track the value of every variable.
19 #include "smatch_slist.h"
20 #include "smatch_extra.h"
24 static struct symbol
*cur_func
;
26 struct data_range whole_range
= {
31 static struct smatch_state
*alloc_extra_state_empty()
33 struct smatch_state
*state
;
34 struct data_info
*dinfo
;
36 dinfo
= __alloc_data_info(0);
37 dinfo
->type
= DATA_RANGE
;
38 dinfo
->value_ranges
= NULL
;
39 state
= __alloc_smatch_state(0);
44 static struct smatch_state
*alloc_extra_state_no_name(int val
)
46 struct smatch_state
*state
;
48 state
= __alloc_smatch_state(0);
50 state
->data
= (void *)alloc_dinfo_range(whole_range
.min
, whole_range
.max
);
52 state
->data
= (void *)alloc_dinfo_range(val
, val
);
56 /* We do this because ->value_ranges is a list */
57 struct smatch_state
*extra_undefined()
59 struct data_info
*dinfo
;
60 static struct smatch_state
*ret
;
61 static struct symbol
*prev_func
;
63 if (prev_func
== cur_func
)
67 dinfo
= alloc_dinfo_range(whole_range
.min
, whole_range
.max
);
68 ret
= __alloc_smatch_state(0);
69 ret
->name
= "unknown";
74 struct smatch_state
*alloc_extra_state(int val
)
76 struct smatch_state
*state
;
79 return extra_undefined();
80 state
= alloc_extra_state_no_name(val
);
81 state
->name
= show_ranges(((struct data_info
*)state
->data
)->value_ranges
);
85 struct smatch_state
*alloc_extra_state_range(long long min
, long long max
)
87 struct smatch_state
*state
;
89 if (min
== whole_range
.min
&& max
== whole_range
.max
)
90 return extra_undefined();
91 state
= __alloc_smatch_state(0);
92 state
->data
= (void *)alloc_dinfo_range(min
, max
);
93 state
->name
= show_ranges(((struct data_info
*)state
->data
)->value_ranges
);
97 struct smatch_state
*alloc_extra_state_range_list(struct range_list
*rl
)
99 struct smatch_state
*state
;
101 state
= __alloc_smatch_state(0);
102 state
->data
= (void *)alloc_dinfo_range_list(rl
);
103 state
->name
= show_ranges(((struct data_info
*)state
->data
)->value_ranges
);
107 struct smatch_state
*filter_range(struct smatch_state
*orig
,
108 long long filter_min
, long long filter_max
)
110 struct smatch_state
*ret
;
111 struct data_info
*orig_info
;
112 struct data_info
*ret_info
;
115 orig
= extra_undefined();
116 orig_info
= (struct data_info
*)orig
->data
;
117 ret
= alloc_extra_state_empty();
118 ret_info
= (struct data_info
*)ret
->data
;
119 ret_info
->value_ranges
= remove_range(orig_info
->value_ranges
, filter_min
, filter_max
);
120 ret
->name
= show_ranges(ret_info
->value_ranges
);
124 struct smatch_state
*add_filter(struct smatch_state
*orig
, long long num
)
126 return filter_range(orig
, num
, num
);
129 static struct smatch_state
*merge_func(const char *name
, struct symbol
*sym
,
130 struct smatch_state
*s1
,
131 struct smatch_state
*s2
)
133 struct data_info
*info1
= (struct data_info
*)s1
->data
;
134 struct data_info
*info2
= (struct data_info
*)s2
->data
;
135 struct data_info
*ret_info
;
136 struct smatch_state
*tmp
;
137 struct range_list
*value_ranges
;
139 value_ranges
= range_list_union(info1
->value_ranges
, info2
->value_ranges
);
140 tmp
= alloc_extra_state_empty();
141 ret_info
= (struct data_info
*)tmp
->data
;
142 ret_info
->value_ranges
= value_ranges
;
143 tmp
->name
= show_ranges(ret_info
->value_ranges
);
147 struct sm_state
*__extra_pre_loop_hook_before(struct statement
*iterator_pre_statement
)
149 struct expression
*expr
;
152 struct sm_state
*ret
= NULL
;
154 if (!iterator_pre_statement
)
156 if (iterator_pre_statement
->type
!= STMT_EXPRESSION
)
158 expr
= iterator_pre_statement
->expression
;
159 if (expr
->type
!= EXPR_ASSIGNMENT
)
161 name
= get_variable_from_expr(expr
->left
, &sym
);
164 ret
= get_sm_state(my_id
, name
, sym
);
170 static const char *get_iter_op(struct expression
*expr
)
172 if (expr
->type
!= EXPR_POSTOP
&& expr
->type
!= EXPR_PREOP
)
174 return show_special(expr
->op
);
177 int __iterator_unchanged(struct sm_state
*sm
, struct statement
*iterator
)
179 struct expression
*iter_expr
;
187 if (iterator
->type
!= STMT_EXPRESSION
)
189 iter_expr
= iterator
->expression
;
190 op
= get_iter_op(iter_expr
);
191 if (!op
|| (strcmp(op
, "--") && strcmp(op
, "++")))
193 name
= get_variable_from_expr(iter_expr
->unop
, &sym
);
196 if (get_sm_state(my_id
, name
, sym
) == sm
)
203 void __extra_pre_loop_hook_after(struct sm_state
*sm
,
204 struct statement
*iterator
,
205 struct expression
*condition
)
207 struct expression
*iter_expr
;
213 struct smatch_state
*state
;
214 struct data_info
*dinfo
;
217 iter_expr
= iterator
->expression
;
219 if (condition
->type
!= EXPR_COMPARE
)
221 value
= get_value(condition
->left
);
222 if (value
== UNDEFINED
) {
223 value
= get_value(condition
->right
);
224 if (value
== UNDEFINED
)
229 name
= get_variable_from_expr(condition
->left
, &sym
);
231 name
= get_variable_from_expr(condition
->right
, &sym
);
234 if (sym
!= sm
->sym
|| strcmp(name
, sm
->name
))
236 op
= get_iter_op(iter_expr
);
237 state
= get_state(my_id
, name
, sym
);
238 dinfo
= (struct data_info
*)state
->data
;
239 min
= get_dinfo_min(dinfo
);
240 max
= get_dinfo_max(dinfo
);
241 if (!strcmp(op
, "++") && min
!= whole_range
.min
&& max
== whole_range
.max
) {
242 set_state(my_id
, name
, sym
, alloc_extra_state(min
));
243 } else if (min
== whole_range
.min
&& max
!= whole_range
.max
) {
244 set_state(my_id
, name
, sym
, alloc_extra_state(max
));
251 static struct smatch_state
*unmatched_state(struct sm_state
*sm
)
253 return extra_undefined();
256 static void match_function_call(struct expression
*expr
)
258 struct expression
*tmp
;
263 FOR_EACH_PTR(expr
->args
, tmp
) {
264 if (tmp
->op
== '&') {
265 name
= get_variable_from_expr(tmp
->unop
, &sym
);
267 set_state(my_id
, name
, sym
, extra_undefined());
272 } END_FOR_EACH_PTR(tmp
);
275 static void match_assign(struct expression
*expr
)
277 struct expression
*left
;
281 left
= strip_expr(expr
->left
);
282 name
= get_variable_from_expr(left
, &sym
);
285 set_state(my_id
, name
, sym
, alloc_extra_state(get_value(expr
->right
)));
289 static void undef_expr(struct expression
*expr
)
299 name
= get_variable_from_expr(expr
->unop
, &sym
);
302 if (!get_state(my_id
, name
, sym
)) {
306 set_state(my_id
, name
, sym
, extra_undefined());
310 static void match_declarations(struct symbol
*sym
)
315 name
= sym
->ident
->name
;
316 if (sym
->initializer
) {
317 set_state(my_id
, name
, sym
, alloc_extra_state(get_value(sym
->initializer
)));
318 scoped_state(name
, my_id
, sym
);
320 set_state(my_id
, name
, sym
, extra_undefined());
321 scoped_state(name
, my_id
, sym
);
326 static void match_function_def(struct symbol
*sym
)
331 FOR_EACH_PTR(sym
->ctype
.base_type
->arguments
, arg
) {
335 set_state(my_id
, arg
->ident
->name
, arg
, extra_undefined());
336 } END_FOR_EACH_PTR(arg
);
343 static long long get_implied_value_helper(struct expression
*expr
, int what
)
345 struct smatch_state
*state
;
350 val
= get_value(expr
);
351 if (val
!= UNDEFINED
)
354 name
= get_variable_from_expr(expr
, &sym
);
357 state
= get_state(my_id
, name
, sym
);
359 if (!state
|| !state
->data
)
361 if (what
== VAL_SINGLE
)
362 return get_single_value_from_range((struct data_info
*)state
->data
);
364 return get_dinfo_max((struct data_info
*)state
->data
);
365 return get_dinfo_min((struct data_info
*)state
->data
);
368 int get_implied_single_val(struct expression
*expr
)
370 return get_implied_value_helper(expr
, VAL_SINGLE
);
373 int get_implied_max(struct expression
*expr
)
377 ret
= get_implied_value_helper(expr
, VAL_MAX
);
378 if (ret
== whole_range
.max
)
383 int get_implied_min(struct expression
*expr
)
387 ret
= get_implied_value_helper(expr
, VAL_MIN
);
388 if (ret
== whole_range
.min
)
393 int last_stmt_val(struct statement
*stmt
)
395 struct expression
*expr
;
397 stmt
= last_ptr_list((struct ptr_list
*)stmt
->stmts
);
398 if (stmt
->type
!= STMT_EXPRESSION
)
400 expr
= stmt
->expression
;
401 return get_value(expr
);
404 static void match_comparison(struct expression
*expr
)
409 struct smatch_state
*one_state
;
410 struct smatch_state
*two_state
;
411 struct smatch_state
*orig
;
413 int comparison
= expr
->op
;
415 value
= get_value(expr
->left
);
416 if (value
== UNDEFINED
) {
417 value
= get_value(expr
->right
);
418 if (value
== UNDEFINED
)
422 if (left
&& expr
->left
->type
== EXPR_CALL
) {
423 function_comparison(comparison
, expr
->left
, value
, left
);
426 if (!left
&& expr
->right
->type
== EXPR_CALL
) {
427 function_comparison(comparison
, expr
->right
, value
, left
);
431 name
= get_variable_from_expr(expr
->left
, &sym
);
433 name
= get_variable_from_expr(expr
->right
, &sym
);
437 orig
= get_state(my_id
, name
, sym
);
439 orig
= extra_undefined();
443 case SPECIAL_UNSIGNED_LT
:
444 one_state
= filter_range(orig
, whole_range
.min
, value
- 1);
445 two_state
= filter_range(orig
, value
, whole_range
.max
);
447 set_true_false_states(my_id
, name
, sym
, two_state
, one_state
);
449 set_true_false_states(my_id
, name
, sym
, one_state
, two_state
);
451 case SPECIAL_UNSIGNED_LTE
:
453 one_state
= filter_range(orig
, whole_range
.min
, value
);
454 two_state
= filter_range(orig
, value
+ 1, whole_range
.max
);
456 set_true_false_states(my_id
, name
, sym
, two_state
, one_state
);
458 set_true_false_states(my_id
, name
, sym
, one_state
, two_state
);
461 // todo. print a warning here for impossible conditions.
462 one_state
= alloc_extra_state(value
);
463 two_state
= filter_range(orig
, value
, value
);
464 set_true_false_states(my_id
, name
, sym
, one_state
, two_state
);
466 case SPECIAL_UNSIGNED_GTE
:
468 one_state
= filter_range(orig
, whole_range
.min
, value
- 1);
469 two_state
= filter_range(orig
, value
, whole_range
.max
);
471 set_true_false_states(my_id
, name
, sym
, one_state
, two_state
);
473 set_true_false_states(my_id
, name
, sym
, two_state
, one_state
);
476 case SPECIAL_UNSIGNED_GT
:
477 one_state
= filter_range(orig
, whole_range
.min
, value
);
478 two_state
= filter_range(orig
, value
+ 1, whole_range
.max
);
480 set_true_false_states(my_id
, name
, sym
, one_state
, two_state
);
482 set_true_false_states(my_id
, name
, sym
, two_state
, one_state
);
484 case SPECIAL_NOTEQUAL
:
485 one_state
= alloc_extra_state(value
);
486 two_state
= filter_range(orig
, value
, value
);
487 set_true_false_states(my_id
, name
, sym
, two_state
, one_state
);
490 sm_msg("unhandled comparison %d\n", comparison
);
498 /* this is actually hooked from smatch_implied.c... it's hacky, yes */
499 void __extra_match_condition(struct expression
*expr
)
503 struct smatch_state
*pre_state
;
504 struct smatch_state
*true_state
;
505 struct smatch_state
*false_state
;
507 expr
= strip_expr(expr
);
510 function_comparison(SPECIAL_NOTEQUAL
, expr
, 0, 1);
515 name
= get_variable_from_expr(expr
, &sym
);
518 pre_state
= get_state(my_id
, name
, sym
);
519 true_state
= add_filter(pre_state
, 0);
520 false_state
= alloc_extra_state(0);
521 set_true_false_states(my_id
, name
, sym
, true_state
, false_state
);
525 match_comparison(expr
);
527 case EXPR_ASSIGNMENT
:
528 __extra_match_condition(expr
->right
);
529 __extra_match_condition(expr
->left
);
534 static int variable_non_zero(struct expression
*expr
)
538 struct smatch_state
*state
;
541 name
= get_variable_from_expr(expr
, &sym
);
544 state
= get_state(my_id
, name
, sym
);
545 if (!state
|| !state
->data
)
547 ret
= !possibly_false(SPECIAL_NOTEQUAL
, (struct data_info
*)state
->data
, 0, 1);
553 int known_condition_true(struct expression
*expr
)
560 tmp
= get_value(expr
);
561 if (tmp
&& tmp
!= UNDEFINED
)
564 expr
= strip_expr(expr
);
567 if (expr
->op
== '!') {
568 if (known_condition_false(expr
->unop
))
579 int known_condition_false(struct expression
*expr
)
589 if (expr
->op
== '!') {
590 if (known_condition_true(expr
->unop
))
601 static int do_comparison_range(struct expression
*expr
)
605 struct smatch_state
*state
;
608 int poss_true
, poss_false
;
610 value
= get_value(expr
->left
);
611 if (value
== UNDEFINED
) {
612 value
= get_value(expr
->right
);
613 if (value
== UNDEFINED
)
618 name
= get_variable_from_expr(expr
->left
, &sym
);
620 name
= get_variable_from_expr(expr
->right
, &sym
);
623 state
= get_state(SMATCH_EXTRA
, name
, sym
);
626 poss_true
= possibly_true(expr
->op
, (struct data_info
*)state
->data
, value
, left
);
627 poss_false
= possibly_false(expr
->op
, (struct data_info
*)state
->data
, value
, left
);
628 if (!poss_true
&& !poss_false
)
630 if (poss_true
&& !poss_false
)
632 if (!poss_true
&& poss_false
)
634 if (poss_true
&& poss_false
)
641 int implied_condition_true(struct expression
*expr
)
643 struct statement
*stmt
;
649 tmp
= get_value(expr
);
650 if (tmp
&& tmp
!= UNDEFINED
)
653 expr
= strip_expr(expr
);
656 if (do_comparison_range(expr
) == 1)
660 if (expr
->op
== '!') {
661 if (implied_condition_false(expr
->unop
))
665 stmt
= get_block_thing(expr
);
666 if (stmt
&& (last_stmt_val(stmt
) == 1))
670 if (variable_non_zero(expr
) == 1)
677 int implied_condition_false(struct expression
*expr
)
679 struct statement
*stmt
;
680 struct expression
*tmp
;
690 if (do_comparison_range(expr
) == 2)
693 if (expr
->op
== '!') {
694 if (implied_condition_true(expr
->unop
))
698 stmt
= get_block_thing(expr
);
699 if (stmt
&& (last_stmt_val(stmt
) == 0))
701 tmp
= strip_expr(expr
);
703 return implied_condition_false(tmp
);
706 if (variable_non_zero(expr
) == 0)
713 void register_smatch_extra(int id
)
716 add_merge_hook(my_id
, &merge_func
);
717 add_unmatched_state_hook(my_id
, &unmatched_state
);
718 add_hook(&undef_expr
, OP_HOOK
);
719 add_hook(&match_function_def
, FUNC_DEF_HOOK
);
720 add_hook(&match_function_call
, FUNCTION_CALL_HOOK
);
721 add_hook(&match_assign
, ASSIGNMENT_HOOK
);
722 add_hook(&match_declarations
, DECLARATION_HOOK
);
725 /* I don't know how to test for the ATTRIB_NORET attribute. :( */
726 add_function_hook("panic", &__match_nullify_path_hook
, NULL
);
727 add_function_hook("do_exit", &__match_nullify_path_hook
, NULL
);
728 add_function_hook("complete_and_exit", &__match_nullify_path_hook
, NULL
);
729 add_function_hook("__module_put_and_exit", &__match_nullify_path_hook
, NULL
);
730 add_function_hook("do_group_exit", &__match_nullify_path_hook
, NULL
);