blob: 20e4d1f8a92ba0d28aba4f33d534858830c08d72 [file] [log] [blame]
Ted Kremenek4adc81e2008-08-13 04:27:00 +00001//= GRState*cpp - Path-Sens. "State" for tracking valuues -----*- C++ -*--=//
Ted Kremenek9153f732008-02-05 07:17:49 +00002//
3// The LLVM Compiler Infrastructure
4//
5// This file is distributed under the University of Illinois Open Source
6// License. See LICENSE.TXT for details.
7//
8//===----------------------------------------------------------------------===//
9//
Ted Kremenek2dabd432008-12-05 02:27:51 +000010// This file defines SymbolRef, ExprBindKey, and GRState*
Ted Kremenek9153f732008-02-05 07:17:49 +000011//
12//===----------------------------------------------------------------------===//
13
Ted Kremeneke7aa9a12008-08-17 02:59:30 +000014#include "clang/Analysis/PathSensitive/GRStateTrait.h"
Ted Kremenek4adc81e2008-08-13 04:27:00 +000015#include "clang/Analysis/PathSensitive/GRState.h"
Ted Kremenek729a9a22008-07-17 23:15:45 +000016#include "clang/Analysis/PathSensitive/GRTransferFuncs.h"
Ted Kremenek05125f12008-08-27 23:13:01 +000017#include "llvm/ADT/SmallSet.h"
Chris Lattner405674c2008-08-23 22:23:37 +000018#include "llvm/Support/raw_ostream.h"
Ted Kremenek05125f12008-08-27 23:13:01 +000019
Ted Kremenekf66ea2cd2008-02-04 21:59:22 +000020using namespace clang;
21
Ted Kremenek05125f12008-08-27 23:13:01 +000022// Give the vtable for ConstraintManager somewhere to live.
23ConstraintManager::~ConstraintManager() {}
24
Ted Kremenek1c72ef02008-08-16 00:49:49 +000025GRStateManager::~GRStateManager() {
26 for (std::vector<GRState::Printer*>::iterator I=Printers.begin(),
27 E=Printers.end(); I!=E; ++I)
28 delete *I;
29
30 for (GDMContextsTy::iterator I=GDMContexts.begin(), E=GDMContexts.end();
31 I!=E; ++I)
32 I->second.second(I->second.first);
33}
34
Ted Kremenek4adc81e2008-08-13 04:27:00 +000035const GRState*
Ted Kremenek2ed14be2008-12-05 00:47:52 +000036GRStateManager::RemoveDeadBindings(const GRState* state, Stmt* Loc,
Ted Kremenek241677a2009-01-21 22:26:05 +000037 SymbolReaper& SymReaper) {
38
Ted Kremenekb87d9092008-02-08 19:17:19 +000039 // This code essentially performs a "mark-and-sweep" of the VariableBindings.
40 // The roots are any Block-level exprs and Decls that our liveness algorithm
41 // tells us are live. We then see what Decls they may reference, and keep
42 // those around. This code more than likely can be made faster, and the
43 // frequency of which this method is called should be experimented with
Ted Kremenek9e240492008-10-04 05:50:14 +000044 // for optimum performance.
45 llvm::SmallVector<const MemRegion*, 10> RegionRoots;
Ted Kremenek2ed14be2008-12-05 00:47:52 +000046 GRState NewState = *state;
Ted Kremenekf59bf482008-07-17 18:38:48 +000047
Ted Kremenek5216ad72009-02-14 03:16:10 +000048 NewState.Env = EnvMgr.RemoveDeadBindings(NewState.Env, Loc, SymReaper, *this,
Ted Kremenek5dc27462009-03-03 02:51:43 +000049 state, RegionRoots);
Ted Kremenek016f52f2008-02-08 21:10:02 +000050
Ted Kremenekf59bf482008-07-17 18:38:48 +000051 // Clean up the store.
Ted Kremenek241677a2009-01-21 22:26:05 +000052 NewState.St = StoreMgr->RemoveDeadBindings(&NewState, Loc, SymReaper,
53 RegionRoots);
Ted Kremenekffdbefd2008-08-17 03:10:22 +000054
Ted Kremenek2ed14be2008-12-05 00:47:52 +000055 return ConstraintMgr->RemoveDeadBindings(getPersistentState(NewState),
Ted Kremenek241677a2009-01-21 22:26:05 +000056 SymReaper);
Ted Kremenekb87d9092008-02-08 19:17:19 +000057}
Ted Kremenek862d5bb2008-02-06 00:54:14 +000058
Zhongxing Xu1c96b242008-10-17 05:57:07 +000059const GRState* GRStateManager::Unbind(const GRState* St, Loc LV) {
Ted Kremenek4323a572008-07-10 22:03:41 +000060 Store OldStore = St->getStore();
Zhongxing Xu6d69b5d2008-10-16 06:09:51 +000061 Store NewStore = StoreMgr->Remove(OldStore, LV);
Ted Kremenek4323a572008-07-10 22:03:41 +000062
63 if (NewStore == OldStore)
64 return St;
65
Ted Kremenek4adc81e2008-08-13 04:27:00 +000066 GRState NewSt = *St;
Ted Kremenek4323a572008-07-10 22:03:41 +000067 NewSt.St = NewStore;
68 return getPersistentState(NewSt);
69}
70
Ted Kremenek4adc81e2008-08-13 04:27:00 +000071const GRState* GRStateManager::getInitialState() {
Ted Kremenek67f28532009-06-17 22:02:04 +000072 GRState StateImpl(this, EnvMgr.getInitialEnvironment(),
Zhongxing Xu6d69b5d2008-10-16 06:09:51 +000073 StoreMgr->getInitialStore(),
Ted Kremenekffdbefd2008-08-17 03:10:22 +000074 GDMFactory.GetEmptyMap());
Ted Kremenekcaa37242008-08-19 16:51:45 +000075
Ted Kremenek9153f732008-02-05 07:17:49 +000076 return getPersistentState(StateImpl);
77}
78
Ted Kremenek4adc81e2008-08-13 04:27:00 +000079const GRState* GRStateManager::getPersistentState(GRState& State) {
Ted Kremenek9153f732008-02-05 07:17:49 +000080
81 llvm::FoldingSetNodeID ID;
82 State.Profile(ID);
Ted Kremeneke7d22112008-02-11 19:21:59 +000083 void* InsertPos;
Ted Kremenek9153f732008-02-05 07:17:49 +000084
Ted Kremenek4adc81e2008-08-13 04:27:00 +000085 if (GRState* I = StateSet.FindNodeOrInsertPos(ID, InsertPos))
Ted Kremenek9153f732008-02-05 07:17:49 +000086 return I;
87
Ted Kremenek4adc81e2008-08-13 04:27:00 +000088 GRState* I = (GRState*) Alloc.Allocate<GRState>();
89 new (I) GRState(State);
Ted Kremenek9153f732008-02-05 07:17:49 +000090 StateSet.InsertNode(I, InsertPos);
91 return I;
92}
Ted Kremeneke7d22112008-02-11 19:21:59 +000093
Ted Kremenek67f28532009-06-17 22:02:04 +000094const GRState* GRState::makeWithStore(Store store) const {
95 GRState NewSt = *this;
Zhongxing Xu4193eca2008-12-20 06:32:12 +000096 NewSt.St = store;
Ted Kremenek67f28532009-06-17 22:02:04 +000097 return Mgr->getPersistentState(NewSt);
Zhongxing Xu4193eca2008-12-20 06:32:12 +000098}
99
Ted Kremenek1c72ef02008-08-16 00:49:49 +0000100//===----------------------------------------------------------------------===//
101// State pretty-printing.
102//===----------------------------------------------------------------------===//
Ted Kremenek461f9772008-03-11 18:57:24 +0000103
Ted Kremeneka622d8c2008-08-19 22:24:03 +0000104void GRState::print(std::ostream& Out, StoreManager& StoreMgr,
Zhongxing Xu39cfed32008-08-29 14:52:36 +0000105 ConstraintManager& ConstraintMgr,
Ted Kremeneka622d8c2008-08-19 22:24:03 +0000106 Printer** Beg, Printer** End,
Ted Kremenekae6814e2008-08-13 21:24:49 +0000107 const char* nl, const char* sep) const {
Ted Kremeneke7d22112008-02-11 19:21:59 +0000108
Ted Kremeneka622d8c2008-08-19 22:24:03 +0000109 // Print the store.
110 StoreMgr.print(getStore(), Out, nl, sep);
Ted Kremeneke7d22112008-02-11 19:21:59 +0000111
112 // Print Subexpression bindings.
Ted Kremeneka622d8c2008-08-19 22:24:03 +0000113 bool isFirst = true;
Ted Kremeneke7d22112008-02-11 19:21:59 +0000114
Ted Kremenekaa1c4e52008-02-21 18:02:17 +0000115 for (seb_iterator I = seb_begin(), E = seb_end(); I != E; ++I) {
Ted Kremeneke7d22112008-02-11 19:21:59 +0000116
117 if (isFirst) {
Ted Kremenek59894f92008-03-04 18:30:35 +0000118 Out << nl << nl << "Sub-Expressions:" << nl;
Ted Kremeneke7d22112008-02-11 19:21:59 +0000119 isFirst = false;
120 }
Ted Kremenek59894f92008-03-04 18:30:35 +0000121 else { Out << nl; }
Ted Kremeneke7d22112008-02-11 19:21:59 +0000122
123 Out << " (" << (void*) I.getKey() << ") ";
Ted Kremeneka95d3752008-09-13 05:16:45 +0000124 llvm::raw_os_ostream OutS(Out);
125 I.getKey()->printPretty(OutS);
126 OutS.flush();
Ted Kremeneke7d22112008-02-11 19:21:59 +0000127 Out << " : ";
128 I.getData().print(Out);
129 }
130
131 // Print block-expression bindings.
Ted Kremeneke7d22112008-02-11 19:21:59 +0000132 isFirst = true;
133
Ted Kremenekaa1c4e52008-02-21 18:02:17 +0000134 for (beb_iterator I = beb_begin(), E = beb_end(); I != E; ++I) {
Ted Kremeneke7d22112008-02-11 19:21:59 +0000135
136 if (isFirst) {
Ted Kremenek59894f92008-03-04 18:30:35 +0000137 Out << nl << nl << "Block-level Expressions:" << nl;
Ted Kremeneke7d22112008-02-11 19:21:59 +0000138 isFirst = false;
139 }
Ted Kremenek59894f92008-03-04 18:30:35 +0000140 else { Out << nl; }
Ted Kremeneke7d22112008-02-11 19:21:59 +0000141
142 Out << " (" << (void*) I.getKey() << ") ";
Ted Kremeneka95d3752008-09-13 05:16:45 +0000143 llvm::raw_os_ostream OutS(Out);
144 I.getKey()->printPretty(OutS);
145 OutS.flush();
Ted Kremeneke7d22112008-02-11 19:21:59 +0000146 Out << " : ";
147 I.getData().print(Out);
148 }
149
Zhongxing Xu39cfed32008-08-29 14:52:36 +0000150 ConstraintMgr.print(this, Out, nl, sep);
Ted Kremenek461f9772008-03-11 18:57:24 +0000151
Ted Kremenekae6814e2008-08-13 21:24:49 +0000152 // Print checker-specific data.
153 for ( ; Beg != End ; ++Beg) (*Beg)->Print(Out, this, nl, sep);
Ted Kremeneke7d22112008-02-11 19:21:59 +0000154}
Ted Kremenek729a9a22008-07-17 23:15:45 +0000155
Ted Kremenek1c72ef02008-08-16 00:49:49 +0000156void GRStateRef::printDOT(std::ostream& Out) const {
157 print(Out, "\\l", "\\|");
158}
159
160void GRStateRef::printStdErr() const {
161 print(*llvm::cerr);
162}
163
164void GRStateRef::print(std::ostream& Out, const char* nl, const char* sep)const{
165 GRState::Printer **beg = Mgr->Printers.empty() ? 0 : &Mgr->Printers[0];
166 GRState::Printer **end = !beg ? 0 : beg + Mgr->Printers.size();
Zhongxing Xu6d69b5d2008-10-16 06:09:51 +0000167 St->print(Out, *Mgr->StoreMgr, *Mgr->ConstraintMgr, beg, end, nl, sep);
Ted Kremenek1c72ef02008-08-16 00:49:49 +0000168}
169
Ted Kremenek72cd17f2008-08-14 21:16:54 +0000170//===----------------------------------------------------------------------===//
171// Generic Data Map.
172//===----------------------------------------------------------------------===//
173
174void* const* GRState::FindGDM(void* K) const {
175 return GDM.lookup(K);
176}
177
Ted Kremenek1c72ef02008-08-16 00:49:49 +0000178void*
179GRStateManager::FindGDMContext(void* K,
180 void* (*CreateContext)(llvm::BumpPtrAllocator&),
181 void (*DeleteContext)(void*)) {
182
183 std::pair<void*, void (*)(void*)>& p = GDMContexts[K];
184 if (!p.first) {
185 p.first = CreateContext(Alloc);
186 p.second = DeleteContext;
187 }
188
189 return p.first;
190}
191
Zhongxing Xu4230da62008-11-03 05:18:34 +0000192const GRState* GRStateManager::addGDM(const GRState* St, void* Key, void* Data){
Ted Kremenek72cd17f2008-08-14 21:16:54 +0000193 GRState::GenericDataMap M1 = St->getGDM();
194 GRState::GenericDataMap M2 = GDMFactory.Add(M1, Key, Data);
195
196 if (M1 == M2)
197 return St;
198
199 GRState NewSt = *St;
200 NewSt.GDM = M2;
201 return getPersistentState(NewSt);
202}
Ted Kremenek584def72008-07-22 00:46:16 +0000203
204//===----------------------------------------------------------------------===//
Ted Kremenek5216ad72009-02-14 03:16:10 +0000205// Utility.
206//===----------------------------------------------------------------------===//
207
Ted Kremenek5dc27462009-03-03 02:51:43 +0000208namespace {
Zhongxing Xu63d1d602009-03-04 06:33:38 +0000209class VISIBILITY_HIDDEN ScanReachableSymbols : public SubRegionMap::Visitor {
Ted Kremenek5dc27462009-03-03 02:51:43 +0000210 typedef llvm::DenseSet<const MemRegion*> VisitedRegionsTy;
211
212 VisitedRegionsTy visited;
213 GRStateRef state;
214 SymbolVisitor &visitor;
215 llvm::OwningPtr<SubRegionMap> SRM;
216public:
217
218 ScanReachableSymbols(GRStateManager* sm, const GRState *st, SymbolVisitor& v)
219 : state(st, *sm), visitor(v) {}
220
221 bool scan(nonloc::CompoundVal val);
222 bool scan(SVal val);
223 bool scan(const MemRegion *R);
224
225 // From SubRegionMap::Visitor.
226 bool Visit(const MemRegion* Parent, const MemRegion* SubRegion) {
227 return scan(SubRegion);
228 }
229};
230}
231
232bool ScanReachableSymbols::scan(nonloc::CompoundVal val) {
Ted Kremenek5216ad72009-02-14 03:16:10 +0000233 for (nonloc::CompoundVal::iterator I=val.begin(), E=val.end(); I!=E; ++I)
Ted Kremenek5dc27462009-03-03 02:51:43 +0000234 if (!scan(*I))
235 return false;
Ted Kremenek5216ad72009-02-14 03:16:10 +0000236
237 return true;
238}
Ted Kremenek5dc27462009-03-03 02:51:43 +0000239
240bool ScanReachableSymbols::scan(SVal val) {
241 if (loc::MemRegionVal *X = dyn_cast<loc::MemRegionVal>(&val))
242 return scan(X->getRegion());
Ted Kremenek380022d2009-03-30 18:45:36 +0000243
244 if (SymbolRef Sym = val.getAsSymbol())
245 return visitor.VisitSymbol(Sym);
Ted Kremenek5216ad72009-02-14 03:16:10 +0000246
247 if (nonloc::CompoundVal *X = dyn_cast<nonloc::CompoundVal>(&val))
Ted Kremenek5dc27462009-03-03 02:51:43 +0000248 return scan(*X);
Ted Kremenek5216ad72009-02-14 03:16:10 +0000249
250 return true;
251}
Ted Kremenek5dc27462009-03-03 02:51:43 +0000252
253bool ScanReachableSymbols::scan(const MemRegion *R) {
Ted Kremenek1cb151e2009-03-04 00:13:10 +0000254 if (isa<MemSpaceRegion>(R) || visited.count(R))
Ted Kremenek5dc27462009-03-03 02:51:43 +0000255 return true;
256
257 visited.insert(R);
258
259 // If this is a symbolic region, visit the symbol for the region.
260 if (const SymbolicRegion *SR = dyn_cast<SymbolicRegion>(R))
261 if (!visitor.VisitSymbol(SR->getSymbol()))
262 return false;
263
264 // If this is a subregion, also visit the parent regions.
265 if (const SubRegion *SR = dyn_cast<SubRegion>(R))
Ted Kremenek6076e0a2009-03-03 18:15:30 +0000266 if (!scan(SR->getSuperRegion()))
Ted Kremenek5dc27462009-03-03 02:51:43 +0000267 return false;
268
269 // Now look at the binding to this region (if any).
Ted Kremenek1cb151e2009-03-04 00:13:10 +0000270 if (!scan(state.GetSValAsScalarOrLoc(R)))
Ted Kremenek5dc27462009-03-03 02:51:43 +0000271 return false;
272
273 // Now look at the subregions.
274 if (!SRM.get())
Ted Kremenek14453bf2009-03-03 19:02:42 +0000275 SRM.reset(state.getManager().getStoreManager().getSubRegionMap(state));
Ted Kremenek5dc27462009-03-03 02:51:43 +0000276
277 return SRM->iterSubRegions(R, *this);
278}
279
280bool GRStateManager::scanReachableSymbols(SVal val, const GRState* state,
281 SymbolVisitor& visitor) {
282 ScanReachableSymbols S(this, state, visitor);
283 return S.scan(val);
284}
Ted Kremenek5216ad72009-02-14 03:16:10 +0000285
286//===----------------------------------------------------------------------===//
Ted Kremenek584def72008-07-22 00:46:16 +0000287// Queries.
288//===----------------------------------------------------------------------===//
289
Ted Kremenek4adc81e2008-08-13 04:27:00 +0000290bool GRStateManager::isEqual(const GRState* state, Expr* Ex,
Ted Kremenek1c72ef02008-08-16 00:49:49 +0000291 const llvm::APSInt& Y) {
292
Zhongxing Xu1c96b242008-10-17 05:57:07 +0000293 SVal V = GetSVal(state, Ex);
Ted Kremenek584def72008-07-22 00:46:16 +0000294
Zhongxing Xu1c96b242008-10-17 05:57:07 +0000295 if (loc::ConcreteInt* X = dyn_cast<loc::ConcreteInt>(&V))
Ted Kremenek584def72008-07-22 00:46:16 +0000296 return X->getValue() == Y;
297
Zhongxing Xu1c96b242008-10-17 05:57:07 +0000298 if (nonloc::ConcreteInt* X = dyn_cast<nonloc::ConcreteInt>(&V))
Ted Kremenek584def72008-07-22 00:46:16 +0000299 return X->getValue() == Y;
300
Ted Kremenek380022d2009-03-30 18:45:36 +0000301 if (SymbolRef Sym = V.getAsSymbol())
302 return ConstraintMgr->isEqual(state, Sym, Y);
303
Ted Kremenek584def72008-07-22 00:46:16 +0000304 return false;
305}
306
Ted Kremenek1c72ef02008-08-16 00:49:49 +0000307bool GRStateManager::isEqual(const GRState* state, Expr* Ex, uint64_t x) {
Ted Kremenek044b6f02009-04-09 16:13:17 +0000308 return isEqual(state, Ex, getBasicVals().getValue(x, Ex->getType()));
Ted Kremenek584def72008-07-22 00:46:16 +0000309}
Ted Kremenek7360fda2008-09-18 23:09:54 +0000310
311//===----------------------------------------------------------------------===//
312// Persistent values for indexing into the Generic Data Map.
313
314int GRState::NullDerefTag::TagInt = 0;
315