blob: c2b8c115fdb17ce46ffee29def61f35538f2688b [file] [log] [blame]
Ted Kremenekf6c62f32008-02-13 17:41:41 +00001//==- GRCoreEngine.cpp - Path-Sensitive Dataflow Engine ----------------*- C++ -*-//
Ted Kremenek3e743662008-01-14 23:24:37 +00002//
3// The LLVM Compiler Infrastructure
4//
5// This file is distributed under the University of Illinois Open Source
6// License. See LICENSE.TXT for details.
7//
8//===----------------------------------------------------------------------===//
9//
10// This file defines a generic engine for intraprocedural, path-sensitive,
11// dataflow analysis via graph reachability engine.
12//
13//===----------------------------------------------------------------------===//
14
Ted Kremenekf6c62f32008-02-13 17:41:41 +000015#include "clang/Analysis/PathSensitive/GRCoreEngine.h"
Ted Kremenek3e743662008-01-14 23:24:37 +000016#include "clang/AST/Expr.h"
17#include "llvm/Support/Compiler.h"
18#include "llvm/Support/Casting.h"
19#include "llvm/ADT/DenseMap.h"
20#include <vector>
21
22using llvm::cast;
23using llvm::isa;
24using namespace clang;
25
26namespace {
27 class VISIBILITY_HIDDEN DFS : public GRWorkList {
28 llvm::SmallVector<GRWorkListUnit,20> Stack;
29public:
30 virtual bool hasWork() const {
31 return !Stack.empty();
32 }
33
34 virtual void Enqueue(const GRWorkListUnit& U) {
35 Stack.push_back(U);
36 }
37
38 virtual GRWorkListUnit Dequeue() {
39 assert (!Stack.empty());
40 const GRWorkListUnit& U = Stack.back();
41 Stack.pop_back(); // This technically "invalidates" U, but we are fine.
42 return U;
43 }
44};
45} // end anonymous namespace
46
Ted Kremenek2e12c2e2008-01-16 18:18:48 +000047// Place the dstor for GRWorkList here because it contains virtual member
48// functions, and we the code for the dstor generated in one compilation unit.
49GRWorkList::~GRWorkList() {}
50
Ted Kremenek3e743662008-01-14 23:24:37 +000051GRWorkList* GRWorkList::MakeDFS() { return new DFS(); }
52
53/// ExecuteWorkList - Run the worklist algorithm for a maximum number of steps.
Ted Kremenekf6c62f32008-02-13 17:41:41 +000054bool GRCoreEngineImpl::ExecuteWorkList(unsigned Steps) {
Ted Kremenek3e743662008-01-14 23:24:37 +000055
56 if (G->num_roots() == 0) { // Initialize the analysis by constructing
57 // the root if none exists.
58
Ted Kremenek997d8722008-01-29 00:33:40 +000059 CFGBlock* Entry = &getCFG().getEntry();
Ted Kremenek3e743662008-01-14 23:24:37 +000060
61 assert (Entry->empty() &&
62 "Entry block must be empty.");
63
64 assert (Entry->succ_size() == 1 &&
65 "Entry block must have 1 successor.");
66
67 // Get the solitary successor.
68 CFGBlock* Succ = *(Entry->succ_begin());
69
70 // Construct an edge representing the
71 // starting location in the function.
Ted Kremenek997d8722008-01-29 00:33:40 +000072 BlockEdge StartLoc(getCFG(), Entry, Succ);
Ted Kremenek3e743662008-01-14 23:24:37 +000073
Ted Kremenek90ae68f2008-02-12 18:08:17 +000074 // Set the current block counter to being empty.
75 WList->setBlockCounter(BCounterFactory.GetEmptyCounter());
76
Ted Kremenek3e743662008-01-14 23:24:37 +000077 // Generate the root.
78 GenerateNode(StartLoc, getInitialState());
79 }
80
81 while (Steps && WList->hasWork()) {
82 --Steps;
83 const GRWorkListUnit& WU = WList->Dequeue();
Ted Kremenek90ae68f2008-02-12 18:08:17 +000084
85 // Set the current block counter.
86 WList->setBlockCounter(WU.getBlockCounter());
87
88 // Retrieve the node.
Ted Kremenek3e743662008-01-14 23:24:37 +000089 ExplodedNodeImpl* Node = WU.getNode();
90
91 // Dispatch on the location type.
92 switch (Node->getLocation().getKind()) {
93 default:
94 assert (isa<BlockEdge>(Node->getLocation()));
95 HandleBlockEdge(cast<BlockEdge>(Node->getLocation()), Node);
96 break;
97
98 case ProgramPoint::BlockEntranceKind:
99 HandleBlockEntrance(cast<BlockEntrance>(Node->getLocation()), Node);
100 break;
101
102 case ProgramPoint::BlockExitKind:
Ted Kremeneke5843592008-01-15 00:24:08 +0000103 assert (false && "BlockExit location never occur in forward analysis.");
Ted Kremenek3e743662008-01-14 23:24:37 +0000104 break;
105
106 case ProgramPoint::PostStmtKind:
107 HandlePostStmt(cast<PostStmt>(Node->getLocation()), WU.getBlock(),
108 WU.getIndex(), Node);
109 break;
110 }
111 }
112
113 return WList->hasWork();
114}
115
Ted Kremenekdf4a5b92008-03-05 19:08:15 +0000116void GRCoreEngineImpl::HandleBlockEdge(const BlockEdge& L,
117 ExplodedNodeImpl* Pred) {
Ted Kremenek3e743662008-01-14 23:24:37 +0000118
119 CFGBlock* Blk = L.getDst();
120
121 // Check if we are entering the EXIT block.
Ted Kremenek997d8722008-01-29 00:33:40 +0000122 if (Blk == &getCFG().getExit()) {
Ted Kremenek3e743662008-01-14 23:24:37 +0000123
Ted Kremenek997d8722008-01-29 00:33:40 +0000124 assert (getCFG().getExit().size() == 0
125 && "EXIT block cannot contain Stmts.");
Ted Kremenek3e743662008-01-14 23:24:37 +0000126
Ted Kremenek811c2b42008-04-11 22:03:04 +0000127 // Process the final state transition.
128 GREndPathNodeBuilderImpl Builder(Blk, Pred, this);
129 ProcessEndPath(Builder);
Ted Kremenek3e743662008-01-14 23:24:37 +0000130
Ted Kremenek3e743662008-01-14 23:24:37 +0000131 // This path is done. Don't enqueue any more nodes.
132 return;
133 }
Ted Kremenek17f4dbd2008-02-29 20:27:50 +0000134
135 // FIXME: Should we allow ProcessBlockEntrance to also manipulate state?
Ted Kremenek3e743662008-01-14 23:24:37 +0000136
Ted Kremenek17f4dbd2008-02-29 20:27:50 +0000137 if (ProcessBlockEntrance(Blk, Pred->State, WList->getBlockCounter()))
138 GenerateNode(BlockEntrance(Blk), Pred->State, Pred);
Ted Kremenek3e743662008-01-14 23:24:37 +0000139}
140
Ted Kremenekf6c62f32008-02-13 17:41:41 +0000141void GRCoreEngineImpl::HandleBlockEntrance(const BlockEntrance& L,
Ted Kremenekdf4a5b92008-03-05 19:08:15 +0000142 ExplodedNodeImpl* Pred) {
Ted Kremenek3e743662008-01-14 23:24:37 +0000143
Ted Kremenek90ae68f2008-02-12 18:08:17 +0000144 // Increment the block counter.
145 GRBlockCounter Counter = WList->getBlockCounter();
146 Counter = BCounterFactory.IncrementCount(Counter, L.getBlock()->getBlockID());
147 WList->setBlockCounter(Counter);
148
149 // Process the entrance of the block.
Ted Kremenek3e743662008-01-14 23:24:37 +0000150 if (Stmt* S = L.getFirstStmt()) {
Ted Kremenekb2cad312008-01-29 22:11:49 +0000151 GRStmtNodeBuilderImpl Builder(L.getBlock(), 0, Pred, this);
Ted Kremenek3e743662008-01-14 23:24:37 +0000152 ProcessStmt(S, Builder);
153 }
Ted Kremeneke5843592008-01-15 00:24:08 +0000154 else
155 HandleBlockExit(L.getBlock(), Pred);
Ted Kremenek3e743662008-01-14 23:24:37 +0000156}
157
158
Ted Kremenekf6c62f32008-02-13 17:41:41 +0000159void GRCoreEngineImpl::HandleBlockExit(CFGBlock * B, ExplodedNodeImpl* Pred) {
Ted Kremenek3e743662008-01-14 23:24:37 +0000160
Ted Kremenek9b4211d2008-01-29 22:56:11 +0000161 if (Stmt* Term = B->getTerminator()) {
162 switch (Term->getStmtClass()) {
163 default:
164 assert(false && "Analysis for this terminator not implemented.");
165 break;
Ted Kremenek822f7372008-02-12 21:51:20 +0000166
167 case Stmt::BinaryOperatorClass: // '&&' and '||'
168 HandleBranch(cast<BinaryOperator>(Term)->getLHS(), Term, B, Pred);
169 return;
Ted Kremenek9b4211d2008-01-29 22:56:11 +0000170
Ted Kremenek3f2f1ad2008-02-05 00:26:40 +0000171 case Stmt::ConditionalOperatorClass:
172 HandleBranch(cast<ConditionalOperator>(Term)->getCond(), Term, B, Pred);
Ted Kremenek822f7372008-02-12 21:51:20 +0000173 return;
174
175 // FIXME: Use constant-folding in CFG construction to simplify this
176 // case.
Ted Kremenek3f2f1ad2008-02-05 00:26:40 +0000177
178 case Stmt::ChooseExprClass:
179 HandleBranch(cast<ChooseExpr>(Term)->getCond(), Term, B, Pred);
Ted Kremenek822f7372008-02-12 21:51:20 +0000180 return;
Ted Kremenek3f2f1ad2008-02-05 00:26:40 +0000181
Ted Kremenek822f7372008-02-12 21:51:20 +0000182 case Stmt::DoStmtClass:
183 HandleBranch(cast<DoStmt>(Term)->getCond(), Term, B, Pred);
184 return;
185
186 case Stmt::ForStmtClass:
187 HandleBranch(cast<ForStmt>(Term)->getCond(), Term, B, Pred);
188 return;
Ted Kremenek632bcb82008-02-13 16:56:51 +0000189
190 case Stmt::ContinueStmtClass:
191 case Stmt::BreakStmtClass:
192 case Stmt::GotoStmtClass:
Ted Kremenek3f2f1ad2008-02-05 00:26:40 +0000193 break;
194
Ted Kremenek9b4211d2008-01-29 22:56:11 +0000195 case Stmt::IfStmtClass:
196 HandleBranch(cast<IfStmt>(Term)->getCond(), Term, B, Pred);
Ted Kremenek822f7372008-02-12 21:51:20 +0000197 return;
Ted Kremenek7022efb2008-02-13 00:24:44 +0000198
199 case Stmt::IndirectGotoStmtClass: {
200 // Only 1 successor: the indirect goto dispatch block.
201 assert (B->succ_size() == 1);
202
203 GRIndirectGotoNodeBuilderImpl
204 builder(Pred, B, cast<IndirectGotoStmt>(Term)->getTarget(),
205 *(B->succ_begin()), this);
206
207 ProcessIndirectGoto(builder);
208 return;
209 }
Ted Kremenek9b4211d2008-01-29 22:56:11 +0000210
Ted Kremenek80ebc1d2008-02-13 23:08:21 +0000211 case Stmt::SwitchStmtClass: {
212 GRSwitchNodeBuilderImpl builder(Pred, B,
213 cast<SwitchStmt>(Term)->getCond(),
214 this);
215
216 ProcessSwitch(builder);
217 return;
218 }
219
Ted Kremenek9b4211d2008-01-29 22:56:11 +0000220 case Stmt::WhileStmtClass:
221 HandleBranch(cast<WhileStmt>(Term)->getCond(), Term, B, Pred);
Ted Kremenek822f7372008-02-12 21:51:20 +0000222 return;
Ted Kremenek9b4211d2008-01-29 22:56:11 +0000223 }
224 }
Ted Kremenek822f7372008-02-12 21:51:20 +0000225
226 assert (B->succ_size() == 1 &&
227 "Blocks with no terminator should have at most 1 successor.");
Ted Kremenek3e743662008-01-14 23:24:37 +0000228
Ted Kremenek822f7372008-02-12 21:51:20 +0000229 GenerateNode(BlockEdge(getCFG(),B,*(B->succ_begin())), Pred->State, Pred);
Ted Kremenek3e743662008-01-14 23:24:37 +0000230}
231
Ted Kremenekf6c62f32008-02-13 17:41:41 +0000232void GRCoreEngineImpl::HandleBranch(Expr* Cond, Stmt* Term, CFGBlock * B,
Ted Kremenek9b4211d2008-01-29 22:56:11 +0000233 ExplodedNodeImpl* Pred) {
234 assert (B->succ_size() == 2);
235
Ted Kremenek90ae68f2008-02-12 18:08:17 +0000236 GRBranchNodeBuilderImpl Builder(B, *(B->succ_begin()), *(B->succ_begin()+1),
Ted Kremenek9b4211d2008-01-29 22:56:11 +0000237 Pred, this);
238
239 ProcessBranch(Cond, Term, Builder);
240}
241
Ted Kremenekf6c62f32008-02-13 17:41:41 +0000242void GRCoreEngineImpl::HandlePostStmt(const PostStmt& L, CFGBlock* B,
Ted Kremenek3e743662008-01-14 23:24:37 +0000243 unsigned StmtIdx, ExplodedNodeImpl* Pred) {
244
245 assert (!B->empty());
246
Ted Kremeneke5843592008-01-15 00:24:08 +0000247 if (StmtIdx == B->size())
248 HandleBlockExit(B, Pred);
Ted Kremenek3e743662008-01-14 23:24:37 +0000249 else {
Ted Kremenekb2cad312008-01-29 22:11:49 +0000250 GRStmtNodeBuilderImpl Builder(B, StmtIdx, Pred, this);
Ted Kremeneke914bb82008-01-16 22:13:19 +0000251 ProcessStmt((*B)[StmtIdx], Builder);
Ted Kremenek3e743662008-01-14 23:24:37 +0000252 }
253}
254
255typedef llvm::DenseMap<Stmt*,Stmt*> ParentMapTy;
256/// PopulateParentMap - Recurse the AST starting at 'Parent' and add the
257/// mappings between child and parent to ParentMap.
258static void PopulateParentMap(Stmt* Parent, ParentMapTy& M) {
259 for (Stmt::child_iterator I=Parent->child_begin(),
260 E=Parent->child_end(); I!=E; ++I) {
261
262 assert (M.find(*I) == M.end());
263 M[*I] = Parent;
264 PopulateParentMap(*I, M);
265 }
266}
267
268/// GenerateNode - Utility method to generate nodes, hook up successors,
269/// and add nodes to the worklist.
Ted Kremenekf6c62f32008-02-13 17:41:41 +0000270void GRCoreEngineImpl::GenerateNode(const ProgramPoint& Loc, void* State,
Ted Kremenek3e743662008-01-14 23:24:37 +0000271 ExplodedNodeImpl* Pred) {
272
273 bool IsNew;
274 ExplodedNodeImpl* Node = G->getNodeImpl(Loc, State, &IsNew);
275
276 if (Pred)
277 Node->addPredecessor(Pred); // Link 'Node' with its predecessor.
278 else {
279 assert (IsNew);
280 G->addRoot(Node); // 'Node' has no predecessor. Make it a root.
281 }
282
283 // Only add 'Node' to the worklist if it was freshly generated.
Ted Kremenek90ae68f2008-02-12 18:08:17 +0000284 if (IsNew) WList->Enqueue(Node);
Ted Kremenek3e743662008-01-14 23:24:37 +0000285}
286
Ted Kremenekb2cad312008-01-29 22:11:49 +0000287GRStmtNodeBuilderImpl::GRStmtNodeBuilderImpl(CFGBlock* b, unsigned idx,
Ted Kremenekf6c62f32008-02-13 17:41:41 +0000288 ExplodedNodeImpl* N, GRCoreEngineImpl* e)
Ted Kremenekc072b822008-04-18 20:35:30 +0000289 : Eng(*e), B(*b), Idx(idx), Pred(N), LastNode(N) {
Ted Kremenek3e743662008-01-14 23:24:37 +0000290 Deferred.insert(N);
291}
292
Ted Kremenekb2cad312008-01-29 22:11:49 +0000293GRStmtNodeBuilderImpl::~GRStmtNodeBuilderImpl() {
Ted Kremenek3e743662008-01-14 23:24:37 +0000294 for (DeferredTy::iterator I=Deferred.begin(), E=Deferred.end(); I!=E; ++I)
Ted Kremeneka50d9852008-01-30 23:03:39 +0000295 if (!(*I)->isSink())
Ted Kremenek3e743662008-01-14 23:24:37 +0000296 GenerateAutoTransition(*I);
297}
298
Ted Kremenekb2cad312008-01-29 22:11:49 +0000299void GRStmtNodeBuilderImpl::GenerateAutoTransition(ExplodedNodeImpl* N) {
Ted Kremeneka50d9852008-01-30 23:03:39 +0000300 assert (!N->isSink());
Ted Kremenek3e743662008-01-14 23:24:37 +0000301
302 PostStmt Loc(getStmt());
303
304 if (Loc == N->getLocation()) {
305 // Note: 'N' should be a fresh node because otherwise it shouldn't be
306 // a member of Deferred.
307 Eng.WList->Enqueue(N, B, Idx+1);
308 return;
309 }
310
311 bool IsNew;
312 ExplodedNodeImpl* Succ = Eng.G->getNodeImpl(Loc, N->State, &IsNew);
313 Succ->addPredecessor(N);
314
315 if (IsNew)
316 Eng.WList->Enqueue(Succ, B, Idx+1);
317}
318
Ted Kremenekb2cad312008-01-29 22:11:49 +0000319ExplodedNodeImpl* GRStmtNodeBuilderImpl::generateNodeImpl(Stmt* S, void* State,
Ted Kremenek3e743662008-01-14 23:24:37 +0000320 ExplodedNodeImpl* Pred) {
321
322 bool IsNew;
323 ExplodedNodeImpl* N = Eng.G->getNodeImpl(PostStmt(S), State, &IsNew);
324 N->addPredecessor(Pred);
325 Deferred.erase(Pred);
326
Ted Kremenek3e743662008-01-14 23:24:37 +0000327 if (IsNew) {
328 Deferred.insert(N);
329 LastNode = N;
330 return N;
331 }
332
333 LastNode = NULL;
334 return NULL;
335}
Ted Kremenek9b4211d2008-01-29 22:56:11 +0000336
Ted Kremeneka50d9852008-01-30 23:03:39 +0000337ExplodedNodeImpl* GRBranchNodeBuilderImpl::generateNodeImpl(void* State,
338 bool branch) {
Ted Kremenek9b4211d2008-01-29 22:56:11 +0000339 bool IsNew;
340
341 ExplodedNodeImpl* Succ =
342 Eng.G->getNodeImpl(BlockEdge(Eng.getCFG(), Src, branch ? DstT : DstF),
343 State, &IsNew);
344
345 Succ->addPredecessor(Pred);
346
Ted Kremenek7ff18932008-01-29 23:32:35 +0000347 if (branch) GeneratedTrue = true;
348 else GeneratedFalse = true;
349
Ted Kremeneka50d9852008-01-30 23:03:39 +0000350 if (IsNew) {
Ted Kremenek2531fce2008-01-30 23:24:39 +0000351 Deferred.push_back(Succ);
Ted Kremeneka50d9852008-01-30 23:03:39 +0000352 return Succ;
353 }
354
355 return NULL;
Ted Kremenek9b4211d2008-01-29 22:56:11 +0000356}
Ted Kremenek7ff18932008-01-29 23:32:35 +0000357
358GRBranchNodeBuilderImpl::~GRBranchNodeBuilderImpl() {
359 if (!GeneratedTrue) generateNodeImpl(Pred->State, true);
360 if (!GeneratedFalse) generateNodeImpl(Pred->State, false);
Ted Kremenek2531fce2008-01-30 23:24:39 +0000361
362 for (DeferredTy::iterator I=Deferred.begin(), E=Deferred.end(); I!=E; ++I)
Ted Kremenek90ae68f2008-02-12 18:08:17 +0000363 if (!(*I)->isSink()) Eng.WList->Enqueue(*I);
Ted Kremenek7ff18932008-01-29 23:32:35 +0000364}
Ted Kremenek7022efb2008-02-13 00:24:44 +0000365
Ted Kremenek7022efb2008-02-13 00:24:44 +0000366
367ExplodedNodeImpl*
Ted Kremenek2bba9012008-02-13 17:27:37 +0000368GRIndirectGotoNodeBuilderImpl::generateNodeImpl(const Iterator& I,
Ted Kremenek7022efb2008-02-13 00:24:44 +0000369 void* St,
370 bool isSink) {
371 bool IsNew;
372
373 ExplodedNodeImpl* Succ =
Ted Kremenek2bba9012008-02-13 17:27:37 +0000374 Eng.G->getNodeImpl(BlockEdge(Eng.getCFG(), Src, I.getBlock(), true),
Ted Kremenek7022efb2008-02-13 00:24:44 +0000375 St, &IsNew);
376
377 Succ->addPredecessor(Pred);
378
379 if (IsNew) {
380
381 if (isSink)
382 Succ->markAsSink();
383 else
384 Eng.WList->Enqueue(Succ);
385
386 return Succ;
387 }
388
389 return NULL;
390}
Ted Kremenek80ebc1d2008-02-13 23:08:21 +0000391
392
393ExplodedNodeImpl*
394GRSwitchNodeBuilderImpl::generateCaseStmtNodeImpl(const Iterator& I, void* St) {
395
396 bool IsNew;
397
398 ExplodedNodeImpl* Succ = Eng.G->getNodeImpl(BlockEdge(Eng.getCFG(), Src,
399 I.getBlock()),
400 St, &IsNew);
401 Succ->addPredecessor(Pred);
402
403 if (IsNew) {
404 Eng.WList->Enqueue(Succ);
405 return Succ;
406 }
407
408 return NULL;
409}
410
411
412ExplodedNodeImpl*
413GRSwitchNodeBuilderImpl::generateDefaultCaseNodeImpl(void* St, bool isSink) {
414
415 // Get the block for the default case.
416 assert (Src->succ_rbegin() != Src->succ_rend());
417 CFGBlock* DefaultBlock = *Src->succ_rbegin();
418
419 bool IsNew;
420
421 ExplodedNodeImpl* Succ = Eng.G->getNodeImpl(BlockEdge(Eng.getCFG(), Src,
422 DefaultBlock),
423 St, &IsNew);
424 Succ->addPredecessor(Pred);
425
426 if (IsNew) {
427 if (isSink)
428 Succ->markAsSink();
429 else
430 Eng.WList->Enqueue(Succ);
431
432 return Succ;
433 }
434
435 return NULL;
436}
Ted Kremenek811c2b42008-04-11 22:03:04 +0000437
438GREndPathNodeBuilderImpl::~GREndPathNodeBuilderImpl() {
439 // Auto-generate an EOP node if one has not been generated.
440 if (!HasGeneratedNode) generateNodeImpl(Pred->State);
441}
442
443ExplodedNodeImpl* GREndPathNodeBuilderImpl::generateNodeImpl(void* State) {
444 HasGeneratedNode = true;
445
446 bool IsNew;
447
448 ExplodedNodeImpl* Node =
Ted Kremenek86051692008-04-16 22:30:40 +0000449 Eng.G->getNodeImpl(BlockEntrance(&B), State, &IsNew);
Ted Kremenek811c2b42008-04-11 22:03:04 +0000450
451
452 Node->addPredecessor(Pred);
453
454 if (IsNew) {
455 Node->markAsSink();
456 Eng.G->addEndOfPath(Node);
Ted Kremenekd004c412008-04-18 16:30:14 +0000457 return Node;
Ted Kremenek811c2b42008-04-11 22:03:04 +0000458 }
459
Ted Kremenekd004c412008-04-18 16:30:14 +0000460 return NULL;
Ted Kremenek811c2b42008-04-11 22:03:04 +0000461}