blob: 10644ccc144e38c75e5215a2c7408024ff4a3825 [file] [log] [blame]
Ted Kremenekd4931632008-11-12 19:21:30 +00001//== Environment.cpp - Map from Stmt* to Locations/Values -------*- C++ -*--==//
Ted Kremenek8133a262008-07-08 21:46:56 +00002//
3// The LLVM Compiler Infrastructure
4//
5// This file is distributed under the University of Illinois Open Source
6// License. See LICENSE.TXT for details.
7//
8//===----------------------------------------------------------------------===//
9//
10// This file defined the Environment and EnvironmentManager classes.
11//
12//===----------------------------------------------------------------------===//
Benjamin Kramer5e2d2c22010-03-27 21:19:47 +000013
14#include "clang/Analysis/AnalysisContext.h"
15#include "clang/Analysis/CFG.h"
Ted Kremenek1309f9a2010-01-25 04:41:41 +000016#include "clang/Checker/PathSensitive/GRState.h"
Ted Kremenek8133a262008-07-08 21:46:56 +000017
18using namespace clang;
19
Zhongxing Xud91ee272009-06-23 09:02:15 +000020SVal Environment::GetSVal(const Stmt *E, ValueManager& ValMgr) const {
Mike Stump1eb44332009-09-09 15:08:12 +000021
Ted Kremenekd72ee902008-07-10 17:19:18 +000022 for (;;) {
Mike Stump1eb44332009-09-09 15:08:12 +000023
Ted Kremenekd72ee902008-07-10 17:19:18 +000024 switch (E->getStmtClass()) {
Mike Stump1eb44332009-09-09 15:08:12 +000025
26 case Stmt::AddrLabelExprClass:
Zhongxing Xud91ee272009-06-23 09:02:15 +000027 return ValMgr.makeLoc(cast<AddrLabelExpr>(E));
Mike Stump1eb44332009-09-09 15:08:12 +000028
Ted Kremenekd72ee902008-07-10 17:19:18 +000029 // ParenExprs are no-ops.
Mike Stump1eb44332009-09-09 15:08:12 +000030
31 case Stmt::ParenExprClass:
Ted Kremenekd72ee902008-07-10 17:19:18 +000032 E = cast<ParenExpr>(E)->getSubExpr();
33 continue;
Mike Stump1eb44332009-09-09 15:08:12 +000034
Ted Kremenekd72ee902008-07-10 17:19:18 +000035 case Stmt::CharacterLiteralClass: {
Ted Kremenek23ec48c2009-06-18 23:58:37 +000036 const CharacterLiteral* C = cast<CharacterLiteral>(E);
Zhongxing Xud91ee272009-06-23 09:02:15 +000037 return ValMgr.makeIntVal(C->getValue(), C->getType());
Ted Kremenekd72ee902008-07-10 17:19:18 +000038 }
Mike Stump1eb44332009-09-09 15:08:12 +000039
Zhongxing Xu477323d2010-04-14 06:29:29 +000040 case Stmt::CXXBoolLiteralExprClass: {
41 const SVal *X = ExprBindings.lookup(E);
42 if (X)
43 return *X;
44 else
45 return ValMgr.makeIntVal(cast<CXXBoolLiteralExpr>(E));
46 }
Ted Kremenekd72ee902008-07-10 17:19:18 +000047 case Stmt::IntegerLiteralClass: {
Zhongxing Xubc37b8d2010-01-09 09:16:47 +000048 // In C++, this expression may have been bound to a temporary object.
49 SVal const *X = ExprBindings.lookup(E);
50 if (X)
51 return *X;
52 else
53 return ValMgr.makeIntVal(cast<IntegerLiteral>(E));
Ted Kremenekd72ee902008-07-10 17:19:18 +000054 }
Mike Stump1eb44332009-09-09 15:08:12 +000055
Zhongxing Xu143bf822008-10-25 14:18:57 +000056 // Casts where the source and target type are the same
57 // are no-ops. We blast through these to get the descendant
58 // subexpression that has a value.
Mike Stump1eb44332009-09-09 15:08:12 +000059
Argyrios Kyrtzidis0835a3c2008-08-18 23:01:59 +000060 case Stmt::ImplicitCastExprClass:
Douglas Gregor6eec8e82008-10-28 15:36:24 +000061 case Stmt::CStyleCastExprClass: {
Ted Kremenek23ec48c2009-06-18 23:58:37 +000062 const CastExpr* C = cast<CastExpr>(E);
Ted Kremenekd72ee902008-07-10 17:19:18 +000063 QualType CT = C->getType();
Mike Stump1eb44332009-09-09 15:08:12 +000064
Ted Kremenekd72ee902008-07-10 17:19:18 +000065 if (CT->isVoidType())
66 return UnknownVal();
Mike Stump1eb44332009-09-09 15:08:12 +000067
Ted Kremenekd72ee902008-07-10 17:19:18 +000068 break;
69 }
Mike Stump1eb44332009-09-09 15:08:12 +000070
Ted Kremenekd4931632008-11-12 19:21:30 +000071 // Handle all other Stmt* using a lookup.
Mike Stump1eb44332009-09-09 15:08:12 +000072
Ted Kremenekd72ee902008-07-10 17:19:18 +000073 default:
74 break;
75 };
Mike Stump1eb44332009-09-09 15:08:12 +000076
Ted Kremenekd72ee902008-07-10 17:19:18 +000077 break;
78 }
Mike Stump1eb44332009-09-09 15:08:12 +000079
Ted Kremenekd72ee902008-07-10 17:19:18 +000080 return LookupExpr(E);
81}
Ted Kremenek8133a262008-07-08 21:46:56 +000082
Ted Kremenek6d4c0222010-09-03 01:07:02 +000083Environment EnvironmentManager::bindExpr(Environment Env, const Stmt *S,
Mike Stump1eb44332009-09-09 15:08:12 +000084 SVal V, bool Invalidate) {
Ted Kremenek0fb0bc42009-08-27 01:39:13 +000085 assert(S);
Mike Stump1eb44332009-09-09 15:08:12 +000086
87 if (V.isUnknown()) {
Ted Kremenekd72ee902008-07-10 17:19:18 +000088 if (Invalidate)
Zhongxing Xuc179a7f2010-03-05 04:45:36 +000089 return Environment(F.Remove(Env.ExprBindings, S));
Ted Kremenekd72ee902008-07-10 17:19:18 +000090 else
91 return Env;
92 }
Ted Kremenek8133a262008-07-08 21:46:56 +000093
Zhongxing Xuc179a7f2010-03-05 04:45:36 +000094 return Environment(F.Add(Env.ExprBindings, S, V));
Ted Kremenekd72ee902008-07-10 17:19:18 +000095}
Ted Kremenekdf9cdf82008-08-20 17:08:29 +000096
Ted Kremenek6d4c0222010-09-03 01:07:02 +000097static inline const Stmt *MakeLocation(const Stmt *S) {
98 return (const Stmt*) (((uintptr_t) S) | 0x1);
99}
100
101Environment EnvironmentManager::bindExprAndLocation(Environment Env,
102 const Stmt *S,
103 SVal location, SVal V) {
Zhanyong Wancf848872010-11-20 07:52:48 +0000104 return Environment(F.Add(F.Add(Env.ExprBindings, MakeLocation(S), location),
105 S, V));
Ted Kremenek6d4c0222010-09-03 01:07:02 +0000106}
107
Ted Kremenek5216ad72009-02-14 03:16:10 +0000108namespace {
Kovarththanan Rajaratnamba5fb5a2009-11-28 06:07:30 +0000109class MarkLiveCallback : public SymbolVisitor {
Ted Kremenek5216ad72009-02-14 03:16:10 +0000110 SymbolReaper &SymReaper;
111public:
Mike Stump1eb44332009-09-09 15:08:12 +0000112 MarkLiveCallback(SymbolReaper &symreaper) : SymReaper(symreaper) {}
Ted Kremenek5216ad72009-02-14 03:16:10 +0000113 bool VisitSymbol(SymbolRef sym) { SymReaper.markLive(sym); return true; }
114};
115} // end anonymous namespace
116
Zhongxing Xu7b73b922010-04-05 13:16:29 +0000117static bool isBlockExprInCallers(const Stmt *E, const LocationContext *LC) {
118 const LocationContext *ParentLC = LC->getParent();
119 while (ParentLC) {
120 CFG &C = *ParentLC->getCFG();
121 if (C.isBlkExpr(E))
122 return true;
123 ParentLC = ParentLC->getParent();
124 }
125
126 return false;
127}
128
Ted Kremenek6d4c0222010-09-03 01:07:02 +0000129// In addition to mapping from Stmt * - > SVals in the Environment, we also
130// maintain a mapping from Stmt * -> SVals (locations) that were used during
131// a load and store.
132static inline bool IsLocation(const Stmt *S) {
133 return (bool) (((uintptr_t) S) & 0x1);
134}
Zhongxing Xu7b73b922010-04-05 13:16:29 +0000135
Zhongxing Xu9d8d0fc2009-03-12 07:54:17 +0000136// RemoveDeadBindings:
137// - Remove subexpression bindings.
138// - Remove dead block expression bindings.
139// - Keep live block expression bindings:
Mike Stump1eb44332009-09-09 15:08:12 +0000140// - Mark their reachable symbols live in SymbolReaper,
Zhongxing Xu9d8d0fc2009-03-12 07:54:17 +0000141// see ScanReachableSymbols.
142// - Mark the region in DRoots if the binding is a loc::MemRegionVal.
Mike Stump1eb44332009-09-09 15:08:12 +0000143Environment
Jordy Rose7dadf792010-07-01 20:09:55 +0000144EnvironmentManager::RemoveDeadBindings(Environment Env,
Ted Kremenek0fb0bc42009-08-27 01:39:13 +0000145 SymbolReaper &SymReaper,
146 const GRState *ST,
147 llvm::SmallVectorImpl<const MemRegion*> &DRoots) {
Mike Stump1eb44332009-09-09 15:08:12 +0000148
Zhongxing Xuc179a7f2010-03-05 04:45:36 +0000149 CFG &C = *SymReaper.getLocationContext()->getCFG();
Mike Stump1eb44332009-09-09 15:08:12 +0000150
Ted Kremenek0fb0bc42009-08-27 01:39:13 +0000151 // We construct a new Environment object entirely, as this is cheaper than
152 // individually removing all the subexpression bindings (which will greatly
153 // outnumber block-level expression bindings).
Zhongxing Xuc179a7f2010-03-05 04:45:36 +0000154 Environment NewEnv = getInitialEnvironment();
Ted Kremenek6d4c0222010-09-03 01:07:02 +0000155
156 llvm::SmallVector<std::pair<const Stmt*, SVal>, 10> deferredLocations;
Mike Stump1eb44332009-09-09 15:08:12 +0000157
Ted Kremenekdf9cdf82008-08-20 17:08:29 +0000158 // Iterate over the block-expr bindings.
Mike Stump1eb44332009-09-09 15:08:12 +0000159 for (Environment::iterator I = Env.begin(), E = Env.end();
Ted Kremenekdf9cdf82008-08-20 17:08:29 +0000160 I != E; ++I) {
Mike Stump1eb44332009-09-09 15:08:12 +0000161
Ted Kremenek23ec48c2009-06-18 23:58:37 +0000162 const Stmt *BlkExpr = I.getKey();
Ted Kremenek6d4c0222010-09-03 01:07:02 +0000163
164 // For recorded locations (used when evaluating loads and stores), we
165 // consider them live only when their associated normal expression is
166 // also live.
167 // NOTE: This assumes that loads/stores that evaluated to UnknownVal
168 // still have an entry in the map.
169 if (IsLocation(BlkExpr)) {
170 deferredLocations.push_back(std::make_pair(BlkExpr, I.getData()));
171 continue;
172 }
173
Zhongxing Xu7b73b922010-04-05 13:16:29 +0000174 const SVal &X = I.getData();
175
176 // Block-level expressions in callers are assumed always live.
177 if (isBlockExprInCallers(BlkExpr, SymReaper.getLocationContext())) {
178 NewEnv.ExprBindings = F.Add(NewEnv.ExprBindings, BlkExpr, X);
179
180 if (isa<loc::MemRegionVal>(X)) {
181 const MemRegion* R = cast<loc::MemRegionVal>(X).getRegion();
182 DRoots.push_back(R);
183 }
184
185 // Mark all symbols in the block expr's value live.
186 MarkLiveCallback cb(SymReaper);
187 ST->scanReachableSymbols(X, cb);
188 continue;
189 }
Mike Stump1eb44332009-09-09 15:08:12 +0000190
Ted Kremenek0fb0bc42009-08-27 01:39:13 +0000191 // Not a block-level expression?
192 if (!C.isBlkExpr(BlkExpr))
193 continue;
Mike Stump1eb44332009-09-09 15:08:12 +0000194
Jordy Rose7dadf792010-07-01 20:09:55 +0000195 if (SymReaper.isLive(BlkExpr)) {
Ted Kremenek0fb0bc42009-08-27 01:39:13 +0000196 // Copy the binding to the new map.
197 NewEnv.ExprBindings = F.Add(NewEnv.ExprBindings, BlkExpr, X);
Mike Stump1eb44332009-09-09 15:08:12 +0000198
Ted Kremenek9e240492008-10-04 05:50:14 +0000199 // If the block expr's value is a memory region, then mark that region.
Zhongxing Xuce2f9bd2009-06-30 13:00:53 +0000200 if (isa<loc::MemRegionVal>(X)) {
201 const MemRegion* R = cast<loc::MemRegionVal>(X).getRegion();
202 DRoots.push_back(R);
Zhongxing Xuce2f9bd2009-06-30 13:00:53 +0000203 }
Ted Kremenek9e240492008-10-04 05:50:14 +0000204
Ted Kremenek5216ad72009-02-14 03:16:10 +0000205 // Mark all symbols in the block expr's value live.
206 MarkLiveCallback cb(SymReaper);
Ted Kremenek0fb0bc42009-08-27 01:39:13 +0000207 ST->scanReachableSymbols(X, cb);
208 continue;
Ted Kremenekdf9cdf82008-08-20 17:08:29 +0000209 }
Ted Kremenek0fb0bc42009-08-27 01:39:13 +0000210
211 // Otherwise the expression is dead with a couple exceptions.
212 // Do not misclean LogicalExpr or ConditionalOperator. It is dead at the
213 // beginning of itself, but we need its UndefinedVal to determine its
214 // SVal.
215 if (X.isUndef() && cast<UndefinedVal>(X).getData())
216 NewEnv.ExprBindings = F.Add(NewEnv.ExprBindings, BlkExpr, X);
Ted Kremenekdf9cdf82008-08-20 17:08:29 +0000217 }
Ted Kremenek6d4c0222010-09-03 01:07:02 +0000218
219 // Go through he deferred locations and add them to the new environment if
220 // the correspond Stmt* is in the map as well.
221 for (llvm::SmallVectorImpl<std::pair<const Stmt*, SVal> >::iterator
222 I = deferredLocations.begin(), E = deferredLocations.end(); I != E; ++I) {
223 const Stmt *S = (Stmt*) (((uintptr_t) I->first) & (uintptr_t) ~0x1);
224 if (NewEnv.ExprBindings.lookup(S))
225 NewEnv.ExprBindings = F.Add(NewEnv.ExprBindings, I->first, I->second);
226 }
Ted Kremenekdf9cdf82008-08-20 17:08:29 +0000227
Ted Kremenek0fb0bc42009-08-27 01:39:13 +0000228 return NewEnv;
Ted Kremenekdf9cdf82008-08-20 17:08:29 +0000229}