2 * Copyright (C) 2011 Dan Carpenter.
4 * This program is free software; you can redistribute it and/or
5 * modify it under the terms of the GNU General Public License
6 * as published by the Free Software Foundation; either version 2
7 * of the License, or (at your option) any later version.
9 * This program is distributed in the hope that it will be useful,
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 * GNU General Public License for more details.
14 * You should have received a copy of the GNU General Public License
15 * along with this program; if not, see http://www.gnu.org/copyleft/gpl.txt
19 * There are a couple checks that try to see if a variable
20 * comes from the user. It would be better to unify them
21 * into one place. Also it we should follow the data down
22 * the call paths. Hence this file.
26 #include "smatch_slist.h"
27 #include "smatch_extra.h"
34 STATE(user_data_passed
);
37 static const char * kstr_funcs
[] = {
38 "kstrtoull", "kstrtoll", "kstrtoul", "kstrtol", "kstrtouint",
39 "kstrtoint", "kstrtou64", "kstrtos64", "kstrtou32", "kstrtos32",
40 "kstrtou16", "kstrtos16", "kstrtou8", "kstrtos8", "kstrtoull_from_user"
41 "kstrtoll_from_user", "kstrtoul_from_user", "kstrtol_from_user",
42 "kstrtouint_from_user", "kstrtoint_from_user", "kstrtou16_from_user",
43 "kstrtos16_from_user", "kstrtou8_from_user", "kstrtos8_from_user",
44 "kstrtou64_from_user", "kstrtos64_from_user", "kstrtou32_from_user",
45 "kstrtos32_from_user",
53 int is_user_macro(struct expression
*expr
)
56 struct range_list
*rl
;
58 macro
= get_macro_name(expr
->pos
);
62 if (get_implied_rl(expr
, &rl
) && !is_whole_rl(rl
))
64 if (strcmp(macro
, "ntohl") == 0)
66 if (strcmp(macro
, "ntohs") == 0)
71 static int has_user_data_state(struct expression
*expr
)
78 expr
= strip_expr(expr
);
79 if (expr
->type
== EXPR_PREOP
&& expr
->op
== '&')
80 expr
= strip_expr(expr
->unop
);
82 name
= expr_to_str_sym(expr
, &sym
);
87 stree
= __get_cur_stree();
88 FOR_EACH_MY_SM(my_id
, stree
, sm
) {
91 } END_FOR_EACH_SM(sm
);
95 static int passes_user_data(struct expression
*expr
)
97 struct expression
*arg
;
99 FOR_EACH_PTR(expr
->args
, arg
) {
100 if (is_user_data(arg
))
102 if (has_user_data_state(arg
))
104 } END_FOR_EACH_PTR(arg
);
109 static struct expression
*db_expr
;
110 static int db_user_data
;
111 static int db_user_data_callback(void *unused
, int argc
, char **argv
, char **azColName
)
113 if (atoi(argv
[0]) == PASSED_DATA
&& !passes_user_data(db_expr
))
119 static int is_user_fn_db(struct expression
*expr
)
122 static char sql_filter
[1024];
124 if (is_fake_call(expr
))
126 if (expr
->fn
->type
!= EXPR_SYMBOL
)
128 sym
= expr
->fn
->symbol
;
132 if (sym
->ctype
.modifiers
& MOD_STATIC
) {
133 snprintf(sql_filter
, 1024, "file = '%s' and function = '%s';",
134 get_filename(), sym
->ident
->name
);
136 snprintf(sql_filter
, 1024, "function = '%s' and static = 0;",
142 run_sql(db_user_data_callback
, NULL
,
143 "select value from return_states where type=%d and parameter = -1 and key = '$' and %s",
144 USER_DATA
, sql_filter
);
148 static int is_user_function(struct expression
*expr
)
150 if (expr
->type
!= EXPR_CALL
)
152 return is_user_fn_db(expr
);
155 static int is_skb_data(struct expression
*expr
)
162 name
= expr_to_var_sym(expr
, &sym
);
166 sym
= get_base_type(sym
);
167 if (!sym
|| sym
->type
!= SYM_PTR
)
169 sym
= get_base_type(sym
);
170 if (!sym
|| sym
->type
!= SYM_STRUCT
|| !sym
->ident
)
172 if (strcmp(sym
->ident
->name
, "sk_buff") != 0)
178 if (strcmp(name
+ len
- 6, "->data") == 0)
186 static int in_container_of_macro(struct expression
*expr
)
190 macro
= get_macro_name(expr
->pos
);
194 if (strcmp(macro
, "container_of") == 0)
199 static int is_user_data_state(struct expression
*expr
)
201 struct stree
*stree
= NULL
;
202 struct sm_state
*tmp
;
207 tmp
= get_sm_state_expr(my_id
, expr
);
209 if (slist_has_state(tmp
->possible
, &user_data_set
))
211 if (slist_has_state(tmp
->possible
, &user_data_passed
))
216 name
= expr_to_str_sym(expr
, &sym
);
220 stree
= __get_cur_stree();
221 FOR_EACH_MY_SM(my_id
, stree
, tmp
) {
224 if (!strncmp(tmp
->name
, name
, strlen(tmp
->name
))) {
225 if (slist_has_state(tmp
->possible
, &user_data_set
))
227 else if (slist_has_state(tmp
->possible
, &user_data_passed
))
231 } END_FOR_EACH_SM(tmp
);
238 int is_user_data(struct expression
*expr
)
240 struct range_list
*rl
;
245 return get_user_rl(expr
, &rl
);
252 if (in_container_of_macro(expr
))
255 user_data
= is_user_macro(expr
);
258 user_data
= is_user_function(expr
);
261 user_data
= is_skb_data(expr
);
265 expr
= strip_expr(expr
); /* this has to come after is_user_macro() */
267 if (expr
->type
== EXPR_BINOP
) {
268 user_data
= is_user_data(expr
->left
);
273 user_data
= is_user_data(expr
->right
);
278 if (expr
->type
== EXPR_PREOP
&& (expr
->op
== '&' || expr
->op
== '*'))
279 expr
= strip_expr(expr
->unop
);
281 return is_user_data_state(expr
);
284 int implied_user_data(struct expression
*expr
, struct range_list
**rl
)
286 if (!is_user_data(expr
))
288 get_absolute_rl(expr
, rl
);
292 int is_capped_user_data(struct expression
*expr
)
296 sm
= get_sm_state_expr(my_id
, expr
);
299 if (slist_has_state(sm
->possible
, &capped
))
304 static void set_called(const char *name
, struct symbol
*sym
, char *key
, char *value
)
306 set_state(my_id
, "this_function", NULL
, &called
);
309 static void set_param_user_data(const char *name
, struct symbol
*sym
, char *key
, char *value
)
313 /* sanity check. this should always be true. */
314 if (strncmp(key
, "$", 1) != 0)
316 snprintf(fullname
, 256, "%s%s", name
, key
+ 1);
317 set_state(my_id
, fullname
, sym
, &user_data_passed
);
320 static void match_syscall_definition(struct symbol
*sym
)
327 macro
= get_macro_name(sym
->pos
);
329 (strncmp("SYSCALL_DEFINE", macro
, strlen("SYSCALL_DEFINE")) == 0 ||
330 strncmp("COMPAT_SYSCALL_DEFINE", macro
, strlen("COMPAT_SYSCALL_DEFINE")) == 0))
333 name
= get_function();
334 if (!option_no_db
&& get_state(my_id
, "this_function", NULL
) != &called
) {
335 if (name
&& strncmp(name
, "sys_", 4) == 0)
339 if (name
&& strncmp(name
, "compat_sys_", 11) == 0)
345 FOR_EACH_PTR(sym
->ctype
.base_type
->arguments
, arg
) {
346 set_state(my_id
, arg
->ident
->name
, arg
, &user_data_set
);
347 } END_FOR_EACH_PTR(arg
);
350 static void match_condition(struct expression
*expr
)
355 case SPECIAL_UNSIGNED_LT
:
356 case SPECIAL_UNSIGNED_LTE
:
357 if (is_user_data(expr
->left
))
358 set_true_false_states_expr(my_id
, expr
->left
, &capped
, NULL
);
359 if (is_user_data(expr
->right
))
360 set_true_false_states_expr(my_id
, expr
->right
, NULL
, &capped
);
364 case SPECIAL_UNSIGNED_GT
:
365 case SPECIAL_UNSIGNED_GTE
:
366 if (is_user_data(expr
->right
))
367 set_true_false_states_expr(my_id
, expr
->right
, &capped
, NULL
);
368 if (is_user_data(expr
->left
))
369 set_true_false_states_expr(my_id
, expr
->left
, NULL
, &capped
);
372 if (is_user_data(expr
->left
))
373 set_true_false_states_expr(my_id
, expr
->left
, &capped
, NULL
);
374 if (is_user_data(expr
->right
))
375 set_true_false_states_expr(my_id
, expr
->right
, &capped
, NULL
);
377 case SPECIAL_NOTEQUAL
:
378 if (is_user_data(expr
->left
))
379 set_true_false_states_expr(my_id
, expr
->left
, NULL
, &capped
);
380 if (is_user_data(expr
->right
))
381 set_true_false_states_expr(my_id
, expr
->right
, NULL
, &capped
);
388 static int handle_get_user(struct expression
*expr
)
393 name
= get_macro_name(expr
->pos
);
394 if (!name
|| strcmp(name
, "get_user") != 0)
397 name
= expr_to_var(expr
->right
);
398 if (!name
|| strcmp(name
, "__val_gu") != 0)
400 set_state_expr(my_id
, expr
->left
, &user_data_set
);
407 static void match_assign(struct expression
*expr
)
411 if (handle_get_user(expr
))
414 user_data
= is_user_data(expr
->right
);
415 if (user_data
== PASSED_DATA
)
416 set_state_expr(my_id
, expr
->left
, &user_data_passed
);
417 else if (user_data
== SET_DATA
)
418 set_state_expr(my_id
, expr
->left
, &user_data_set
);
419 else if (get_state_expr(my_id
, expr
->left
))
420 set_state_expr(my_id
, expr
->left
, &capped
);
423 static void tag_struct_members(struct symbol
*type
, struct expression
*expr
)
426 struct expression
*member
;
429 if (expr
->type
== EXPR_PREOP
&& expr
->op
== '&') {
430 expr
= strip_expr(expr
->unop
);
434 FOR_EACH_PTR(type
->symbol_list
, tmp
) {
437 member
= member_expression(expr
, op
, tmp
->ident
);
438 set_state_expr(my_id
, member
, &user_data_set
);
439 } END_FOR_EACH_PTR(tmp
);
442 static void tag_base_type(struct expression
*expr
)
444 if (expr
->type
== EXPR_PREOP
&& expr
->op
== '&')
445 expr
= strip_expr(expr
->unop
);
447 expr
= deref_expression(expr
);
448 set_state_expr(my_id
, expr
, &user_data_set
);
451 static void tag_as_user_data(struct expression
*expr
)
455 expr
= strip_expr(expr
);
457 type
= get_type(expr
);
458 if (!type
|| type
->type
!= SYM_PTR
)
460 type
= get_real_base_type(type
);
463 if (type
== &void_ctype
) {
464 set_state_expr(my_id
, deref_expression(expr
), &user_data_set
);
467 if (type
->type
== SYM_BASETYPE
)
469 if (type
->type
== SYM_STRUCT
) {
470 if (expr
->type
!= EXPR_PREOP
|| expr
->op
!= '&')
471 expr
= deref_expression(expr
);
472 tag_struct_members(type
, expr
);
476 static void match_user_copy(const char *fn
, struct expression
*expr
, void *_param
)
478 int param
= PTR_INT(_param
);
479 struct expression
*dest
;
481 dest
= get_argument_from_call_expr(expr
->args
, param
);
482 dest
= strip_expr(dest
);
485 tag_as_user_data(dest
);
488 static void match_user_assign_function(const char *fn
, struct expression
*expr
, void *unused
)
490 set_state_expr(my_id
, expr
->left
, &user_data_set
);
493 static void match_caller_info(struct expression
*expr
)
495 struct expression
*tmp
;
499 FOR_EACH_PTR(expr
->args
, tmp
) {
500 if (is_user_data(tmp
))
501 sql_insert_caller_info(expr
, USER_DATA
, i
, "$", "");
503 } END_FOR_EACH_PTR(tmp
);
506 static void struct_member_callback(struct expression
*call
, int param
, char *printed_name
, struct sm_state
*sm
)
508 if (sm
->state
== &capped
)
510 sql_insert_caller_info(call
, USER_DATA
, param
, printed_name
, "");
513 static void returned_member_callback(int return_id
, char *return_ranges
, struct expression
*expr
, char *printed_name
, struct smatch_state
*state
)
515 if (state
== &capped
)
517 sql_insert_return_states(return_id
, return_ranges
, USER_DATA
, -1, printed_name
, "");
520 static void print_returned_user_data(int return_id
, char *return_ranges
, struct expression
*expr
)
523 struct sm_state
*tmp
;
526 const char *passed_or_new
;
528 user_data
= is_user_data(expr
);
529 if (user_data
== PASSED_DATA
) {
530 sql_insert_return_states(return_id
, return_ranges
, USER_DATA
,
533 if (user_data
== SET_DATA
) {
534 sql_insert_return_states(return_id
, return_ranges
, USER_DATA
,
538 stree
= __get_cur_stree();
540 FOR_EACH_MY_SM(my_id
, stree
, tmp
) {
541 const char *param_name
;
543 param
= get_param_num_from_sym(tmp
->sym
);
547 if (is_capped_var_sym(tmp
->name
, tmp
->sym
))
549 /* ignore states that were already USER_DATA to begin with */
550 if (get_state_stree(get_start_states(), my_id
, tmp
->name
, tmp
->sym
))
553 param_name
= get_param_name(tmp
);
554 if (!param_name
|| strcmp(param_name
, "$") == 0)
557 if (slist_has_state(tmp
->possible
, &user_data_set
))
559 else if (slist_has_state(tmp
->possible
, &user_data_passed
))
564 sql_insert_return_states(return_id
, return_ranges
, USER_DATA
,
565 param
, param_name
, passed_or_new
);
566 } END_FOR_EACH_SM(tmp
);
569 static void db_return_states_userdata(struct expression
*expr
, int param
, char *key
, char *value
)
574 if (expr
->type
== EXPR_ASSIGNMENT
&& param
== -1 && strcmp(key
, "*$") == 0) {
575 tag_as_user_data(expr
->left
);
579 name
= return_state_to_var_sym(expr
, param
, key
, &sym
);
583 set_state(my_id
, name
, sym
, &user_data_set
);
588 void check_user_data(int id
)
592 if (option_project
!= PROJ_KERNEL
)
595 select_caller_info_hook(set_called
, INTERNAL
);
596 select_caller_info_hook(set_param_user_data
, USER_DATA
);
597 add_hook(&match_syscall_definition
, AFTER_DEF_HOOK
);
598 add_hook(&match_condition
, CONDITION_HOOK
);
599 add_hook(&match_assign
, ASSIGNMENT_HOOK
);
600 add_function_hook("copy_from_user", &match_user_copy
, INT_PTR(0));
601 add_function_hook("__copy_from_user", &match_user_copy
, INT_PTR(0));
602 add_function_hook("memcpy_fromiovec", &match_user_copy
, INT_PTR(0));
603 add_function_assign_hook("memdup_user", &match_user_assign_function
, NULL
);
604 add_function_assign_hook("kmap_atomic", &match_user_assign_function
, NULL
);
605 for (i
= 0; i
< ARRAY_SIZE(kstr_funcs
); i
++)
606 add_function_hook(kstr_funcs
[i
], &match_user_copy
, INT_PTR(2));
608 add_hook(&match_caller_info
, FUNCTION_CALL_HOOK
);
609 add_member_info_callback(my_id
, struct_member_callback
);
610 add_returned_member_callback(my_id
, returned_member_callback
);
611 add_split_return_callback(print_returned_user_data
);
612 select_return_states_hook(USER_DATA
, &db_return_states_userdata
);