Print this page
12724 update smatch to 0.6.1-rc1-il-5
Split |
Close |
Expand all |
Collapse all |
--- old/usr/src/tools/smatch/src/smatch_type_val.c
+++ new/usr/src/tools/smatch/src/smatch_type_val.c
1 1 /*
2 2 * Copyright (C) 2013 Oracle.
3 3 *
4 4 * This program is free software; you can redistribute it and/or
5 5 * modify it under the terms of the GNU General Public License
6 6 * as published by the Free Software Foundation; either version 2
7 7 * of the License, or (at your option) any later version.
8 8 *
9 9 * This program is distributed in the hope that it will be useful,
10 10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 12 * GNU General Public License for more details.
13 13 *
14 14 * You should have received a copy of the GNU General Public License
15 15 * along with this program; if not, see http://www.gnu.org/copyleft/gpl.txt
16 16 */
17 17
18 18 /*
19 19 * The plan here is to save all the possible values store to a given struct
20 20 * member.
21 21 *
22 22 * We will load all the values in to the function_type_val table first then
23 23 * run a script on that and load all the resulting values into the type_val
24 24 * table.
25 25 *
26 26 * So in this file we want to take the union of everything assigned to the
27 27 * struct member and insert it into the function_type_val at the end.
28 28 *
29 29 * You would think that we could use smatch_modification_hooks.c or
30 30 * extra_modification_hook() here to get the information here but in the end we
31 31 * need to code everything again a third time.
32 32 *
33 33 */
34 34
35 35 #include "smatch.h"
36 36 #include "smatch_slist.h"
37 37 #include "smatch_extra.h"
38 38
39 39 static int my_id;
40 40
41 41 struct stree_stack *fn_type_val_stack;
42 42 struct stree *fn_type_val;
43 43 struct stree *global_type_val;
44 44
45 45 static int get_vals(void *_db_vals, int argc, char **argv, char **azColName)
46 46 {
47 47 char **db_vals = _db_vals;
48 48
49 49 *db_vals = alloc_string(argv[0]);
50 50 return 0;
51 51 }
52 52
53 53 static void match_inline_start(struct expression *expr)
54 54 {
55 55 push_stree(&fn_type_val_stack, fn_type_val);
56 56 fn_type_val = NULL;
57 57 }
58 58
59 59 static void match_inline_end(struct expression *expr)
60 60 {
61 61 free_stree(&fn_type_val);
62 62 fn_type_val = pop_stree(&fn_type_val_stack);
63 63 }
64 64
65 65 struct expr_rl {
66 66 struct expression *expr;
67 67 struct range_list *rl;
68 68 };
69 69 static struct expr_rl cached_results[10];
70 70 static int res_idx;
71 71
72 72 static int get_cached(struct expression *expr, struct range_list **rl, int *ret)
73 73 {
74 74 int i;
75 75
76 76 *ret = 0;
77 77
78 78 for (i = 0; i < ARRAY_SIZE(cached_results); i++) {
79 79 if (expr == cached_results[i].expr) {
80 80 if (cached_results[i].rl) {
81 81 *rl = clone_rl(cached_results[i].rl);
82 82 *ret = 1;
83 83 }
84 84 return 1;
85 85 }
86 86 }
87 87
88 88 return 0;
89 89 }
90 90
91 91 int get_db_type_rl(struct expression *expr, struct range_list **rl)
92 92 {
93 93 char *db_vals = NULL;
94 94 char *member;
95 95 struct range_list *tmp;
96 96 struct symbol *type;
97 97 int ret;
98 98
99 99 if (get_cached(expr, rl, &ret))
100 100 return ret;
101 101
102 102 member = get_member_name(expr);
103 103 if (!member)
104 104 return 0;
105 105
106 106 res_idx = (res_idx + 1) % ARRAY_SIZE(cached_results);
107 107 cached_results[res_idx].expr = expr;
108 108 cached_results[res_idx].rl = NULL;
109 109
110 110 run_sql(get_vals, &db_vals,
111 111 "select value from type_value where type = '%s';", member);
112 112 free_string(member);
113 113 if (!db_vals)
114 114 return 0;
115 115 type = get_type(expr);
116 116 str_to_rl(type, db_vals, &tmp);
117 117 free_string(db_vals);
118 118 if (is_whole_rl(tmp))
119 119 return 0;
120 120
121 121 *rl = tmp;
122 122 cached_results[res_idx].rl = clone_rl(tmp);
123 123
124 124 return 1;
125 125 }
126 126
127 127 static void add_type_val(char *member, struct range_list *rl)
128 128 {
129 129 struct smatch_state *old, *add, *new;
130 130
131 131 member = alloc_string(member);
132 132 old = get_state_stree(fn_type_val, my_id, member, NULL);
133 133 add = alloc_estate_rl(rl);
134 134 if (old)
135 135 new = merge_estates(old, add);
136 136 else
137 137 new = add;
138 138 set_state_stree(&fn_type_val, my_id, member, NULL, new);
139 139 }
140 140
141 141 static void add_fake_type_val(char *member, struct range_list *rl, int ignore)
142 142 {
143 143 struct smatch_state *old, *add, *new;
144 144
145 145 member = alloc_string(member);
146 146 old = get_state_stree(fn_type_val, my_id, member, NULL);
147 147 if (old && strcmp(old->name, "min-max") == 0)
148 148 return;
149 149 if (ignore && old && strcmp(old->name, "ignore") == 0)
150 150 return;
151 151 add = alloc_estate_rl(rl);
152 152 if (old) {
153 153 new = merge_estates(old, add);
154 154 } else {
155 155 new = add;
156 156 if (ignore)
157 157 new->name = alloc_string("ignore");
158 158 else
159 159 new->name = alloc_string("min-max");
160 160 }
161 161 set_state_stree(&fn_type_val, my_id, member, NULL, new);
162 162 }
163 163
164 164 static void add_global_type_val(char *member, struct range_list *rl)
165 165 {
166 166 struct smatch_state *old, *add, *new;
167 167
168 168 member = alloc_string(member);
169 169 old = get_state_stree(global_type_val, my_id, member, NULL);
170 170 add = alloc_estate_rl(rl);
171 171 if (old)
172 172 new = merge_estates(old, add);
173 173 else
174 174 new = add;
175 175 new = clone_estate_perm(new);
176 176 set_state_stree_perm(&global_type_val, my_id, member, NULL, new);
177 177 }
178 178
179 179 static int has_link_cb(void *has_link, int argc, char **argv, char **azColName)
180 180 {
181 181 *(int *)has_link = 1;
182 182 return 0;
183 183 }
184 184
185 185 static int is_ignored_fake_assignment(void)
186 186 {
187 187 struct expression *expr;
188 188 struct symbol *type;
189 189 char *member_name;
190 190 int has_link = 0;
191 191
192 192 expr = get_faked_expression();
193 193 if (!expr || expr->type != EXPR_ASSIGNMENT)
194 194 return 0;
195 195 if (!is_void_pointer(expr->right))
196 196 return 0;
197 197 member_name = get_member_name(expr->right);
198 198 if (!member_name)
199 199 return 0;
200 200
201 201 type = get_type(expr->left);
202 202 if (!type || type->type != SYM_PTR)
203 203 return 0;
204 204 type = get_real_base_type(type);
205 205 if (!type || type->type != SYM_STRUCT)
206 206 return 0;
207 207
208 208 run_sql(has_link_cb, &has_link,
209 209 "select * from data_info where type = %d and data = '%s' and value = '%s';",
210 210 TYPE_LINK, member_name, type_to_str(type));
211 211 return has_link;
212 212 }
213 213
214 214 static int is_container_of(void)
215 215 {
216 216 /* We already check the macro name in is_ignored_macro() */
217 217 struct expression *expr;
218 218 int offset;
219 219
220 220 expr = get_faked_expression();
221 221 if (!expr || expr->type != EXPR_ASSIGNMENT)
222 222 return 0;
223 223
224 224 offset = get_offset_from_container_of(expr->right);
225 225 if (offset < 0)
226 226 return 0;
227 227 return 1;
228 228 }
229 229
230 230 static bool is_driver_data(void)
231 231 {
232 232 static struct expression *prev_expr;
233 233 struct expression *expr;
234 234 char *name;
235 235 static bool prev_ret;
236 236 bool ret = false;
237 237
238 238 expr = get_faked_expression();
239 239 if (!expr || expr->type != EXPR_ASSIGNMENT)
240 240 return false;
241 241
242 242 if (expr == prev_expr)
243 243 return prev_ret;
244 244 prev_expr = expr;
245 245
246 246 name = expr_to_str(expr->right);
247 247 if (!name) {
248 248 prev_ret = false;
249 249 return false;
250 250 }
251 251
252 252 if (strstr(name, "get_drvdata(") ||
253 253 strstr(name, "dev.driver_data") ||
254 254 strstr(name, "dev->driver_data"))
255 255 ret = true;
256 256
257 257 free_string(name);
258 258
259 259 prev_ret = ret;
260 260 return ret;
261 261 }
262 262
263 263 static int is_ignored_macro(void)
264 264 {
265 265 struct expression *expr;
266 266 char *name;
267 267
268 268 expr = get_faked_expression();
269 269 if (!expr || expr->type != EXPR_ASSIGNMENT || expr->op != '=')
270 270 return 0;
271 271 name = get_macro_name(expr->right->pos);
272 272 if (!name)
273 273 return 0;
274 274 if (strcmp(name, "container_of") == 0)
275 275 return 1;
276 276 if (strcmp(name, "rb_entry") == 0)
277 277 return 1;
278 278 if (strcmp(name, "list_entry") == 0)
279 279 return 1;
280 280 if (strcmp(name, "list_first_entry") == 0)
281 281 return 1;
282 282 if (strcmp(name, "hlist_entry") == 0)
283 283 return 1;
284 284 if (strcmp(name, "per_cpu_ptr") == 0)
285 285 return 1;
286 286 if (strcmp(name, "raw_cpu_ptr") == 0)
287 287 return 1;
288 288 if (strcmp(name, "this_cpu_ptr") == 0)
289 289 return 1;
290 290
291 291 if (strcmp(name, "TRACE_EVENT") == 0)
292 292 return 1;
293 293 if (strcmp(name, "DECLARE_EVENT_CLASS") == 0)
294 294 return 1;
295 295 if (strcmp(name, "DEFINE_EVENT") == 0)
296 296 return 1;
297 297
298 298 if (strstr(name, "for_each"))
299 299 return 1;
300 300 return 0;
301 301 }
302 302
303 303 static int is_ignored_function(void)
304 304 {
305 305 struct expression *expr;
306 306
307 307 expr = get_faked_expression();
308 308 if (!expr || expr->type != EXPR_ASSIGNMENT)
309 309 return 0;
310 310 expr = strip_expr(expr->right);
311 311 if (!expr || expr->type != EXPR_CALL || expr->fn->type != EXPR_SYMBOL)
312 312 return 0;
313 313
314 314 if (sym_name_is("kmalloc", expr->fn))
315 315 return 1;
316 316 if (sym_name_is("vmalloc", expr->fn))
317 317 return 1;
318 318 if (sym_name_is("kvmalloc", expr->fn))
319 319 return 1;
320 320 if (sym_name_is("kmalloc_array", expr->fn))
321 321 return 1;
322 322 if (sym_name_is("vmalloc_array", expr->fn))
323 323 return 1;
324 324 if (sym_name_is("kvmalloc_array", expr->fn))
325 325 return 1;
326 326
327 327 if (sym_name_is("mmu_memory_cache_alloc", expr->fn))
328 328 return 1;
329 329 if (sym_name_is("kmem_alloc", expr->fn))
↓ open down ↓ |
329 lines elided |
↑ open up ↑ |
330 330 return 1;
331 331 if (sym_name_is("alloc_pages", expr->fn))
332 332 return 1;
333 333
334 334 if (sym_name_is("netdev_priv", expr->fn))
335 335 return 1;
336 336 if (sym_name_is("dev_get_drvdata", expr->fn))
337 337 return 1;
338 338 if (sym_name_is("i2c_get_clientdata", expr->fn))
339 339 return 1;
340 + if (sym_name_is("idr_find", expr->fn))
341 + return 1;
340 342
341 343 return 0;
342 344 }
343 345
344 346 static int is_uncasted_pointer_assign(void)
345 347 {
346 348 struct expression *expr;
347 349 struct symbol *left_type, *right_type;
348 350
349 351 expr = get_faked_expression();
350 352 if (!expr)
351 353 return 0;
352 354 if (expr->type == EXPR_PREOP || expr->type == EXPR_POSTOP) {
353 355 if (expr->op == SPECIAL_INCREMENT || expr->op == SPECIAL_DECREMENT)
354 356 return 1;
355 357 }
356 358 if (expr->type != EXPR_ASSIGNMENT)
357 359 return 0;
358 360 left_type = get_type(expr->left);
359 361 right_type = get_type(expr->right);
360 362
361 363 if (!left_type || !right_type)
362 364 return 0;
363 365
364 366 if (left_type->type == SYM_STRUCT && left_type == right_type)
365 367 return 1;
366 368
367 369 if (left_type->type != SYM_PTR &&
368 370 left_type->type != SYM_ARRAY)
369 371 return 0;
370 372 if (right_type->type != SYM_PTR &&
371 373 right_type->type != SYM_ARRAY)
372 374 return 0;
373 375 left_type = get_real_base_type(left_type);
374 376 right_type = get_real_base_type(right_type);
375 377
376 378 if (left_type == right_type)
377 379 return 1;
378 380 return 0;
379 381 }
380 382
381 383 static int set_param_type(void *_type_str, int argc, char **argv, char **azColName)
382 384 {
383 385 char **type_str = _type_str;
384 386 static char type_buf[128];
385 387
386 388 if (*type_str) {
387 389 if (strcmp(*type_str, argv[0]) == 0)
388 390 return 0;
389 391 strncpy(type_buf, "unknown", sizeof(type_buf));
390 392 return 0;
391 393 }
392 394 strncpy(type_buf, argv[0], sizeof(type_buf));
393 395 *type_str = type_buf;
394 396
395 397 return 0;
396 398 }
397 399
398 400 static char *db_get_parameter_type(int param)
399 401 {
400 402 char *ret = NULL;
401 403
402 404 if (!cur_func_sym)
403 405 return NULL;
404 406
405 407 run_sql(set_param_type, &ret,
406 408 "select value from fn_data_link where "
407 409 "file = '%s' and function = '%s' and static = %d and type = %d and parameter = %d and key = '$';",
408 410 (cur_func_sym->ctype.modifiers & MOD_STATIC) ? get_base_file() : "extern",
409 411 cur_func_sym->ident->name,
410 412 !!(cur_func_sym->ctype.modifiers & MOD_STATIC),
411 413 PASSES_TYPE, param);
412 414
413 415 return ret;
414 416 }
415 417
416 418 static int is_uncasted_fn_param_from_db(void)
417 419 {
418 420 struct expression *expr, *right;
419 421 struct symbol *left_type;
420 422 char left_type_name[128];
421 423 int param;
422 424 char *right_type_name;
423 425 static struct expression *prev_expr;
424 426 static int prev_ans;
425 427
426 428 expr = get_faked_expression();
427 429
428 430 if (expr == prev_expr)
429 431 return prev_ans;
430 432 prev_expr = expr;
431 433 prev_ans = 0;
432 434
433 435 if (!expr || expr->type != EXPR_ASSIGNMENT)
434 436 return 0;
435 437 left_type = get_type(expr->left);
436 438 if (!left_type || left_type->type != SYM_PTR)
437 439 return 0;
438 440 left_type = get_real_base_type(left_type);
439 441 if (!left_type || left_type->type != SYM_STRUCT)
440 442 return 0;
441 443 snprintf(left_type_name, sizeof(left_type_name), "%s", type_to_str(left_type));
442 444
443 445 right = strip_expr(expr->right);
444 446 param = get_param_num(right);
445 447 if (param < 0)
446 448 return 0;
447 449 right_type_name = db_get_parameter_type(param);
448 450 if (!right_type_name)
449 451 return 0;
450 452
451 453 if (strcmp(right_type_name, left_type_name) == 0) {
452 454 prev_ans = 1;
453 455 return 1;
454 456 }
455 457
456 458 return 0;
457 459 }
458 460
459 461 static void match_assign_value(struct expression *expr)
460 462 {
461 463 char *member, *right_member;
462 464 struct range_list *rl;
463 465 struct symbol *type;
464 466
465 467 if (!cur_func_sym)
466 468 return;
467 469
468 470 type = get_type(expr->left);
469 471 if (type && type->type == SYM_STRUCT)
470 472 return;
471 473 member = get_member_name(expr->left);
472 474 if (!member)
473 475 return;
474 476
475 477 /* if we're saying foo->mtu = bar->mtu then that doesn't add information */
476 478 right_member = get_member_name(expr->right);
477 479 if (right_member && strcmp(right_member, member) == 0)
478 480 goto free;
479 481
480 482 if (is_fake_call(expr->right)) {
481 483 if (is_ignored_macro())
482 484 goto free;
483 485 if (is_ignored_function())
484 486 goto free;
485 487 if (is_uncasted_pointer_assign())
486 488 goto free;
487 489 if (is_uncasted_fn_param_from_db())
488 490 goto free;
489 491 if (is_container_of())
490 492 goto free;
491 493 if (is_driver_data())
492 494 goto free;
493 495 add_fake_type_val(member, alloc_whole_rl(get_type(expr->left)), is_ignored_fake_assignment());
494 496 goto free;
495 497 }
496 498
497 499 if (expr->op == '=') {
498 500 get_absolute_rl(expr->right, &rl);
499 501 rl = cast_rl(type, rl);
500 502 } else {
501 503 /*
502 504 * This is a bit cheating. We order it so this will already be set
503 505 * by smatch_extra.c and we just look up the value.
504 506 */
505 507 get_absolute_rl(expr->left, &rl);
506 508 }
507 509 add_type_val(member, rl);
508 510 free:
509 511 free_string(right_member);
510 512 free_string(member);
511 513 }
512 514
513 515 /*
514 516 * If we too: int *p = &my_struct->member then abandon all hope of tracking
515 517 * my_struct->member.
516 518 */
517 519 static void match_assign_pointer(struct expression *expr)
518 520 {
519 521 struct expression *right;
520 522 char *member;
521 523 struct range_list *rl;
522 524 struct symbol *type;
523 525
524 526 right = strip_expr(expr->right);
525 527 if (right->type != EXPR_PREOP || right->op != '&')
526 528 return;
527 529 right = strip_expr(right->unop);
528 530
529 531 member = get_member_name(right);
530 532 if (!member)
531 533 return;
532 534 type = get_type(right);
533 535 rl = alloc_whole_rl(type);
534 536 add_type_val(member, rl);
535 537 free_string(member);
536 538 }
537 539
538 540 static void match_global_assign(struct expression *expr)
539 541 {
540 542 char *member;
541 543 struct range_list *rl;
542 544 struct symbol *type;
543 545
544 546 type = get_type(expr->left);
545 547 if (type && (type->type == SYM_ARRAY || type->type == SYM_STRUCT))
546 548 return;
547 549 member = get_member_name(expr->left);
548 550 if (!member)
549 551 return;
550 552 get_absolute_rl(expr->right, &rl);
551 553 rl = cast_rl(type, rl);
552 554 add_global_type_val(member, rl);
553 555 free_string(member);
554 556 }
555 557
556 558 static void unop_expr(struct expression *expr)
557 559 {
558 560 struct range_list *rl;
559 561 char *member;
560 562
561 563 if (expr->op != SPECIAL_DECREMENT && expr->op != SPECIAL_INCREMENT)
562 564 return;
563 565
564 566 expr = strip_expr(expr->unop);
565 567 member = get_member_name(expr);
566 568 if (!member)
567 569 return;
568 570 rl = alloc_whole_rl(get_type(expr));
569 571 add_type_val(member, rl);
570 572 free_string(member);
571 573 }
572 574
573 575 static void asm_expr(struct statement *stmt)
574 576 {
575 577 struct expression *expr;
576 578 struct range_list *rl;
577 579 char *member;
578 580
579 581 FOR_EACH_PTR(stmt->asm_outputs, expr) {
580 582 member = get_member_name(expr->expr);
581 583 if (!member)
582 584 continue;
583 585 rl = alloc_whole_rl(get_type(expr->expr));
584 586 add_type_val(member, rl);
585 587 free_string(member);
586 588 } END_FOR_EACH_PTR(expr);
587 589 }
588 590
589 591 static void db_param_add(struct expression *expr, int param, char *key, char *value)
590 592 {
591 593 struct expression *arg;
592 594 struct symbol *type;
593 595 struct range_list *rl;
594 596 char *member;
595 597
596 598 if (strcmp(key, "*$") != 0)
597 599 return;
598 600
599 601 while (expr->type == EXPR_ASSIGNMENT)
600 602 expr = strip_expr(expr->right);
601 603 if (expr->type != EXPR_CALL)
602 604 return;
603 605
604 606 arg = get_argument_from_call_expr(expr->args, param);
605 607 arg = strip_expr(arg);
606 608 if (!arg)
607 609 return;
608 610 type = get_member_type_from_key(arg, key);
609 611 /*
610 612 * The situation here is that say we memset() a void pointer to zero
611 613 * then that's returned to the called as "*$ = 0;" but on the caller's
612 614 * side it's not void, it's a struct.
613 615 *
614 616 * So the question is should we be passing that slightly bogus
615 617 * information back to the caller? Maybe, maybe not, but either way we
616 618 * are not going to record it here because a struct can't be zero.
617 619 *
618 620 */
619 621 if (type && type->type == SYM_STRUCT)
620 622 return;
621 623
622 624 if (arg->type != EXPR_PREOP || arg->op != '&')
623 625 return;
624 626 arg = strip_expr(arg->unop);
625 627
626 628 member = get_member_name(arg);
627 629 if (!member)
628 630 return;
629 631 call_results_to_rl(expr, type, value, &rl);
630 632 add_type_val(member, rl);
631 633 free_string(member);
632 634 }
633 635
634 636 static void match_end_func_info(struct symbol *sym)
635 637 {
636 638 struct sm_state *sm;
637 639
638 640 FOR_EACH_SM(fn_type_val, sm) {
639 641 sql_insert_function_type_value(sm->name, sm->state->name);
640 642 } END_FOR_EACH_SM(sm);
641 643 }
642 644
643 645 static void clear_cache(struct symbol *sym)
644 646 {
645 647 memset(cached_results, 0, sizeof(cached_results));
646 648 }
647 649
648 650 static void match_after_func(struct symbol *sym)
649 651 {
650 652 free_stree(&fn_type_val);
651 653 }
652 654
653 655 static void match_end_file(struct symbol_list *sym_list)
654 656 {
655 657 struct sm_state *sm;
656 658
657 659 FOR_EACH_SM(global_type_val, sm) {
658 660 sql_insert_function_type_value(sm->name, sm->state->name);
659 661 } END_FOR_EACH_SM(sm);
660 662 }
661 663
662 664 void register_type_val(int id)
663 665 {
664 666 my_id = id;
665 667 add_hook(&clear_cache, AFTER_FUNC_HOOK);
666 668
667 669 if (!option_info)
668 670 return;
669 671
670 672 add_hook(&match_assign_value, ASSIGNMENT_HOOK_AFTER);
671 673 add_hook(&match_assign_pointer, ASSIGNMENT_HOOK);
672 674 add_hook(&unop_expr, OP_HOOK);
673 675 add_hook(&asm_expr, ASM_HOOK);
674 676 select_return_states_hook(PARAM_ADD, &db_param_add);
675 677 select_return_states_hook(PARAM_SET, &db_param_add);
676 678
677 679
678 680 add_hook(&match_inline_start, INLINE_FN_START);
679 681 add_hook(&match_inline_end, INLINE_FN_END);
680 682
681 683 add_hook(&match_end_func_info, END_FUNC_HOOK);
682 684 add_hook(&match_after_func, AFTER_FUNC_HOOK);
683 685
684 686 add_hook(&match_global_assign, GLOBAL_ASSIGNMENT_HOOK);
685 687 add_hook(&match_end_file, END_FILE_HOOK);
686 688 }
↓ open down ↓ |
337 lines elided |
↑ open up ↑ |
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX