Missed a crashing bug in the int => struct conversion.
[smatch.git] / smatch_conditions.c
blobc052885df7d37ee0aebc2d6946427c215dad13f5
1 /*
2 * sparse/smatch_conditions.c
4 * Copyright (C) 2006,2008 Dan Carpenter.
6 * Licensed under the Open Software License version 1.1
8 */
11 * The simplest type of condition is
12 * if (a) { ...
14 * The next simplest kind of conditions is
15 * if (a && b) { c;
16 * In that case 'a' is true when we get to 'b' and both are true
17 * when we get to c.
19 * Or's are a little more complicated.
20 * if (a || b) { c;
21 * We know 'a' is not true when we get to 'b' but it may be true
22 * when we get to c.
24 * If we mix and's and or's that's even more complicated.
25 * if (a && b && c || a && d) { d ;
26 * 'a' is true when we get to 'b', 'c' and 'd'.
27 * 'b' is true when we reach 'c' but otherwise we don't know.
29 * The other thing that complicates matters is if we negate
30 * some if conditions.
31 * if (!a) { ...
32 * We pass the un-negated version to the client and flip the true
33 * and false values internally.
35 * And negations can be part of a compound.
36 * if (a && !(b || c)) { d;
37 * In that situation we multiply the negative through to simplify
38 * stuff so that we can remove the parens like this:
39 * if (a && !b && !c) { d;
41 * One other thing is that:
42 * if ((a) != 0){ ...
43 * that's basically the same as testing for just 'a' so we simplify
44 * it before passing it to the script.
47 #include "smatch.h"
49 #define KERNEL
51 static void split_conditions(struct expression *expr);
53 static int is_logical_and(struct expression *expr)
55 if (expr->op == SPECIAL_LOGICAL_AND)
56 return 1;
57 return 0;
60 static int handle_zero_comparisons(struct expression *expr)
62 struct expression *tmp = NULL;
64 // if left is zero or right is zero
65 if (is_zero(expr->left))
66 tmp = expr->right;
67 else if (is_zero(expr->right))
68 tmp = expr->left;
69 else
70 return 0;
72 // "if (foo != 0)" is the same as "if (foo)"
73 if (expr->op == SPECIAL_NOTEQUAL) {
74 split_conditions(tmp);
75 return 1;
78 // "if (foo == 0)" is the same as "if (!foo)"
79 if (expr->op == SPECIAL_EQUAL) {
80 split_conditions(tmp);
81 __negate_cond_stacks();
82 return 1;
85 return 0;
89 * This function is for handling calls to likely/unlikely
92 static int ignore_builtin_expect(struct expression *expr)
94 if (sym_name_is("__builtin_expect", expr->fn)) {
95 split_conditions(first_ptr_list((struct ptr_list *) expr->args));
96 return 1;
98 return 0;
101 static int handle_preop(struct expression *expr)
103 if (expr->op == '!') {
104 split_conditions(expr->unop);
105 __negate_cond_stacks();
106 return 1;
108 if (expr->op == '(') {
109 split_conditions(expr->unop);
110 return 1;
112 return 0;
115 static void handle_logical(struct expression *expr)
118 * If we come to an "and" expr then:
119 * We split the left side.
120 * We keep all the current states.
121 * We split the right side.
122 * We keep all the states from both true sides.
124 * If it's an "or" expr then:
125 * We save the current slist.
126 * We split the left side.
127 * We use the false states for the right side.
128 * We split the right side.
129 * We save all the states that are the same on both sides.
132 split_conditions(expr->left);
134 if (is_logical_and(expr)) {
135 __use_cond_true_states();
136 } else {
137 __use_cond_false_states();
140 __save_pre_cond_states();
141 __push_cond_stacks();
143 split_conditions(expr->right);
145 if (is_logical_and(expr)) {
146 __and_cond_states();
147 } else {
148 __or_cond_states();
151 __pop_pre_cond_states();
152 __use_cond_true_states();
155 static void split_conditions(struct expression *expr)
158 SM_DEBUG("%d in split_conditions type=%d\n", get_lineno(), expr->type);
160 switch(expr->type) {
161 case EXPR_LOGICAL:
162 handle_logical(expr);
163 return;
164 case EXPR_COMPARE:
165 if (handle_zero_comparisons(expr))
166 return;
167 break;
168 case EXPR_CALL:
169 if (ignore_builtin_expect(expr))
170 return;
171 break;
172 case EXPR_PREOP:
173 if (handle_preop(expr))
174 return;
175 break;
178 __pass_to_client(expr, CONDITION_HOOK);
179 __split_expr(expr);
182 void __split_whole_condition(struct expression *expr)
184 SM_DEBUG("%d in __split_whole_condition\n", get_lineno());
185 __pass_to_client(expr, WHOLE_CONDITION_HOOK);
186 __save_pre_cond_states();
187 __push_cond_stacks();
188 if (expr)
189 split_conditions(expr);
190 __use_cond_states();