blob: e9b8f6a27fe7ed4ebf16b23fcc78e5c8e125e97a [file] [log] [blame]
Ted Kremenekc62abc12009-04-21 21:51:34 +00001//== Store.cpp - Interface for maps from Locations to Values ----*- C++ -*--==//
2//
3// The LLVM Compiler Infrastructure
4//
5// This file is distributed under the University of Illinois Open Source
6// License. See LICENSE.TXT for details.
7//
8//===----------------------------------------------------------------------===//
9//
10// This file defined the types Store and StoreManager.
11//
12//===----------------------------------------------------------------------===//
13
14#include "clang/Analysis/PathSensitive/Store.h"
15#include "clang/Analysis/PathSensitive/GRState.h"
16
17using namespace clang;
18
19StoreManager::StoreManager(GRStateManager &stateMgr)
20 : ValMgr(stateMgr.getValueManager()),
21 StateMgr(stateMgr),
22 MRMgr(ValMgr.getRegionManager()) {}
23
24StoreManager::CastResult
25StoreManager::CastRegion(const GRState* state, const MemRegion* R,
Ted Kremenekfd6b4f32009-05-04 06:35:49 +000026 QualType CastToTy) {
Ted Kremenekc62abc12009-04-21 21:51:34 +000027
Ted Kremenek30d1b992009-04-21 23:31:46 +000028 ASTContext& Ctx = StateMgr.getContext();
29
30 // We need to know the real type of CastToTy.
31 QualType ToTy = Ctx.getCanonicalType(CastToTy);
32
Ted Kremenekc62abc12009-04-21 21:51:34 +000033 // Return the same region if the region types are compatible.
34 if (const TypedRegion* TR = dyn_cast<TypedRegion>(R)) {
Ted Kremenekc62abc12009-04-21 21:51:34 +000035 QualType Ta = Ctx.getCanonicalType(TR->getLValueType(Ctx));
Ted Kremenek30d1b992009-04-21 23:31:46 +000036
37 if (Ta == ToTy)
Ted Kremenekc62abc12009-04-21 21:51:34 +000038 return CastResult(state, R);
39 }
40
Ted Kremenekfd6b4f32009-05-04 06:35:49 +000041 if (const PointerType* PTy = dyn_cast<PointerType>(ToTy.getTypePtr())) {
42 // Check if we are casting to 'void*'.
43 // FIXME: Handle arbitrary upcasts.
44 QualType Pointee = PTy->getPointeeType();
45 if (Pointee->isVoidType()) {
Ted Kremenek30d1b992009-04-21 23:31:46 +000046
47 // Casts to void* only removes TypedViewRegion. If there is no
48 // TypedViewRegion, leave the region untouched. This happens when:
49 //
50 // void foo(void*);
51 // ...
52 // void bar() {
53 // int x;
54 // foo(&x);
55 // }
56
57 if (const TypedViewRegion *TR = dyn_cast<TypedViewRegion>(R))
58 R = TR->removeViews();
59
60 return CastResult(state, R);
61 }
Ted Kremenekfd6b4f32009-05-04 06:35:49 +000062 else if (Pointee->isIntegerType()) {
63 // FIXME: At some point, it stands to reason that this 'dyn_cast' should
64 // become a 'cast' and that 'R' will always be a TypedRegion.
65 if (const TypedRegion *TR = dyn_cast<TypedRegion>(R)) {
66 // Check if we are casting to a region with an integer type. We now
67 // the types aren't the same, so we construct an ElementRegion.
68 // FIXME: We should have a standard query function to get the size
69 // of the array index.
70 SVal Idx = ValMgr.makeZeroVal(ValMgr.getContext().VoidPtrTy);
71 ElementRegion* ER = MRMgr.getElementRegion(Pointee, Idx, TR);
72 return CastResult(state, ER);
73 }
74 }
75 }
Ted Kremenek30d1b992009-04-21 23:31:46 +000076
Ted Kremeneka8607d12009-05-01 19:22:20 +000077 // FIXME: Need to handle arbitrary downcasts.
78 // FIXME: Handle the case where a TypedViewRegion (layering a SymbolicRegion
79 // or an AllocaRegion is cast to another view, thus causing the memory
80 // to be re-used for a different purpose.
Ted Kremenek30d1b992009-04-21 23:31:46 +000081
Ted Kremeneka8607d12009-05-01 19:22:20 +000082 if (isa<SymbolicRegion>(R) || isa<AllocaRegion>(R)) {
83 const MemRegion* ViewR = MRMgr.getTypedViewRegion(CastToTy, R);
84 return CastResult(AddRegionView(state, ViewR, R), ViewR);
85 }
86
87 return CastResult(state, R);
Ted Kremenekc62abc12009-04-21 21:51:34 +000088}