2 * Copyright (C) 2012 Oracle.
4 * This program is free software; you can redistribute it and/or
5 * modify it under the terms of the GNU General Public License
6 * as published by the Free Software Foundation; either version 2
7 * of the License, or (at your option) any later version.
9 * This program is distributed in the hope that it will be useful,
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 * GNU General Public License for more details.
14 * You should have received a copy of the GNU General Public License
15 * along with this program; if not, see http://www.gnu.org/copyleft/gpl.txt
19 * This is for functions like:
30 * If we return 1 that means the value of *x has been set to 0. If we return
31 * 0 then we have left *x alone.
36 #include "smatch_slist.h"
37 #include "smatch_extra.h"
41 static struct smatch_state
*unmatched_state(struct sm_state
*sm
)
43 return alloc_estate_empty();
46 static int parent_is_set(const char *name
, struct symbol
*sym
, struct smatch_state
*state
)
48 struct expression
*faked
;
53 if (!__in_fake_assign
)
55 if (!is_whole_rl(estate_rl(state
)))
57 if (get_state(my_id
, name
, sym
))
60 faked
= get_faked_expression();
63 if ((faked
->type
== EXPR_PREOP
|| faked
->type
== EXPR_POSTOP
) &&
64 (faked
->op
== SPECIAL_INCREMENT
|| faked
->op
== SPECIAL_DECREMENT
)) {
65 faked
= strip_expr(faked
->unop
);
66 if (faked
->type
== EXPR_SYMBOL
)
70 if (faked
->type
!= EXPR_ASSIGNMENT
)
73 left_name
= expr_to_var(faked
->left
);
77 len
= strlen(left_name
);
78 if (strncmp(name
, left_name
, len
) == 0 && name
[len
] == '-')
80 free_string(left_name
);
85 static bool is_probably_worthless(struct expression
*expr
)
87 struct expression
*faked
;
89 if (!__in_fake_struct_assign
)
92 faked
= get_faked_expression();
93 if (!faked
|| faked
->type
!= EXPR_ASSIGNMENT
)
96 if (faked
->left
->type
== EXPR_PREOP
&&
97 faked
->left
->op
== '*')
103 static bool name_is_sym_name(const char *name
, struct symbol
*sym
)
105 if (!name
|| !sym
|| !sym
->ident
)
108 return strcmp(name
, sym
->ident
->name
) == 0;
111 static void extra_mod_hook(const char *name
, struct symbol
*sym
, struct expression
*expr
, struct smatch_state
*state
)
113 struct symbol
*param_sym
;
117 if (expr
&& expr
->smatch_flags
& Fake
)
120 if (is_probably_worthless(expr
))
123 type
= get_type(expr
);
124 if (type
&& (type
->type
== SYM_STRUCT
|| type
->type
== SYM_UNION
))
127 if (name_is_sym_name(name
, sym
))
130 param_name
= get_param_var_sym_var_sym(name
, sym
, NULL
, ¶m_sym
);
131 if (!param_name
|| !param_sym
)
133 if (get_param_num_from_sym(param_sym
) < 0)
135 if (parent_is_set(param_name
, param_sym
, state
))
138 set_state(my_id
, param_name
, param_sym
, state
);
140 free_string(param_name
);
144 * This function is is a dirty hack because extra_mod_hook is giving us a NULL
145 * sym instead of a vsl.
147 static void match_array_assignment(struct expression
*expr
)
149 struct expression
*array
, *offset
;
152 struct range_list
*rl
;
156 if (__in_fake_assign
)
159 if (!is_array(expr
->left
))
161 array
= get_array_base(expr
->left
);
162 offset
= get_array_offset(expr
->left
);
164 /* These are handled by extra_mod_hook() */
165 if (get_value(offset
, &sval
))
167 name
= expr_to_var_sym(array
, &sym
);
170 if (map_to_param(name
, sym
) < 0)
172 get_absolute_rl(expr
->right
, &rl
);
173 rl
= cast_rl(get_type(expr
->left
), rl
);
175 snprintf(buf
, sizeof(buf
), "*%s", name
);
176 set_state(my_id
, buf
, sym
, alloc_estate_rl(rl
));
181 static char *get_two_dots(const char *name
)
186 for (i
= 0; i
< sizeof(buf
); i
++) {
187 if (name
[i
] == '.') {
200 * This relies on the fact that these states are stored so that
201 * foo->bar is before foo->bar->baz.
203 static int parent_set(struct string_list
*list
, const char *param_name
, struct sm_state
*sm
)
209 if (strncmp(param_name
, "(*$)->", 6) == 0 && sm
->sym
&& sm
->sym
->ident
) {
212 snprintf(buf
, sizeof(buf
), "*%s", sm
->sym
->ident
->name
);
213 if (get_state(my_id
, buf
, sm
->sym
))
217 FOR_EACH_PTR(list
, tmp
) {
219 ret
= strncmp(tmp
, sm
->name
, len
);
224 if (sm
->name
[len
] == '-')
226 } END_FOR_EACH_PTR(tmp
);
231 static void print_return_value_param_helper(int return_id
, char *return_ranges
, struct expression
*expr
, int limit
)
234 struct smatch_state
*extra
;
236 struct range_list
*rl
;
237 const char *param_name
;
238 struct string_list
*set_list
= NULL
;
241 char two_dot
[80] = "";
244 __promote_sets_to_clears(return_id
, return_ranges
, expr
);
246 FOR_EACH_MY_SM(my_id
, __get_cur_stree(), sm
) {
247 bool untracked
= false;
249 if (!estate_rl(sm
->state
))
251 extra
= __get_state(SMATCH_EXTRA
, sm
->name
, sm
->sym
);
253 rl
= rl_intersection(estate_rl(sm
->state
), estate_rl(extra
));
257 rl
= estate_rl(sm
->state
);
260 param
= get_param_key_from_sm(sm
, NULL
, ¶m_name
);
261 if (param
< 0 || !param_name
)
263 if (param_name
[0] == '&')
265 if (strcmp(param_name
, "$") == 0 ||
266 is_recursive_member(param_name
) ||
267 is_ignored_kernel_data(param_name
)) {
268 insert_string(&set_list
, (char *)sm
->name
);
272 if (parent_was_PARAM_CLEAR(sm
->name
, sm
->sym
))
275 sql_insert_return_states(return_id
, return_ranges
,
276 UNTRACKED_PARAM
, param
, param_name
, "");
281 char *new = get_two_dots(param_name
);
283 /* no useful information here. */
284 if (is_whole_rl(rl
) && parent_set(set_list
, param_name
, sm
))
288 if (strcmp(new, two_dot
) == 0)
291 strncpy(two_dot
, new, sizeof(two_dot
));
292 insert_string(&set_list
, (char *)sm
->name
);
293 sql_insert_return_states(return_id
, return_ranges
,
294 PARAM_SET
, param
, new, "s64min-s64max");
299 math_str
= get_value_in_terms_of_parameter_math_var_sym(sm
->name
, sm
->sym
);
301 snprintf(buf
, sizeof(buf
), "%s[%s]", show_rl(rl
), math_str
);
302 insert_string(&set_list
, (char *)sm
->name
);
303 sql_insert_return_states(return_id
, return_ranges
,
304 param_has_filter_data(sm
) ? PARAM_ADD
: PARAM_SET
,
305 param
, param_name
, buf
);
309 /* no useful information here. */
310 if (is_whole_rl(rl
) && parent_set(set_list
, param_name
, sm
))
312 if (is_whole_rl(rl
) && parent_was_PARAM_CLEAR(sm
->name
, sm
->sym
))
314 if (rl_is_zero(rl
) && parent_was_PARAM_CLEAR_ZERO(sm
->name
, sm
->sym
))
317 insert_string(&set_list
, (char *)sm
->name
);
319 sql_insert_return_states(return_id
, return_ranges
,
320 param_has_filter_data(sm
) ? PARAM_ADD
: PARAM_SET
,
321 param
, param_name
, show_rl(rl
));
322 if (limit
&& ++count
> limit
)
325 } END_FOR_EACH_SM(sm
);
327 free_ptr_list((struct ptr_list
**)&set_list
);
330 static void print_return_value_param(int return_id
, char *return_ranges
, struct expression
*expr
)
332 print_return_value_param_helper(return_id
, return_ranges
, expr
, 0);
335 void print_limited_param_set(int return_id
, char *return_ranges
, struct expression
*expr
)
337 print_return_value_param_helper(return_id
, return_ranges
, expr
, 1000);
340 static int possibly_empty(struct sm_state
*sm
)
342 struct sm_state
*tmp
;
344 FOR_EACH_PTR(sm
->possible
, tmp
) {
345 if (strcmp(tmp
->name
, "") == 0)
347 } END_FOR_EACH_PTR(tmp
);
351 static bool sym_was_set(struct symbol
*sym
)
355 if (!sym
|| !sym
->ident
)
358 snprintf(buf
, sizeof(buf
), "%s orig", sym
->ident
->name
);
359 if (get_comparison_strings(sym
->ident
->name
, buf
) == SPECIAL_EQUAL
)
365 int param_was_set_var_sym(const char *name
, struct symbol
*sym
)
367 struct symbol
*param_sym
;
368 const char *param_name
;
373 param_name
= get_param_var_sym_var_sym(name
, sym
, NULL
, ¶m_sym
);
374 if (param_name
&& param_sym
) {
385 if (sym_was_set(sym
))
389 if (len
>= sizeof(buf
))
390 len
= sizeof(buf
) - 1;
392 for (i
= 0; i
<= len
; i
++) {
393 if (name
[i
] != '-' && name
[i
] != '\0')
396 memcpy(buf
, name
, i
);
399 sm
= get_sm_state(my_id
, buf
, sym
);
402 if (possibly_empty(sm
))
408 return param_was_set_var_sym(name
+ 1, sym
);
413 static struct expression
*get_unfaked_expr(struct expression
*expr
)
415 struct expression
*tmp
;
417 if (!is_fake_var(expr
))
419 tmp
= expr_get_fake_parent_expr(expr
);
420 if (!tmp
|| tmp
->type
!= EXPR_ASSIGNMENT
)
425 int param_was_set(struct expression
*expr
)
431 expr
= get_unfaked_expr(expr
);
433 name
= expr_to_var_sym(expr
, &sym
);
437 ret
= param_was_set_var_sym(name
, sym
);
443 void register_param_set(int id
)
447 set_dynamic_states(my_id
);
448 add_extra_mod_hook(&extra_mod_hook
);
449 add_hook(match_array_assignment
, ASSIGNMENT_HOOK
);
450 add_unmatched_state_hook(my_id
, &unmatched_state
);
451 add_merge_hook(my_id
, &merge_estates
);
452 add_split_return_callback(&print_return_value_param
);