user_data2: silence some false positives handling ntohl(foo[x])
[smatch.git] / smatch_param_set.c
blob21287a282654a56e74228941d239aeda0248b6d0
1 /*
2 * Copyright (C) 2012 Oracle.
4 * This program is free software; you can redistribute it and/or
5 * modify it under the terms of the GNU General Public License
6 * as published by the Free Software Foundation; either version 2
7 * of the License, or (at your option) any later version.
9 * This program is distributed in the hope that it will be useful,
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 * GNU General Public License for more details.
14 * You should have received a copy of the GNU General Public License
15 * along with this program; if not, see http://www.gnu.org/copyleft/gpl.txt
19 * This is for functions like:
21 * int foo(int *x)
22 * {
23 * if (*x == 42) {
24 * *x = 0;
25 * return 1;
26 * }
27 * return 0;
28 * }
30 * If we return 1 that means the value of *x has been set to 0. If we return
31 * 0 then we have left *x alone.
35 #include "scope.h"
36 #include "smatch.h"
37 #include "smatch_slist.h"
38 #include "smatch_extra.h"
40 static int my_id;
42 static struct smatch_state *unmatched_state(struct sm_state *sm)
44 return alloc_estate_empty();
47 static void extra_mod_hook(const char *name, struct symbol *sym, struct expression *expr, struct smatch_state *state)
49 if (get_param_num_from_sym(sym) < 0)
50 return;
51 set_state(my_id, name, sym, state);
55 * This function is is a dirty hack because extra_mod_hook is giving us a NULL
56 * sym instead of a vsl.
58 static void match_array_assignment(struct expression *expr)
60 struct expression *array, *offset;
61 char *name;
62 struct symbol *sym;
63 struct range_list *rl;
64 sval_t sval;
65 char buf[256];
67 if (__in_fake_assign)
68 return;
70 if (!is_array(expr->left))
71 return;
72 array = get_array_base(expr->left);
73 offset = get_array_offset(expr->left);
75 /* These are handled by extra_mod_hook() */
76 if (get_value(offset, &sval))
77 return;
78 name = expr_to_var_sym(array, &sym);
79 if (!name || !sym)
80 goto free;
81 if (get_param_num_from_sym(sym) < 0)
82 goto free;
83 get_absolute_rl(expr->right, &rl);
84 rl = cast_rl(get_type(expr->left), rl);
86 snprintf(buf, sizeof(buf), "*%s", name);
87 set_state(my_id, buf, sym, alloc_estate_rl(rl));
88 free:
89 free_string(name);
93 * This relies on the fact that these states are stored so that
94 * foo->bar is before foo->bar->baz.
96 static int parent_set(struct string_list *list, const char *name)
98 char *tmp;
99 int len;
100 int ret;
102 FOR_EACH_PTR(list, tmp) {
103 len = strlen(tmp);
104 ret = strncmp(tmp, name, len);
105 if (ret < 0)
106 continue;
107 if (ret > 0)
108 return 0;
109 if (name[len] == '-')
110 return 1;
111 } END_FOR_EACH_PTR(tmp);
113 return 0;
116 static void print_return_value_param(int return_id, char *return_ranges, struct expression *expr)
118 struct sm_state *sm;
119 struct smatch_state *extra;
120 int param;
121 struct range_list *rl;
122 const char *param_name;
123 struct string_list *set_list = NULL;
124 char *math_str;
125 char buf[256];
126 sval_t sval;
128 FOR_EACH_MY_SM(my_id, __get_cur_stree(), sm) {
129 if (!estate_rl(sm->state))
130 continue;
131 extra = get_state(SMATCH_EXTRA, sm->name, sm->sym);
132 if (extra) {
133 rl = rl_intersection(estate_rl(sm->state), estate_rl(extra));
134 if (!rl)
135 continue;
136 } else {
137 rl = estate_rl(sm->state);
140 param = get_param_num_from_sym(sm->sym);
141 if (param < 0)
142 continue;
143 param_name = get_param_name(sm);
144 if (!param_name)
145 continue;
146 if (strcmp(param_name, "$") == 0)
147 continue;
149 if (rl_to_sval(rl, &sval)) {
150 insert_string(&set_list, (char *)sm->name);
151 sql_insert_return_states(return_id, return_ranges,
152 param_has_filter_data(sm) ? PARAM_ADD : PARAM_SET,
153 param, param_name, show_rl(rl));
154 continue;
157 math_str = get_value_in_terms_of_parameter_math_var_sym(sm->name, sm->sym);
158 if (math_str) {
159 snprintf(buf, sizeof(buf), "%s[%s]", show_rl(rl), math_str);
160 insert_string(&set_list, (char *)sm->name);
161 sql_insert_return_states(return_id, return_ranges,
162 param_has_filter_data(sm) ? PARAM_ADD : PARAM_SET,
163 param, param_name, buf);
164 continue;
167 /* no useful information here. */
168 if (is_whole_rl(rl) && parent_set(set_list, sm->name))
169 continue;
170 insert_string(&set_list, (char *)sm->name);
172 sql_insert_return_states(return_id, return_ranges,
173 param_has_filter_data(sm) ? PARAM_ADD : PARAM_SET,
174 param, param_name, show_rl(rl));
176 } END_FOR_EACH_SM(sm);
178 free_ptr_list((struct ptr_list **)&set_list);
181 int param_was_set_var_sym(const char *name, struct symbol *sym)
183 struct sm_state *sm;
184 int len;
186 FOR_EACH_MY_SM(my_id, __get_cur_stree(), sm) {
187 if (sm->sym != sym)
188 continue;
189 len = strlen(sm->name);
190 if (strncmp(sm->name, name, len) != 0)
191 continue;
192 if (name[len] == '\0' ||
193 name[len] == '-')
194 return 1;
195 } END_FOR_EACH_SM(sm);
197 return 0;
200 int param_was_set(struct expression *expr)
202 char *name;
203 struct symbol *sym;
204 int ret = 0;
206 name = expr_to_var_sym(expr, &sym);
207 if (!name || !sym)
208 goto free;
210 ret = param_was_set_var_sym(name, sym);
211 free:
212 free_string(name);
213 return ret;
216 void register_param_set(int id)
218 my_id = id;
220 add_extra_mod_hook(&extra_mod_hook);
221 add_hook(match_array_assignment, ASSIGNMENT_HOOK);
222 add_unmatched_state_hook(my_id, &unmatched_state);
223 add_merge_hook(my_id, &merge_estates);
224 add_split_return_callback(&print_return_value_param);