2 * Copyright (C) 2008,2009 Dan Carpenter.
4 * This program is free software; you can redistribute it and/or
5 * modify it under the terms of the GNU General Public License
6 * as published by the Free Software Foundation; either version 2
7 * of the License, or (at your option) any later version.
9 * This program is distributed in the hope that it will be useful,
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 * GNU General Public License for more details.
14 * You should have received a copy of the GNU General Public License
15 * along with this program; if not, see http://www.gnu.org/copyleft/gpl.txt
21 #include "smatch_slist.h"
25 ALLOCATOR(smatch_state
, "smatch state");
26 ALLOCATOR(sm_state
, "sm state");
27 ALLOCATOR(named_stree
, "named slist");
28 __DO_ALLOCATOR(char, 1, 4, "state names", sname
);
30 static int sm_state_counter
;
32 static struct stree_stack
*all_pools
;
34 char *show_sm(struct sm_state
*sm
)
41 pos
= snprintf(buf
, sizeof(buf
), "[%s] '%s' = '%s'",
42 check_name(sm
->owner
), sm
->name
, show_state(sm
->state
));
43 if (pos
> sizeof(buf
))
46 if (ptr_list_size((struct ptr_list
*)sm
->possible
) == 1)
49 pos
+= snprintf(buf
+ pos
, sizeof(buf
) - pos
, " (");
50 if (pos
> sizeof(buf
))
53 FOR_EACH_PTR(sm
->possible
, tmp
) {
55 pos
+= snprintf(buf
+ pos
, sizeof(buf
) - pos
, ", ");
56 if (pos
> sizeof(buf
))
58 pos
+= snprintf(buf
+ pos
, sizeof(buf
) - pos
, "%s",
59 show_state(tmp
->state
));
60 if (pos
> sizeof(buf
))
62 } END_FOR_EACH_PTR(tmp
);
63 snprintf(buf
+ pos
, sizeof(buf
) - pos
, ")");
68 for (i
= 0; i
< 3; i
++)
69 buf
[sizeof(buf
) - 2 - i
] = '.';
73 void __print_stree(struct stree
*stree
)
77 printf("dumping stree at %d\n", get_lineno());
78 FOR_EACH_SM(stree
, sm
) {
79 printf("%s\n", show_sm(sm
));
80 } END_FOR_EACH_SM(sm
);
84 /* NULL states go at the end to simplify merge_slist */
85 int cmp_tracker(const struct sm_state
*a
, const struct sm_state
*b
)
96 if (a
->owner
> b
->owner
)
98 if (a
->owner
< b
->owner
)
101 ret
= strcmp(a
->name
, b
->name
);
105 if (!b
->sym
&& a
->sym
)
107 if (!a
->sym
&& b
->sym
)
117 static int cmp_sm_states(const struct sm_state
*a
, const struct sm_state
*b
, int preserve
)
121 ret
= cmp_tracker(a
, b
);
125 /* todo: add hook for smatch_extra.c */
126 if (a
->state
> b
->state
)
128 if (a
->state
< b
->state
)
130 /* This is obviously a massive disgusting hack but we need to preserve
131 * the unmerged states for smatch extra because we use them in
132 * smatch_db.c. Meanwhile if we preserve all the other unmerged states
133 * then it uses a lot of memory and we don't use it. Hence this hack.
135 * Also sometimes even just preserving every possible SMATCH_EXTRA state
136 * takes too much resources so we have to cap that. Capping is probably
137 * not often a problem in real life.
139 if (a
->owner
== SMATCH_EXTRA
&& preserve
) {
142 if (a
->merged
== 1 && b
->merged
== 0)
151 struct sm_state
*alloc_sm_state(int owner
, const char *name
,
152 struct symbol
*sym
, struct smatch_state
*state
)
154 struct sm_state
*sm_state
= __alloc_sm_state(0);
158 sm_state
->name
= alloc_sname(name
);
159 sm_state
->owner
= owner
;
161 sm_state
->state
= state
;
162 sm_state
->line
= get_lineno();
163 sm_state
->merged
= 0;
164 sm_state
->implied
= 0;
165 sm_state
->pool
= NULL
;
166 sm_state
->left
= NULL
;
167 sm_state
->right
= NULL
;
168 sm_state
->nr_children
= 1;
169 sm_state
->possible
= NULL
;
170 add_ptr_list(&sm_state
->possible
, sm_state
);
174 static struct sm_state
*alloc_state_no_name(int owner
, const char *name
,
176 struct smatch_state
*state
)
178 struct sm_state
*tmp
;
180 tmp
= alloc_sm_state(owner
, NULL
, sym
, state
);
185 int too_many_possible(struct sm_state
*sm
)
187 if (ptr_list_size((struct ptr_list
*)sm
->possible
) >= 100)
192 void add_possible_sm(struct sm_state
*to
, struct sm_state
*new)
194 struct sm_state
*tmp
;
197 if (too_many_possible(to
))
200 FOR_EACH_PTR(to
->possible
, tmp
) {
201 if (cmp_sm_states(tmp
, new, preserve
) < 0)
203 else if (cmp_sm_states(tmp
, new, preserve
) == 0) {
206 INSERT_CURRENT(new, tmp
);
209 } END_FOR_EACH_PTR(tmp
);
210 add_ptr_list(&to
->possible
, new);
213 static void copy_possibles(struct sm_state
*to
, struct sm_state
*from
)
215 struct sm_state
*tmp
;
217 FOR_EACH_PTR(from
->possible
, tmp
) {
218 add_possible_sm(to
, tmp
);
219 } END_FOR_EACH_PTR(tmp
);
222 char *alloc_sname(const char *str
)
228 tmp
= __alloc_sname(strlen(str
) + 1);
233 int out_of_memory(void)
236 * I decided to use 50M here based on trial and error.
237 * It works out OK for the kernel and so it should work
238 * for most other projects as well.
240 if (sm_state_counter
* sizeof(struct sm_state
) >= 50000000)
245 int low_on_memory(void)
247 if (sm_state_counter
* sizeof(struct sm_state
) >= 25000000)
252 static void free_sm_state(struct sm_state
*sm
)
254 free_slist(&sm
->possible
);
256 * fixme. Free the actual state.
257 * Right now we leave it until the end of the function
258 * because we don't want to double free it.
259 * Use the freelist to not double free things
263 static void free_all_sm_states(struct allocation_blob
*blob
)
265 unsigned int size
= sizeof(struct sm_state
);
266 unsigned int offset
= 0;
268 while (offset
< blob
->offset
) {
269 free_sm_state((struct sm_state
*)(blob
->data
+ offset
));
274 /* At the end of every function we free all the sm_states */
275 void free_every_single_sm_state(void)
277 struct allocator_struct
*desc
= &sm_state_allocator
;
278 struct allocation_blob
*blob
= desc
->blobs
;
281 desc
->allocations
= 0;
282 desc
->total_bytes
= 0;
283 desc
->useful_bytes
= 0;
284 desc
->freelist
= NULL
;
286 struct allocation_blob
*next
= blob
->next
;
287 free_all_sm_states(blob
);
288 blob_free(blob
, desc
->chunking
);
292 clear_smatch_state_alloc();
294 free_stack_and_strees(&all_pools
);
295 sm_state_counter
= 0;
298 struct sm_state
*clone_sm(struct sm_state
*s
)
300 struct sm_state
*ret
;
302 ret
= alloc_state_no_name(s
->owner
, s
->name
, s
->sym
, s
->state
);
303 ret
->merged
= s
->merged
;
304 ret
->implied
= s
->implied
;
306 /* clone_sm() doesn't copy the pools. Each state needs to have
308 ret
->possible
= clone_slist(s
->possible
);
310 ret
->right
= s
->right
;
311 ret
->nr_children
= s
->nr_children
;
315 int is_merged(struct sm_state
*sm
)
320 int is_implied(struct sm_state
*sm
)
325 int slist_has_state(struct state_list
*slist
, struct smatch_state
*state
)
327 struct sm_state
*tmp
;
329 FOR_EACH_PTR(slist
, tmp
) {
330 if (tmp
->state
== state
)
332 } END_FOR_EACH_PTR(tmp
);
336 struct state_list
*clone_slist(struct state_list
*from_slist
)
339 struct state_list
*to_slist
= NULL
;
341 FOR_EACH_PTR(from_slist
, sm
) {
342 add_ptr_list(&to_slist
, sm
);
343 } END_FOR_EACH_PTR(sm
);
347 struct smatch_state
*merge_states(int owner
, const char *name
,
349 struct smatch_state
*state1
,
350 struct smatch_state
*state2
)
352 struct smatch_state
*ret
;
354 if (state1
== state2
)
356 else if (__has_merge_function(owner
))
357 ret
= __client_merge_function(owner
, state1
, state2
);
358 else if (state1
== &ghost
)
360 else if (state2
== &ghost
)
362 else if (!state1
|| !state2
)
369 struct sm_state
*merge_sm_states(struct sm_state
*one
, struct sm_state
*two
)
371 struct smatch_state
*s
;
372 struct sm_state
*result
;
376 s
= merge_states(one
->owner
, one
->name
, one
->sym
, one
->state
, two
->state
);
377 result
= alloc_state_no_name(one
->owner
, one
->name
, one
->sym
, s
);
381 result
->nr_children
= one
->nr_children
+ two
->nr_children
;
382 copy_possibles(result
, one
);
383 copy_possibles(result
, two
);
386 strcmp(check_name(one
->owner
), option_debug_check
) == 0) {
387 struct sm_state
*tmp
;
390 printf("%s:%d %s() merge [%s] '%s' %s(L %d) + %s(L %d) => %s (",
391 get_filename(), get_lineno(), get_function(),
392 check_name(one
->owner
), one
->name
,
393 show_state(one
->state
), one
->line
,
394 show_state(two
->state
), two
->line
,
397 FOR_EACH_PTR(result
->possible
, tmp
) {
400 printf("%s", show_state(tmp
->state
));
401 } END_FOR_EACH_PTR(tmp
);
408 struct sm_state
*get_sm_state_stree(struct stree
*stree
, int owner
, const char *name
,
411 struct tracker tracker
= {
413 .name
= (char *)name
,
421 return avl_lookup(stree
, (struct sm_state
*)&tracker
);
424 struct smatch_state
*get_state_stree(struct stree
*stree
,
425 int owner
, const char *name
,
430 sm
= get_sm_state_stree(stree
, owner
, name
, sym
);
436 /* FIXME: this is almost exactly the same as set_sm_state_slist() */
437 void overwrite_sm_state_stree(struct stree
**stree
, struct sm_state
*new)
439 avl_insert(stree
, new);
442 void overwrite_sm_state_stree_stack(struct stree_stack
**stack
,
447 stree
= pop_stree(stack
);
448 overwrite_sm_state_stree(&stree
, sm
);
449 push_stree(stack
, stree
);
452 void set_sm_state_stree_stack_if_not_already_set(struct stree_stack
**stack
,
457 stree
= pop_stree(stack
);
458 if (get_state_stree(stree
, sm
->owner
, sm
->name
, sm
->sym
))
460 overwrite_sm_state_stree(&stree
, sm
);
462 push_stree(stack
, stree
);
465 struct sm_state
*set_state_stree(struct stree
**stree
, int owner
, const char *name
,
466 struct symbol
*sym
, struct smatch_state
*state
)
468 struct sm_state
*new = alloc_sm_state(owner
, name
, sym
, state
);
470 avl_insert(stree
, new);
474 void set_state_stree_perm(struct stree
**stree
, int owner
, const char *name
,
475 struct symbol
*sym
, struct smatch_state
*state
)
479 sm
= malloc(sizeof(*sm
) + strlen(name
) + 1);
480 memset(sm
, 0, sizeof(*sm
));
482 sm
->name
= (char *)(sm
+ 1);
483 strcpy((char *)sm
->name
, name
);
487 overwrite_sm_state_stree(stree
, sm
);
490 void delete_state_stree(struct stree
**stree
, int owner
, const char *name
,
493 struct tracker tracker
= {
495 .name
= (char *)name
,
499 avl_remove(stree
, (struct sm_state
*)&tracker
);
502 void delete_state_stree_stack(struct stree_stack
**stack
, int owner
, const char *name
,
507 stree
= pop_stree(stack
);
508 delete_state_stree(&stree
, owner
, name
, sym
);
509 push_stree(stack
, stree
);
512 void push_stree(struct stree_stack
**stack
, struct stree
*stree
)
514 add_ptr_list(stack
, stree
);
517 struct stree
*pop_stree(struct stree_stack
**stack
)
521 stree
= last_ptr_list((struct ptr_list
*)*stack
);
522 delete_ptr_list_last((struct ptr_list
**)stack
);
526 void free_slist(struct state_list
**slist
)
528 __free_ptr_list((struct ptr_list
**)slist
);
531 void free_stree_stack(struct stree_stack
**stack
)
533 __free_ptr_list((struct ptr_list
**)stack
);
536 void free_stack_and_strees(struct stree_stack
**stree_stack
)
540 FOR_EACH_PTR(*stree_stack
, stree
) {
542 } END_FOR_EACH_PTR(stree
);
543 free_stree_stack(stree_stack
);
546 struct sm_state
*set_state_stree_stack(struct stree_stack
**stack
, int owner
, const char *name
,
547 struct symbol
*sym
, struct smatch_state
*state
)
552 stree
= pop_stree(stack
);
553 sm
= set_state_stree(&stree
, owner
, name
, sym
, state
);
554 push_stree(stack
, stree
);
560 * get_sm_state_stack() gets the state for the top slist on the stack.
562 struct sm_state
*get_sm_state_stree_stack(struct stree_stack
*stack
,
563 int owner
, const char *name
,
567 struct sm_state
*ret
;
569 stree
= pop_stree(&stack
);
570 ret
= get_sm_state_stree(stree
, owner
, name
, sym
);
571 push_stree(&stack
, stree
);
575 struct smatch_state
*get_state_stree_stack(struct stree_stack
*stack
,
576 int owner
, const char *name
,
581 sm
= get_sm_state_stree_stack(stack
, owner
, name
, sym
);
587 static void match_states_stree(struct stree
**one
, struct stree
**two
)
589 struct smatch_state
*tmp_state
;
591 struct state_list
*add_to_one
= NULL
;
592 struct state_list
*add_to_two
= NULL
;
596 avl_iter_begin(&one_iter
, *one
, FORWARD
);
597 avl_iter_begin(&two_iter
, *two
, FORWARD
);
600 if (!one_iter
.sm
&& !two_iter
.sm
)
602 if (cmp_tracker(one_iter
.sm
, two_iter
.sm
) < 0) {
603 __set_fake_cur_stree_fast(*two
);
604 tmp_state
= __client_unmatched_state_function(one_iter
.sm
);
605 __pop_fake_cur_stree_fast();
606 sm
= alloc_state_no_name(one_iter
.sm
->owner
, one_iter
.sm
->name
,
607 one_iter
.sm
->sym
, tmp_state
);
608 add_ptr_list(&add_to_two
, sm
);
609 avl_iter_next(&one_iter
);
610 } else if (cmp_tracker(one_iter
.sm
, two_iter
.sm
) == 0) {
611 avl_iter_next(&one_iter
);
612 avl_iter_next(&two_iter
);
614 __set_fake_cur_stree_fast(*one
);
615 tmp_state
= __client_unmatched_state_function(two_iter
.sm
);
616 __pop_fake_cur_stree_fast();
617 sm
= alloc_state_no_name(two_iter
.sm
->owner
, two_iter
.sm
->name
,
618 two_iter
.sm
->sym
, tmp_state
);
619 add_ptr_list(&add_to_one
, sm
);
620 avl_iter_next(&two_iter
);
624 FOR_EACH_PTR(add_to_one
, sm
) {
626 } END_FOR_EACH_PTR(sm
);
628 FOR_EACH_PTR(add_to_two
, sm
) {
630 } END_FOR_EACH_PTR(sm
);
632 free_slist(&add_to_one
);
633 free_slist(&add_to_two
);
636 static void call_pre_merge_hooks(struct stree
**one
, struct stree
**two
)
642 __swap_cur_stree(*one
);
643 FOR_EACH_SM(*two
, sm
) {
644 call_pre_merge_hook(sm
);
645 } END_FOR_EACH_SM(sm
);
646 *one
= clone_stree(__get_cur_stree());
648 __swap_cur_stree(*two
);
649 FOR_EACH_SM(*one
, sm
) {
650 call_pre_merge_hook(sm
);
651 } END_FOR_EACH_SM(sm
);
652 *two
= clone_stree(__get_cur_stree());
654 restore_all_states();
657 static void clone_pool_havers_stree(struct stree
**stree
)
659 struct sm_state
*sm
, *tmp
;
660 struct state_list
*slist
= NULL
;
662 FOR_EACH_SM(*stree
, sm
) {
665 add_ptr_list(&slist
, tmp
);
667 } END_FOR_EACH_SM(sm
);
669 FOR_EACH_PTR(slist
, sm
) {
670 avl_insert(stree
, sm
);
671 } END_FOR_EACH_PTR(sm
);
679 * merge_slist() is called whenever paths merge, such as after
680 * an if statement. It takes the two slists and creates one.
682 static void __merge_stree(struct stree
**to
, struct stree
*stree
, int add_pool
)
684 struct stree
*results
= NULL
;
685 struct stree
*implied_one
= NULL
;
686 struct stree
*implied_two
= NULL
;
689 struct sm_state
*tmp_sm
;
694 /* merging a null and nonnull path gives you only the nonnull path */
701 *to
= clone_stree(stree
);
705 implied_one
= clone_stree(*to
);
706 implied_two
= clone_stree(stree
);
708 match_states_stree(&implied_one
, &implied_two
);
709 call_pre_merge_hooks(&implied_one
, &implied_two
);
712 clone_pool_havers_stree(&implied_one
);
713 clone_pool_havers_stree(&implied_two
);
715 set_stree_id(&implied_one
, ++__stree_id
);
716 set_stree_id(&implied_two
, ++__stree_id
);
719 push_stree(&all_pools
, implied_one
);
720 push_stree(&all_pools
, implied_two
);
722 avl_iter_begin(&one_iter
, implied_one
, FORWARD
);
723 avl_iter_begin(&two_iter
, implied_two
, FORWARD
);
726 if (!one_iter
.sm
&& !two_iter
.sm
)
728 if (cmp_tracker(one_iter
.sm
, two_iter
.sm
) < 0) {
729 sm_msg("error: Internal smatch error.");
730 avl_iter_next(&one_iter
);
731 } else if (cmp_tracker(one_iter
.sm
, two_iter
.sm
) == 0) {
732 if (add_pool
&& one_iter
.sm
!= two_iter
.sm
) {
733 one_iter
.sm
->pool
= implied_one
;
734 two_iter
.sm
->pool
= implied_two
;
736 tmp_sm
= merge_sm_states(one_iter
.sm
, two_iter
.sm
);
737 add_possible_sm(tmp_sm
, one_iter
.sm
);
738 add_possible_sm(tmp_sm
, two_iter
.sm
);
739 avl_insert(&results
, tmp_sm
);
740 avl_iter_next(&one_iter
);
741 avl_iter_next(&two_iter
);
743 sm_msg("error: Internal smatch error.");
744 avl_iter_next(&two_iter
);
752 void merge_stree(struct stree
**to
, struct stree
*stree
)
754 __merge_stree(to
, stree
, 1);
757 void merge_stree_no_pools(struct stree
**to
, struct stree
*stree
)
759 __merge_stree(to
, stree
, 0);
763 * This is unfortunately a bit subtle... The problem is that if a
764 * state is set on one fake stree but not the other then we should
765 * look up the the original state and use that as the unset state.
766 * Fortunately, after you pop your fake stree then the cur_slist should
767 * reflect the original state.
769 void merge_fake_stree(struct stree
**to
, struct stree
*stree
)
771 struct stree
*one
= *to
;
772 struct stree
*two
= stree
;
774 struct state_list
*add_to_one
= NULL
;
775 struct state_list
*add_to_two
= NULL
;
784 *to
= clone_stree(stree
);
788 avl_iter_begin(&one_iter
, one
, FORWARD
);
789 avl_iter_begin(&two_iter
, two
, FORWARD
);
792 if (!one_iter
.sm
&& !two_iter
.sm
)
794 if (cmp_tracker(one_iter
.sm
, two_iter
.sm
) < 0) {
795 sm
= get_sm_state(one_iter
.sm
->owner
, one_iter
.sm
->name
,
798 add_ptr_list(&add_to_two
, sm
);
799 avl_iter_next(&one_iter
);
800 } else if (cmp_tracker(one_iter
.sm
, two_iter
.sm
) == 0) {
801 avl_iter_next(&one_iter
);
802 avl_iter_next(&two_iter
);
804 sm
= get_sm_state(two_iter
.sm
->owner
, two_iter
.sm
->name
,
807 add_ptr_list(&add_to_one
, sm
);
808 avl_iter_next(&two_iter
);
812 FOR_EACH_PTR(add_to_one
, sm
) {
813 avl_insert(&one
, sm
);
814 } END_FOR_EACH_PTR(sm
);
816 FOR_EACH_PTR(add_to_two
, sm
) {
817 avl_insert(&two
, sm
);
818 } END_FOR_EACH_PTR(sm
);
820 free_slist(&add_to_one
);
821 free_slist(&add_to_two
);
823 __merge_stree(&one
, two
, 1);
829 * filter_slist() removes any sm states "slist" holds in common with "filter"
831 void filter_stree(struct stree
**stree
, struct stree
*filter
)
833 struct stree
*results
= NULL
;
837 avl_iter_begin(&one_iter
, *stree
, FORWARD
);
838 avl_iter_begin(&two_iter
, filter
, FORWARD
);
840 /* FIXME: This should probably be re-written with trees in mind */
843 if (!one_iter
.sm
&& !two_iter
.sm
)
845 if (cmp_tracker(one_iter
.sm
, two_iter
.sm
) < 0) {
846 avl_insert(&results
, one_iter
.sm
);
847 avl_iter_next(&one_iter
);
848 } else if (cmp_tracker(one_iter
.sm
, two_iter
.sm
) == 0) {
849 if (one_iter
.sm
!= two_iter
.sm
)
850 avl_insert(&results
, one_iter
.sm
);
851 avl_iter_next(&one_iter
);
852 avl_iter_next(&two_iter
);
854 avl_iter_next(&two_iter
);
864 * and_slist_stack() pops the top two slists, overwriting the one with
865 * the other and pushing it back on the stack.
867 void and_stree_stack(struct stree_stack
**stack
)
869 struct sm_state
*tmp
;
870 struct stree
*right_stree
= pop_stree(stack
);
872 FOR_EACH_SM(right_stree
, tmp
) {
873 overwrite_sm_state_stree_stack(stack
, tmp
);
874 } END_FOR_EACH_SM(tmp
);
875 free_stree(&right_stree
);
879 * or_slist_stack() is for if we have: if (foo || bar) { foo->baz;
880 * It pops the two slists from the top of the stack and merges them
881 * together in a way that preserves the things they have in common
882 * but creates a merged state for most of the rest.
883 * You could have code that had: if (foo || foo) { foo->baz;
884 * It's this function which ensures smatch does the right thing.
886 void or_stree_stack(struct stree_stack
**pre_conds
,
887 struct stree
*cur_stree
,
888 struct stree_stack
**stack
)
892 struct stree
*pre_stree
;
894 struct stree
*tmp_stree
;
896 new = pop_stree(stack
);
897 old
= pop_stree(stack
);
899 pre_stree
= pop_stree(pre_conds
);
900 push_stree(pre_conds
, clone_stree(pre_stree
));
902 res
= clone_stree(pre_stree
);
903 overwrite_stree(old
, &res
);
905 tmp_stree
= clone_stree(cur_stree
);
906 overwrite_stree(new, &tmp_stree
);
908 merge_stree(&res
, tmp_stree
);
909 filter_stree(&res
, pre_stree
);
911 push_stree(stack
, res
);
912 free_stree(&tmp_stree
);
913 free_stree(&pre_stree
);
919 * get_named_stree() is only used for gotos.
921 struct stree
**get_named_stree(struct named_stree_stack
*stack
,
924 struct named_stree
*tmp
;
926 FOR_EACH_PTR(stack
, tmp
) {
927 if (!strcmp(tmp
->name
, name
))
929 } END_FOR_EACH_PTR(tmp
);
933 /* FIXME: These parameters are in a different order from expected */
934 void overwrite_stree(struct stree
*from
, struct stree
**to
)
936 struct sm_state
*tmp
;
938 FOR_EACH_SM(from
, tmp
) {
939 overwrite_sm_state_stree(to
, tmp
);
940 } END_FOR_EACH_SM(tmp
);