Ted Kremenek | d493163 | 2008-11-12 19:21:30 +0000 | [diff] [blame] | 1 | //== Environment.cpp - Map from Stmt* to Locations/Values -------*- C++ -*--==// |
Ted Kremenek | 8133a26 | 2008-07-08 21:46:56 +0000 | [diff] [blame] | 2 | // |
| 3 | // The LLVM Compiler Infrastructure |
| 4 | // |
| 5 | // This file is distributed under the University of Illinois Open Source |
| 6 | // License. See LICENSE.TXT for details. |
| 7 | // |
| 8 | //===----------------------------------------------------------------------===// |
| 9 | // |
| 10 | // This file defined the Environment and EnvironmentManager classes. |
| 11 | // |
| 12 | //===----------------------------------------------------------------------===// |
Benjamin Kramer | 5e2d2c2 | 2010-03-27 21:19:47 +0000 | [diff] [blame] | 13 | |
| 14 | #include "clang/Analysis/AnalysisContext.h" |
| 15 | #include "clang/Analysis/CFG.h" |
Ted Kremenek | 1309f9a | 2010-01-25 04:41:41 +0000 | [diff] [blame] | 16 | #include "clang/Checker/PathSensitive/GRState.h" |
Ted Kremenek | 8133a26 | 2008-07-08 21:46:56 +0000 | [diff] [blame] | 17 | |
| 18 | using namespace clang; |
| 19 | |
Zhongxing Xu | d91ee27 | 2009-06-23 09:02:15 +0000 | [diff] [blame] | 20 | SVal Environment::GetSVal(const Stmt *E, ValueManager& ValMgr) const { |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 21 | |
Ted Kremenek | d72ee90 | 2008-07-10 17:19:18 +0000 | [diff] [blame] | 22 | for (;;) { |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 23 | |
Ted Kremenek | d72ee90 | 2008-07-10 17:19:18 +0000 | [diff] [blame] | 24 | switch (E->getStmtClass()) { |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 25 | |
| 26 | case Stmt::AddrLabelExprClass: |
Zhongxing Xu | d91ee27 | 2009-06-23 09:02:15 +0000 | [diff] [blame] | 27 | return ValMgr.makeLoc(cast<AddrLabelExpr>(E)); |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 28 | |
Ted Kremenek | d72ee90 | 2008-07-10 17:19:18 +0000 | [diff] [blame] | 29 | // ParenExprs are no-ops. |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 30 | |
| 31 | case Stmt::ParenExprClass: |
Ted Kremenek | d72ee90 | 2008-07-10 17:19:18 +0000 | [diff] [blame] | 32 | E = cast<ParenExpr>(E)->getSubExpr(); |
| 33 | continue; |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 34 | |
Ted Kremenek | d72ee90 | 2008-07-10 17:19:18 +0000 | [diff] [blame] | 35 | case Stmt::CharacterLiteralClass: { |
Ted Kremenek | 23ec48c | 2009-06-18 23:58:37 +0000 | [diff] [blame] | 36 | const CharacterLiteral* C = cast<CharacterLiteral>(E); |
Zhongxing Xu | d91ee27 | 2009-06-23 09:02:15 +0000 | [diff] [blame] | 37 | return ValMgr.makeIntVal(C->getValue(), C->getType()); |
Ted Kremenek | d72ee90 | 2008-07-10 17:19:18 +0000 | [diff] [blame] | 38 | } |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 39 | |
Zhongxing Xu | 477323d | 2010-04-14 06:29:29 +0000 | [diff] [blame] | 40 | case Stmt::CXXBoolLiteralExprClass: { |
| 41 | const SVal *X = ExprBindings.lookup(E); |
| 42 | if (X) |
| 43 | return *X; |
| 44 | else |
| 45 | return ValMgr.makeIntVal(cast<CXXBoolLiteralExpr>(E)); |
| 46 | } |
Ted Kremenek | d72ee90 | 2008-07-10 17:19:18 +0000 | [diff] [blame] | 47 | case Stmt::IntegerLiteralClass: { |
Zhongxing Xu | bc37b8d | 2010-01-09 09:16:47 +0000 | [diff] [blame] | 48 | // In C++, this expression may have been bound to a temporary object. |
| 49 | SVal const *X = ExprBindings.lookup(E); |
| 50 | if (X) |
| 51 | return *X; |
| 52 | else |
| 53 | return ValMgr.makeIntVal(cast<IntegerLiteral>(E)); |
Ted Kremenek | d72ee90 | 2008-07-10 17:19:18 +0000 | [diff] [blame] | 54 | } |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 55 | |
Zhongxing Xu | 8ed119f | 2010-11-25 02:52:17 +0000 | [diff] [blame] | 56 | // We blast through no-op casts to get the descendant |
Zhongxing Xu | 143bf82 | 2008-10-25 14:18:57 +0000 | [diff] [blame] | 57 | // subexpression that has a value. |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 58 | |
Argyrios Kyrtzidis | 0835a3c | 2008-08-18 23:01:59 +0000 | [diff] [blame] | 59 | case Stmt::ImplicitCastExprClass: |
Douglas Gregor | 6eec8e8 | 2008-10-28 15:36:24 +0000 | [diff] [blame] | 60 | case Stmt::CStyleCastExprClass: { |
Ted Kremenek | 23ec48c | 2009-06-18 23:58:37 +0000 | [diff] [blame] | 61 | const CastExpr* C = cast<CastExpr>(E); |
Ted Kremenek | d72ee90 | 2008-07-10 17:19:18 +0000 | [diff] [blame] | 62 | QualType CT = C->getType(); |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 63 | |
Ted Kremenek | d72ee90 | 2008-07-10 17:19:18 +0000 | [diff] [blame] | 64 | if (CT->isVoidType()) |
| 65 | return UnknownVal(); |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 66 | |
Zhongxing Xu | d706434 | 2010-11-24 13:08:51 +0000 | [diff] [blame] | 67 | if (C->getCastKind() == CK_NoOp) { |
| 68 | E = C->getSubExpr(); |
| 69 | continue; |
| 70 | } |
Ted Kremenek | d72ee90 | 2008-07-10 17:19:18 +0000 | [diff] [blame] | 71 | break; |
| 72 | } |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 73 | |
Zhongxing Xu | d706434 | 2010-11-24 13:08:51 +0000 | [diff] [blame] | 74 | case Stmt::CXXExprWithTemporariesClass: |
| 75 | E = cast<CXXExprWithTemporaries>(E)->getSubExpr(); |
| 76 | continue; |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 77 | |
Zhongxing Xu | d706434 | 2010-11-24 13:08:51 +0000 | [diff] [blame] | 78 | case Stmt::CXXBindTemporaryExprClass: |
| 79 | E = cast<CXXBindTemporaryExpr>(E)->getSubExpr(); |
| 80 | continue; |
Zhongxing Xu | 0e38d5d | 2010-11-25 03:18:57 +0000 | [diff] [blame^] | 81 | |
| 82 | case Stmt::CXXFunctionalCastExprClass: |
| 83 | E = cast<CXXFunctionalCastExpr>(E)->getSubExpr(); |
| 84 | continue; |
Zhongxing Xu | d706434 | 2010-11-24 13:08:51 +0000 | [diff] [blame] | 85 | |
| 86 | // Handle all other Stmt* using a lookup. |
Ted Kremenek | d72ee90 | 2008-07-10 17:19:18 +0000 | [diff] [blame] | 87 | default: |
| 88 | break; |
| 89 | }; |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 90 | |
Ted Kremenek | d72ee90 | 2008-07-10 17:19:18 +0000 | [diff] [blame] | 91 | break; |
| 92 | } |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 93 | |
Ted Kremenek | d72ee90 | 2008-07-10 17:19:18 +0000 | [diff] [blame] | 94 | return LookupExpr(E); |
| 95 | } |
Ted Kremenek | 8133a26 | 2008-07-08 21:46:56 +0000 | [diff] [blame] | 96 | |
Ted Kremenek | 6d4c022 | 2010-09-03 01:07:02 +0000 | [diff] [blame] | 97 | Environment EnvironmentManager::bindExpr(Environment Env, const Stmt *S, |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 98 | SVal V, bool Invalidate) { |
Ted Kremenek | 0fb0bc4 | 2009-08-27 01:39:13 +0000 | [diff] [blame] | 99 | assert(S); |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 100 | |
| 101 | if (V.isUnknown()) { |
Ted Kremenek | d72ee90 | 2008-07-10 17:19:18 +0000 | [diff] [blame] | 102 | if (Invalidate) |
Ted Kremenek | 3baf672 | 2010-11-24 00:54:37 +0000 | [diff] [blame] | 103 | return Environment(F.remove(Env.ExprBindings, S)); |
Ted Kremenek | d72ee90 | 2008-07-10 17:19:18 +0000 | [diff] [blame] | 104 | else |
| 105 | return Env; |
| 106 | } |
Ted Kremenek | 8133a26 | 2008-07-08 21:46:56 +0000 | [diff] [blame] | 107 | |
Ted Kremenek | 3baf672 | 2010-11-24 00:54:37 +0000 | [diff] [blame] | 108 | return Environment(F.add(Env.ExprBindings, S, V)); |
Ted Kremenek | d72ee90 | 2008-07-10 17:19:18 +0000 | [diff] [blame] | 109 | } |
Ted Kremenek | df9cdf8 | 2008-08-20 17:08:29 +0000 | [diff] [blame] | 110 | |
Ted Kremenek | 6d4c022 | 2010-09-03 01:07:02 +0000 | [diff] [blame] | 111 | static inline const Stmt *MakeLocation(const Stmt *S) { |
| 112 | return (const Stmt*) (((uintptr_t) S) | 0x1); |
| 113 | } |
| 114 | |
| 115 | Environment EnvironmentManager::bindExprAndLocation(Environment Env, |
| 116 | const Stmt *S, |
| 117 | SVal location, SVal V) { |
Ted Kremenek | 3baf672 | 2010-11-24 00:54:37 +0000 | [diff] [blame] | 118 | return Environment(F.add(F.add(Env.ExprBindings, MakeLocation(S), location), |
Zhanyong Wan | cf84887 | 2010-11-20 07:52:48 +0000 | [diff] [blame] | 119 | S, V)); |
Ted Kremenek | 6d4c022 | 2010-09-03 01:07:02 +0000 | [diff] [blame] | 120 | } |
| 121 | |
Ted Kremenek | 5216ad7 | 2009-02-14 03:16:10 +0000 | [diff] [blame] | 122 | namespace { |
Kovarththanan Rajaratnam | ba5fb5a | 2009-11-28 06:07:30 +0000 | [diff] [blame] | 123 | class MarkLiveCallback : public SymbolVisitor { |
Ted Kremenek | 5216ad7 | 2009-02-14 03:16:10 +0000 | [diff] [blame] | 124 | SymbolReaper &SymReaper; |
| 125 | public: |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 126 | MarkLiveCallback(SymbolReaper &symreaper) : SymReaper(symreaper) {} |
Ted Kremenek | 5216ad7 | 2009-02-14 03:16:10 +0000 | [diff] [blame] | 127 | bool VisitSymbol(SymbolRef sym) { SymReaper.markLive(sym); return true; } |
| 128 | }; |
| 129 | } // end anonymous namespace |
| 130 | |
Zhongxing Xu | 7b73b92 | 2010-04-05 13:16:29 +0000 | [diff] [blame] | 131 | static bool isBlockExprInCallers(const Stmt *E, const LocationContext *LC) { |
| 132 | const LocationContext *ParentLC = LC->getParent(); |
| 133 | while (ParentLC) { |
| 134 | CFG &C = *ParentLC->getCFG(); |
| 135 | if (C.isBlkExpr(E)) |
| 136 | return true; |
| 137 | ParentLC = ParentLC->getParent(); |
| 138 | } |
| 139 | |
| 140 | return false; |
| 141 | } |
| 142 | |
Ted Kremenek | 6d4c022 | 2010-09-03 01:07:02 +0000 | [diff] [blame] | 143 | // In addition to mapping from Stmt * - > SVals in the Environment, we also |
| 144 | // maintain a mapping from Stmt * -> SVals (locations) that were used during |
| 145 | // a load and store. |
| 146 | static inline bool IsLocation(const Stmt *S) { |
| 147 | return (bool) (((uintptr_t) S) & 0x1); |
| 148 | } |
Zhongxing Xu | 7b73b92 | 2010-04-05 13:16:29 +0000 | [diff] [blame] | 149 | |
Zhongxing Xu | 9d8d0fc | 2009-03-12 07:54:17 +0000 | [diff] [blame] | 150 | // RemoveDeadBindings: |
| 151 | // - Remove subexpression bindings. |
| 152 | // - Remove dead block expression bindings. |
| 153 | // - Keep live block expression bindings: |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 154 | // - Mark their reachable symbols live in SymbolReaper, |
Zhongxing Xu | 9d8d0fc | 2009-03-12 07:54:17 +0000 | [diff] [blame] | 155 | // see ScanReachableSymbols. |
| 156 | // - Mark the region in DRoots if the binding is a loc::MemRegionVal. |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 157 | Environment |
Jordy Rose | 7dadf79 | 2010-07-01 20:09:55 +0000 | [diff] [blame] | 158 | EnvironmentManager::RemoveDeadBindings(Environment Env, |
Ted Kremenek | 0fb0bc4 | 2009-08-27 01:39:13 +0000 | [diff] [blame] | 159 | SymbolReaper &SymReaper, |
| 160 | const GRState *ST, |
| 161 | llvm::SmallVectorImpl<const MemRegion*> &DRoots) { |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 162 | |
Zhongxing Xu | c179a7f | 2010-03-05 04:45:36 +0000 | [diff] [blame] | 163 | CFG &C = *SymReaper.getLocationContext()->getCFG(); |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 164 | |
Ted Kremenek | 0fb0bc4 | 2009-08-27 01:39:13 +0000 | [diff] [blame] | 165 | // We construct a new Environment object entirely, as this is cheaper than |
| 166 | // individually removing all the subexpression bindings (which will greatly |
| 167 | // outnumber block-level expression bindings). |
Zhongxing Xu | c179a7f | 2010-03-05 04:45:36 +0000 | [diff] [blame] | 168 | Environment NewEnv = getInitialEnvironment(); |
Ted Kremenek | 6d4c022 | 2010-09-03 01:07:02 +0000 | [diff] [blame] | 169 | |
| 170 | llvm::SmallVector<std::pair<const Stmt*, SVal>, 10> deferredLocations; |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 171 | |
Ted Kremenek | df9cdf8 | 2008-08-20 17:08:29 +0000 | [diff] [blame] | 172 | // Iterate over the block-expr bindings. |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 173 | for (Environment::iterator I = Env.begin(), E = Env.end(); |
Ted Kremenek | df9cdf8 | 2008-08-20 17:08:29 +0000 | [diff] [blame] | 174 | I != E; ++I) { |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 175 | |
Ted Kremenek | 23ec48c | 2009-06-18 23:58:37 +0000 | [diff] [blame] | 176 | const Stmt *BlkExpr = I.getKey(); |
Ted Kremenek | 6d4c022 | 2010-09-03 01:07:02 +0000 | [diff] [blame] | 177 | |
| 178 | // For recorded locations (used when evaluating loads and stores), we |
| 179 | // consider them live only when their associated normal expression is |
| 180 | // also live. |
| 181 | // NOTE: This assumes that loads/stores that evaluated to UnknownVal |
| 182 | // still have an entry in the map. |
| 183 | if (IsLocation(BlkExpr)) { |
| 184 | deferredLocations.push_back(std::make_pair(BlkExpr, I.getData())); |
| 185 | continue; |
| 186 | } |
| 187 | |
Zhongxing Xu | 7b73b92 | 2010-04-05 13:16:29 +0000 | [diff] [blame] | 188 | const SVal &X = I.getData(); |
| 189 | |
| 190 | // Block-level expressions in callers are assumed always live. |
| 191 | if (isBlockExprInCallers(BlkExpr, SymReaper.getLocationContext())) { |
Ted Kremenek | 3baf672 | 2010-11-24 00:54:37 +0000 | [diff] [blame] | 192 | NewEnv.ExprBindings = F.add(NewEnv.ExprBindings, BlkExpr, X); |
Zhongxing Xu | 7b73b92 | 2010-04-05 13:16:29 +0000 | [diff] [blame] | 193 | |
| 194 | if (isa<loc::MemRegionVal>(X)) { |
| 195 | const MemRegion* R = cast<loc::MemRegionVal>(X).getRegion(); |
| 196 | DRoots.push_back(R); |
| 197 | } |
| 198 | |
| 199 | // Mark all symbols in the block expr's value live. |
| 200 | MarkLiveCallback cb(SymReaper); |
| 201 | ST->scanReachableSymbols(X, cb); |
| 202 | continue; |
| 203 | } |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 204 | |
Ted Kremenek | 0fb0bc4 | 2009-08-27 01:39:13 +0000 | [diff] [blame] | 205 | // Not a block-level expression? |
| 206 | if (!C.isBlkExpr(BlkExpr)) |
| 207 | continue; |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 208 | |
Jordy Rose | 7dadf79 | 2010-07-01 20:09:55 +0000 | [diff] [blame] | 209 | if (SymReaper.isLive(BlkExpr)) { |
Ted Kremenek | 0fb0bc4 | 2009-08-27 01:39:13 +0000 | [diff] [blame] | 210 | // Copy the binding to the new map. |
Ted Kremenek | 3baf672 | 2010-11-24 00:54:37 +0000 | [diff] [blame] | 211 | NewEnv.ExprBindings = F.add(NewEnv.ExprBindings, BlkExpr, X); |
Mike Stump | 1eb4433 | 2009-09-09 15:08:12 +0000 | [diff] [blame] | 212 | |
Ted Kremenek | 9e24049 | 2008-10-04 05:50:14 +0000 | [diff] [blame] | 213 | // If the block expr's value is a memory region, then mark that region. |
Zhongxing Xu | ce2f9bd | 2009-06-30 13:00:53 +0000 | [diff] [blame] | 214 | if (isa<loc::MemRegionVal>(X)) { |
| 215 | const MemRegion* R = cast<loc::MemRegionVal>(X).getRegion(); |
| 216 | DRoots.push_back(R); |
Zhongxing Xu | ce2f9bd | 2009-06-30 13:00:53 +0000 | [diff] [blame] | 217 | } |
Ted Kremenek | 9e24049 | 2008-10-04 05:50:14 +0000 | [diff] [blame] | 218 | |
Ted Kremenek | 5216ad7 | 2009-02-14 03:16:10 +0000 | [diff] [blame] | 219 | // Mark all symbols in the block expr's value live. |
| 220 | MarkLiveCallback cb(SymReaper); |
Ted Kremenek | 0fb0bc4 | 2009-08-27 01:39:13 +0000 | [diff] [blame] | 221 | ST->scanReachableSymbols(X, cb); |
| 222 | continue; |
Ted Kremenek | df9cdf8 | 2008-08-20 17:08:29 +0000 | [diff] [blame] | 223 | } |
Ted Kremenek | 0fb0bc4 | 2009-08-27 01:39:13 +0000 | [diff] [blame] | 224 | |
| 225 | // Otherwise the expression is dead with a couple exceptions. |
| 226 | // Do not misclean LogicalExpr or ConditionalOperator. It is dead at the |
| 227 | // beginning of itself, but we need its UndefinedVal to determine its |
| 228 | // SVal. |
| 229 | if (X.isUndef() && cast<UndefinedVal>(X).getData()) |
Ted Kremenek | 3baf672 | 2010-11-24 00:54:37 +0000 | [diff] [blame] | 230 | NewEnv.ExprBindings = F.add(NewEnv.ExprBindings, BlkExpr, X); |
Ted Kremenek | df9cdf8 | 2008-08-20 17:08:29 +0000 | [diff] [blame] | 231 | } |
Ted Kremenek | 6d4c022 | 2010-09-03 01:07:02 +0000 | [diff] [blame] | 232 | |
| 233 | // Go through he deferred locations and add them to the new environment if |
| 234 | // the correspond Stmt* is in the map as well. |
| 235 | for (llvm::SmallVectorImpl<std::pair<const Stmt*, SVal> >::iterator |
| 236 | I = deferredLocations.begin(), E = deferredLocations.end(); I != E; ++I) { |
| 237 | const Stmt *S = (Stmt*) (((uintptr_t) I->first) & (uintptr_t) ~0x1); |
| 238 | if (NewEnv.ExprBindings.lookup(S)) |
Ted Kremenek | 3baf672 | 2010-11-24 00:54:37 +0000 | [diff] [blame] | 239 | NewEnv.ExprBindings = F.add(NewEnv.ExprBindings, I->first, I->second); |
Ted Kremenek | 6d4c022 | 2010-09-03 01:07:02 +0000 | [diff] [blame] | 240 | } |
Ted Kremenek | df9cdf8 | 2008-08-20 17:08:29 +0000 | [diff] [blame] | 241 | |
Ted Kremenek | 0fb0bc4 | 2009-08-27 01:39:13 +0000 | [diff] [blame] | 242 | return NewEnv; |
Ted Kremenek | df9cdf8 | 2008-08-20 17:08:29 +0000 | [diff] [blame] | 243 | } |