1 /*
   2  * Copyright (C) 2015 Oracle.
   3  *
   4  * This program is free software; you can redistribute it and/or
   5  * modify it under the terms of the GNU General Public License
   6  * as published by the Free Software Foundation; either version 2
   7  * of the License, or (at your option) any later version.
   8  *
   9  * This program is distributed in the hope that it will be useful,
  10  * but WITHOUT ANY WARRANTY; without even the implied warranty of
  11  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
  12  * GNU General Public License for more details.
  13  *
  14  * You should have received a copy of the GNU General Public License
  15  * along with this program; if not, see http://www.gnu.org/copyleft/gpl.txt
  16  */
  17 
  18 /*
  19  * Say we have a line like:
  20  * foo = bar / 8;
  21  * Assume we don't know anything about bar.  Well, now we know that foo is less
  22  * than UINT_MAX / 8.  Which might be useful, but it probably is misleading
  23  * useless knowledge.  Up to now we have ignored those but now we have said to
  24  * store them.
  25  *
  26  * It also works if you have something like "foo = (int)(char)unknown_var;".
  27  *
  28  * I feel like this data doesn't have to be perfect, it just has to be better
  29  * than nothing and that will help eliminate some false positives.
  30  *
  31  */
  32 
  33 #include "smatch.h"
  34 #include "smatch_slist.h"
  35 #include "smatch_extra.h"
  36 
  37 static int my_id;
  38 
  39 void set_real_absolute(struct expression *expr, struct smatch_state *state)
  40 {
  41         set_state_expr(my_id, expr, clone_estate(state));
  42 }
  43 
  44 static void extra_mod_hook(const char *name, struct symbol *sym, struct expression *expr, struct smatch_state *state)
  45 {
  46         struct smatch_state *abs;
  47         struct range_list *rl;
  48 
  49         abs = get_state(my_id, name, sym);
  50         if (!abs || !estate_rl(abs))
  51                 return;
  52         rl = rl_intersection(estate_rl(abs), estate_rl(state));
  53         set_state(my_id, name, sym, alloc_estate_rl(clone_rl(rl)));
  54 }
  55 
  56 static void pre_merge_hook(struct sm_state *cur, struct sm_state *other)
  57 {
  58         struct smatch_state *extra;
  59         struct range_list *rl;
  60 
  61         extra = get_state(SMATCH_EXTRA, cur->name, cur->sym);
  62         if (!extra || !estate_rl(extra))
  63                 return;
  64         if (!estate_rl(cur->state)) {
  65                 set_state(my_id, cur->name, cur->sym, clone_estate(extra));
  66                 return;
  67         }
  68         rl = rl_intersection(estate_rl(cur->state), estate_rl(extra));
  69         set_state(my_id, cur->name, cur->sym, alloc_estate_rl(clone_rl(rl)));
  70 }
  71 
  72 static struct smatch_state *empty_state(struct sm_state *sm)
  73 {
  74         return alloc_estate_empty();
  75 }
  76 
  77 static int in_iterator_pre_statement(void)
  78 {
  79         struct statement *stmt;
  80 
  81         /*
  82          * we can't use __cur_stmt because that isn't set for
  83          * iterator_pre_statement.  Kind of a mess.
  84          *
  85          */
  86 
  87         stmt = last_ptr_list((struct ptr_list *)big_statement_stack);
  88 
  89         if (!stmt || !stmt->parent)
  90                 return 0;
  91         if (stmt->parent->type != STMT_ITERATOR)
  92                 return 0;
  93         if (stmt->parent->iterator_pre_statement != stmt)
  94                 return 0;
  95         return 1;
  96 }
  97 
  98 static void match_assign(struct expression *expr)
  99 {
 100         struct range_list *rl;
 101         struct symbol *type;
 102         sval_t sval;
 103 
 104         if (expr->op != '=')
 105                 return;
 106         if (is_fake_call(expr->right))
 107                 return;
 108         if (in_iterator_pre_statement())
 109                 return;
 110 
 111         get_real_absolute_rl(expr->right, &rl);
 112 
 113         type = get_type(expr->left);
 114         if (!type)
 115                 return;
 116         if (type->type != SYM_PTR && type->type != SYM_BASETYPE &&
 117             type->type != SYM_ENUM)
 118                 return;
 119 
 120         rl = cast_rl(type, rl);
 121         if (is_whole_rl(rl) && !get_state_expr(my_id, expr->left))
 122                 return;
 123         /* These are handled by smatch_extra.c */
 124         if (rl_to_sval(rl, &sval) && !get_state_expr(my_id, expr->left))
 125                 return;
 126 
 127         set_state_expr(my_id, expr->left, alloc_estate_rl(clone_rl(rl)));
 128 }
 129 
 130 struct smatch_state *get_real_absolute_state(struct expression *expr)
 131 {
 132         return get_state_expr(my_id, expr);
 133 }
 134 
 135 struct smatch_state *get_real_absolute_state_var_sym(const char *name, struct symbol *sym)
 136 {
 137         return __get_state(my_id, name, sym);
 138 }
 139 
 140 void register_real_absolute(int id)
 141 {
 142         my_id = id;
 143 
 144         set_dynamic_states(my_id);
 145         add_pre_merge_hook(my_id, &pre_merge_hook);
 146         add_unmatched_state_hook(my_id, &empty_state);
 147         add_merge_hook(my_id, &merge_estates);
 148         add_extra_mod_hook(&extra_mod_hook);
 149 
 150         add_hook(&match_assign, ASSIGNMENT_HOOK);
 151 }
 152