blob: 99c225f5e83d31a7dcfcb2f848a8f4c3ebde74a2 [file] [log] [blame]
Zhongxing Xu17892752008-10-08 02:50:44 +00001//== RegionStore.cpp - Field-sensitive store model --------------*- C++ -*--==//
2//
3// The LLVM Compiler Infrastructure
4//
5// This file is distributed under the University of Illinois Open Source
6// License. See LICENSE.TXT for details.
7//
8//===----------------------------------------------------------------------===//
9//
10// This file defines a basic region store model. In this model, we do have field
11// sensitivity. But we assume nothing about the heap shape. So recursive data
12// structures are largely ignored. Basically we do 1-limiting analysis.
13// Parameter pointers are assumed with no aliasing. Pointee objects of
14// parameters are created lazily.
15//
16//===----------------------------------------------------------------------===//
17#include "clang/Analysis/PathSensitive/MemRegion.h"
18#include "clang/Analysis/PathSensitive/GRState.h"
Zhongxing Xudc0a25d2008-11-16 04:07:26 +000019#include "clang/Analysis/PathSensitive/GRStateTrait.h"
Zhongxing Xu17892752008-10-08 02:50:44 +000020#include "clang/Analysis/Analyses/LiveVariables.h"
21
22#include "llvm/ADT/ImmutableMap.h"
Zhongxing Xudc0a25d2008-11-16 04:07:26 +000023#include "llvm/ADT/ImmutableList.h"
Zhongxing Xua071eb02008-10-24 06:01:33 +000024#include "llvm/Support/raw_ostream.h"
Zhongxing Xu17892752008-10-08 02:50:44 +000025#include "llvm/Support/Compiler.h"
26
27using namespace clang;
28
Zhongxing Xu1c96b242008-10-17 05:57:07 +000029typedef llvm::ImmutableMap<const MemRegion*, SVal> RegionBindingsTy;
Zhongxing Xudc0a25d2008-11-16 04:07:26 +000030typedef llvm::ImmutableList<const MemRegion*> RegionViewTy;
31typedef llvm::ImmutableMap<const MemRegion*, RegionViewTy> RegionViewMapTy;
32
33static int RegionViewMapTyIndex = 0;
34
35namespace clang {
36template<> struct GRStateTrait<RegionViewMapTy>
37 : public GRStatePartialTrait<RegionViewMapTy> {
38 static void* GDMIndex() { return &RegionViewMapTyIndex; }
39};
40}
Zhongxing Xu17892752008-10-08 02:50:44 +000041
42namespace {
43
44class VISIBILITY_HIDDEN RegionStoreManager : public StoreManager {
45 RegionBindingsTy::Factory RBFactory;
Zhongxing Xudc0a25d2008-11-16 04:07:26 +000046 RegionViewTy::Factory RVFactory;
47 RegionViewMapTy::Factory RVMFactory;
48
Zhongxing Xu17892752008-10-08 02:50:44 +000049 GRStateManager& StateMgr;
50 MemRegionManager MRMgr;
51
52public:
53 RegionStoreManager(GRStateManager& mgr)
Zhongxing Xudc0a25d2008-11-16 04:07:26 +000054 : RBFactory(mgr.getAllocator()),
55 RVFactory(mgr.getAllocator()),
56 RVMFactory(mgr.getAllocator()),
57 StateMgr(mgr),
58 MRMgr(StateMgr.getAllocator()) {}
Zhongxing Xu17892752008-10-08 02:50:44 +000059
60 virtual ~RegionStoreManager() {}
61
Zhongxing Xu24194ef2008-10-24 01:38:55 +000062 MemRegionManager& getRegionManager() { return MRMgr; }
63
64 // FIXME: Is this function necessary?
65 SVal GetRegionSVal(Store St, const MemRegion* R) {
66 return Retrieve(St, loc::MemRegionVal(R));
67 }
Ted Kremenek4f090272008-10-27 21:54:31 +000068
Zhongxing Xuf22679e2008-11-07 10:38:33 +000069 Store BindCompoundLiteral(Store store, const CompoundLiteralExpr* CL, SVal V);
Zhongxing Xu24194ef2008-10-24 01:38:55 +000070
Zhongxing Xu143bf822008-10-25 14:18:57 +000071 SVal getLValueString(const GRState* St, const StringLiteral* S);
72
Zhongxing Xuf22679e2008-11-07 10:38:33 +000073 SVal getLValueCompoundLiteral(const GRState* St, const CompoundLiteralExpr*);
74
Zhongxing Xuc4bf72c2008-10-22 13:44:38 +000075 SVal getLValueVar(const GRState* St, const VarDecl* VD);
76
77 SVal getLValueIvar(const GRState* St, const ObjCIvarDecl* D, SVal Base);
78
79 SVal getLValueField(const GRState* St, SVal Base, const FieldDecl* D);
80
Zhongxing Xub1d542a2008-10-24 01:09:32 +000081 SVal getLValueElement(const GRState* St, SVal Base, SVal Offset);
82
Zhongxing Xue8a964b2008-11-22 13:21:46 +000083 SVal getSizeInElements(const GRState* St, const MemRegion* R);
84
Zhongxing Xub1d542a2008-10-24 01:09:32 +000085 SVal ArrayToPointer(SVal Array);
86
Zhongxing Xucb529b52008-11-16 07:06:26 +000087 std::pair<const GRState*, SVal>
88 CastRegion(const GRState* St, SVal VoidPtr, QualType CastToTy, Stmt* CastE);
Zhongxing Xudc0a25d2008-11-16 04:07:26 +000089
Zhongxing Xu24194ef2008-10-24 01:38:55 +000090 SVal Retrieve(Store S, Loc L, QualType T = QualType());
Zhongxing Xuc4bf72c2008-10-22 13:44:38 +000091
Zhongxing Xu8485ec62008-10-21 06:27:32 +000092 Store Bind(Store St, Loc LV, SVal V);
Zhongxing Xu17892752008-10-08 02:50:44 +000093
Zhongxing Xu24194ef2008-10-24 01:38:55 +000094 Store Remove(Store store, Loc LV) {
95 // FIXME: Implement.
96 return store;
97 }
98
Zhongxing Xu17892752008-10-08 02:50:44 +000099 Store getInitialStore();
Ted Kremenek9deb0e32008-10-24 20:32:16 +0000100
101 /// getSelfRegion - Returns the region for the 'self' (Objective-C) or
102 /// 'this' object (C++). When used when analyzing a normal function this
103 /// method returns NULL.
104 const MemRegion* getSelfRegion(Store) {
105 assert (false && "Not implemented.");
106 return 0;
107 }
Zhongxing Xu17892752008-10-08 02:50:44 +0000108
Zhongxing Xu24194ef2008-10-24 01:38:55 +0000109 Store RemoveDeadBindings(Store store, Stmt* Loc, const LiveVariables& Live,
110 llvm::SmallVectorImpl<const MemRegion*>& RegionRoots,
Zhongxing Xu8916d5b2008-11-10 09:39:04 +0000111 LiveSymbolsTy& LSymbols, DeadSymbolsTy& DSymbols);
Zhongxing Xu24194ef2008-10-24 01:38:55 +0000112
Ted Kremenek42577d12008-11-12 19:18:35 +0000113 Store BindDecl(Store store, const VarDecl* VD, SVal* InitVal, unsigned Count);
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000114
Zhongxing Xu17892752008-10-08 02:50:44 +0000115 static inline RegionBindingsTy GetRegionBindings(Store store) {
116 return RegionBindingsTy(static_cast<const RegionBindingsTy::TreeTy*>(store));
117 }
Zhongxing Xu24194ef2008-10-24 01:38:55 +0000118
Zhongxing Xu5b8b6f22008-10-24 04:33:15 +0000119 void print(Store store, std::ostream& Out, const char* nl, const char *sep);
Zhongxing Xu24194ef2008-10-24 01:38:55 +0000120
121 void iterBindings(Store store, BindingsHandler& f) {
122 // FIXME: Implement.
123 }
Zhongxing Xua82512a2008-10-24 08:42:28 +0000124
125private:
126 Loc getVarLoc(const VarDecl* VD) {
127 return loc::MemRegionVal(MRMgr.getVarRegion(VD));
128 }
129
Zhongxing Xud463d442008-11-02 12:13:30 +0000130 Store InitializeArray(Store store, const TypedRegion* R, SVal Init);
131 Store BindArrayToVal(Store store, const TypedRegion* BaseR, SVal V);
Zhongxing Xuc3a05992008-11-19 11:06:24 +0000132 Store BindArrayToSymVal(Store store, const TypedRegion* BaseR);
133
Zhongxing Xud463d442008-11-02 12:13:30 +0000134 Store InitializeStruct(Store store, const TypedRegion* R, SVal Init);
135 Store BindStructToVal(Store store, const TypedRegion* BaseR, SVal V);
Zhongxing Xuc3a05992008-11-19 11:06:24 +0000136 Store BindStructToSymVal(Store store, const TypedRegion* BaseR);
Zhongxing Xu6e3f01c2008-10-31 07:16:08 +0000137
138 SVal RetrieveStruct(Store store, const TypedRegion* R);
Zhongxing Xuf0dfa8d2008-10-31 08:10:01 +0000139 Store BindStruct(Store store, const TypedRegion* R, SVal V);
Zhongxing Xu63123d82008-11-23 04:30:35 +0000140
Zhongxing Xu6e3f01c2008-10-31 07:16:08 +0000141 // Utility methods.
142 BasicValueFactory& getBasicVals() { return StateMgr.getBasicVals(); }
143 ASTContext& getContext() { return StateMgr.getContext(); }
Zhongxing Xu63123d82008-11-23 04:30:35 +0000144 SymbolManager& getSymbolManager() { return StateMgr.getSymbolManager(); }
Zhongxing Xudc0a25d2008-11-16 04:07:26 +0000145
146 const GRState* AddRegionView(const GRState* St,
147 const MemRegion* View, const MemRegion* Base);
Zhongxing Xu17892752008-10-08 02:50:44 +0000148};
149
150} // end anonymous namespace
151
Ted Kremenek95c7b002008-10-24 01:04:59 +0000152StoreManager* clang::CreateRegionStoreManager(GRStateManager& StMgr) {
Zhongxing Xu24194ef2008-10-24 01:38:55 +0000153 return new RegionStoreManager(StMgr);
Ted Kremenek95c7b002008-10-24 01:04:59 +0000154}
155
Zhongxing Xu143bf822008-10-25 14:18:57 +0000156SVal RegionStoreManager::getLValueString(const GRState* St,
157 const StringLiteral* S) {
158 return loc::MemRegionVal(MRMgr.getStringRegion(S));
159}
160
Zhongxing Xuc4bf72c2008-10-22 13:44:38 +0000161SVal RegionStoreManager::getLValueVar(const GRState* St, const VarDecl* VD) {
162 return loc::MemRegionVal(MRMgr.getVarRegion(VD));
163}
Zhongxing Xuf22679e2008-11-07 10:38:33 +0000164
165SVal RegionStoreManager::getLValueCompoundLiteral(const GRState* St,
166 const CompoundLiteralExpr* CL) {
167 return loc::MemRegionVal(MRMgr.getCompoundLiteralRegion(CL));
168}
169
Zhongxing Xuc4bf72c2008-10-22 13:44:38 +0000170SVal RegionStoreManager::getLValueIvar(const GRState* St, const ObjCIvarDecl* D,
171 SVal Base) {
172 return UnknownVal();
173}
174
175SVal RegionStoreManager::getLValueField(const GRState* St, SVal Base,
176 const FieldDecl* D) {
177 if (Base.isUnknownOrUndef())
178 return Base;
179
180 Loc BaseL = cast<Loc>(Base);
181 const MemRegion* BaseR = 0;
182
183 switch (BaseL.getSubKind()) {
184 case loc::MemRegionKind:
185 BaseR = cast<loc::MemRegionVal>(BaseL).getRegion();
186 break;
187
188 case loc::SymbolValKind:
189 BaseR = MRMgr.getSymbolicRegion(cast<loc::SymbolVal>(&BaseL)->getSymbol());
190 break;
191
192 case loc::GotoLabelKind:
193 case loc::FuncValKind:
194 // These are anormal cases. Flag an undefined value.
195 return UndefinedVal();
196
197 case loc::ConcreteIntKind:
Zhongxing Xuc4bf72c2008-10-22 13:44:38 +0000198 // While these seem funny, this can happen through casts.
199 // FIXME: What we should return is the field offset. For example,
200 // add the field offset to the integer value. That way funny things
201 // like this work properly: &(((struct foo *) 0xa)->f)
202 return Base;
203
204 default:
Zhongxing Xu13d1ee22008-11-07 08:57:30 +0000205 assert(0 && "Unhandled Base.");
Zhongxing Xuc4bf72c2008-10-22 13:44:38 +0000206 return Base;
207 }
208
209 return loc::MemRegionVal(MRMgr.getFieldRegion(D, BaseR));
210}
211
Zhongxing Xub1d542a2008-10-24 01:09:32 +0000212SVal RegionStoreManager::getLValueElement(const GRState* St,
213 SVal Base, SVal Offset) {
214 if (Base.isUnknownOrUndef())
215 return Base;
216
Zhongxing Xu4a1513e2008-10-27 12:23:17 +0000217 if (isa<loc::SymbolVal>(Base))
218 return Base;
219
Zhongxing Xub1d542a2008-10-24 01:09:32 +0000220 loc::MemRegionVal& BaseL = cast<loc::MemRegionVal>(Base);
221
Zhongxing Xue4d13932008-11-13 09:48:44 +0000222 // Pointer of any type can be cast and used as array base. We do not support
223 // that case yet.
224 if (!isa<ElementRegion>(BaseL.getRegion())) {
225 // Record what we have seen in real code.
226 assert(isa<FieldRegion>(BaseL.getRegion()));
227 return UnknownVal();
228 }
229
Zhongxing Xub1d542a2008-10-24 01:09:32 +0000230 // We expect BaseR is an ElementRegion, not a base VarRegion.
231
232 const ElementRegion* ElemR = cast<ElementRegion>(BaseL.getRegion());
233
234 SVal Idx = ElemR->getIndex();
235
236 nonloc::ConcreteInt *CI1, *CI2;
237
238 // Only handle integer indices for now.
239 if ((CI1 = dyn_cast<nonloc::ConcreteInt>(&Idx)) &&
240 (CI2 = dyn_cast<nonloc::ConcreteInt>(&Offset))) {
Zhongxing Xucc0d0ec2008-11-13 09:15:14 +0000241
242 // Temporary SVal to hold a potential signed APSInt.
243 SVal SignedInt;
244
245 // Index might be unsigned. We have to convert it to signed.
246 if (CI2->getValue().isUnsigned()) {
247 llvm::APSInt SI = CI2->getValue();
248 SI.setIsSigned(true);
249 SignedInt = nonloc::ConcreteInt(getBasicVals().getValue(SI));
250 CI2 = cast<nonloc::ConcreteInt>(&SignedInt);
251 }
252
Zhongxing Xu63123d82008-11-23 04:30:35 +0000253 SVal NewIdx = CI1->EvalBinOp(getBasicVals(), BinaryOperator::Add, *CI2);
Zhongxing Xub1d542a2008-10-24 01:09:32 +0000254 return loc::MemRegionVal(MRMgr.getElementRegion(NewIdx,
255 ElemR->getSuperRegion()));
256 }
257
258 return UnknownVal();
259}
260
Zhongxing Xue8a964b2008-11-22 13:21:46 +0000261SVal RegionStoreManager::getSizeInElements(const GRState* St,
262 const MemRegion* R) {
263 if (const VarRegion* VR = dyn_cast<VarRegion>(R)) {
264 // Get the type of the variable.
265 QualType T = VR->getType(getContext());
266
267 // It must be of array type.
268 const ConstantArrayType* CAT = cast<ConstantArrayType>(T.getTypePtr());
269
270 // return the size as signed integer.
271 return NonLoc::MakeVal(getBasicVals(), CAT->getSize(), false);
272 }
273
274 if (const StringRegion* SR = dyn_cast<StringRegion>(R)) {
Zhongxing Xu6613d082008-11-24 02:18:56 +0000275 const StringLiteral* Str = SR->getStringLiteral();
Zhongxing Xud0fd3b72008-11-24 02:30:48 +0000276 // We intentionally made the size value signed because it participates in
277 // operations with signed indices.
Zhongxing Xu4b89e032008-11-24 05:16:01 +0000278 return NonLoc::MakeVal(getBasicVals(), Str->getByteLength() + 1, false);
Zhongxing Xue8a964b2008-11-22 13:21:46 +0000279 }
280
281 if (const AnonTypedRegion* ATR = dyn_cast<AnonTypedRegion>(R)) {
282 // FIXME: Unsupported yet.
283 ATR = 0;
284 return UnknownVal();
285 }
286
287 if (const FieldRegion* FR = dyn_cast<FieldRegion>(R)) {
288 // FIXME: Unsupported yet.
289 FR = 0;
290 return UnknownVal();
291 }
Zhongxing Xu369f4292008-11-22 13:23:00 +0000292
Zhongxing Xue8a964b2008-11-22 13:21:46 +0000293 assert(0 && "Other regions are not supported yet.");
294}
295
Zhongxing Xub1d542a2008-10-24 01:09:32 +0000296// Cast 'pointer to array' to 'pointer to the first element of array'.
297
298SVal RegionStoreManager::ArrayToPointer(SVal Array) {
299 const MemRegion* ArrayR = cast<loc::MemRegionVal>(&Array)->getRegion();
Zhongxing Xu143bf822008-10-25 14:18:57 +0000300
Zhongxing Xu63123d82008-11-23 04:30:35 +0000301 nonloc::ConcreteInt Idx(getBasicVals().getZeroWithPtrWidth(false));
Zhongxing Xu0b7e6422008-10-26 02:23:57 +0000302 ElementRegion* ER = MRMgr.getElementRegion(Idx, ArrayR);
303
304 return loc::MemRegionVal(ER);
Zhongxing Xub1d542a2008-10-24 01:09:32 +0000305}
306
Zhongxing Xucb529b52008-11-16 07:06:26 +0000307std::pair<const GRState*, SVal>
308RegionStoreManager::CastRegion(const GRState* St, SVal VoidPtr,
309 QualType CastToTy, Stmt* CastE) {
Zhongxing Xudc0a25d2008-11-16 04:07:26 +0000310 if (const AllocaRegion* AR =
311 dyn_cast<AllocaRegion>(cast<loc::MemRegionVal>(VoidPtr).getRegion())) {
312
313 // Create a new region to attach type information to it.
314 const AnonTypedRegion* TR = MRMgr.getAnonTypedRegion(CastToTy, AR);
315
316 // Get the pointer to the first element.
317 nonloc::ConcreteInt Idx(getBasicVals().getZeroWithPtrWidth(false));
318 const ElementRegion* ER = MRMgr.getElementRegion(Idx, TR);
319
Zhongxing Xudc0a25d2008-11-16 04:07:26 +0000320 // Add a RegionView to base region.
Zhongxing Xucb529b52008-11-16 07:06:26 +0000321 return std::pair<const GRState*, SVal>(AddRegionView(St, TR, AR),
322 loc::MemRegionVal(ER));
Zhongxing Xudc0a25d2008-11-16 04:07:26 +0000323 }
324
325 // Default case.
Zhongxing Xucb529b52008-11-16 07:06:26 +0000326 return std::pair<const GRState*, SVal>(St, UnknownVal());
Zhongxing Xudc0a25d2008-11-16 04:07:26 +0000327}
328
Zhongxing Xu8485ec62008-10-21 06:27:32 +0000329SVal RegionStoreManager::Retrieve(Store S, Loc L, QualType T) {
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000330 assert(!isa<UnknownVal>(L) && "location unknown");
331 assert(!isa<UndefinedVal>(L) && "location undefined");
332
333 switch (L.getSubKind()) {
334 case loc::MemRegionKind: {
335 const MemRegion* R = cast<loc::MemRegionVal>(L).getRegion();
336 assert(R && "bad region");
337
Zhongxing Xu6e3f01c2008-10-31 07:16:08 +0000338 if (const TypedRegion* TR = dyn_cast<TypedRegion>(R))
339 if (TR->getType(getContext())->isStructureType())
340 return RetrieveStruct(S, TR);
341
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000342 RegionBindingsTy B(static_cast<const RegionBindingsTy::TreeTy*>(S));
343 RegionBindingsTy::data_type* V = B.lookup(R);
344 return V ? *V : UnknownVal();
345 }
346
347 case loc::SymbolValKind:
348 return UnknownVal();
349
350 case loc::ConcreteIntKind:
351 return UndefinedVal(); // As in BasicStoreManager.
352
353 case loc::FuncValKind:
354 return L;
355
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000356 default:
357 assert(false && "Invalid Location");
Ted Kremenekab7b32b2008-11-19 00:27:37 +0000358 return L;
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000359 }
360}
361
Zhongxing Xu6e3f01c2008-10-31 07:16:08 +0000362SVal RegionStoreManager::RetrieveStruct(Store store, const TypedRegion* R) {
363 QualType T = R->getType(getContext());
364 assert(T->isStructureType());
365
366 const RecordType* RT = cast<RecordType>(T.getTypePtr());
367 RecordDecl* RD = RT->getDecl();
368 assert(RD->isDefinition());
369
370 llvm::ImmutableList<SVal> StructVal = getBasicVals().getEmptySValList();
371
372 for (int i = RD->getNumMembers() - 1; i >= 0; --i) {
373 FieldRegion* FR = MRMgr.getFieldRegion(RD->getMember(i), R);
374 RegionBindingsTy B(static_cast<const RegionBindingsTy::TreeTy*>(store));
Zhongxing Xuf0dfa8d2008-10-31 08:10:01 +0000375 RegionBindingsTy::data_type* data = B.lookup(FR);
Zhongxing Xu6e3f01c2008-10-31 07:16:08 +0000376
377 SVal FieldValue = data ? *data : UnknownVal();
378
379 StructVal = getBasicVals().consVals(FieldValue, StructVal);
380 }
381
382 return NonLoc::MakeCompoundVal(T, StructVal, getBasicVals());
383}
384
Zhongxing Xu8485ec62008-10-21 06:27:32 +0000385Store RegionStoreManager::Bind(Store store, Loc LV, SVal V) {
Zhongxing Xu8fe63af2008-10-27 09:24:07 +0000386 if (LV.getSubKind() == loc::SymbolValKind)
387 return store;
388
Zhongxing Xu1c96b242008-10-17 05:57:07 +0000389 assert(LV.getSubKind() == loc::MemRegionKind);
Zhongxing Xu17892752008-10-08 02:50:44 +0000390
Ted Kremenek993f1c72008-10-17 20:28:54 +0000391 const MemRegion* R = cast<loc::MemRegionVal>(LV).getRegion();
Zhongxing Xu17892752008-10-08 02:50:44 +0000392
Zhongxing Xuf0dfa8d2008-10-31 08:10:01 +0000393 assert(R);
394
395 if (const TypedRegion* TR = dyn_cast<TypedRegion>(R))
396 if (TR->getType(getContext())->isStructureType())
397 return BindStruct(store, TR, V);
Zhongxing Xu17892752008-10-08 02:50:44 +0000398
399 RegionBindingsTy B = GetRegionBindings(store);
400 return V.isUnknown()
401 ? RBFactory.Remove(B, R).getRoot()
402 : RBFactory.Add(B, R, V).getRoot();
403}
404
Zhongxing Xuf0dfa8d2008-10-31 08:10:01 +0000405Store RegionStoreManager::BindStruct(Store store, const TypedRegion* R, SVal V){
406 QualType T = R->getType(getContext());
407 assert(T->isStructureType());
408
409 const RecordType* RT = cast<RecordType>(T.getTypePtr());
410 RecordDecl* RD = RT->getDecl();
Zhongxing Xua4f28ff2008-11-13 08:41:36 +0000411
412 if (!RD->isDefinition()) {
Zhongxing Xuc3a05992008-11-19 11:06:24 +0000413 // This can only occur when a pointer of incomplete struct type is used as a
Zhongxing Xua4f28ff2008-11-13 08:41:36 +0000414 // function argument.
415 assert(V.isUnknown());
416 return store;
417 }
Zhongxing Xuf0dfa8d2008-10-31 08:10:01 +0000418
419 RegionBindingsTy B = GetRegionBindings(store);
420
Zhongxing Xud463d442008-11-02 12:13:30 +0000421 if (isa<UnknownVal>(V))
422 return BindStructToVal(store, R, UnknownVal());
423
Zhongxing Xuf0dfa8d2008-10-31 08:10:01 +0000424 nonloc::CompoundVal& CV = cast<nonloc::CompoundVal>(V);
425
426 nonloc::CompoundVal::iterator VI = CV.begin(), VE = CV.end();
427 RecordDecl::field_iterator FI = RD->field_begin(), FE = RD->field_end();
428
429 for (; FI != FE; ++FI, ++VI) {
430 assert(VI != VE);
431
432 FieldRegion* FR = MRMgr.getFieldRegion(*FI, R);
433
434 B = RBFactory.Add(B, FR, *VI);
435 }
436
437 return B.getRoot();
438}
439
Zhongxing Xu17892752008-10-08 02:50:44 +0000440Store RegionStoreManager::getInitialStore() {
441 typedef LiveVariables::AnalysisDataTy LVDataTy;
442 LVDataTy& D = StateMgr.getLiveVariables().getAnalysisData();
443
444 Store St = RBFactory.GetEmptyMap().getRoot();
445
446 for (LVDataTy::decl_iterator I=D.begin_decl(), E=D.end_decl(); I != E; ++I) {
Douglas Gregor8e9bebd2008-10-21 16:13:35 +0000447 NamedDecl* ND = const_cast<NamedDecl*>(I->first);
Zhongxing Xu17892752008-10-08 02:50:44 +0000448
Douglas Gregor8e9bebd2008-10-21 16:13:35 +0000449 if (VarDecl* VD = dyn_cast<VarDecl>(ND)) {
Zhongxing Xu17892752008-10-08 02:50:44 +0000450 // Punt on static variables for now.
451 if (VD->getStorageClass() == VarDecl::Static)
452 continue;
453
Zhongxing Xuc3a05992008-11-19 11:06:24 +0000454 VarRegion* VR = MRMgr.getVarRegion(VD);
455
Zhongxing Xu17892752008-10-08 02:50:44 +0000456 QualType T = VD->getType();
457 // Only handle pointers and integers for now.
Zhongxing Xu1c96b242008-10-17 05:57:07 +0000458 if (Loc::IsLocType(T) || T->isIntegerType()) {
Zhongxing Xu17892752008-10-08 02:50:44 +0000459 // Initialize globals and parameters to symbolic values.
460 // Initialize local variables to undefined.
Zhongxing Xu1c96b242008-10-17 05:57:07 +0000461 SVal X = (VD->hasGlobalStorage() || isa<ParmVarDecl>(VD) ||
Zhongxing Xu17892752008-10-08 02:50:44 +0000462 isa<ImplicitParamDecl>(VD))
Zhongxing Xu63123d82008-11-23 04:30:35 +0000463 ? SVal::GetSymbolValue(getSymbolManager(), VD)
Zhongxing Xu17892752008-10-08 02:50:44 +0000464 : UndefinedVal();
465
Zhongxing Xu8485ec62008-10-21 06:27:32 +0000466 St = Bind(St, getVarLoc(VD), X);
Zhongxing Xuc3a05992008-11-19 11:06:24 +0000467 }
468 else if (T->isArrayType()) {
469 if (VD->hasGlobalStorage()) // Params cannot have array type.
470 St = BindArrayToSymVal(St, VR);
471 else
472 St = BindArrayToVal(St, VR, UndefinedVal());
473 }
474 else if (T->isStructureType()) {
475 if (VD->hasGlobalStorage() || isa<ParmVarDecl>(VD) ||
476 isa<ImplicitParamDecl>(VD))
477 St = BindStructToSymVal(St, VR);
478 else
479 St = BindStructToVal(St, VR, UndefinedVal());
Zhongxing Xu17892752008-10-08 02:50:44 +0000480 }
481 }
482 }
483 return St;
484}
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000485
Ted Kremenek42577d12008-11-12 19:18:35 +0000486Store RegionStoreManager::BindDecl(Store store, const VarDecl* VD,
487 SVal* InitVal, unsigned Count) {
488
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000489 if (VD->hasGlobalStorage()) {
490 // Static global variables should not be visited here.
491 assert(!(VD->getStorageClass() == VarDecl::Static &&
492 VD->isFileVarDecl()));
493 // Process static variables.
494 if (VD->getStorageClass() == VarDecl::Static) {
Ted Kremenek42577d12008-11-12 19:18:35 +0000495 if (!InitVal) {
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000496 // Only handle pointer and integer static variables.
497
498 QualType T = VD->getType();
499
500 if (Loc::IsLocType(T))
Zhongxing Xu8485ec62008-10-21 06:27:32 +0000501 store = Bind(store, getVarLoc(VD),
Zhongxing Xu63123d82008-11-23 04:30:35 +0000502 loc::ConcreteInt(getBasicVals().getValue(0, T)));
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000503
504 else if (T->isIntegerType())
Zhongxing Xu8485ec62008-10-21 06:27:32 +0000505 store = Bind(store, getVarLoc(VD),
Zhongxing Xu63123d82008-11-23 04:30:35 +0000506 loc::ConcreteInt(getBasicVals().getValue(0, T)));
Zhongxing Xu1a12a0e2008-10-31 10:24:47 +0000507
508 // Other types of static local variables are not handled yet.
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000509 } else {
Ted Kremenek42577d12008-11-12 19:18:35 +0000510 store = Bind(store, getVarLoc(VD), *InitVal);
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000511 }
512 }
513 } else {
514 // Process local variables.
515
516 QualType T = VD->getType();
517
Zhongxing Xua82512a2008-10-24 08:42:28 +0000518 VarRegion* VR = MRMgr.getVarRegion(VD);
519
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000520 if (Loc::IsLocType(T) || T->isIntegerType()) {
Ted Kremenek42577d12008-11-12 19:18:35 +0000521 SVal V = InitVal ? *InitVal : UndefinedVal();
Zhongxing Xua82512a2008-10-24 08:42:28 +0000522 store = Bind(store, loc::MemRegionVal(VR), V);
Ted Kremenek42577d12008-11-12 19:18:35 +0000523 }
524 else if (T->isArrayType()) {
525 if (!InitVal)
Zhongxing Xud463d442008-11-02 12:13:30 +0000526 store = BindArrayToVal(store, VR, UndefinedVal());
Zhongxing Xu1a12a0e2008-10-31 10:24:47 +0000527 else
Ted Kremenek42577d12008-11-12 19:18:35 +0000528 store = InitializeArray(store, VR, *InitVal);
529 }
530 else if (T->isStructureType()) {
531 if (!InitVal)
Zhongxing Xud463d442008-11-02 12:13:30 +0000532 store = BindStructToVal(store, VR, UndefinedVal());
Zhongxing Xuaf0a8442008-10-31 10:53:01 +0000533 else
Ted Kremenek42577d12008-11-12 19:18:35 +0000534 store = InitializeStruct(store, VR, *InitVal);
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000535 }
Zhongxing Xu1a12a0e2008-10-31 10:24:47 +0000536
537 // Other types of local variables are not handled yet.
Zhongxing Xu53bcdd42008-10-21 05:29:26 +0000538 }
539 return store;
540}
541
Zhongxing Xuf22679e2008-11-07 10:38:33 +0000542Store RegionStoreManager::BindCompoundLiteral(Store store,
543 const CompoundLiteralExpr* CL,
544 SVal V) {
545 CompoundLiteralRegion* R = MRMgr.getCompoundLiteralRegion(CL);
546 store = Bind(store, loc::MemRegionVal(R), V);
547 return store;
548}
549
Zhongxing Xu8916d5b2008-11-10 09:39:04 +0000550Store RegionStoreManager::RemoveDeadBindings(Store store, Stmt* Loc,
551 const LiveVariables& Live,
552 llvm::SmallVectorImpl<const MemRegion*>& RegionRoots,
553 LiveSymbolsTy& LSymbols, DeadSymbolsTy& DSymbols) {
554
555 RegionBindingsTy B = GetRegionBindings(store);
556 typedef SVal::symbol_iterator symbol_iterator;
557
558 // FIXME: Mark all region binding value's symbol as live. We also omit symbols
559 // in SymbolicRegions.
560 for (RegionBindingsTy::iterator I = B.begin(), E = B.end(); I != E; ++I) {
561 SVal X = I.getData();
562 for (symbol_iterator SI=X.symbol_begin(), SE=X.symbol_end(); SI!=SE; ++SI)
563 LSymbols.insert(*SI);
564 }
565
566 return store;
567}
568
Zhongxing Xua071eb02008-10-24 06:01:33 +0000569void RegionStoreManager::print(Store store, std::ostream& Out,
570 const char* nl, const char *sep) {
571 llvm::raw_os_ostream OS(Out);
572 RegionBindingsTy B = GetRegionBindings(store);
573 OS << "Store:" << nl;
574
575 for (RegionBindingsTy::iterator I = B.begin(), E = B.end(); I != E; ++I) {
576 OS << ' '; I.getKey()->print(OS); OS << " : ";
577 I.getData().print(OS); OS << nl;
578 }
Zhongxing Xu5b8b6f22008-10-24 04:33:15 +0000579}
Zhongxing Xua82512a2008-10-24 08:42:28 +0000580
Zhongxing Xud463d442008-11-02 12:13:30 +0000581Store RegionStoreManager::InitializeArray(Store store, const TypedRegion* R,
Zhongxing Xu1a12a0e2008-10-31 10:24:47 +0000582 SVal Init) {
583 QualType T = R->getType(getContext());
584 assert(T->isArrayType());
585
586 ConstantArrayType* CAT = cast<ConstantArrayType>(T.getTypePtr());
587
588 llvm::APInt Size = CAT->getSize();
589
590 llvm::APInt i = llvm::APInt::getNullValue(Size.getBitWidth());
591
592 nonloc::CompoundVal& CV = cast<nonloc::CompoundVal>(Init);
593
594 nonloc::CompoundVal::iterator VI = CV.begin(), VE = CV.end();
595
596 for (; i != Size; ++i) {
597 nonloc::ConcreteInt Idx(getBasicVals().getValue(llvm::APSInt(i)));
598
599 ElementRegion* ER = MRMgr.getElementRegion(Idx, R);
600
601 store = Bind(store, loc::MemRegionVal(ER), (VI!=VE) ? *VI : UndefinedVal());
602 // The init list might be shorter than the array decl.
603 if (VI != VE) ++VI;
604 }
605
606 return store;
607}
608
Zhongxing Xud463d442008-11-02 12:13:30 +0000609// Bind all elements of the array to some value.
610Store RegionStoreManager::BindArrayToVal(Store store, const TypedRegion* BaseR,
611 SVal V){
Zhongxing Xuea8a1852008-10-31 11:02:48 +0000612 QualType T = BaseR->getType(getContext());
Zhongxing Xua82512a2008-10-24 08:42:28 +0000613 assert(T->isArrayType());
614
Zhongxing Xua82512a2008-10-24 08:42:28 +0000615 // Only handle constant size array for now.
616 if (ConstantArrayType* CAT=dyn_cast<ConstantArrayType>(T.getTypePtr())) {
617
618 llvm::APInt Size = CAT->getSize();
Zhongxing Xu1a12a0e2008-10-31 10:24:47 +0000619 llvm::APInt i = llvm::APInt::getNullValue(Size.getBitWidth());
620 for (; i != Size; ++i) {
Zhongxing Xuea8a1852008-10-31 11:02:48 +0000621 nonloc::ConcreteInt Idx(getBasicVals().getValue(llvm::APSInt(i)));
Zhongxing Xua82512a2008-10-24 08:42:28 +0000622
623 ElementRegion* ER = MRMgr.getElementRegion(Idx, BaseR);
624
Zhongxing Xu9b6ceb12008-11-18 13:11:04 +0000625 if (CAT->getElementType()->isStructureType())
626 store = BindStructToVal(store, ER, V);
627 else
628 store = Bind(store, loc::MemRegionVal(ER), V);
Zhongxing Xua82512a2008-10-24 08:42:28 +0000629 }
630 }
631
632 return store;
633}
634
Zhongxing Xuc3a05992008-11-19 11:06:24 +0000635Store RegionStoreManager::BindArrayToSymVal(Store store,
636 const TypedRegion* BaseR) {
637 QualType T = BaseR->getType(getContext());
638 assert(T->isArrayType());
639
640 if (ConstantArrayType* CAT = dyn_cast<ConstantArrayType>(T.getTypePtr())) {
641 llvm::APInt Size = CAT->getSize();
642 llvm::APInt i = llvm::APInt::getNullValue(Size.getBitWidth());
643 for (; i != Size; ++i) {
644 nonloc::ConcreteInt Idx(getBasicVals().getValue(llvm::APSInt(i)));
645
646 ElementRegion* ER = MRMgr.getElementRegion(Idx, BaseR);
647
648 if (CAT->getElementType()->isStructureType()) {
649 store = BindStructToSymVal(store, ER);
650 }
651 else {
652 SVal V = SVal::getSymbolValue(getSymbolManager(), BaseR,
653 &Idx.getValue(), CAT->getElementType());
654 store = Bind(store, loc::MemRegionVal(ER), V);
655 }
656 }
657 }
658
659 return store;
660}
661
Zhongxing Xud463d442008-11-02 12:13:30 +0000662Store RegionStoreManager::InitializeStruct(Store store, const TypedRegion* R,
Zhongxing Xuea8a1852008-10-31 11:02:48 +0000663 SVal Init) {
Zhongxing Xuaf0a8442008-10-31 10:53:01 +0000664 QualType T = R->getType(getContext());
665 assert(T->isStructureType());
666
667 RecordType* RT = cast<RecordType>(T.getTypePtr());
668 RecordDecl* RD = RT->getDecl();
669 assert(RD->isDefinition());
670
671 nonloc::CompoundVal& CV = cast<nonloc::CompoundVal>(Init);
672 nonloc::CompoundVal::iterator VI = CV.begin(), VE = CV.end();
673 RecordDecl::field_iterator FI = RD->field_begin(), FE = RD->field_end();
674
675 for (; FI != FE; ++FI) {
676 QualType FTy = (*FI)->getType();
677 FieldRegion* FR = MRMgr.getFieldRegion(*FI, R);
678
679 if (Loc::IsLocType(FTy) || FTy->isIntegerType()) {
680 if (VI != VE) {
681 store = Bind(store, loc::MemRegionVal(FR), *VI);
682 ++VI;
683 } else
684 store = Bind(store, loc::MemRegionVal(FR), UndefinedVal());
685 }
686 else if (FTy->isArrayType()) {
687 if (VI != VE) {
688 store = InitializeArray(store, FR, *VI);
689 ++VI;
690 } else
Zhongxing Xud463d442008-11-02 12:13:30 +0000691 store = BindArrayToVal(store, FR, UndefinedVal());
Zhongxing Xuaf0a8442008-10-31 10:53:01 +0000692 }
693 else if (FTy->isStructureType()) {
694 if (VI != VE) {
695 store = InitializeStruct(store, FR, *VI);
696 ++VI;
697 } else
Zhongxing Xud463d442008-11-02 12:13:30 +0000698 store = BindStructToVal(store, FR, UndefinedVal());
Zhongxing Xuaf0a8442008-10-31 10:53:01 +0000699 }
700 }
701 return store;
702}
703
Zhongxing Xud463d442008-11-02 12:13:30 +0000704// Bind all fields of the struct to some value.
705Store RegionStoreManager::BindStructToVal(Store store, const TypedRegion* BaseR,
706 SVal V) {
Zhongxing Xuea8a1852008-10-31 11:02:48 +0000707 QualType T = BaseR->getType(getContext());
708 assert(T->isStructureType());
709
710 const RecordType* RT = cast<RecordType>(T.getTypePtr());
Zhongxing Xua82512a2008-10-24 08:42:28 +0000711 RecordDecl* RD = RT->getDecl();
712 assert(RD->isDefinition());
Zhongxing Xuea8a1852008-10-31 11:02:48 +0000713
714 RecordDecl::field_iterator I = RD->field_begin(), E = RD->field_end();
715
716 for (; I != E; ++I) {
Zhongxing Xua82512a2008-10-24 08:42:28 +0000717
718 QualType FTy = (*I)->getType();
719 FieldRegion* FR = MRMgr.getFieldRegion(*I, BaseR);
720
721 if (Loc::IsLocType(FTy) || FTy->isIntegerType()) {
Zhongxing Xud463d442008-11-02 12:13:30 +0000722 store = Bind(store, loc::MemRegionVal(FR), V);
Zhongxing Xua82512a2008-10-24 08:42:28 +0000723
724 } else if (FTy->isArrayType()) {
Zhongxing Xud463d442008-11-02 12:13:30 +0000725 store = BindArrayToVal(store, FR, V);
Zhongxing Xua82512a2008-10-24 08:42:28 +0000726
727 } else if (FTy->isStructureType()) {
Zhongxing Xud463d442008-11-02 12:13:30 +0000728 store = BindStructToVal(store, FR, V);
Zhongxing Xua82512a2008-10-24 08:42:28 +0000729 }
730 }
731
732 return store;
733}
Zhongxing Xudc0a25d2008-11-16 04:07:26 +0000734
Zhongxing Xuc3a05992008-11-19 11:06:24 +0000735Store RegionStoreManager::BindStructToSymVal(Store store,
736 const TypedRegion* BaseR) {
737 QualType T = BaseR->getType(getContext());
738 assert(T->isStructureType());
739
740 const RecordType* RT = cast<RecordType>(T.getTypePtr());
741 RecordDecl* RD = RT->getDecl();
742 assert(RD->isDefinition());
743
744 RecordDecl::field_iterator I = RD->field_begin(), E = RD->field_end();
745
746 for (; I != E; ++I) {
747 QualType FTy = (*I)->getType();
748 FieldRegion* FR = MRMgr.getFieldRegion(*I, BaseR);
749
750 if (Loc::IsLocType(FTy) || FTy->isIntegerType()) {
751 store = Bind(store, loc::MemRegionVal(FR),
752 SVal::getSymbolValue(getSymbolManager(), BaseR, *I, FTy));
753 }
754 else if (FTy->isArrayType()) {
755 store = BindArrayToSymVal(store, FR);
756 }
757 else if (FTy->isStructureType()) {
758 store = BindStructToSymVal(store, FR);
759 }
760 }
761
762 return store;
763}
764
Zhongxing Xudc0a25d2008-11-16 04:07:26 +0000765const GRState* RegionStoreManager::AddRegionView(const GRState* St,
766 const MemRegion* View,
767 const MemRegion* Base) {
768 GRStateRef state(St, StateMgr);
769
770 // First, retrieve the region view of the base region.
771 RegionViewMapTy::data_type* d = state.get<RegionViewMapTy>(Base);
772 RegionViewTy L = d ? *d : RVFactory.GetEmptyList();
773
774 // Now add View to the region view.
775 L = RVFactory.Add(View, L);
776
777 // Create a new state with the new region view.
778 return state.set<RegionViewMapTy>(Base, L);
779}