db: Avoid dereferencing null pointer
[smatch.git] / smatch_type_val.c
blobe67ade5c4a2f082c8d280e52b15fc978573a946c
1 /*
2 * Copyright (C) 2013 Oracle.
4 * This program is free software; you can redistribute it and/or
5 * modify it under the terms of the GNU General Public License
6 * as published by the Free Software Foundation; either version 2
7 * of the License, or (at your option) any later version.
9 * This program is distributed in the hope that it will be useful,
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 * GNU General Public License for more details.
14 * You should have received a copy of the GNU General Public License
15 * along with this program; if not, see http://www.gnu.org/copyleft/gpl.txt
19 * The plan here is to save all the possible values store to a given struct
20 * member.
22 * We will load all the values in to the function_type_val table first then
23 * run a script on that and load all the resulting values into the type_val
24 * table.
26 * So in this file we want to take the union of everything assigned to the
27 * struct member and insert it into the function_type_val at the end.
29 * You would think that we could use smatch_modification_hooks.c or
30 * extra_modification_hook() here to get the information here but in the end we
31 * need to code everything again a third time.
35 #include "smatch.h"
36 #include "smatch_slist.h"
37 #include "smatch_extra.h"
39 static int my_id;
41 struct stree_stack *fn_type_val_stack;
42 struct stree *fn_type_val;
43 struct stree *global_type_val;
45 static char *db_vals;
46 static int get_vals(void *unused, int argc, char **argv, char **azColName)
48 db_vals = alloc_string(argv[0]);
49 return 0;
52 static void match_inline_start(struct expression *expr)
54 push_stree(&fn_type_val_stack, fn_type_val);
55 fn_type_val = NULL;
58 static void match_inline_end(struct expression *expr)
60 free_stree(&fn_type_val);
61 fn_type_val = pop_stree(&fn_type_val_stack);
64 int get_db_type_rl(struct expression *expr, struct range_list **rl)
66 char *member;
67 struct range_list *tmp;
69 member = get_member_name(expr);
70 if (!member)
71 return 0;
73 db_vals = NULL;
74 run_sql(get_vals, NULL,
75 "select value from type_value where type = '%s';", member);
76 free_string(member);
77 if (!db_vals)
78 return 0;
79 str_to_rl(&llong_ctype, db_vals, &tmp);
80 tmp = cast_rl(get_type(expr), tmp);
81 if (is_whole_rl(tmp))
82 return 0;
83 *rl = tmp;
84 free_string(db_vals);
86 return 1;
89 static void add_type_val(char *member, struct range_list *rl)
91 struct smatch_state *old, *add, *new;
93 member = alloc_string(member);
94 old = get_state_stree(fn_type_val, my_id, member, NULL);
95 add = alloc_estate_rl(rl);
96 if (old)
97 new = merge_estates(old, add);
98 else
99 new = add;
100 set_state_stree(&fn_type_val, my_id, member, NULL, new);
103 static void add_fake_type_val(char *member, struct range_list *rl, int ignore)
105 struct smatch_state *old, *add, *new;
107 member = alloc_string(member);
108 old = get_state_stree(fn_type_val, my_id, member, NULL);
109 if (old && strcmp(old->name, "min-max") == 0)
110 return;
111 if (ignore && old && strcmp(old->name, "ignore") == 0)
112 return;
113 add = alloc_estate_rl(rl);
114 if (old) {
115 new = merge_estates(old, add);
116 } else {
117 new = add;
118 if (ignore)
119 new->name = alloc_string("ignore");
120 else
121 new->name = alloc_string("min-max");
123 set_state_stree(&fn_type_val, my_id, member, NULL, new);
126 static void add_global_type_val(char *member, struct range_list *rl)
128 struct smatch_state *old, *add, *new;
130 member = alloc_string(member);
131 old = get_state_stree(global_type_val, my_id, member, NULL);
132 add = alloc_estate_rl(rl);
133 if (old)
134 new = merge_estates(old, add);
135 else
136 new = add;
137 new = clone_estate_perm(new);
138 set_state_stree_perm(&global_type_val, my_id, member, NULL, new);
141 static int has_link_cb(void *has_link, int argc, char **argv, char **azColName)
143 *(int *)has_link = 1;
144 return 0;
147 static int is_ignored_fake_assignment(void)
149 struct expression *expr;
150 struct symbol *type;
151 char *member_name;
152 int has_link = 0;
154 expr = get_faked_expression();
155 if (!expr || expr->type != EXPR_ASSIGNMENT)
156 return 0;
157 if (!is_void_pointer(expr->right))
158 return 0;
159 member_name = get_member_name(expr->right);
160 if (!member_name)
161 return 0;
163 type = get_type(expr->left);
164 if (!type || type->type != SYM_PTR)
165 return 0;
166 type = get_real_base_type(type);
167 if (!type || type->type != SYM_STRUCT)
168 return 0;
170 run_sql(has_link_cb, &has_link,
171 "select * from data_info where type = %d and data = '%s' and value = '%s';",
172 TYPE_LINK, member_name, type_to_str(type));
173 return has_link;
176 static int is_ignored_macro(void)
178 struct expression *expr;
179 char *name;
181 expr = get_faked_expression();
182 if (!expr || expr->type != EXPR_ASSIGNMENT)
183 return 0;
184 name = get_macro_name(expr->right->pos);
185 if (!name)
186 return 0;
187 if (strcmp(name, "container_of") == 0)
188 return 1;
189 if (strcmp(name, "rb_entry") == 0)
190 return 1;
191 if (strcmp(name, "list_entry") == 0)
192 return 1;
193 if (strcmp(name, "list_first_entry") == 0)
194 return 1;
195 if (strcmp(name, "hlist_entry") == 0)
196 return 1;
197 if (strstr(name, "for_each"))
198 return 1;
199 return 0;
202 static int is_ignored_function(void)
204 struct expression *expr;
206 expr = get_faked_expression();
207 if (!expr || expr->type != EXPR_ASSIGNMENT)
208 return 0;
209 expr = strip_expr(expr->right);
210 if (!expr || expr->type != EXPR_CALL || expr->fn->type != EXPR_SYMBOL)
211 return 0;
213 if (sym_name_is("kmalloc", expr->fn))
214 return 1;
215 if (sym_name_is("netdev_priv", expr->fn))
216 return 1;
218 return 0;
221 static int is_uncasted_function(void)
223 struct expression *expr;
225 expr = get_faked_expression();
226 if (!expr || expr->type != EXPR_ASSIGNMENT)
227 return 0;
228 if (expr->right->type == EXPR_CALL)
229 return 1;
230 return 0;
233 static void match_assign_value(struct expression *expr)
235 char *member, *right_member;
236 struct range_list *rl;
237 struct symbol *type;
239 type = get_type(expr->left);
240 if (type && type->type == SYM_STRUCT)
241 return;
243 member = get_member_name(expr->left);
244 if (!member)
245 return;
247 /* if we're saying foo->mtu = bar->mtu then that doesn't add information */
248 right_member = get_member_name(expr->right);
249 if (right_member && strcmp(right_member, member) == 0)
250 goto free;
252 if (is_fake_call(expr->right)) {
253 if (is_ignored_macro())
254 goto free;
255 if (is_ignored_function())
256 goto free;
257 if (is_uncasted_function())
258 goto free;
259 add_fake_type_val(member, alloc_whole_rl(get_type(expr->left)), is_ignored_fake_assignment());
260 goto free;
263 if (expr->op != '=') {
264 add_type_val(member, alloc_whole_rl(get_type(expr->left)));
265 goto free;
267 get_absolute_rl(expr->right, &rl);
268 rl = cast_rl(type, rl);
269 add_type_val(member, rl);
270 free:
271 free_string(right_member);
272 free_string(member);
276 * If we too: int *p = &my_struct->member then abandon all hope of tracking
277 * my_struct->member.
279 static void match_assign_pointer(struct expression *expr)
281 struct expression *right;
282 char *member;
283 struct range_list *rl;
284 struct symbol *type;
286 right = strip_expr(expr->right);
287 if (right->type != EXPR_PREOP || right->op != '&')
288 return;
289 right = strip_expr(right->unop);
291 member = get_member_name(right);
292 if (!member)
293 return;
294 type = get_type(right);
295 rl = alloc_whole_rl(type);
296 add_type_val(member, rl);
297 free_string(member);
300 static void match_global_assign(struct expression *expr)
302 char *member;
303 struct range_list *rl;
305 member = get_member_name(expr->left);
306 if (!member)
307 return;
308 get_absolute_rl(expr->right, &rl);
309 add_global_type_val(member, rl);
310 free_string(member);
313 static void unop_expr(struct expression *expr)
315 struct range_list *rl;
316 char *member;
318 if (expr->op != SPECIAL_DECREMENT && expr->op != SPECIAL_INCREMENT)
319 return;
321 expr = strip_expr(expr->unop);
322 member = get_member_name(expr);
323 if (!member)
324 return;
325 rl = alloc_whole_rl(get_type(expr));
326 add_type_val(member, rl);
327 free_string(member);
330 static void asm_expr(struct statement *stmt)
332 struct expression *expr;
333 struct range_list *rl;
334 char *member;
335 int state = 0;
337 FOR_EACH_PTR(stmt->asm_outputs, expr) {
338 switch (state) {
339 case 0: /* identifier */
340 case 1: /* constraint */
341 state++;
342 continue;
343 case 2: /* expression */
344 state = 0;
345 member = get_member_name(expr);
346 if (!member)
347 continue;
348 rl = alloc_whole_rl(get_type(expr));
349 add_type_val(member, rl);
350 free_string(member);
351 continue;
353 } END_FOR_EACH_PTR(expr);
356 static void db_param_add(struct expression *expr, int param, char *key, char *value)
358 struct expression *arg;
359 struct symbol *type;
360 struct range_list *rl;
361 char *member;
363 if (strcmp(key, "*$") != 0)
364 return;
366 while (expr->type == EXPR_ASSIGNMENT)
367 expr = strip_expr(expr->right);
368 if (expr->type != EXPR_CALL)
369 return;
371 arg = get_argument_from_call_expr(expr->args, param);
372 arg = strip_expr(arg);
373 if (!arg)
374 return;
375 type = get_member_type_from_key(arg, key);
376 if (arg->type != EXPR_PREOP || arg->op != '&')
377 return;
378 arg = strip_expr(arg->unop);
380 member = get_member_name(arg);
381 if (!member)
382 return;
383 call_results_to_rl(expr, type, value, &rl);
384 add_type_val(member, rl);
385 free_string(member);
388 static void match_end_func_info(struct symbol *sym)
390 struct sm_state *sm;
392 FOR_EACH_SM(fn_type_val, sm) {
393 sql_insert_function_type_value(sm->name, sm->state->name);
394 } END_FOR_EACH_SM(sm);
396 free_stree(&fn_type_val);
399 static void match_end_file(struct symbol_list *sym_list)
401 struct sm_state *sm;
403 FOR_EACH_SM(global_type_val, sm) {
404 sql_insert_function_type_value(sm->name, sm->state->name);
405 } END_FOR_EACH_SM(sm);
408 void register_type_val(int id)
410 if (!option_info)
411 return;
413 my_id = id;
415 add_hook(&match_assign_value, ASSIGNMENT_HOOK);
416 add_hook(&match_assign_pointer, ASSIGNMENT_HOOK);
417 add_hook(&unop_expr, OP_HOOK);
418 add_hook(&asm_expr, ASM_HOOK);
419 select_return_states_hook(PARAM_ADD, &db_param_add);
420 select_return_states_hook(PARAM_SET, &db_param_add);
423 add_hook(&match_inline_start, INLINE_FN_START);
424 add_hook(&match_inline_end, INLINE_FN_END);
426 add_hook(&match_end_func_info, END_FUNC_HOOK);
428 add_hook(&match_global_assign, GLOBAL_ASSIGNMENT_HOOK);
429 add_hook(&match_end_file, END_FILE_HOOK);