blob: e065c5c410e67ee2f5364f212ec57bf496e14373 [file] [log] [blame]
Zhongxing Xu17892752008-10-08 02:50:44 +00001//== RegionStore.cpp - Field-sensitive store model --------------*- C++ -*--==//
2//
3// The LLVM Compiler Infrastructure
4//
5// This file is distributed under the University of Illinois Open Source
6// License. See LICENSE.TXT for details.
7//
8//===----------------------------------------------------------------------===//
9//
10// This file defines a basic region store model. In this model, we do have field
11// sensitivity. But we assume nothing about the heap shape. So recursive data
12// structures are largely ignored. Basically we do 1-limiting analysis.
13// Parameter pointers are assumed with no aliasing. Pointee objects of
14// parameters are created lazily.
15//
16//===----------------------------------------------------------------------===//
17#include "clang/Analysis/PathSensitive/MemRegion.h"
18#include "clang/Analysis/PathSensitive/GRState.h"
Zhongxing Xudc0a25d2008-11-16 04:07:26 +000019#include "clang/Analysis/PathSensitive/GRStateTrait.h"
Zhongxing Xu17892752008-10-08 02:50:44 +000020#include "clang/Analysis/Analyses/LiveVariables.h"
21
22#include "llvm/ADT/ImmutableMap.h"
Zhongxing Xudc0a25d2008-11-16 04:07:26 +000023#include "llvm/ADT/ImmutableList.h"
Zhongxing Xua071eb02008-10-24 06:01:33 +000024#include "llvm/Support/raw_ostream.h"
Zhongxing Xu17892752008-10-08 02:50:44 +000025#include "llvm/Support/Compiler.h"
26
27using namespace clang;
28
Zhongxing Xubaf03a72008-11-24 09:44:56 +000029// Actual Store type.
Zhongxing Xu1c96b242008-10-17 05:57:07 +000030typedef llvm::ImmutableMap<const MemRegion*, SVal> RegionBindingsTy;
Zhongxing Xubaf03a72008-11-24 09:44:56 +000031
32// RegionView GDM stuff.
Zhongxing Xudc0a25d2008-11-16 04:07:26 +000033typedef llvm::ImmutableList<const MemRegion*> RegionViewTy;
34typedef llvm::ImmutableMap<const MemRegion*, RegionViewTy> RegionViewMapTy;
Zhongxing Xudc0a25d2008-11-16 04:07:26 +000035static int RegionViewMapTyIndex = 0;
Zhongxing Xudc0a25d2008-11-16 04:07:26 +000036namespace clang {
37template<> struct GRStateTrait<RegionViewMapTy>
38 : public GRStatePartialTrait<RegionViewMapTy> {
39 static void* GDMIndex() { return &RegionViewMapTyIndex; }
40};
41}
Zhongxing Xu17892752008-10-08 02:50:44 +000042
Zhongxing Xubaf03a72008-11-24 09:44:56 +000043// RegionExtents GDM stuff.
44// Currently RegionExtents are in bytes. We can change this representation when
45// there are real requirements.
46typedef llvm::ImmutableMap<const MemRegion*, SVal> RegionExtentsTy;
47static int RegionExtentsTyIndex = 0;
48namespace clang {
49template<> struct GRStateTrait<RegionExtentsTy>
50 : public GRStatePartialTrait<RegionExtentsTy> {
51 static void* GDMIndex() { return &RegionExtentsTyIndex; }
52};
53}
54
Ted Kremenekc48ea6e2008-12-04 02:08:27 +000055// KillSet GDM stuff.
Ted Kremenek2ed14be2008-12-05 00:47:52 +000056typedef llvm::ImmutableSet<const MemRegion*> RegionKills;
57static int RegionKillsIndex = 0;
Ted Kremenekc48ea6e2008-12-04 02:08:27 +000058namespace clang {
Ted Kremenek2ed14be2008-12-05 00:47:52 +000059 template<> struct GRStateTrait<RegionKills>
60 : public GRStatePartialTrait<RegionKills> {
61 static void* GDMIndex() { return &RegionKillsIndex; }
Ted Kremenekc48ea6e2008-12-04 02:08:27 +000062 };
63}
64
65
Zhongxing Xu17892752008-10-08 02:50:44 +000066namespace {
67
68class VISIBILITY_HIDDEN RegionStoreManager : public StoreManager {
69 RegionBindingsTy::Factory RBFactory;
Zhongxing Xudc0a25d2008-11-16 04:07:26 +000070 RegionViewTy::Factory RVFactory;
Zhongxing Xudc0a25d2008-11-16 04:07:26 +000071
Zhongxing Xu17892752008-10-08 02:50:44 +000072 GRStateManager& StateMgr;
73 MemRegionManager MRMgr;
74
75public:
76 RegionStoreManager(GRStateManager& mgr)
Zhongxing Xudc0a25d2008-11-16 04:07:26 +000077 : RBFactory(mgr.getAllocator()),
78 RVFactory(mgr.getAllocator()),
Zhongxing Xudc0a25d2008-11-16 04:07:26 +000079 StateMgr(mgr),
80 MRMgr(StateMgr.getAllocator()) {}
Zhongxing Xu17892752008-10-08 02:50:44 +000081
82 virtual ~RegionStoreManager() {}
83
Zhongxing Xu24194ef2008-10-24 01:38:55 +000084 MemRegionManager& getRegionManager() { return MRMgr; }
Ted Kremenek4f090272008-10-27 21:54:31 +000085
Zhongxing Xuf22679e2008-11-07 10:38:33 +000086 Store BindCompoundLiteral(Store store, const CompoundLiteralExpr* CL, SVal V);
Zhongxing Xu24194ef2008-10-24 01:38:55 +000087
Zhongxing Xu143bf822008-10-25 14:18:57 +000088 SVal getLValueString(const GRState* St, const StringLiteral* S);
89
Zhongxing Xuf22679e2008-11-07 10:38:33 +000090 SVal getLValueCompoundLiteral(const GRState* St, const CompoundLiteralExpr*);
91
Zhongxing Xuc4bf72c2008-10-22 13:44:38 +000092 SVal getLValueVar(const GRState* St, const VarDecl* VD);
93
94 SVal getLValueIvar(const GRState* St, const ObjCIvarDecl* D, SVal Base);
95
96 SVal getLValueField(const GRState* St, SVal Base, const FieldDecl* D);
97
Zhongxing Xub1d542a2008-10-24 01:09:32 +000098 SVal getLValueElement(const GRState* St, SVal Base, SVal Offset);
99
Zhongxing Xue8a964b2008-11-22 13:21:46 +0000100 SVal getSizeInElements(const GRState* St, const MemRegion* R);
101
Zhongxing Xub1d542a2008-10-24 01:09:32 +0000102 SVal ArrayToPointer(SVal Array);
103
Zhongxing Xucb529b52008-11-16 07:06:26 +0000104 std::pair<const GRState*, SVal>
105 CastRegion(const GRState* St, SVal VoidPtr, QualType CastToTy, Stmt* CastE);
Zhongxing Xudc0a25d2008-11-16 04:07:26 +0000106
Ted Kremenek2ed14be2008-12-05 00:47:52 +0000107 SVal Retrieve(const GRState* state, Loc L, QualType T = QualType());
Zhongxing Xuc4bf72c2008-10-22 13:44:38 +0000108
Zhongxing Xu8485ec62008-10-21 06:27:32 +0000109 Store Bind(Store St, Loc LV, SVal V);
Zhongxing Xu17892752008-10-08 02:50:44 +0000110
Zhongxing Xu24194ef2008-10-24 01:38:55 +0000111 Store Remove(Store store, Loc LV) {
112 // FIXME: Implement.
113 return store;
114 }
115
Zhongxing Xu17892752008-10-08 02:50:44 +0000116 Store getInitialStore();
Ted Kremenek9deb0e32008-10-24 20:32:16 +0000117
118 /// getSelfRegion - Returns the region for the 'self' (Objective-C) or
119 /// 'this' object (C++). When used when analyzing a normal function this
120 /// method returns NULL.
121 const MemRegion* getSelfRegion(Store) {
122 assert (false && "Not implemented.");
123 return 0;
124 }
Ted Kremenekc48ea6e2008-12-04 02:08:27 +0000125
Ted Kremenek2ed14be2008-12-05 00:47:52 +0000126 /// RemoveDeadBindings - Scans the RegionStore of 'state' for dead values.
127 /// It returns a new Store with these values removed, and populates LSymbols
128 // and DSymbols with the known set of live and dead symbols respectively.
129 Store RemoveDeadBindings(const GRState* state, Stmt* Loc,
130 const LiveVariables& Live,
Zhongxing Xu24194ef2008-10-24 01:38:55 +0000131 llvm::SmallVectorImpl<const MemRegion*>& RegionRoots,
Zhongxing Xu8916d5b2008-11-10 09:39:04 +0000132 LiveSymbolsTy& LSymbols, DeadSymbolsTy& DSymbols);
Ted Kremenek2ed14be2008-12-05 00:47:52 +0000133
Ted Kremenekc48ea6e2008-12-04 02:08:27 +0000134 void UpdateLiveSymbols(SVal X, LiveSymbolsTy& LSymbols);
Zhongxing Xu24194ef2008-10-24 01:38:55 +0000135
Ted Kremenek42577d12008-11-12 19:18:35 +0000136 Store BindDecl(Store store, const VarDecl* VD, SVal* InitVal, unsigned Count);
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000137
Zhongxing Xubaf03a72008-11-24 09:44:56 +0000138 const GRState* setExtent(const GRState* St, const MemRegion* R, SVal Extent);
139
Zhongxing Xu17892752008-10-08 02:50:44 +0000140 static inline RegionBindingsTy GetRegionBindings(Store store) {
Ted Kremenek2ed14be2008-12-05 00:47:52 +0000141 return RegionBindingsTy(static_cast<const RegionBindingsTy::TreeTy*>(store));
Zhongxing Xu17892752008-10-08 02:50:44 +0000142 }
Zhongxing Xu24194ef2008-10-24 01:38:55 +0000143
Zhongxing Xu5b8b6f22008-10-24 04:33:15 +0000144 void print(Store store, std::ostream& Out, const char* nl, const char *sep);
Zhongxing Xu24194ef2008-10-24 01:38:55 +0000145
146 void iterBindings(Store store, BindingsHandler& f) {
147 // FIXME: Implement.
148 }
Zhongxing Xua82512a2008-10-24 08:42:28 +0000149
150private:
151 Loc getVarLoc(const VarDecl* VD) {
152 return loc::MemRegionVal(MRMgr.getVarRegion(VD));
153 }
154
Zhongxing Xud463d442008-11-02 12:13:30 +0000155 Store InitializeArray(Store store, const TypedRegion* R, SVal Init);
156 Store BindArrayToVal(Store store, const TypedRegion* BaseR, SVal V);
Zhongxing Xuc3a05992008-11-19 11:06:24 +0000157 Store BindArrayToSymVal(Store store, const TypedRegion* BaseR);
158
Zhongxing Xud463d442008-11-02 12:13:30 +0000159 Store InitializeStruct(Store store, const TypedRegion* R, SVal Init);
160 Store BindStructToVal(Store store, const TypedRegion* BaseR, SVal V);
Zhongxing Xuc3a05992008-11-19 11:06:24 +0000161 Store BindStructToSymVal(Store store, const TypedRegion* BaseR);
Zhongxing Xu6e3f01c2008-10-31 07:16:08 +0000162
Zhongxing Xu0b242ec2008-12-04 01:12:41 +0000163 /// Retrieve the values in a struct and return a CompoundVal, used when doing
164 /// struct copy:
165 /// struct s x, y;
166 /// x = y;
167 /// y's value is retrieved by this method.
Zhongxing Xu6e3f01c2008-10-31 07:16:08 +0000168 SVal RetrieveStruct(Store store, const TypedRegion* R);
Zhongxing Xu0b242ec2008-12-04 01:12:41 +0000169
Zhongxing Xuf0dfa8d2008-10-31 08:10:01 +0000170 Store BindStruct(Store store, const TypedRegion* R, SVal V);
Zhongxing Xu63123d82008-11-23 04:30:35 +0000171
Zhongxing Xu6e3f01c2008-10-31 07:16:08 +0000172 // Utility methods.
173 BasicValueFactory& getBasicVals() { return StateMgr.getBasicVals(); }
174 ASTContext& getContext() { return StateMgr.getContext(); }
Zhongxing Xu63123d82008-11-23 04:30:35 +0000175 SymbolManager& getSymbolManager() { return StateMgr.getSymbolManager(); }
Zhongxing Xudc0a25d2008-11-16 04:07:26 +0000176
177 const GRState* AddRegionView(const GRState* St,
178 const MemRegion* View, const MemRegion* Base);
Zhongxing Xu17892752008-10-08 02:50:44 +0000179};
180
181} // end anonymous namespace
182
Ted Kremenek95c7b002008-10-24 01:04:59 +0000183StoreManager* clang::CreateRegionStoreManager(GRStateManager& StMgr) {
Zhongxing Xu24194ef2008-10-24 01:38:55 +0000184 return new RegionStoreManager(StMgr);
Ted Kremenek95c7b002008-10-24 01:04:59 +0000185}
186
Zhongxing Xu143bf822008-10-25 14:18:57 +0000187SVal RegionStoreManager::getLValueString(const GRState* St,
188 const StringLiteral* S) {
189 return loc::MemRegionVal(MRMgr.getStringRegion(S));
190}
191
Zhongxing Xuc4bf72c2008-10-22 13:44:38 +0000192SVal RegionStoreManager::getLValueVar(const GRState* St, const VarDecl* VD) {
193 return loc::MemRegionVal(MRMgr.getVarRegion(VD));
194}
Zhongxing Xuf22679e2008-11-07 10:38:33 +0000195
196SVal RegionStoreManager::getLValueCompoundLiteral(const GRState* St,
197 const CompoundLiteralExpr* CL) {
198 return loc::MemRegionVal(MRMgr.getCompoundLiteralRegion(CL));
199}
200
Zhongxing Xuc4bf72c2008-10-22 13:44:38 +0000201SVal RegionStoreManager::getLValueIvar(const GRState* St, const ObjCIvarDecl* D,
202 SVal Base) {
203 return UnknownVal();
204}
205
206SVal RegionStoreManager::getLValueField(const GRState* St, SVal Base,
207 const FieldDecl* D) {
208 if (Base.isUnknownOrUndef())
209 return Base;
210
211 Loc BaseL = cast<Loc>(Base);
212 const MemRegion* BaseR = 0;
213
214 switch (BaseL.getSubKind()) {
215 case loc::MemRegionKind:
216 BaseR = cast<loc::MemRegionVal>(BaseL).getRegion();
217 break;
218
219 case loc::SymbolValKind:
220 BaseR = MRMgr.getSymbolicRegion(cast<loc::SymbolVal>(&BaseL)->getSymbol());
221 break;
222
223 case loc::GotoLabelKind:
224 case loc::FuncValKind:
225 // These are anormal cases. Flag an undefined value.
226 return UndefinedVal();
227
228 case loc::ConcreteIntKind:
Zhongxing Xuc4bf72c2008-10-22 13:44:38 +0000229 // While these seem funny, this can happen through casts.
230 // FIXME: What we should return is the field offset. For example,
231 // add the field offset to the integer value. That way funny things
232 // like this work properly: &(((struct foo *) 0xa)->f)
233 return Base;
234
235 default:
Zhongxing Xu13d1ee22008-11-07 08:57:30 +0000236 assert(0 && "Unhandled Base.");
Zhongxing Xuc4bf72c2008-10-22 13:44:38 +0000237 return Base;
238 }
239
240 return loc::MemRegionVal(MRMgr.getFieldRegion(D, BaseR));
241}
242
Zhongxing Xub1d542a2008-10-24 01:09:32 +0000243SVal RegionStoreManager::getLValueElement(const GRState* St,
244 SVal Base, SVal Offset) {
245 if (Base.isUnknownOrUndef())
246 return Base;
247
Zhongxing Xu4a1513e2008-10-27 12:23:17 +0000248 if (isa<loc::SymbolVal>(Base))
249 return Base;
250
Zhongxing Xub1d542a2008-10-24 01:09:32 +0000251 loc::MemRegionVal& BaseL = cast<loc::MemRegionVal>(Base);
252
Zhongxing Xue4d13932008-11-13 09:48:44 +0000253 // Pointer of any type can be cast and used as array base. We do not support
254 // that case yet.
255 if (!isa<ElementRegion>(BaseL.getRegion())) {
256 // Record what we have seen in real code.
257 assert(isa<FieldRegion>(BaseL.getRegion()));
258 return UnknownVal();
259 }
260
Zhongxing Xub1d542a2008-10-24 01:09:32 +0000261 // We expect BaseR is an ElementRegion, not a base VarRegion.
262
263 const ElementRegion* ElemR = cast<ElementRegion>(BaseL.getRegion());
264
265 SVal Idx = ElemR->getIndex();
266
267 nonloc::ConcreteInt *CI1, *CI2;
268
269 // Only handle integer indices for now.
270 if ((CI1 = dyn_cast<nonloc::ConcreteInt>(&Idx)) &&
271 (CI2 = dyn_cast<nonloc::ConcreteInt>(&Offset))) {
Zhongxing Xucc0d0ec2008-11-13 09:15:14 +0000272
Sebastian Redle95db4f2008-11-24 19:35:33 +0000273 // Temporary SVal to hold a potential signed and extended APSInt.
Zhongxing Xucc0d0ec2008-11-13 09:15:14 +0000274 SVal SignedInt;
275
Sebastian Redle95db4f2008-11-24 19:35:33 +0000276 // Index might be unsigned. We have to convert it to signed. It might also
277 // be less wide than the size. We have to extend it.
278 if (CI2->getValue().isUnsigned() ||
279 CI2->getValue().getBitWidth() < CI1->getValue().getBitWidth()) {
Zhongxing Xucc0d0ec2008-11-13 09:15:14 +0000280 llvm::APSInt SI = CI2->getValue();
Sebastian Redlddee68b2008-11-24 19:39:40 +0000281 if (CI2->getValue().getBitWidth() < CI1->getValue().getBitWidth())
282 SI.extend(CI1->getValue().getBitWidth());
Zhongxing Xucc0d0ec2008-11-13 09:15:14 +0000283 SI.setIsSigned(true);
284 SignedInt = nonloc::ConcreteInt(getBasicVals().getValue(SI));
285 CI2 = cast<nonloc::ConcreteInt>(&SignedInt);
286 }
287
Zhongxing Xu63123d82008-11-23 04:30:35 +0000288 SVal NewIdx = CI1->EvalBinOp(getBasicVals(), BinaryOperator::Add, *CI2);
Zhongxing Xub1d542a2008-10-24 01:09:32 +0000289 return loc::MemRegionVal(MRMgr.getElementRegion(NewIdx,
290 ElemR->getSuperRegion()));
291 }
292
293 return UnknownVal();
294}
295
Zhongxing Xue8a964b2008-11-22 13:21:46 +0000296SVal RegionStoreManager::getSizeInElements(const GRState* St,
297 const MemRegion* R) {
298 if (const VarRegion* VR = dyn_cast<VarRegion>(R)) {
299 // Get the type of the variable.
300 QualType T = VR->getType(getContext());
301
302 // It must be of array type.
303 const ConstantArrayType* CAT = cast<ConstantArrayType>(T.getTypePtr());
304
305 // return the size as signed integer.
306 return NonLoc::MakeVal(getBasicVals(), CAT->getSize(), false);
307 }
308
309 if (const StringRegion* SR = dyn_cast<StringRegion>(R)) {
Zhongxing Xu6613d082008-11-24 02:18:56 +0000310 const StringLiteral* Str = SR->getStringLiteral();
Zhongxing Xud0fd3b72008-11-24 02:30:48 +0000311 // We intentionally made the size value signed because it participates in
312 // operations with signed indices.
Zhongxing Xu4b89e032008-11-24 05:16:01 +0000313 return NonLoc::MakeVal(getBasicVals(), Str->getByteLength() + 1, false);
Zhongxing Xue8a964b2008-11-22 13:21:46 +0000314 }
315
316 if (const AnonTypedRegion* ATR = dyn_cast<AnonTypedRegion>(R)) {
Zhongxing Xubaf03a72008-11-24 09:44:56 +0000317 GRStateRef state(St, StateMgr);
318
319 // Get the size of the super region in bytes.
320 RegionExtentsTy::data_type* T
321 = state.get<RegionExtentsTy>(ATR->getSuperRegion());
322
323 assert(T && "region extent not exist");
324
325 // Assume it's ConcreteInt for now.
326 llvm::APSInt SSize = cast<nonloc::ConcreteInt>(*T).getValue();
327
328 // Get the size of the element in bits.
329 QualType ElemTy = cast<PointerType>(ATR->getType(getContext()).getTypePtr())
330 ->getPointeeType();
331
332 uint64_t X = getContext().getTypeSize(ElemTy);
333
334 const llvm::APSInt& ESize = getBasicVals().getValue(X, SSize.getBitWidth(),
335 false);
336
337 // Calculate the number of elements.
338
339 // FIXME: What do we do with signed-ness problem? Shall we make all APSInts
340 // signed?
341 if (SSize.isUnsigned())
342 SSize.setIsSigned(true);
343
344 // FIXME: move this operation into BasicVals.
345 const llvm::APSInt S =
346 (SSize * getBasicVals().getValue(8, SSize.getBitWidth(), false)) / ESize;
347
348 return NonLoc::MakeVal(getBasicVals(), S);
Zhongxing Xue8a964b2008-11-22 13:21:46 +0000349 }
350
351 if (const FieldRegion* FR = dyn_cast<FieldRegion>(R)) {
352 // FIXME: Unsupported yet.
353 FR = 0;
354 return UnknownVal();
355 }
Zhongxing Xu369f4292008-11-22 13:23:00 +0000356
Zhongxing Xue8a964b2008-11-22 13:21:46 +0000357 assert(0 && "Other regions are not supported yet.");
358}
359
Zhongxing Xub1d542a2008-10-24 01:09:32 +0000360// Cast 'pointer to array' to 'pointer to the first element of array'.
361
362SVal RegionStoreManager::ArrayToPointer(SVal Array) {
363 const MemRegion* ArrayR = cast<loc::MemRegionVal>(&Array)->getRegion();
Zhongxing Xu143bf822008-10-25 14:18:57 +0000364
Zhongxing Xu63123d82008-11-23 04:30:35 +0000365 nonloc::ConcreteInt Idx(getBasicVals().getZeroWithPtrWidth(false));
Zhongxing Xu0b7e6422008-10-26 02:23:57 +0000366 ElementRegion* ER = MRMgr.getElementRegion(Idx, ArrayR);
367
368 return loc::MemRegionVal(ER);
Zhongxing Xub1d542a2008-10-24 01:09:32 +0000369}
370
Zhongxing Xucb529b52008-11-16 07:06:26 +0000371std::pair<const GRState*, SVal>
372RegionStoreManager::CastRegion(const GRState* St, SVal VoidPtr,
373 QualType CastToTy, Stmt* CastE) {
Zhongxing Xudc0a25d2008-11-16 04:07:26 +0000374 if (const AllocaRegion* AR =
375 dyn_cast<AllocaRegion>(cast<loc::MemRegionVal>(VoidPtr).getRegion())) {
376
377 // Create a new region to attach type information to it.
378 const AnonTypedRegion* TR = MRMgr.getAnonTypedRegion(CastToTy, AR);
379
380 // Get the pointer to the first element.
381 nonloc::ConcreteInt Idx(getBasicVals().getZeroWithPtrWidth(false));
382 const ElementRegion* ER = MRMgr.getElementRegion(Idx, TR);
383
Zhongxing Xudc0a25d2008-11-16 04:07:26 +0000384 // Add a RegionView to base region.
Zhongxing Xu353cbe12008-11-28 03:55:52 +0000385 return std::make_pair(AddRegionView(St, TR, AR), loc::MemRegionVal(ER));
Zhongxing Xudc0a25d2008-11-16 04:07:26 +0000386 }
387
388 // Default case.
Zhongxing Xu353cbe12008-11-28 03:55:52 +0000389 return std::make_pair(St, UnknownVal());
Zhongxing Xudc0a25d2008-11-16 04:07:26 +0000390}
391
Ted Kremenek2ed14be2008-12-05 00:47:52 +0000392SVal RegionStoreManager::Retrieve(const GRState* state, Loc L, QualType T) {
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000393 assert(!isa<UnknownVal>(L) && "location unknown");
394 assert(!isa<UndefinedVal>(L) && "location undefined");
Ted Kremenek2ed14be2008-12-05 00:47:52 +0000395 Store S = state->getStore();
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000396
397 switch (L.getSubKind()) {
398 case loc::MemRegionKind: {
399 const MemRegion* R = cast<loc::MemRegionVal>(L).getRegion();
400 assert(R && "bad region");
401
Zhongxing Xu6e3f01c2008-10-31 07:16:08 +0000402 if (const TypedRegion* TR = dyn_cast<TypedRegion>(R))
403 if (TR->getType(getContext())->isStructureType())
404 return RetrieveStruct(S, TR);
405
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000406 RegionBindingsTy B(static_cast<const RegionBindingsTy::TreeTy*>(S));
407 RegionBindingsTy::data_type* V = B.lookup(R);
408 return V ? *V : UnknownVal();
409 }
410
411 case loc::SymbolValKind:
412 return UnknownVal();
413
414 case loc::ConcreteIntKind:
415 return UndefinedVal(); // As in BasicStoreManager.
416
417 case loc::FuncValKind:
418 return L;
419
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000420 default:
421 assert(false && "Invalid Location");
Ted Kremenekab7b32b2008-11-19 00:27:37 +0000422 return L;
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000423 }
424}
425
Zhongxing Xu6e3f01c2008-10-31 07:16:08 +0000426SVal RegionStoreManager::RetrieveStruct(Store store, const TypedRegion* R) {
427 QualType T = R->getType(getContext());
428 assert(T->isStructureType());
429
430 const RecordType* RT = cast<RecordType>(T.getTypePtr());
431 RecordDecl* RD = RT->getDecl();
432 assert(RD->isDefinition());
433
434 llvm::ImmutableList<SVal> StructVal = getBasicVals().getEmptySValList();
435
Douglas Gregore267ff32008-12-11 20:41:00 +0000436 std::vector<FieldDecl *> Fields(RD->field_begin(), RD->field_end());
Douglas Gregor44b43212008-12-11 16:49:14 +0000437
Douglas Gregore267ff32008-12-11 20:41:00 +0000438 for (std::vector<FieldDecl *>::reverse_iterator Field = Fields.rbegin(),
439 FieldEnd = Fields.rend();
440 Field != FieldEnd; ++Field) {
441 FieldRegion* FR = MRMgr.getFieldRegion(*Field, R);
Zhongxing Xu6e3f01c2008-10-31 07:16:08 +0000442 RegionBindingsTy B(static_cast<const RegionBindingsTy::TreeTy*>(store));
Zhongxing Xuf0dfa8d2008-10-31 08:10:01 +0000443 RegionBindingsTy::data_type* data = B.lookup(FR);
Zhongxing Xu6e3f01c2008-10-31 07:16:08 +0000444
445 SVal FieldValue = data ? *data : UnknownVal();
446
447 StructVal = getBasicVals().consVals(FieldValue, StructVal);
448 }
449
450 return NonLoc::MakeCompoundVal(T, StructVal, getBasicVals());
451}
452
Zhongxing Xu8485ec62008-10-21 06:27:32 +0000453Store RegionStoreManager::Bind(Store store, Loc LV, SVal V) {
Zhongxing Xu8fe63af2008-10-27 09:24:07 +0000454 if (LV.getSubKind() == loc::SymbolValKind)
455 return store;
456
Zhongxing Xu1c96b242008-10-17 05:57:07 +0000457 assert(LV.getSubKind() == loc::MemRegionKind);
Zhongxing Xu17892752008-10-08 02:50:44 +0000458
Ted Kremenek993f1c72008-10-17 20:28:54 +0000459 const MemRegion* R = cast<loc::MemRegionVal>(LV).getRegion();
Zhongxing Xu17892752008-10-08 02:50:44 +0000460
Zhongxing Xuf0dfa8d2008-10-31 08:10:01 +0000461 assert(R);
462
463 if (const TypedRegion* TR = dyn_cast<TypedRegion>(R))
464 if (TR->getType(getContext())->isStructureType())
465 return BindStruct(store, TR, V);
Zhongxing Xu17892752008-10-08 02:50:44 +0000466
467 RegionBindingsTy B = GetRegionBindings(store);
468 return V.isUnknown()
469 ? RBFactory.Remove(B, R).getRoot()
470 : RBFactory.Add(B, R, V).getRoot();
471}
472
Zhongxing Xuf0dfa8d2008-10-31 08:10:01 +0000473Store RegionStoreManager::BindStruct(Store store, const TypedRegion* R, SVal V){
474 QualType T = R->getType(getContext());
475 assert(T->isStructureType());
476
477 const RecordType* RT = cast<RecordType>(T.getTypePtr());
478 RecordDecl* RD = RT->getDecl();
Zhongxing Xua4f28ff2008-11-13 08:41:36 +0000479
480 if (!RD->isDefinition()) {
Zhongxing Xuc3a05992008-11-19 11:06:24 +0000481 // This can only occur when a pointer of incomplete struct type is used as a
Zhongxing Xua4f28ff2008-11-13 08:41:36 +0000482 // function argument.
483 assert(V.isUnknown());
484 return store;
485 }
Zhongxing Xuf0dfa8d2008-10-31 08:10:01 +0000486
487 RegionBindingsTy B = GetRegionBindings(store);
488
Zhongxing Xud463d442008-11-02 12:13:30 +0000489 if (isa<UnknownVal>(V))
490 return BindStructToVal(store, R, UnknownVal());
491
Zhongxing Xuf0dfa8d2008-10-31 08:10:01 +0000492 nonloc::CompoundVal& CV = cast<nonloc::CompoundVal>(V);
493
494 nonloc::CompoundVal::iterator VI = CV.begin(), VE = CV.end();
495 RecordDecl::field_iterator FI = RD->field_begin(), FE = RD->field_end();
496
497 for (; FI != FE; ++FI, ++VI) {
498 assert(VI != VE);
499
500 FieldRegion* FR = MRMgr.getFieldRegion(*FI, R);
501
502 B = RBFactory.Add(B, FR, *VI);
503 }
504
505 return B.getRoot();
506}
507
Zhongxing Xu17892752008-10-08 02:50:44 +0000508Store RegionStoreManager::getInitialStore() {
509 typedef LiveVariables::AnalysisDataTy LVDataTy;
510 LVDataTy& D = StateMgr.getLiveVariables().getAnalysisData();
511
512 Store St = RBFactory.GetEmptyMap().getRoot();
513
514 for (LVDataTy::decl_iterator I=D.begin_decl(), E=D.end_decl(); I != E; ++I) {
Douglas Gregor8e9bebd2008-10-21 16:13:35 +0000515 NamedDecl* ND = const_cast<NamedDecl*>(I->first);
Zhongxing Xu17892752008-10-08 02:50:44 +0000516
Douglas Gregor8e9bebd2008-10-21 16:13:35 +0000517 if (VarDecl* VD = dyn_cast<VarDecl>(ND)) {
Zhongxing Xu17892752008-10-08 02:50:44 +0000518 // Punt on static variables for now.
519 if (VD->getStorageClass() == VarDecl::Static)
520 continue;
521
Zhongxing Xuc3a05992008-11-19 11:06:24 +0000522 VarRegion* VR = MRMgr.getVarRegion(VD);
523
Zhongxing Xu17892752008-10-08 02:50:44 +0000524 QualType T = VD->getType();
525 // Only handle pointers and integers for now.
Zhongxing Xu1c96b242008-10-17 05:57:07 +0000526 if (Loc::IsLocType(T) || T->isIntegerType()) {
Zhongxing Xu17892752008-10-08 02:50:44 +0000527 // Initialize globals and parameters to symbolic values.
528 // Initialize local variables to undefined.
Zhongxing Xu1c96b242008-10-17 05:57:07 +0000529 SVal X = (VD->hasGlobalStorage() || isa<ParmVarDecl>(VD) ||
Zhongxing Xu17892752008-10-08 02:50:44 +0000530 isa<ImplicitParamDecl>(VD))
Zhongxing Xu63123d82008-11-23 04:30:35 +0000531 ? SVal::GetSymbolValue(getSymbolManager(), VD)
Zhongxing Xu17892752008-10-08 02:50:44 +0000532 : UndefinedVal();
533
Zhongxing Xu8485ec62008-10-21 06:27:32 +0000534 St = Bind(St, getVarLoc(VD), X);
Zhongxing Xuc3a05992008-11-19 11:06:24 +0000535 }
536 else if (T->isArrayType()) {
537 if (VD->hasGlobalStorage()) // Params cannot have array type.
538 St = BindArrayToSymVal(St, VR);
539 else
540 St = BindArrayToVal(St, VR, UndefinedVal());
541 }
542 else if (T->isStructureType()) {
543 if (VD->hasGlobalStorage() || isa<ParmVarDecl>(VD) ||
544 isa<ImplicitParamDecl>(VD))
545 St = BindStructToSymVal(St, VR);
546 else
547 St = BindStructToVal(St, VR, UndefinedVal());
Zhongxing Xu17892752008-10-08 02:50:44 +0000548 }
549 }
550 }
551 return St;
552}
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000553
Ted Kremenek42577d12008-11-12 19:18:35 +0000554Store RegionStoreManager::BindDecl(Store store, const VarDecl* VD,
555 SVal* InitVal, unsigned Count) {
556
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000557 if (VD->hasGlobalStorage()) {
558 // Static global variables should not be visited here.
559 assert(!(VD->getStorageClass() == VarDecl::Static &&
560 VD->isFileVarDecl()));
561 // Process static variables.
562 if (VD->getStorageClass() == VarDecl::Static) {
Ted Kremenek42577d12008-11-12 19:18:35 +0000563 if (!InitVal) {
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000564 // Only handle pointer and integer static variables.
565
566 QualType T = VD->getType();
567
568 if (Loc::IsLocType(T))
Zhongxing Xu8485ec62008-10-21 06:27:32 +0000569 store = Bind(store, getVarLoc(VD),
Zhongxing Xu63123d82008-11-23 04:30:35 +0000570 loc::ConcreteInt(getBasicVals().getValue(0, T)));
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000571
572 else if (T->isIntegerType())
Zhongxing Xu8485ec62008-10-21 06:27:32 +0000573 store = Bind(store, getVarLoc(VD),
Zhongxing Xu63123d82008-11-23 04:30:35 +0000574 loc::ConcreteInt(getBasicVals().getValue(0, T)));
Zhongxing Xu1a12a0e2008-10-31 10:24:47 +0000575
576 // Other types of static local variables are not handled yet.
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000577 } else {
Ted Kremenek42577d12008-11-12 19:18:35 +0000578 store = Bind(store, getVarLoc(VD), *InitVal);
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000579 }
580 }
581 } else {
582 // Process local variables.
583
584 QualType T = VD->getType();
585
Zhongxing Xua82512a2008-10-24 08:42:28 +0000586 VarRegion* VR = MRMgr.getVarRegion(VD);
587
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000588 if (Loc::IsLocType(T) || T->isIntegerType()) {
Ted Kremenek42577d12008-11-12 19:18:35 +0000589 SVal V = InitVal ? *InitVal : UndefinedVal();
Zhongxing Xua82512a2008-10-24 08:42:28 +0000590 store = Bind(store, loc::MemRegionVal(VR), V);
Ted Kremenek42577d12008-11-12 19:18:35 +0000591 }
592 else if (T->isArrayType()) {
593 if (!InitVal)
Zhongxing Xud463d442008-11-02 12:13:30 +0000594 store = BindArrayToVal(store, VR, UndefinedVal());
Zhongxing Xu1a12a0e2008-10-31 10:24:47 +0000595 else
Ted Kremenek42577d12008-11-12 19:18:35 +0000596 store = InitializeArray(store, VR, *InitVal);
597 }
598 else if (T->isStructureType()) {
599 if (!InitVal)
Zhongxing Xud463d442008-11-02 12:13:30 +0000600 store = BindStructToVal(store, VR, UndefinedVal());
Zhongxing Xuaf0a8442008-10-31 10:53:01 +0000601 else
Ted Kremenek42577d12008-11-12 19:18:35 +0000602 store = InitializeStruct(store, VR, *InitVal);
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000603 }
Zhongxing Xu1a12a0e2008-10-31 10:24:47 +0000604
605 // Other types of local variables are not handled yet.
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000606 }
607 return store;
608}
609
Zhongxing Xuf22679e2008-11-07 10:38:33 +0000610Store RegionStoreManager::BindCompoundLiteral(Store store,
611 const CompoundLiteralExpr* CL,
612 SVal V) {
613 CompoundLiteralRegion* R = MRMgr.getCompoundLiteralRegion(CL);
614 store = Bind(store, loc::MemRegionVal(R), V);
615 return store;
616}
617
Zhongxing Xubaf03a72008-11-24 09:44:56 +0000618const GRState* RegionStoreManager::setExtent(const GRState* St,
619 const MemRegion* R, SVal Extent) {
620 GRStateRef state(St, StateMgr);
621 return state.set<RegionExtentsTy>(R, Extent);
622}
623
624
Ted Kremenekc48ea6e2008-12-04 02:08:27 +0000625void RegionStoreManager::UpdateLiveSymbols(SVal X, LiveSymbolsTy& LSymbols) {
626 for (SVal::symbol_iterator SI=X.symbol_begin(),SE=X.symbol_end();SI!=SE;++SI)
627 LSymbols.insert(*SI);
628}
629
Ted Kremenek2ed14be2008-12-05 00:47:52 +0000630Store RegionStoreManager::RemoveDeadBindings(const GRState* state, Stmt* Loc,
Zhongxing Xu8916d5b2008-11-10 09:39:04 +0000631 const LiveVariables& Live,
632 llvm::SmallVectorImpl<const MemRegion*>& RegionRoots,
633 LiveSymbolsTy& LSymbols, DeadSymbolsTy& DSymbols) {
634
Ted Kremenek2ed14be2008-12-05 00:47:52 +0000635 Store store = state->getStore();
Zhongxing Xu8916d5b2008-11-10 09:39:04 +0000636 RegionBindingsTy B = GetRegionBindings(store);
Ted Kremenekc48ea6e2008-12-04 02:08:27 +0000637
638 // Lazily constructed backmap from MemRegions to SubRegions.
639 typedef llvm::ImmutableSet<const MemRegion*> SubRegionsTy;
640 typedef llvm::ImmutableMap<const MemRegion*, SubRegionsTy> SubRegionsMapTy;
641
642 // FIXME: As a future optimization we can modifiy BumpPtrAllocator to have
643 // the ability to reuse memory. This way we can keep TmpAlloc around as
644 // an instance variable of RegionStoreManager (avoiding repeated malloc
645 // overhead).
646 llvm::BumpPtrAllocator TmpAlloc;
647
648 // Factory objects.
649 SubRegionsMapTy::Factory SubRegMapF(TmpAlloc);
650 SubRegionsTy::Factory SubRegF(TmpAlloc);
651
652 // The backmap from regions to subregions.
653 SubRegionsMapTy SubRegMap = SubRegMapF.GetEmptyMap();
654
655 // Do a pass over the regions in the store. For VarRegions we check if
656 // the variable is still live and if so add it to the list of live roots.
657 // For other regions we populate our region backmap.
Zhongxing Xu8916d5b2008-11-10 09:39:04 +0000658 for (RegionBindingsTy::iterator I = B.begin(), E = B.end(); I != E; ++I) {
Ted Kremenekc48ea6e2008-12-04 02:08:27 +0000659 const MemRegion* R = I.getKey();
660 if (const VarRegion* VR = dyn_cast<VarRegion>(R)) {
661 if (Live.isLive(Loc, VR->getDecl()))
662 RegionRoots.push_back(VR); // This is a live "root".
663 }
664 else {
665 // Get the super region for R.
666 const MemRegion* SuperR = cast<SubRegion>(R)->getSuperRegion();
667 // Get the current set of subregions for SuperR.
668 const SubRegionsTy* SRptr = SubRegMap.lookup(SuperR);
669 SubRegionsTy SR = SRptr ? *SRptr : SubRegF.GetEmptySet();
670 // Add R to the subregions of SuperR.
671 SubRegMap = SubRegMapF.Add(SubRegMap, SuperR, SubRegF.Add(SR, R));
672
673 // Finally, check if SuperR is a VarRegion. We need to do this
674 // to also mark SuperR as a root (as it may not have a value directly
675 // bound to it in the store).
676 if (const VarRegion* VR = dyn_cast<VarRegion>(SuperR)) {
677 if (Live.isLive(Loc, VR->getDecl()))
678 RegionRoots.push_back(VR); // This is a live "root".
679 }
680 }
Zhongxing Xu8916d5b2008-11-10 09:39:04 +0000681 }
Ted Kremenekc48ea6e2008-12-04 02:08:27 +0000682
683 // Process the worklist of RegionRoots. This performs a "mark-and-sweep"
684 // of the store. We want to find all live symbols and dead regions.
685 llvm::SmallPtrSet<const MemRegion*, 10> Marked;
686
687 while (!RegionRoots.empty()) {
688 // Dequeue the next region on the worklist.
689 const MemRegion* R = RegionRoots.back();
690 RegionRoots.pop_back();
Zhongxing Xu8916d5b2008-11-10 09:39:04 +0000691
Ted Kremenekc48ea6e2008-12-04 02:08:27 +0000692 // Check if we have already processed this region.
693 if (Marked.count(R)) continue;
694
695 // Mark this region as processed. This is needed for termination in case
696 // a region is referenced more than once.
697 Marked.insert(R);
698
699 // Mark the symbol for any live SymbolicRegion as "live". This means we
700 // should continue to track that symbol.
701 if (const SymbolicRegion* SymR = dyn_cast<SymbolicRegion>(R))
702 LSymbols.insert(SymR->getSymbol());
703
704 // Get the data binding for R (if any).
705 RegionBindingsTy::data_type* Xptr = B.lookup(R);
706 if (Xptr) {
707 SVal X = *Xptr;
708 UpdateLiveSymbols(X, LSymbols); // Update the set of live symbols.
709
710 // If X is a region, then add it the RegionRoots.
711 if (loc::MemRegionVal* RegionX = dyn_cast<loc::MemRegionVal>(&X))
712 RegionRoots.push_back(RegionX->getRegion());
713 }
714
715 // Get the subregions of R. These are RegionRoots as well since they
716 // represent values that are also bound to R.
717 const SubRegionsTy* SRptr = SubRegMap.lookup(R);
718 if (!SRptr) continue;
719 SubRegionsTy SR = *SRptr;
720
721 for (SubRegionsTy::iterator I=SR.begin(), E=SR.end(); I!=E; ++I)
722 RegionRoots.push_back(*I);
723 }
724
725 // We have now scanned the store, marking reachable regions and symbols
726 // as live. We now remove all the regions that are dead from the store
727 // as well as update DSymbols with the set symbols that are now dead.
728
729 for (RegionBindingsTy::iterator I = B.begin(), E = B.end(); I != E; ++I) {
730 const MemRegion* R = I.getKey();
731
732 // If this region live? Is so, none of its symbols are dead.
733 if (Marked.count(R))
734 continue;
735
736 // Remove this dead region from the store.
737 store = Remove(store, loc::MemRegionVal(R));
738
739 // Mark all non-live symbols that this region references as dead.
740 if (const SymbolicRegion* SymR = dyn_cast<SymbolicRegion>(R)) {
Ted Kremenek2dabd432008-12-05 02:27:51 +0000741 SymbolRef Sym = SymR->getSymbol();
Ted Kremenekc48ea6e2008-12-04 02:08:27 +0000742 if (!LSymbols.count(Sym)) DSymbols.insert(Sym);
743 }
744
745 SVal X = I.getData();
746 SVal::symbol_iterator SI = X.symbol_begin(), SE = X.symbol_end();
747 for (; SI != SE; ++SI) { if (!LSymbols.count(*SI)) DSymbols.insert(*SI); }
748 }
749
Zhongxing Xu8916d5b2008-11-10 09:39:04 +0000750 return store;
751}
752
Zhongxing Xua071eb02008-10-24 06:01:33 +0000753void RegionStoreManager::print(Store store, std::ostream& Out,
754 const char* nl, const char *sep) {
755 llvm::raw_os_ostream OS(Out);
756 RegionBindingsTy B = GetRegionBindings(store);
757 OS << "Store:" << nl;
758
759 for (RegionBindingsTy::iterator I = B.begin(), E = B.end(); I != E; ++I) {
760 OS << ' '; I.getKey()->print(OS); OS << " : ";
761 I.getData().print(OS); OS << nl;
762 }
Zhongxing Xu5b8b6f22008-10-24 04:33:15 +0000763}
Zhongxing Xua82512a2008-10-24 08:42:28 +0000764
Zhongxing Xud463d442008-11-02 12:13:30 +0000765Store RegionStoreManager::InitializeArray(Store store, const TypedRegion* R,
Zhongxing Xu1a12a0e2008-10-31 10:24:47 +0000766 SVal Init) {
767 QualType T = R->getType(getContext());
768 assert(T->isArrayType());
769
770 ConstantArrayType* CAT = cast<ConstantArrayType>(T.getTypePtr());
771
Zhongxing Xu6987c7b2008-11-30 05:49:49 +0000772 llvm::APSInt Size(CAT->getSize(), false);
Zhongxing Xu1a12a0e2008-10-31 10:24:47 +0000773
Sebastian Redl50038612008-12-02 16:47:35 +0000774 llvm::APSInt i = getBasicVals().getValue(0, Size.getBitWidth(),
775 Size.isUnsigned());
Zhongxing Xu6987c7b2008-11-30 05:49:49 +0000776
777 // Check if the init expr is a StringLiteral.
778 if (isa<loc::MemRegionVal>(Init)) {
779 const MemRegion* InitR = cast<loc::MemRegionVal>(Init).getRegion();
780 const StringLiteral* S = cast<StringRegion>(InitR)->getStringLiteral();
781 const char* str = S->getStrData();
782 unsigned len = S->getByteLength();
783 unsigned j = 0;
784
785 for (; i < Size; ++i, ++j) {
786 SVal Idx = NonLoc::MakeVal(getBasicVals(), i);
787 ElementRegion* ER = MRMgr.getElementRegion(Idx, R);
788
789 // Copy bytes from the string literal into the target array. Trailing
790 // bytes in the array that are not covered by the string literal are
791 // initialized to zero.
792 SVal V = (j < len)
793 ? NonLoc::MakeVal(getBasicVals(), str[j], sizeof(char)*8, true)
794 : NonLoc::MakeVal(getBasicVals(), 0, sizeof(char)*8, true);
795
796 store = Bind(store, loc::MemRegionVal(ER), V);
797 }
798
799 return store;
800 }
801
Zhongxing Xu1a12a0e2008-10-31 10:24:47 +0000802
803 nonloc::CompoundVal& CV = cast<nonloc::CompoundVal>(Init);
804
805 nonloc::CompoundVal::iterator VI = CV.begin(), VE = CV.end();
806
Zhongxing Xu6987c7b2008-11-30 05:49:49 +0000807 for (; i < Size; ++i) {
808 SVal Idx = NonLoc::MakeVal(getBasicVals(), i);
Zhongxing Xu1a12a0e2008-10-31 10:24:47 +0000809 ElementRegion* ER = MRMgr.getElementRegion(Idx, R);
810
811 store = Bind(store, loc::MemRegionVal(ER), (VI!=VE) ? *VI : UndefinedVal());
812 // The init list might be shorter than the array decl.
813 if (VI != VE) ++VI;
814 }
815
816 return store;
817}
818
Zhongxing Xud463d442008-11-02 12:13:30 +0000819// Bind all elements of the array to some value.
820Store RegionStoreManager::BindArrayToVal(Store store, const TypedRegion* BaseR,
821 SVal V){
Zhongxing Xuea8a1852008-10-31 11:02:48 +0000822 QualType T = BaseR->getType(getContext());
Zhongxing Xua82512a2008-10-24 08:42:28 +0000823 assert(T->isArrayType());
824
Zhongxing Xua82512a2008-10-24 08:42:28 +0000825 // Only handle constant size array for now.
826 if (ConstantArrayType* CAT=dyn_cast<ConstantArrayType>(T.getTypePtr())) {
827
828 llvm::APInt Size = CAT->getSize();
Zhongxing Xu1a12a0e2008-10-31 10:24:47 +0000829 llvm::APInt i = llvm::APInt::getNullValue(Size.getBitWidth());
Zhongxing Xu96cb9fb2008-11-28 08:41:39 +0000830
Zhongxing Xu1a12a0e2008-10-31 10:24:47 +0000831 for (; i != Size; ++i) {
Zhongxing Xu96cb9fb2008-11-28 08:41:39 +0000832 nonloc::ConcreteInt Idx(getBasicVals().getValue(llvm::APSInt(i, false)));
Zhongxing Xua82512a2008-10-24 08:42:28 +0000833
834 ElementRegion* ER = MRMgr.getElementRegion(Idx, BaseR);
835
Zhongxing Xu9b6ceb12008-11-18 13:11:04 +0000836 if (CAT->getElementType()->isStructureType())
837 store = BindStructToVal(store, ER, V);
838 else
839 store = Bind(store, loc::MemRegionVal(ER), V);
Zhongxing Xua82512a2008-10-24 08:42:28 +0000840 }
841 }
842
843 return store;
844}
845
Zhongxing Xuc3a05992008-11-19 11:06:24 +0000846Store RegionStoreManager::BindArrayToSymVal(Store store,
847 const TypedRegion* BaseR) {
848 QualType T = BaseR->getType(getContext());
849 assert(T->isArrayType());
850
851 if (ConstantArrayType* CAT = dyn_cast<ConstantArrayType>(T.getTypePtr())) {
852 llvm::APInt Size = CAT->getSize();
853 llvm::APInt i = llvm::APInt::getNullValue(Size.getBitWidth());
854 for (; i != Size; ++i) {
Zhongxing Xu96cb9fb2008-11-28 08:41:39 +0000855 nonloc::ConcreteInt Idx(getBasicVals().getValue(llvm::APSInt(i, false)));
Zhongxing Xuc3a05992008-11-19 11:06:24 +0000856
857 ElementRegion* ER = MRMgr.getElementRegion(Idx, BaseR);
858
859 if (CAT->getElementType()->isStructureType()) {
860 store = BindStructToSymVal(store, ER);
861 }
862 else {
863 SVal V = SVal::getSymbolValue(getSymbolManager(), BaseR,
864 &Idx.getValue(), CAT->getElementType());
865 store = Bind(store, loc::MemRegionVal(ER), V);
866 }
867 }
868 }
869
870 return store;
871}
872
Zhongxing Xud463d442008-11-02 12:13:30 +0000873Store RegionStoreManager::InitializeStruct(Store store, const TypedRegion* R,
Zhongxing Xuea8a1852008-10-31 11:02:48 +0000874 SVal Init) {
Zhongxing Xuaf0a8442008-10-31 10:53:01 +0000875 QualType T = R->getType(getContext());
876 assert(T->isStructureType());
877
878 RecordType* RT = cast<RecordType>(T.getTypePtr());
879 RecordDecl* RD = RT->getDecl();
880 assert(RD->isDefinition());
881
882 nonloc::CompoundVal& CV = cast<nonloc::CompoundVal>(Init);
883 nonloc::CompoundVal::iterator VI = CV.begin(), VE = CV.end();
884 RecordDecl::field_iterator FI = RD->field_begin(), FE = RD->field_end();
885
886 for (; FI != FE; ++FI) {
887 QualType FTy = (*FI)->getType();
888 FieldRegion* FR = MRMgr.getFieldRegion(*FI, R);
889
890 if (Loc::IsLocType(FTy) || FTy->isIntegerType()) {
891 if (VI != VE) {
892 store = Bind(store, loc::MemRegionVal(FR), *VI);
893 ++VI;
894 } else
895 store = Bind(store, loc::MemRegionVal(FR), UndefinedVal());
896 }
897 else if (FTy->isArrayType()) {
898 if (VI != VE) {
899 store = InitializeArray(store, FR, *VI);
900 ++VI;
901 } else
Zhongxing Xud463d442008-11-02 12:13:30 +0000902 store = BindArrayToVal(store, FR, UndefinedVal());
Zhongxing Xuaf0a8442008-10-31 10:53:01 +0000903 }
904 else if (FTy->isStructureType()) {
905 if (VI != VE) {
906 store = InitializeStruct(store, FR, *VI);
907 ++VI;
908 } else
Zhongxing Xud463d442008-11-02 12:13:30 +0000909 store = BindStructToVal(store, FR, UndefinedVal());
Zhongxing Xuaf0a8442008-10-31 10:53:01 +0000910 }
911 }
912 return store;
913}
914
Zhongxing Xud463d442008-11-02 12:13:30 +0000915// Bind all fields of the struct to some value.
916Store RegionStoreManager::BindStructToVal(Store store, const TypedRegion* BaseR,
917 SVal V) {
Zhongxing Xuea8a1852008-10-31 11:02:48 +0000918 QualType T = BaseR->getType(getContext());
919 assert(T->isStructureType());
920
921 const RecordType* RT = cast<RecordType>(T.getTypePtr());
Zhongxing Xua82512a2008-10-24 08:42:28 +0000922 RecordDecl* RD = RT->getDecl();
923 assert(RD->isDefinition());
Zhongxing Xuea8a1852008-10-31 11:02:48 +0000924
925 RecordDecl::field_iterator I = RD->field_begin(), E = RD->field_end();
926
927 for (; I != E; ++I) {
Zhongxing Xua82512a2008-10-24 08:42:28 +0000928
929 QualType FTy = (*I)->getType();
930 FieldRegion* FR = MRMgr.getFieldRegion(*I, BaseR);
931
932 if (Loc::IsLocType(FTy) || FTy->isIntegerType()) {
Zhongxing Xud463d442008-11-02 12:13:30 +0000933 store = Bind(store, loc::MemRegionVal(FR), V);
Zhongxing Xua82512a2008-10-24 08:42:28 +0000934
935 } else if (FTy->isArrayType()) {
Zhongxing Xud463d442008-11-02 12:13:30 +0000936 store = BindArrayToVal(store, FR, V);
Zhongxing Xua82512a2008-10-24 08:42:28 +0000937
938 } else if (FTy->isStructureType()) {
Zhongxing Xud463d442008-11-02 12:13:30 +0000939 store = BindStructToVal(store, FR, V);
Zhongxing Xua82512a2008-10-24 08:42:28 +0000940 }
941 }
942
943 return store;
944}
Zhongxing Xudc0a25d2008-11-16 04:07:26 +0000945
Zhongxing Xuc3a05992008-11-19 11:06:24 +0000946Store RegionStoreManager::BindStructToSymVal(Store store,
947 const TypedRegion* BaseR) {
948 QualType T = BaseR->getType(getContext());
949 assert(T->isStructureType());
950
951 const RecordType* RT = cast<RecordType>(T.getTypePtr());
952 RecordDecl* RD = RT->getDecl();
953 assert(RD->isDefinition());
954
955 RecordDecl::field_iterator I = RD->field_begin(), E = RD->field_end();
956
957 for (; I != E; ++I) {
958 QualType FTy = (*I)->getType();
959 FieldRegion* FR = MRMgr.getFieldRegion(*I, BaseR);
960
961 if (Loc::IsLocType(FTy) || FTy->isIntegerType()) {
962 store = Bind(store, loc::MemRegionVal(FR),
963 SVal::getSymbolValue(getSymbolManager(), BaseR, *I, FTy));
964 }
965 else if (FTy->isArrayType()) {
966 store = BindArrayToSymVal(store, FR);
967 }
968 else if (FTy->isStructureType()) {
969 store = BindStructToSymVal(store, FR);
970 }
971 }
972
973 return store;
974}
975
Zhongxing Xudc0a25d2008-11-16 04:07:26 +0000976const GRState* RegionStoreManager::AddRegionView(const GRState* St,
977 const MemRegion* View,
978 const MemRegion* Base) {
979 GRStateRef state(St, StateMgr);
980
981 // First, retrieve the region view of the base region.
982 RegionViewMapTy::data_type* d = state.get<RegionViewMapTy>(Base);
983 RegionViewTy L = d ? *d : RVFactory.GetEmptyList();
984
985 // Now add View to the region view.
986 L = RVFactory.Add(View, L);
987
988 // Create a new state with the new region view.
989 return state.set<RegionViewMapTy>(Base, L);
990}