Ted Kremenek | 294fd0a | 2011-08-20 06:00:03 +0000 | [diff] [blame] | 1 | //=-- ExprEngineCallAndReturn.cpp - Support for call/return -----*- C++ -*-===// |
| 2 | // |
| 3 | // The LLVM Compiler Infrastructure |
| 4 | // |
| 5 | // This file is distributed under the University of Illinois Open Source |
| 6 | // License. See LICENSE.TXT for details. |
| 7 | // |
| 8 | //===----------------------------------------------------------------------===// |
| 9 | // |
| 10 | // This file defines ExprEngine's support for calls and returns. |
| 11 | // |
| 12 | //===----------------------------------------------------------------------===// |
| 13 | |
Anna Zaks | e90d3f8 | 2012-08-09 00:21:33 +0000 | [diff] [blame] | 14 | #define DEBUG_TYPE "ExprEngine" |
| 15 | |
Ted Kremenek | d4aeb80 | 2012-07-02 20:21:52 +0000 | [diff] [blame] | 16 | #include "clang/Analysis/Analyses/LiveVariables.h" |
Ted Kremenek | 294fd0a | 2011-08-20 06:00:03 +0000 | [diff] [blame] | 17 | #include "clang/StaticAnalyzer/Core/CheckerManager.h" |
| 18 | #include "clang/StaticAnalyzer/Core/PathSensitive/ExprEngine.h" |
Jordan Rose | f540c54 | 2012-07-26 21:39:41 +0000 | [diff] [blame] | 19 | #include "clang/StaticAnalyzer/Core/PathSensitive/CallEvent.h" |
Ted Kremenek | 294fd0a | 2011-08-20 06:00:03 +0000 | [diff] [blame] | 20 | #include "clang/AST/DeclCXX.h" |
Jordan Rose | 6fe4dfb | 2012-08-27 18:39:22 +0000 | [diff] [blame^] | 21 | #include "clang/AST/ParentMap.h" |
Benjamin Kramer | 4a5f724 | 2012-04-01 19:30:51 +0000 | [diff] [blame] | 22 | #include "llvm/ADT/SmallSet.h" |
Anna Zaks | e90d3f8 | 2012-08-09 00:21:33 +0000 | [diff] [blame] | 23 | #include "llvm/ADT/Statistic.h" |
Benjamin Kramer | 4a5f724 | 2012-04-01 19:30:51 +0000 | [diff] [blame] | 24 | #include "llvm/Support/SaveAndRestore.h" |
Ted Kremenek | 294fd0a | 2011-08-20 06:00:03 +0000 | [diff] [blame] | 25 | |
| 26 | using namespace clang; |
| 27 | using namespace ento; |
| 28 | |
Anna Zaks | e90d3f8 | 2012-08-09 00:21:33 +0000 | [diff] [blame] | 29 | STATISTIC(NumOfDynamicDispatchPathSplits, |
| 30 | "The # of times we split the path due to imprecise dynamic dispatch info"); |
| 31 | |
Anna Zaks | 210f5a2 | 2012-08-27 18:38:32 +0000 | [diff] [blame] | 32 | STATISTIC(NumInlinedCalls, |
| 33 | "The # of times we inlined a call"); |
| 34 | |
Ted Kremenek | 3070e13 | 2012-01-07 01:03:17 +0000 | [diff] [blame] | 35 | void ExprEngine::processCallEnter(CallEnter CE, ExplodedNode *Pred) { |
| 36 | // Get the entry block in the CFG of the callee. |
Ted Kremenek | 0849ade | 2012-01-12 19:25:46 +0000 | [diff] [blame] | 37 | const StackFrameContext *calleeCtx = CE.getCalleeContext(); |
| 38 | const CFG *CalleeCFG = calleeCtx->getCFG(); |
Ted Kremenek | 3070e13 | 2012-01-07 01:03:17 +0000 | [diff] [blame] | 39 | const CFGBlock *Entry = &(CalleeCFG->getEntry()); |
| 40 | |
| 41 | // Validate the CFG. |
| 42 | assert(Entry->empty()); |
| 43 | assert(Entry->succ_size() == 1); |
| 44 | |
| 45 | // Get the solitary sucessor. |
| 46 | const CFGBlock *Succ = *(Entry->succ_begin()); |
| 47 | |
| 48 | // Construct an edge representing the starting location in the callee. |
Ted Kremenek | 0849ade | 2012-01-12 19:25:46 +0000 | [diff] [blame] | 49 | BlockEdge Loc(Entry, Succ, calleeCtx); |
Ted Kremenek | 3070e13 | 2012-01-07 01:03:17 +0000 | [diff] [blame] | 50 | |
Jordan Rose | e54cfc7 | 2012-07-10 22:07:57 +0000 | [diff] [blame] | 51 | ProgramStateRef state = Pred->getState(); |
Ted Kremenek | 3070e13 | 2012-01-07 01:03:17 +0000 | [diff] [blame] | 52 | |
| 53 | // Construct a new node and add it to the worklist. |
| 54 | bool isNew; |
| 55 | ExplodedNode *Node = G.getNode(Loc, state, false, &isNew); |
| 56 | Node->addPredecessor(Pred, G); |
| 57 | if (isNew) |
| 58 | Engine.getWorkList()->enqueue(Node); |
Ted Kremenek | 294fd0a | 2011-08-20 06:00:03 +0000 | [diff] [blame] | 59 | } |
| 60 | |
Anna Zaks | 0b3ade8 | 2012-04-20 21:59:08 +0000 | [diff] [blame] | 61 | // Find the last statement on the path to the exploded node and the |
| 62 | // corresponding Block. |
| 63 | static std::pair<const Stmt*, |
| 64 | const CFGBlock*> getLastStmt(const ExplodedNode *Node) { |
| 65 | const Stmt *S = 0; |
Anna Zaks | 0b3ade8 | 2012-04-20 21:59:08 +0000 | [diff] [blame] | 66 | const StackFrameContext *SF = |
| 67 | Node->getLocation().getLocationContext()->getCurrentStackFrame(); |
Jordan Rose | 888c90a | 2012-07-26 20:04:13 +0000 | [diff] [blame] | 68 | |
| 69 | // Back up through the ExplodedGraph until we reach a statement node. |
Ted Kremenek | 256ef64 | 2012-01-11 01:06:27 +0000 | [diff] [blame] | 70 | while (Node) { |
| 71 | const ProgramPoint &PP = Node->getLocation(); |
Jordan Rose | 888c90a | 2012-07-26 20:04:13 +0000 | [diff] [blame] | 72 | |
Ted Kremenek | 256ef64 | 2012-01-11 01:06:27 +0000 | [diff] [blame] | 73 | if (const StmtPoint *SP = dyn_cast<StmtPoint>(&PP)) { |
Anna Zaks | 0b3ade8 | 2012-04-20 21:59:08 +0000 | [diff] [blame] | 74 | S = SP->getStmt(); |
Anna Zaks | 0b3ade8 | 2012-04-20 21:59:08 +0000 | [diff] [blame] | 75 | break; |
Jordan Rose | 888c90a | 2012-07-26 20:04:13 +0000 | [diff] [blame] | 76 | } else if (const CallExitEnd *CEE = dyn_cast<CallExitEnd>(&PP)) { |
| 77 | S = CEE->getCalleeContext()->getCallSite(); |
| 78 | if (S) |
| 79 | break; |
| 80 | // If we have an implicit call, we'll probably end up with a |
| 81 | // StmtPoint inside the callee, which is acceptable. |
| 82 | // (It's possible a function ONLY contains implicit calls -- such as an |
| 83 | // implicitly-generated destructor -- so we shouldn't just skip back to |
| 84 | // the CallEnter node and keep going.) |
| 85 | } else if (const CallEnter *CE = dyn_cast<CallEnter>(&PP)) { |
| 86 | // If we reached the CallEnter for this function, it has no statements. |
| 87 | if (CE->getCalleeContext() == SF) |
| 88 | break; |
Ted Kremenek | 256ef64 | 2012-01-11 01:06:27 +0000 | [diff] [blame] | 89 | } |
Jordan Rose | 888c90a | 2012-07-26 20:04:13 +0000 | [diff] [blame] | 90 | |
| 91 | Node = *Node->pred_begin(); |
Ted Kremenek | 256ef64 | 2012-01-11 01:06:27 +0000 | [diff] [blame] | 92 | } |
Jordan Rose | 888c90a | 2012-07-26 20:04:13 +0000 | [diff] [blame] | 93 | |
| 94 | const CFGBlock *Blk = 0; |
| 95 | if (S) { |
| 96 | // Now, get the enclosing basic block. |
| 97 | while (Node && Node->pred_size() >=1 ) { |
| 98 | const ProgramPoint &PP = Node->getLocation(); |
| 99 | if (isa<BlockEdge>(PP) && |
| 100 | (PP.getLocationContext()->getCurrentStackFrame() == SF)) { |
| 101 | BlockEdge &EPP = cast<BlockEdge>(PP); |
| 102 | Blk = EPP.getDst(); |
| 103 | break; |
| 104 | } |
| 105 | Node = *Node->pred_begin(); |
| 106 | } |
| 107 | } |
| 108 | |
Anna Zaks | 0b3ade8 | 2012-04-20 21:59:08 +0000 | [diff] [blame] | 109 | return std::pair<const Stmt*, const CFGBlock*>(S, Blk); |
Ted Kremenek | 256ef64 | 2012-01-11 01:06:27 +0000 | [diff] [blame] | 110 | } |
| 111 | |
Anna Zaks | 0b3ade8 | 2012-04-20 21:59:08 +0000 | [diff] [blame] | 112 | /// The call exit is simulated with a sequence of nodes, which occur between |
| 113 | /// CallExitBegin and CallExitEnd. The following operations occur between the |
| 114 | /// two program points: |
| 115 | /// 1. CallExitBegin (triggers the start of call exit sequence) |
| 116 | /// 2. Bind the return value |
| 117 | /// 3. Run Remove dead bindings to clean up the dead symbols from the callee. |
| 118 | /// 4. CallExitEnd (switch to the caller context) |
| 119 | /// 5. PostStmt<CallExpr> |
| 120 | void ExprEngine::processCallExit(ExplodedNode *CEBNode) { |
| 121 | // Step 1 CEBNode was generated before the call. |
| 122 | |
| 123 | const StackFrameContext *calleeCtx = |
| 124 | CEBNode->getLocationContext()->getCurrentStackFrame(); |
Ted Kremenek | 7fa9b4f | 2012-06-01 20:04:04 +0000 | [diff] [blame] | 125 | |
| 126 | // The parent context might not be a stack frame, so make sure we |
| 127 | // look up the first enclosing stack frame. |
| 128 | const StackFrameContext *callerCtx = |
| 129 | calleeCtx->getParent()->getCurrentStackFrame(); |
| 130 | |
Ted Kremenek | 294fd0a | 2011-08-20 06:00:03 +0000 | [diff] [blame] | 131 | const Stmt *CE = calleeCtx->getCallSite(); |
Anna Zaks | 0b3ade8 | 2012-04-20 21:59:08 +0000 | [diff] [blame] | 132 | ProgramStateRef state = CEBNode->getState(); |
| 133 | // Find the last statement in the function and the corresponding basic block. |
| 134 | const Stmt *LastSt = 0; |
| 135 | const CFGBlock *Blk = 0; |
| 136 | llvm::tie(LastSt, Blk) = getLastStmt(CEBNode); |
| 137 | |
Jordan Rose | 852aa0d | 2012-07-10 22:07:52 +0000 | [diff] [blame] | 138 | // Step 2: generate node with bound return value: CEBNode -> BindedRetNode. |
Anna Zaks | 0b3ade8 | 2012-04-20 21:59:08 +0000 | [diff] [blame] | 139 | |
Ted Kremenek | 294fd0a | 2011-08-20 06:00:03 +0000 | [diff] [blame] | 140 | // If the callee returns an expression, bind its value to CallExpr. |
Jordan Rose | 852aa0d | 2012-07-10 22:07:52 +0000 | [diff] [blame] | 141 | if (CE) { |
| 142 | if (const ReturnStmt *RS = dyn_cast_or_null<ReturnStmt>(LastSt)) { |
| 143 | const LocationContext *LCtx = CEBNode->getLocationContext(); |
| 144 | SVal V = state->getSVal(RS, LCtx); |
Jordan Rose | 57c0336 | 2012-07-30 23:39:47 +0000 | [diff] [blame] | 145 | state = state->BindExpr(CE, callerCtx, V); |
Jordan Rose | 852aa0d | 2012-07-10 22:07:52 +0000 | [diff] [blame] | 146 | } |
Anna Zaks | 0b3ade8 | 2012-04-20 21:59:08 +0000 | [diff] [blame] | 147 | |
Jordan Rose | 852aa0d | 2012-07-10 22:07:52 +0000 | [diff] [blame] | 148 | // Bind the constructed object value to CXXConstructExpr. |
| 149 | if (const CXXConstructExpr *CCE = dyn_cast<CXXConstructExpr>(CE)) { |
| 150 | loc::MemRegionVal This = |
| 151 | svalBuilder.getCXXThis(CCE->getConstructor()->getParent(), calleeCtx); |
| 152 | SVal ThisV = state->getSVal(This); |
Anna Zaks | 0b3ade8 | 2012-04-20 21:59:08 +0000 | [diff] [blame] | 153 | |
Jordan Rose | 852aa0d | 2012-07-10 22:07:52 +0000 | [diff] [blame] | 154 | // Always bind the region to the CXXConstructExpr. |
Jordan Rose | 57c0336 | 2012-07-30 23:39:47 +0000 | [diff] [blame] | 155 | state = state->BindExpr(CCE, callerCtx, ThisV); |
Jordan Rose | 852aa0d | 2012-07-10 22:07:52 +0000 | [diff] [blame] | 156 | } |
Ted Kremenek | 294fd0a | 2011-08-20 06:00:03 +0000 | [diff] [blame] | 157 | } |
Anna Zaks | 0b3ade8 | 2012-04-20 21:59:08 +0000 | [diff] [blame] | 158 | |
Jordan Rose | 4e79fdf | 2012-08-15 20:07:17 +0000 | [diff] [blame] | 159 | // Generate a CallEvent /before/ cleaning the state, so that we can get the |
| 160 | // correct value for 'this' (if necessary). |
| 161 | CallEventManager &CEMgr = getStateManager().getCallEventManager(); |
| 162 | CallEventRef<> Call = CEMgr.getCaller(calleeCtx, state); |
| 163 | |
Anna Zaks | 0b3ade8 | 2012-04-20 21:59:08 +0000 | [diff] [blame] | 164 | // Step 3: BindedRetNode -> CleanedNodes |
| 165 | // If we can find a statement and a block in the inlined function, run remove |
| 166 | // dead bindings before returning from the call. This is important to ensure |
| 167 | // that we report the issues such as leaks in the stack contexts in which |
| 168 | // they occurred. |
| 169 | ExplodedNodeSet CleanedNodes; |
| 170 | if (LastSt && Blk) { |
Jordan Rose | 48b6247 | 2012-07-10 22:08:01 +0000 | [diff] [blame] | 171 | static SimpleProgramPointTag retValBind("ExprEngine : Bind Return Value"); |
| 172 | PostStmt Loc(LastSt, calleeCtx, &retValBind); |
| 173 | bool isNew; |
| 174 | ExplodedNode *BindedRetNode = G.getNode(Loc, state, false, &isNew); |
| 175 | BindedRetNode->addPredecessor(CEBNode, G); |
| 176 | if (!isNew) |
| 177 | return; |
| 178 | |
Anna Zaks | 0b3ade8 | 2012-04-20 21:59:08 +0000 | [diff] [blame] | 179 | NodeBuilderContext Ctx(getCoreEngine(), Blk, BindedRetNode); |
Ted Kremenek | 66c486f | 2012-08-22 06:26:15 +0000 | [diff] [blame] | 180 | currBldrCtx = &Ctx; |
Anna Zaks | 0b3ade8 | 2012-04-20 21:59:08 +0000 | [diff] [blame] | 181 | // Here, we call the Symbol Reaper with 0 statement and caller location |
| 182 | // context, telling it to clean up everything in the callee's context |
| 183 | // (and it's children). We use LastStmt as a diagnostic statement, which |
| 184 | // which the PreStmtPurge Dead point will be associated. |
| 185 | removeDead(BindedRetNode, CleanedNodes, 0, callerCtx, LastSt, |
| 186 | ProgramPoint::PostStmtPurgeDeadSymbolsKind); |
Ted Kremenek | 66c486f | 2012-08-22 06:26:15 +0000 | [diff] [blame] | 187 | currBldrCtx = 0; |
Anna Zaks | 144e52b | 2012-06-01 23:48:40 +0000 | [diff] [blame] | 188 | } else { |
| 189 | CleanedNodes.Add(CEBNode); |
Anna Zaks | 0b3ade8 | 2012-04-20 21:59:08 +0000 | [diff] [blame] | 190 | } |
| 191 | |
| 192 | for (ExplodedNodeSet::iterator I = CleanedNodes.begin(), |
| 193 | E = CleanedNodes.end(); I != E; ++I) { |
| 194 | |
| 195 | // Step 4: Generate the CallExit and leave the callee's context. |
| 196 | // CleanedNodes -> CEENode |
Jordan Rose | 852aa0d | 2012-07-10 22:07:52 +0000 | [diff] [blame] | 197 | CallExitEnd Loc(calleeCtx, callerCtx); |
Anna Zaks | 0b3ade8 | 2012-04-20 21:59:08 +0000 | [diff] [blame] | 198 | bool isNew; |
Jordan Rose | 48b6247 | 2012-07-10 22:08:01 +0000 | [diff] [blame] | 199 | ProgramStateRef CEEState = (*I == CEBNode) ? state : (*I)->getState(); |
| 200 | ExplodedNode *CEENode = G.getNode(Loc, CEEState, false, &isNew); |
Anna Zaks | 0b3ade8 | 2012-04-20 21:59:08 +0000 | [diff] [blame] | 201 | CEENode->addPredecessor(*I, G); |
| 202 | if (!isNew) |
| 203 | return; |
| 204 | |
| 205 | // Step 5: Perform the post-condition check of the CallExpr and enqueue the |
| 206 | // result onto the work list. |
| 207 | // CEENode -> Dst -> WorkList |
Anna Zaks | 0b3ade8 | 2012-04-20 21:59:08 +0000 | [diff] [blame] | 208 | NodeBuilderContext Ctx(Engine, calleeCtx->getCallSiteBlock(), CEENode); |
Ted Kremenek | 66c486f | 2012-08-22 06:26:15 +0000 | [diff] [blame] | 209 | SaveAndRestore<const NodeBuilderContext*> NBCSave(currBldrCtx, |
Anna Zaks | 0b3ade8 | 2012-04-20 21:59:08 +0000 | [diff] [blame] | 210 | &Ctx); |
Ted Kremenek | 66c486f | 2012-08-22 06:26:15 +0000 | [diff] [blame] | 211 | SaveAndRestore<unsigned> CBISave(currStmtIdx, calleeCtx->getIndex()); |
Anna Zaks | 0b3ade8 | 2012-04-20 21:59:08 +0000 | [diff] [blame] | 212 | |
Jordan Rose | 4e79fdf | 2012-08-15 20:07:17 +0000 | [diff] [blame] | 213 | CallEventRef<> UpdatedCall = Call.cloneWithState(CEEState); |
Jordan Rose | 57c0336 | 2012-07-30 23:39:47 +0000 | [diff] [blame] | 214 | |
| 215 | ExplodedNodeSet DstPostCall; |
Jordan Rose | 4e79fdf | 2012-08-15 20:07:17 +0000 | [diff] [blame] | 216 | getCheckerManager().runCheckersForPostCall(DstPostCall, CEENode, |
| 217 | *UpdatedCall, *this, |
| 218 | /*WasInlined=*/true); |
Jordan Rose | 57c0336 | 2012-07-30 23:39:47 +0000 | [diff] [blame] | 219 | |
| 220 | ExplodedNodeSet Dst; |
Jordan Rose | 4e79fdf | 2012-08-15 20:07:17 +0000 | [diff] [blame] | 221 | if (const ObjCMethodCall *Msg = dyn_cast<ObjCMethodCall>(Call)) { |
| 222 | getCheckerManager().runCheckersForPostObjCMessage(Dst, DstPostCall, *Msg, |
| 223 | *this, |
| 224 | /*WasInlined=*/true); |
Jordan Rose | 57c0336 | 2012-07-30 23:39:47 +0000 | [diff] [blame] | 225 | } else if (CE) { |
| 226 | getCheckerManager().runCheckersForPostStmt(Dst, DstPostCall, CE, |
Jordan Rose | 4e79fdf | 2012-08-15 20:07:17 +0000 | [diff] [blame] | 227 | *this, /*WasInlined=*/true); |
Jordan Rose | 57c0336 | 2012-07-30 23:39:47 +0000 | [diff] [blame] | 228 | } else { |
| 229 | Dst.insert(DstPostCall); |
| 230 | } |
Anna Zaks | 0b3ade8 | 2012-04-20 21:59:08 +0000 | [diff] [blame] | 231 | |
| 232 | // Enqueue the next element in the block. |
| 233 | for (ExplodedNodeSet::iterator PSI = Dst.begin(), PSE = Dst.end(); |
| 234 | PSI != PSE; ++PSI) { |
| 235 | Engine.getWorkList()->enqueue(*PSI, calleeCtx->getCallSiteBlock(), |
| 236 | calleeCtx->getIndex()+1); |
| 237 | } |
Ted Kremenek | 242384d | 2012-01-07 00:10:49 +0000 | [diff] [blame] | 238 | } |
Ted Kremenek | 294fd0a | 2011-08-20 06:00:03 +0000 | [diff] [blame] | 239 | } |
| 240 | |
Ted Kremenek | 0849ade | 2012-01-12 19:25:46 +0000 | [diff] [blame] | 241 | static unsigned getNumberStackFrames(const LocationContext *LCtx) { |
| 242 | unsigned count = 0; |
| 243 | while (LCtx) { |
| 244 | if (isa<StackFrameContext>(LCtx)) |
| 245 | ++count; |
| 246 | LCtx = LCtx->getParent(); |
| 247 | } |
| 248 | return count; |
| 249 | } |
| 250 | |
Anna Zaks | 6cc0969 | 2012-03-13 22:15:58 +0000 | [diff] [blame] | 251 | // Determine if we should inline the call. |
Ted Kremenek | 7fa9b4f | 2012-06-01 20:04:04 +0000 | [diff] [blame] | 252 | bool ExprEngine::shouldInlineDecl(const Decl *D, ExplodedNode *Pred) { |
| 253 | AnalysisDeclContext *CalleeADC = AMgr.getAnalysisDeclContext(D); |
Anna Zaks | 6cc0969 | 2012-03-13 22:15:58 +0000 | [diff] [blame] | 254 | const CFG *CalleeCFG = CalleeADC->getCFG(); |
| 255 | |
Ted Kremenek | 01561d1 | 2012-04-17 01:36:03 +0000 | [diff] [blame] | 256 | // It is possible that the CFG cannot be constructed. |
| 257 | // Be safe, and check if the CalleeCFG is valid. |
| 258 | if (!CalleeCFG) |
| 259 | return false; |
| 260 | |
Anna Zaks | 6cc0969 | 2012-03-13 22:15:58 +0000 | [diff] [blame] | 261 | if (getNumberStackFrames(Pred->getLocationContext()) |
| 262 | == AMgr.InlineMaxStackDepth) |
| 263 | return false; |
| 264 | |
Ted Kremenek | 7fa9b4f | 2012-06-01 20:04:04 +0000 | [diff] [blame] | 265 | if (Engine.FunctionSummaries->hasReachedMaxBlockCount(D)) |
Anna Zaks | 3bbd8cd | 2012-03-30 05:48:10 +0000 | [diff] [blame] | 266 | return false; |
| 267 | |
Anna Zaks | 6cc0969 | 2012-03-13 22:15:58 +0000 | [diff] [blame] | 268 | if (CalleeCFG->getNumBlockIDs() > AMgr.InlineMaxFunctionSize) |
| 269 | return false; |
| 270 | |
Ted Kremenek | 10f77ad | 2012-06-22 23:55:50 +0000 | [diff] [blame] | 271 | // Do not inline variadic calls (for now). |
| 272 | if (const BlockDecl *BD = dyn_cast<BlockDecl>(D)) { |
| 273 | if (BD->isVariadic()) |
| 274 | return false; |
Anna Zaks | 5903a37 | 2012-03-27 20:02:53 +0000 | [diff] [blame] | 275 | } |
Ted Kremenek | 10f77ad | 2012-06-22 23:55:50 +0000 | [diff] [blame] | 276 | else if (const FunctionDecl *FD = dyn_cast<FunctionDecl>(D)) { |
| 277 | if (FD->isVariadic()) |
| 278 | return false; |
| 279 | } |
Anna Zaks | 5903a37 | 2012-03-27 20:02:53 +0000 | [diff] [blame] | 280 | |
Ted Kremenek | d4aeb80 | 2012-07-02 20:21:52 +0000 | [diff] [blame] | 281 | // It is possible that the live variables analysis cannot be |
| 282 | // run. If so, bail out. |
| 283 | if (!CalleeADC->getAnalysis<RelaxedLiveVariables>()) |
| 284 | return false; |
| 285 | |
Ted Kremenek | 10f77ad | 2012-06-22 23:55:50 +0000 | [diff] [blame] | 286 | return true; |
Anna Zaks | 5903a37 | 2012-03-27 20:02:53 +0000 | [diff] [blame] | 287 | } |
| 288 | |
Anna Zaks | e90d3f8 | 2012-08-09 00:21:33 +0000 | [diff] [blame] | 289 | /// The GDM component containing the dynamic dispatch bifurcation info. When |
| 290 | /// the exact type of the receiver is not known, we want to explore both paths - |
| 291 | /// one on which we do inline it and the other one on which we don't. This is |
| 292 | /// done to ensure we do not drop coverage. |
| 293 | /// This is the map from the receiver region to a bool, specifying either we |
| 294 | /// consider this region's information precise or not along the given path. |
| 295 | namespace clang { |
| 296 | namespace ento { |
Anna Zaks | 6960f6e | 2012-08-09 21:02:41 +0000 | [diff] [blame] | 297 | enum DynamicDispatchMode { DynamicDispatchModeInlined = 1, |
| 298 | DynamicDispatchModeConservative }; |
| 299 | |
Anna Zaks | e90d3f8 | 2012-08-09 00:21:33 +0000 | [diff] [blame] | 300 | struct DynamicDispatchBifurcationMap {}; |
| 301 | typedef llvm::ImmutableMap<const MemRegion*, |
Anna Zaks | 6960f6e | 2012-08-09 21:02:41 +0000 | [diff] [blame] | 302 | unsigned int> DynamicDispatchBifur; |
Anna Zaks | e90d3f8 | 2012-08-09 00:21:33 +0000 | [diff] [blame] | 303 | template<> struct ProgramStateTrait<DynamicDispatchBifurcationMap> |
| 304 | : public ProgramStatePartialTrait<DynamicDispatchBifur> { |
| 305 | static void *GDMIndex() { static int index; return &index; } |
| 306 | }; |
Anna Zaks | 6960f6e | 2012-08-09 21:02:41 +0000 | [diff] [blame] | 307 | |
Anna Zaks | e90d3f8 | 2012-08-09 00:21:33 +0000 | [diff] [blame] | 308 | }} |
Anna Zaks | 5903a37 | 2012-03-27 20:02:53 +0000 | [diff] [blame] | 309 | |
Jordan Rose | c568e2f | 2012-08-21 21:44:21 +0000 | [diff] [blame] | 310 | static bool shouldInlineCXX(AnalysisManager &AMgr) { |
| 311 | switch (AMgr.IPAMode) { |
| 312 | case None: |
| 313 | case BasicInlining: |
| 314 | return false; |
| 315 | case Inlining: |
| 316 | case DynamicDispatch: |
| 317 | case DynamicDispatchBifurcate: |
| 318 | return true; |
| 319 | case NumIPAModes: |
| 320 | llvm_unreachable("not actually a valid option"); |
| 321 | } |
Matt Beaumont-Gay | 12e2fb0 | 2012-08-21 22:27:18 +0000 | [diff] [blame] | 322 | llvm_unreachable("bogus IPAMode"); |
Jordan Rose | c568e2f | 2012-08-21 21:44:21 +0000 | [diff] [blame] | 323 | } |
| 324 | |
Anna Zaks | e90d3f8 | 2012-08-09 00:21:33 +0000 | [diff] [blame] | 325 | bool ExprEngine::inlineCall(const CallEvent &Call, const Decl *D, |
| 326 | NodeBuilder &Bldr, ExplodedNode *Pred, |
| 327 | ProgramStateRef State) { |
| 328 | assert(D); |
Jordan Rose | ee158bc | 2012-07-09 16:54:49 +0000 | [diff] [blame] | 329 | |
Jordan Rose | c36b30c | 2012-07-12 00:16:25 +0000 | [diff] [blame] | 330 | const LocationContext *CurLC = Pred->getLocationContext(); |
| 331 | const StackFrameContext *CallerSFC = CurLC->getCurrentStackFrame(); |
Ted Kremenek | 7fa9b4f | 2012-06-01 20:04:04 +0000 | [diff] [blame] | 332 | const LocationContext *ParentOfCallee = 0; |
Jordan Rose | 69f87c9 | 2012-07-02 19:28:09 +0000 | [diff] [blame] | 333 | |
Jordan Rose | ef15831 | 2012-07-31 01:07:55 +0000 | [diff] [blame] | 334 | // FIXME: Refactor this check into a hypothetical CallEvent::canInline. |
Jordan Rose | 69f87c9 | 2012-07-02 19:28:09 +0000 | [diff] [blame] | 335 | switch (Call.getKind()) { |
| 336 | case CE_Function: |
Jordan Rose | 2f9c40a | 2012-07-31 18:22:40 +0000 | [diff] [blame] | 337 | break; |
Jordan Rose | 69f87c9 | 2012-07-02 19:28:09 +0000 | [diff] [blame] | 338 | case CE_CXXMember: |
Jordan Rose | e54cfc7 | 2012-07-10 22:07:57 +0000 | [diff] [blame] | 339 | case CE_CXXMemberOperator: |
Jordan Rose | c568e2f | 2012-08-21 21:44:21 +0000 | [diff] [blame] | 340 | if (!shouldInlineCXX(getAnalysisManager())) |
Jordan Rose | 2f9c40a | 2012-07-31 18:22:40 +0000 | [diff] [blame] | 341 | return false; |
Jordan Rose | 69f87c9 | 2012-07-02 19:28:09 +0000 | [diff] [blame] | 342 | break; |
Jordan Rose | ef15831 | 2012-07-31 01:07:55 +0000 | [diff] [blame] | 343 | case CE_CXXConstructor: { |
Jordan Rose | c568e2f | 2012-08-21 21:44:21 +0000 | [diff] [blame] | 344 | if (!shouldInlineCXX(getAnalysisManager())) |
Jordan Rose | 2f9c40a | 2012-07-31 18:22:40 +0000 | [diff] [blame] | 345 | return false; |
| 346 | |
Jordan Rose | ef15831 | 2012-07-31 01:07:55 +0000 | [diff] [blame] | 347 | const CXXConstructorCall &Ctor = cast<CXXConstructorCall>(Call); |
| 348 | |
| 349 | // FIXME: We don't handle constructors or destructors for arrays properly. |
| 350 | const MemRegion *Target = Ctor.getCXXThisVal().getAsRegion(); |
| 351 | if (Target && isa<ElementRegion>(Target)) |
| 352 | return false; |
| 353 | |
Jordan Rose | 6fe4dfb | 2012-08-27 18:39:22 +0000 | [diff] [blame^] | 354 | // FIXME: This is a hack. We don't use the correct region for a new |
| 355 | // expression, so if we inline the constructor its result will just be |
| 356 | // thrown away. This short-term hack is tracked in <rdar://problem/12180598> |
| 357 | // and the longer-term possible fix is discussed in PR12014. |
| 358 | const CXXConstructExpr *CtorExpr = Ctor.getOriginExpr(); |
| 359 | if (const Stmt *Parent = CurLC->getParentMap().getParent(CtorExpr)) |
| 360 | if (isa<CXXNewExpr>(Parent)) |
| 361 | return false; |
| 362 | |
Jordan Rose | c210cb7 | 2012-08-27 17:50:07 +0000 | [diff] [blame] | 363 | // If the destructor is trivial, it's always safe to inline the constructor. |
| 364 | if (Ctor.getDecl()->getParent()->hasTrivialDestructor()) |
| 365 | break; |
| 366 | |
| 367 | // For other types, only inline constructors if we built the CFGs for the |
| 368 | // destructor properly. |
| 369 | const AnalysisDeclContext *ADC = CallerSFC->getAnalysisDeclContext(); |
| 370 | assert(ADC->getCFGBuildOptions().AddInitializers && "No CFG initializers"); |
| 371 | if (!ADC->getCFGBuildOptions().AddImplicitDtors) |
| 372 | return false; |
| 373 | |
Jordan Rose | ef15831 | 2012-07-31 01:07:55 +0000 | [diff] [blame] | 374 | // FIXME: This is a hack. We don't handle temporary destructors |
| 375 | // right now, so we shouldn't inline their constructors. |
Jordan Rose | ef15831 | 2012-07-31 01:07:55 +0000 | [diff] [blame] | 376 | if (CtorExpr->getConstructionKind() == CXXConstructExpr::CK_Complete) |
| 377 | if (!Target || !isa<DeclRegion>(Target)) |
| 378 | return false; |
| 379 | |
| 380 | break; |
| 381 | } |
Jordan Rose | da5fc53 | 2012-07-26 20:04:00 +0000 | [diff] [blame] | 382 | case CE_CXXDestructor: { |
Jordan Rose | c568e2f | 2012-08-21 21:44:21 +0000 | [diff] [blame] | 383 | if (!shouldInlineCXX(getAnalysisManager())) |
Jordan Rose | 2f9c40a | 2012-07-31 18:22:40 +0000 | [diff] [blame] | 384 | return false; |
| 385 | |
Jordan Rose | da5fc53 | 2012-07-26 20:04:00 +0000 | [diff] [blame] | 386 | // Only inline constructors and destructors if we built the CFGs for them |
| 387 | // properly. |
| 388 | const AnalysisDeclContext *ADC = CallerSFC->getAnalysisDeclContext(); |
Jordan Rose | c210cb7 | 2012-08-27 17:50:07 +0000 | [diff] [blame] | 389 | if (!ADC->getCFGBuildOptions().AddImplicitDtors) |
Jordan Rose | da5fc53 | 2012-07-26 20:04:00 +0000 | [diff] [blame] | 390 | return false; |
Jordan Rose | 3a0a9e3 | 2012-07-26 20:04:21 +0000 | [diff] [blame] | 391 | |
Jordan Rose | ef15831 | 2012-07-31 01:07:55 +0000 | [diff] [blame] | 392 | const CXXDestructorCall &Dtor = cast<CXXDestructorCall>(Call); |
| 393 | |
Jordan Rose | e460c46 | 2012-07-26 20:04:25 +0000 | [diff] [blame] | 394 | // FIXME: We don't handle constructors or destructors for arrays properly. |
Jordan Rose | ef15831 | 2012-07-31 01:07:55 +0000 | [diff] [blame] | 395 | const MemRegion *Target = Dtor.getCXXThisVal().getAsRegion(); |
Jordan Rose | e460c46 | 2012-07-26 20:04:25 +0000 | [diff] [blame] | 396 | if (Target && isa<ElementRegion>(Target)) |
| 397 | return false; |
| 398 | |
Jordan Rose | da5fc53 | 2012-07-26 20:04:00 +0000 | [diff] [blame] | 399 | break; |
| 400 | } |
Jordan Rose | 70cbf3c | 2012-07-02 22:21:47 +0000 | [diff] [blame] | 401 | case CE_CXXAllocator: |
Jordan Rose | c568e2f | 2012-08-21 21:44:21 +0000 | [diff] [blame] | 402 | if (!shouldInlineCXX(getAnalysisManager())) |
Jordan Rose | 2f9c40a | 2012-07-31 18:22:40 +0000 | [diff] [blame] | 403 | return false; |
| 404 | |
Jordan Rose | 70cbf3c | 2012-07-02 22:21:47 +0000 | [diff] [blame] | 405 | // Do not inline allocators until we model deallocators. |
| 406 | // This is unfortunate, but basically necessary for smart pointers and such. |
| 407 | return false; |
Jordan Rose | 69f87c9 | 2012-07-02 19:28:09 +0000 | [diff] [blame] | 408 | case CE_Block: { |
| 409 | const BlockDataRegion *BR = cast<BlockCall>(Call).getBlockRegion(); |
Jordan Rose | ee158bc | 2012-07-09 16:54:49 +0000 | [diff] [blame] | 410 | assert(BR && "If we have the block definition we should have its region"); |
Jordan Rose | 69f87c9 | 2012-07-02 19:28:09 +0000 | [diff] [blame] | 411 | AnalysisDeclContext *BlockCtx = AMgr.getAnalysisDeclContext(D); |
Ted Kremenek | 7fa9b4f | 2012-06-01 20:04:04 +0000 | [diff] [blame] | 412 | ParentOfCallee = BlockCtx->getBlockInvocationContext(CallerSFC, |
Jordan Rose | 69f87c9 | 2012-07-02 19:28:09 +0000 | [diff] [blame] | 413 | cast<BlockDecl>(D), |
Ted Kremenek | 7fa9b4f | 2012-06-01 20:04:04 +0000 | [diff] [blame] | 414 | BR); |
Jordan Rose | 69f87c9 | 2012-07-02 19:28:09 +0000 | [diff] [blame] | 415 | break; |
| 416 | } |
| 417 | case CE_ObjCMessage: |
Anna Zaks | e90d3f8 | 2012-08-09 00:21:33 +0000 | [diff] [blame] | 418 | if (!(getAnalysisManager().IPAMode == DynamicDispatch || |
| 419 | getAnalysisManager().IPAMode == DynamicDispatchBifurcate)) |
Anna Zaks | e13056a | 2012-07-30 20:31:18 +0000 | [diff] [blame] | 420 | return false; |
Anna Zaks | 9dc5167 | 2012-07-26 00:27:51 +0000 | [diff] [blame] | 421 | break; |
Ted Kremenek | 7fa9b4f | 2012-06-01 20:04:04 +0000 | [diff] [blame] | 422 | } |
Jordan Rose | ee158bc | 2012-07-09 16:54:49 +0000 | [diff] [blame] | 423 | |
| 424 | if (!shouldInlineDecl(D, Pred)) |
Ted Kremenek | 256ef64 | 2012-01-11 01:06:27 +0000 | [diff] [blame] | 425 | return false; |
| 426 | |
Ted Kremenek | 7fa9b4f | 2012-06-01 20:04:04 +0000 | [diff] [blame] | 427 | if (!ParentOfCallee) |
| 428 | ParentOfCallee = CallerSFC; |
Anna Zaks | 8235f9c | 2012-03-02 19:05:03 +0000 | [diff] [blame] | 429 | |
Jordan Rose | 852aa0d | 2012-07-10 22:07:52 +0000 | [diff] [blame] | 430 | // This may be NULL, but that's fine. |
Jordan Rose | 69f87c9 | 2012-07-02 19:28:09 +0000 | [diff] [blame] | 431 | const Expr *CallE = Call.getOriginExpr(); |
Jordan Rose | 69f87c9 | 2012-07-02 19:28:09 +0000 | [diff] [blame] | 432 | |
Ted Kremenek | 7fa9b4f | 2012-06-01 20:04:04 +0000 | [diff] [blame] | 433 | // Construct a new stack frame for the callee. |
| 434 | AnalysisDeclContext *CalleeADC = AMgr.getAnalysisDeclContext(D); |
| 435 | const StackFrameContext *CalleeSFC = |
Jordan Rose | 69f87c9 | 2012-07-02 19:28:09 +0000 | [diff] [blame] | 436 | CalleeADC->getStackFrame(ParentOfCallee, CallE, |
Ted Kremenek | 66c486f | 2012-08-22 06:26:15 +0000 | [diff] [blame] | 437 | currBldrCtx->getBlock(), |
| 438 | currStmtIdx); |
Ted Kremenek | 7fa9b4f | 2012-06-01 20:04:04 +0000 | [diff] [blame] | 439 | |
Jordan Rose | c36b30c | 2012-07-12 00:16:25 +0000 | [diff] [blame] | 440 | CallEnter Loc(CallE, CalleeSFC, CurLC); |
Jordan Rose | e54cfc7 | 2012-07-10 22:07:57 +0000 | [diff] [blame] | 441 | |
| 442 | // Construct a new state which contains the mapping from actual to |
| 443 | // formal arguments. |
Anna Zaks | e90d3f8 | 2012-08-09 00:21:33 +0000 | [diff] [blame] | 444 | State = State->enterStackFrame(Call, CalleeSFC); |
Jordan Rose | e54cfc7 | 2012-07-10 22:07:57 +0000 | [diff] [blame] | 445 | |
Ted Kremenek | 7fa9b4f | 2012-06-01 20:04:04 +0000 | [diff] [blame] | 446 | bool isNew; |
Jordan Rose | e54cfc7 | 2012-07-10 22:07:57 +0000 | [diff] [blame] | 447 | if (ExplodedNode *N = G.getNode(Loc, State, false, &isNew)) { |
Ted Kremenek | 7fa9b4f | 2012-06-01 20:04:04 +0000 | [diff] [blame] | 448 | N->addPredecessor(Pred, G); |
| 449 | if (isNew) |
| 450 | Engine.getWorkList()->enqueue(N); |
Ted Kremenek | 256ef64 | 2012-01-11 01:06:27 +0000 | [diff] [blame] | 451 | } |
Anna Zaks | e90d3f8 | 2012-08-09 00:21:33 +0000 | [diff] [blame] | 452 | |
| 453 | // If we decided to inline the call, the successor has been manually |
| 454 | // added onto the work list so remove it from the node builder. |
| 455 | Bldr.takeNodes(Pred); |
| 456 | |
Anna Zaks | 210f5a2 | 2012-08-27 18:38:32 +0000 | [diff] [blame] | 457 | NumInlinedCalls++; |
| 458 | |
Ted Kremenek | 7fa9b4f | 2012-06-01 20:04:04 +0000 | [diff] [blame] | 459 | return true; |
Ted Kremenek | 256ef64 | 2012-01-11 01:06:27 +0000 | [diff] [blame] | 460 | } |
| 461 | |
Anna Zaks | e81ce25 | 2012-07-19 23:38:13 +0000 | [diff] [blame] | 462 | static ProgramStateRef getInlineFailedState(ProgramStateRef State, |
Jordan Rose | 69f87c9 | 2012-07-02 19:28:09 +0000 | [diff] [blame] | 463 | const Stmt *CallE) { |
Anna Zaks | e81ce25 | 2012-07-19 23:38:13 +0000 | [diff] [blame] | 464 | void *ReplayState = State->get<ReplayWithoutInlining>(); |
Anna Zaks | 5903a37 | 2012-03-27 20:02:53 +0000 | [diff] [blame] | 465 | if (!ReplayState) |
| 466 | return 0; |
Jordan Rose | 28038f3 | 2012-07-10 22:07:42 +0000 | [diff] [blame] | 467 | |
| 468 | assert(ReplayState == (const void*)CallE && "Backtracked to the wrong call."); |
| 469 | (void)CallE; |
| 470 | |
Anna Zaks | e81ce25 | 2012-07-19 23:38:13 +0000 | [diff] [blame] | 471 | return State->remove<ReplayWithoutInlining>(); |
Ted Kremenek | 10520d7 | 2012-02-09 21:59:52 +0000 | [diff] [blame] | 472 | } |
| 473 | |
Ted Kremenek | 294fd0a | 2011-08-20 06:00:03 +0000 | [diff] [blame] | 474 | void ExprEngine::VisitCallExpr(const CallExpr *CE, ExplodedNode *Pred, |
| 475 | ExplodedNodeSet &dst) { |
| 476 | // Perform the previsit of the CallExpr. |
| 477 | ExplodedNodeSet dstPreVisit; |
| 478 | getCheckerManager().runCheckersForPreStmt(dstPreVisit, Pred, CE, *this); |
Anna Zaks | 5903a37 | 2012-03-27 20:02:53 +0000 | [diff] [blame] | 479 | |
Jordan Rose | d563d3f | 2012-07-30 20:22:09 +0000 | [diff] [blame] | 480 | // Get the call in its initial state. We use this as a template to perform |
| 481 | // all the checks. |
| 482 | CallEventManager &CEMgr = getStateManager().getCallEventManager(); |
Jordan Rose | 645baee | 2012-08-13 23:46:05 +0000 | [diff] [blame] | 483 | CallEventRef<> CallTemplate |
Jordan Rose | d563d3f | 2012-07-30 20:22:09 +0000 | [diff] [blame] | 484 | = CEMgr.getSimpleCall(CE, Pred->getState(), Pred->getLocationContext()); |
Anna Zaks | 5903a37 | 2012-03-27 20:02:53 +0000 | [diff] [blame] | 485 | |
Jordan Rose | 69f87c9 | 2012-07-02 19:28:09 +0000 | [diff] [blame] | 486 | // Evaluate the function call. We try each of the checkers |
Ted Kremenek | 294fd0a | 2011-08-20 06:00:03 +0000 | [diff] [blame] | 487 | // to see if the can evaluate the function call. |
| 488 | ExplodedNodeSet dstCallEvaluated; |
Jordan Rose | 69f87c9 | 2012-07-02 19:28:09 +0000 | [diff] [blame] | 489 | for (ExplodedNodeSet::iterator I = dstPreVisit.begin(), E = dstPreVisit.end(); |
| 490 | I != E; ++I) { |
Jordan Rose | d563d3f | 2012-07-30 20:22:09 +0000 | [diff] [blame] | 491 | evalCall(dstCallEvaluated, *I, *CallTemplate); |
Jordan Rose | 69f87c9 | 2012-07-02 19:28:09 +0000 | [diff] [blame] | 492 | } |
| 493 | |
Ted Kremenek | 294fd0a | 2011-08-20 06:00:03 +0000 | [diff] [blame] | 494 | // Finally, perform the post-condition check of the CallExpr and store |
| 495 | // the created nodes in 'Dst'. |
Jordan Rose | 69f87c9 | 2012-07-02 19:28:09 +0000 | [diff] [blame] | 496 | // Note that if the call was inlined, dstCallEvaluated will be empty. |
| 497 | // The post-CallExpr check will occur in processCallExit. |
Ted Kremenek | 294fd0a | 2011-08-20 06:00:03 +0000 | [diff] [blame] | 498 | getCheckerManager().runCheckersForPostStmt(dst, dstCallEvaluated, CE, |
| 499 | *this); |
| 500 | } |
| 501 | |
Jordan Rose | 69f87c9 | 2012-07-02 19:28:09 +0000 | [diff] [blame] | 502 | void ExprEngine::evalCall(ExplodedNodeSet &Dst, ExplodedNode *Pred, |
Jordan Rose | 645baee | 2012-08-13 23:46:05 +0000 | [diff] [blame] | 503 | const CallEvent &Call) { |
Jordan Rose | d563d3f | 2012-07-30 20:22:09 +0000 | [diff] [blame] | 504 | // WARNING: At this time, the state attached to 'Call' may be older than the |
| 505 | // state in 'Pred'. This is a minor optimization since CheckerManager will |
| 506 | // use an updated CallEvent instance when calling checkers, but if 'Call' is |
| 507 | // ever used directly in this function all callers should be updated to pass |
| 508 | // the most recent state. (It is probably not worth doing the work here since |
| 509 | // for some callers this will not be necessary.) |
| 510 | |
Jordan Rose | 96479da | 2012-07-02 19:28:16 +0000 | [diff] [blame] | 511 | // Run any pre-call checks using the generic call interface. |
| 512 | ExplodedNodeSet dstPreVisit; |
| 513 | getCheckerManager().runCheckersForPreCall(dstPreVisit, Pred, Call, *this); |
| 514 | |
| 515 | // Actually evaluate the function call. We try each of the checkers |
| 516 | // to see if the can evaluate the function call, and get a callback at |
| 517 | // defaultEvalCall if all of them fail. |
| 518 | ExplodedNodeSet dstCallEvaluated; |
| 519 | getCheckerManager().runCheckersForEvalCall(dstCallEvaluated, dstPreVisit, |
| 520 | Call, *this); |
| 521 | |
| 522 | // Finally, run any post-call checks. |
| 523 | getCheckerManager().runCheckersForPostCall(Dst, dstCallEvaluated, |
| 524 | Call, *this); |
Jordan Rose | 69f87c9 | 2012-07-02 19:28:09 +0000 | [diff] [blame] | 525 | } |
| 526 | |
Anna Zaks | e81ce25 | 2012-07-19 23:38:13 +0000 | [diff] [blame] | 527 | ProgramStateRef ExprEngine::bindReturnValue(const CallEvent &Call, |
| 528 | const LocationContext *LCtx, |
| 529 | ProgramStateRef State) { |
| 530 | const Expr *E = Call.getOriginExpr(); |
| 531 | if (!E) |
| 532 | return State; |
| 533 | |
| 534 | // Some method families have known return values. |
| 535 | if (const ObjCMethodCall *Msg = dyn_cast<ObjCMethodCall>(&Call)) { |
| 536 | switch (Msg->getMethodFamily()) { |
| 537 | default: |
| 538 | break; |
| 539 | case OMF_autorelease: |
| 540 | case OMF_retain: |
| 541 | case OMF_self: { |
| 542 | // These methods return their receivers. |
| 543 | return State->BindExpr(E, LCtx, Msg->getReceiverSVal()); |
Anna Zaks | e81ce25 | 2012-07-19 23:38:13 +0000 | [diff] [blame] | 544 | } |
| 545 | } |
Jordan Rose | e460c46 | 2012-07-26 20:04:25 +0000 | [diff] [blame] | 546 | } else if (const CXXConstructorCall *C = dyn_cast<CXXConstructorCall>(&Call)){ |
| 547 | return State->BindExpr(E, LCtx, C->getCXXThisVal()); |
Anna Zaks | e81ce25 | 2012-07-19 23:38:13 +0000 | [diff] [blame] | 548 | } |
| 549 | |
| 550 | // Conjure a symbol if the return value is unknown. |
| 551 | QualType ResultTy = Call.getResultType(); |
| 552 | SValBuilder &SVB = getSValBuilder(); |
Ted Kremenek | 66c486f | 2012-08-22 06:26:15 +0000 | [diff] [blame] | 553 | unsigned Count = currBldrCtx->blockCount(); |
Ted Kremenek | 3b1df8b | 2012-08-22 06:26:06 +0000 | [diff] [blame] | 554 | SVal R = SVB.conjureSymbolVal(0, E, LCtx, ResultTy, Count); |
Anna Zaks | e81ce25 | 2012-07-19 23:38:13 +0000 | [diff] [blame] | 555 | return State->BindExpr(E, LCtx, R); |
| 556 | } |
| 557 | |
Anna Zaks | e90d3f8 | 2012-08-09 00:21:33 +0000 | [diff] [blame] | 558 | // Conservatively evaluate call by invalidating regions and binding |
| 559 | // a conjured return value. |
| 560 | void ExprEngine::conservativeEvalCall(const CallEvent &Call, NodeBuilder &Bldr, |
| 561 | ExplodedNode *Pred, ProgramStateRef State) { |
Ted Kremenek | 66c486f | 2012-08-22 06:26:15 +0000 | [diff] [blame] | 562 | State = Call.invalidateRegions(currBldrCtx->blockCount(), State); |
Anna Zaks | e90d3f8 | 2012-08-09 00:21:33 +0000 | [diff] [blame] | 563 | State = bindReturnValue(Call, Pred->getLocationContext(), State); |
| 564 | |
| 565 | // And make the result node. |
| 566 | Bldr.generateNode(Call.getProgramPoint(), State, Pred); |
| 567 | } |
| 568 | |
Anna Zaks | e81ce25 | 2012-07-19 23:38:13 +0000 | [diff] [blame] | 569 | void ExprEngine::defaultEvalCall(NodeBuilder &Bldr, ExplodedNode *Pred, |
Jordan Rose | d563d3f | 2012-07-30 20:22:09 +0000 | [diff] [blame] | 570 | const CallEvent &CallTemplate) { |
| 571 | // Make sure we have the most recent state attached to the call. |
| 572 | ProgramStateRef State = Pred->getState(); |
| 573 | CallEventRef<> Call = CallTemplate.cloneWithState(State); |
Anna Zaks | e81ce25 | 2012-07-19 23:38:13 +0000 | [diff] [blame] | 574 | |
Anna Zaks | 5960f4a | 2012-08-09 18:43:00 +0000 | [diff] [blame] | 575 | if (!getAnalysisManager().shouldInlineCall()) { |
| 576 | conservativeEvalCall(*Call, Bldr, Pred, State); |
| 577 | return; |
| 578 | } |
Jordan Rose | 69f87c9 | 2012-07-02 19:28:09 +0000 | [diff] [blame] | 579 | // Try to inline the call. |
Jordan Rose | 28038f3 | 2012-07-10 22:07:42 +0000 | [diff] [blame] | 580 | // The origin expression here is just used as a kind of checksum; |
Jordan Rose | d563d3f | 2012-07-30 20:22:09 +0000 | [diff] [blame] | 581 | // this should still be safe even for CallEvents that don't come from exprs. |
| 582 | const Expr *E = Call->getOriginExpr(); |
| 583 | ProgramStateRef InlinedFailedState = getInlineFailedState(State, E); |
| 584 | |
| 585 | if (InlinedFailedState) { |
| 586 | // If we already tried once and failed, make sure we don't retry later. |
| 587 | State = InlinedFailedState; |
Anna Zaks | 5960f4a | 2012-08-09 18:43:00 +0000 | [diff] [blame] | 588 | } else { |
Anna Zaks | e90d3f8 | 2012-08-09 00:21:33 +0000 | [diff] [blame] | 589 | RuntimeDefinition RD = Call->getRuntimeDefinition(); |
Anna Zaks | fc05dec | 2012-08-09 02:57:02 +0000 | [diff] [blame] | 590 | const Decl *D = RD.getDecl(); |
Anna Zaks | e90d3f8 | 2012-08-09 00:21:33 +0000 | [diff] [blame] | 591 | if (D) { |
Jordan Rose | b763ede | 2012-08-15 00:52:00 +0000 | [diff] [blame] | 592 | if (RD.mayHaveOtherDefinitions()) { |
| 593 | // Explore with and without inlining the call. |
| 594 | if (getAnalysisManager().IPAMode == DynamicDispatchBifurcate) { |
| 595 | BifurcateCall(RD.getDispatchRegion(), *Call, D, Bldr, Pred); |
| 596 | return; |
| 597 | } |
| 598 | |
| 599 | // Don't inline if we're not in any dynamic dispatch mode. |
Jordan Rose | da29ac5 | 2012-08-15 21:05:15 +0000 | [diff] [blame] | 600 | if (getAnalysisManager().IPAMode != DynamicDispatch) { |
| 601 | conservativeEvalCall(*Call, Bldr, Pred, State); |
Jordan Rose | b763ede | 2012-08-15 00:52:00 +0000 | [diff] [blame] | 602 | return; |
Jordan Rose | da29ac5 | 2012-08-15 21:05:15 +0000 | [diff] [blame] | 603 | } |
Anna Zaks | e90d3f8 | 2012-08-09 00:21:33 +0000 | [diff] [blame] | 604 | } |
Jordan Rose | b763ede | 2012-08-15 00:52:00 +0000 | [diff] [blame] | 605 | |
Anna Zaks | 5960f4a | 2012-08-09 18:43:00 +0000 | [diff] [blame] | 606 | // We are not bifurcating and we do have a Decl, so just inline. |
| 607 | if (inlineCall(*Call, D, Bldr, Pred, State)) |
| 608 | return; |
Anna Zaks | e90d3f8 | 2012-08-09 00:21:33 +0000 | [diff] [blame] | 609 | } |
Anna Zaks | e81ce25 | 2012-07-19 23:38:13 +0000 | [diff] [blame] | 610 | } |
Jordan Rose | 69f87c9 | 2012-07-02 19:28:09 +0000 | [diff] [blame] | 611 | |
| 612 | // If we can't inline it, handle the return value and invalidate the regions. |
Anna Zaks | e90d3f8 | 2012-08-09 00:21:33 +0000 | [diff] [blame] | 613 | conservativeEvalCall(*Call, Bldr, Pred, State); |
Jordan Rose | 69f87c9 | 2012-07-02 19:28:09 +0000 | [diff] [blame] | 614 | } |
| 615 | |
Anna Zaks | e90d3f8 | 2012-08-09 00:21:33 +0000 | [diff] [blame] | 616 | void ExprEngine::BifurcateCall(const MemRegion *BifurReg, |
| 617 | const CallEvent &Call, const Decl *D, |
| 618 | NodeBuilder &Bldr, ExplodedNode *Pred) { |
| 619 | assert(BifurReg); |
Jordan Rose | b763ede | 2012-08-15 00:52:00 +0000 | [diff] [blame] | 620 | BifurReg = BifurReg->StripCasts(); |
Anna Zaks | e90d3f8 | 2012-08-09 00:21:33 +0000 | [diff] [blame] | 621 | |
| 622 | // Check if we've performed the split already - note, we only want |
| 623 | // to split the path once per memory region. |
| 624 | ProgramStateRef State = Pred->getState(); |
Anna Zaks | 6960f6e | 2012-08-09 21:02:41 +0000 | [diff] [blame] | 625 | const unsigned int *BState = |
| 626 | State->get<DynamicDispatchBifurcationMap>(BifurReg); |
Anna Zaks | 5960f4a | 2012-08-09 18:43:00 +0000 | [diff] [blame] | 627 | if (BState) { |
| 628 | // If we are on "inline path", keep inlining if possible. |
Anna Zaks | 6960f6e | 2012-08-09 21:02:41 +0000 | [diff] [blame] | 629 | if (*BState == DynamicDispatchModeInlined) |
Anna Zaks | 5960f4a | 2012-08-09 18:43:00 +0000 | [diff] [blame] | 630 | if (inlineCall(Call, D, Bldr, Pred, State)) |
| 631 | return; |
| 632 | // If inline failed, or we are on the path where we assume we |
| 633 | // don't have enough info about the receiver to inline, conjure the |
| 634 | // return value and invalidate the regions. |
| 635 | conservativeEvalCall(Call, Bldr, Pred, State); |
| 636 | return; |
Anna Zaks | e90d3f8 | 2012-08-09 00:21:33 +0000 | [diff] [blame] | 637 | } |
| 638 | |
| 639 | // If we got here, this is the first time we process a message to this |
| 640 | // region, so split the path. |
| 641 | ProgramStateRef IState = |
Anna Zaks | 6960f6e | 2012-08-09 21:02:41 +0000 | [diff] [blame] | 642 | State->set<DynamicDispatchBifurcationMap>(BifurReg, |
| 643 | DynamicDispatchModeInlined); |
Anna Zaks | e90d3f8 | 2012-08-09 00:21:33 +0000 | [diff] [blame] | 644 | inlineCall(Call, D, Bldr, Pred, IState); |
| 645 | |
| 646 | ProgramStateRef NoIState = |
Anna Zaks | 6960f6e | 2012-08-09 21:02:41 +0000 | [diff] [blame] | 647 | State->set<DynamicDispatchBifurcationMap>(BifurReg, |
| 648 | DynamicDispatchModeConservative); |
Anna Zaks | e90d3f8 | 2012-08-09 00:21:33 +0000 | [diff] [blame] | 649 | conservativeEvalCall(Call, Bldr, Pred, NoIState); |
| 650 | |
| 651 | NumOfDynamicDispatchPathSplits++; |
| 652 | return; |
| 653 | } |
| 654 | |
| 655 | |
Ted Kremenek | 294fd0a | 2011-08-20 06:00:03 +0000 | [diff] [blame] | 656 | void ExprEngine::VisitReturnStmt(const ReturnStmt *RS, ExplodedNode *Pred, |
| 657 | ExplodedNodeSet &Dst) { |
Ted Kremenek | 256ef64 | 2012-01-11 01:06:27 +0000 | [diff] [blame] | 658 | |
| 659 | ExplodedNodeSet dstPreVisit; |
| 660 | getCheckerManager().runCheckersForPreStmt(dstPreVisit, Pred, RS, *this); |
| 661 | |
Ted Kremenek | 66c486f | 2012-08-22 06:26:15 +0000 | [diff] [blame] | 662 | StmtNodeBuilder B(dstPreVisit, Dst, *currBldrCtx); |
Ted Kremenek | 256ef64 | 2012-01-11 01:06:27 +0000 | [diff] [blame] | 663 | |
| 664 | if (RS->getRetValue()) { |
| 665 | for (ExplodedNodeSet::iterator it = dstPreVisit.begin(), |
| 666 | ei = dstPreVisit.end(); it != ei; ++it) { |
| 667 | B.generateNode(RS, *it, (*it)->getState()); |
Ted Kremenek | 294fd0a | 2011-08-20 06:00:03 +0000 | [diff] [blame] | 668 | } |
Ted Kremenek | 294fd0a | 2011-08-20 06:00:03 +0000 | [diff] [blame] | 669 | } |
Ted Kremenek | 294fd0a | 2011-08-20 06:00:03 +0000 | [diff] [blame] | 670 | } |