2 * Copyright (C) 2015 Oracle.
4 * This program is free software; you can redistribute it and/or
5 * modify it under the terms of the GNU General Public License
6 * as published by the Free Software Foundation; either version 2
7 * of the License, or (at your option) any later version.
9 * This program is distributed in the hope that it will be useful,
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 * GNU General Public License for more details.
14 * You should have received a copy of the GNU General Public License
15 * along with this program; if not, see http://www.gnu.org/copyleft/gpl.txt
19 #include "smatch_slist.h"
20 #include "smatch_extra.h"
22 static bool is_non_null_array(struct expression
*expr
)
29 type
= get_type(expr
);
30 if (!type
|| type
->type
!= SYM_ARRAY
)
32 if (expr
->type
== EXPR_SYMBOL
)
34 if (implied_not_equal(expr
, 0))
37 /* verify that it's not the first member of the struct */
38 if (expr
->type
!= EXPR_DEREF
|| !expr
->member
)
40 sym
= expr_to_sym(expr
);
43 type
= get_real_base_type(sym
);
44 if (!type
|| type
->type
!= SYM_PTR
)
46 type
= get_real_base_type(type
);
47 if (type
->type
!= SYM_STRUCT
)
51 FOR_EACH_PTR(type
->symbol_list
, tmp
) {
55 if (strcmp(expr
->member
->name
, tmp
->ident
->name
) == 0) {
60 } END_FOR_EACH_PTR(tmp
);
65 int get_member_offset(struct symbol
*type
, const char *member_name
)
70 if (!type
|| type
->type
!= SYM_STRUCT
)
74 FOR_EACH_PTR(type
->symbol_list
, tmp
) {
75 if (!type
->ctype
.attribute
->is_packed
)
76 offset
= ALIGN(offset
, tmp
->ctype
.alignment
);
78 strcmp(member_name
, tmp
->ident
->name
) == 0) {
81 offset
+= type_bytes(tmp
);
82 } END_FOR_EACH_PTR(tmp
);
86 int get_member_offset_from_deref(struct expression
*expr
)
92 if (expr
->type
!= EXPR_DEREF
) /* hopefully, this doesn't happen */
95 if (expr
->member_offset
>= 0)
96 return expr
->member_offset
;
98 member
= expr
->member
;
102 type
= get_type(expr
->deref
);
103 if (!type
|| type
->type
!= SYM_STRUCT
)
106 offset
= get_member_offset(type
, member
->name
);
108 expr
->member_offset
= offset
;
112 static struct range_list
*filter_unknown_negatives(struct range_list
*rl
)
114 struct data_range
*first
;
115 struct range_list
*filter
= NULL
;
117 first
= first_ptr_list((struct ptr_list
*)rl
);
119 if (sval_is_min(first
->min
) &&
120 sval_is_negative(first
->max
) &&
121 first
->max
.value
== -1) {
122 add_ptr_list(&filter
, first
);
123 return rl_filter(rl
, filter
);
129 static void add_offset_to_pointer(struct range_list
**rl
, int offset
)
131 sval_t min
, remove
, max
;
132 struct range_list
*orig
= *rl
;
135 * Ha ha. Treating zero as a special case means I'm correct at least a
136 * tiny fraction of the time. Which is better than nothing.
143 * This function doesn't necessarily work how you might expect...
145 * Say you have s64min-(-1),1-s64max and you add 8 then I guess what
146 * we want to say is maybe something like 9-s64max. This shows that the
147 * min it could be is 9 which is potentially useful information. But
148 * if we start with (-12),5000000-57777777 and we add 8 then we'd want
149 * the result to be (-4),5000008-57777777 but (-4),5000000-57777777 is
150 * also probably acceptable. If you start with s64min-s64max then the
151 * result should be 8-s64max.
155 if (!orig
|| is_whole_rl(orig
)) {
156 min
= sval_type_min(&ptr_ctype
);
157 max
= sval_type_max(&ptr_ctype
);
160 *rl
= alloc_rl(min
, max
);
164 orig
= filter_unknown_negatives(orig
);
169 * FIXME: This is not really accurate but we're a bit screwed anyway
170 * when we start doing pointer math with error pointers so it's probably
174 if (sval_is_negative(min
))
178 remove
.value
+= (offset
- 1);
179 *rl
= remove_range(orig
, min
, remove
);
182 static struct range_list
*where_allocated_rl(struct symbol
*sym
)
187 if (sym
->ctype
.modifiers
& (MOD_TOPLEVEL
| MOD_STATIC
)) {
188 if (sym
->initializer
)
189 return alloc_rl(data_seg_min
, data_seg_max
);
191 return alloc_rl(bss_seg_min
, bss_seg_max
);
193 return alloc_rl(stack_seg_min
, stack_seg_max
);
196 int get_address_rl(struct expression
*expr
, struct range_list
**rl
)
198 expr
= strip_expr(expr
);
202 if (expr
->type
== EXPR_STRING
) {
203 *rl
= alloc_rl(text_seg_min
, text_seg_max
);
207 if (expr
->type
== EXPR_PREOP
&& expr
->op
== '&') {
208 struct expression
*unop
;
210 unop
= strip_expr(expr
->unop
);
211 if (unop
->type
== EXPR_SYMBOL
) {
212 *rl
= where_allocated_rl(unop
->symbol
);
216 if (unop
->type
== EXPR_DEREF
) {
217 int offset
= get_member_offset_from_deref(unop
);
219 unop
= strip_expr(unop
->unop
);
220 if (unop
->type
== EXPR_SYMBOL
) {
221 *rl
= where_allocated_rl(unop
->symbol
);
222 } else if (unop
->type
== EXPR_PREOP
&& unop
->op
== '*') {
223 unop
= strip_expr(unop
->unop
);
224 get_absolute_rl(unop
, rl
);
229 add_offset_to_pointer(rl
, offset
);
236 if (is_non_null_array(expr
)) {
237 *rl
= alloc_rl(array_min_sval
, array_max_sval
);