GCC Middle and Back End API Reference
region-model.h
Go to the documentation of this file.
1/* Classes for modeling the state of memory.
2 Copyright (C) 2019-2026 Free Software Foundation, Inc.
3 Contributed by David Malcolm <dmalcolm@redhat.com>.
4
5This file is part of GCC.
6
7GCC is free software; you can redistribute it and/or modify it
8under the terms of the GNU General Public License as published by
9the Free Software Foundation; either version 3, or (at your option)
10any later version.
11
12GCC is distributed in the hope that it will be useful, but
13WITHOUT ANY WARRANTY; without even the implied warranty of
14MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
15General Public License for more details.
16
17You should have received a copy of the GNU General Public License
18along with GCC; see the file COPYING3. If not see
19<http://www.gnu.org/licenses/>. */
20
21#ifndef GCC_ANALYZER_REGION_MODEL_H
22#define GCC_ANALYZER_REGION_MODEL_H
23
24/* Implementation of the region-based ternary model described in:
25 "A Memory Model for Static Analysis of C Programs"
26 (Zhongxing Xu, Ted Kremenek, and Jian Zhang)
27 http://lcs.ios.ac.cn/~xuzb/canalyze/memmodel.pdf */
28
29#include "bitmap.h"
30#include "stringpool.h"
31#include "attribs.h" // for rdwr_map
32#include "selftest.h"
33#include "analyzer/svalue.h"
34#include "analyzer/region.h"
39#include "text-art/widget.h"
40#include "text-art/dump.h"
41
42using namespace ana;
43
44namespace inchash
45{
46 extern void add_path_var (path_var pv, hash &hstate);
47} // namespace inchash
48
49namespace ana {
50
51template <typename T>
53{
54 public:
55 one_way_id_map (int num_ids);
56 void put (T src, T dst);
57 T get_dst_for_src (T src) const;
58 void dump_to_pp (pretty_printer *pp) const;
59 void dump () const;
60 void update (T *) const;
61
62 private:
64 };
65
66/* class one_way_id_map. */
67
68/* one_way_id_map's ctor, which populates the map with dummy null values. */
69
70template <typename T>
71inline one_way_id_map<T>::one_way_id_map (int num_svalues)
72: m_src_to_dst (num_svalues)
73{
74 for (int i = 0; i < num_svalues; i++)
75 m_src_to_dst.quick_push (T::null ());
76}
77
78/* Record that SRC is to be mapped to DST. */
79
80template <typename T>
81inline void
83{
84 m_src_to_dst[src.as_int ()] = dst;
85}
86
87/* Get the new value for SRC within the map. */
88
89template <typename T>
90inline T
92{
93 if (src.null_p ())
94 return src;
95 return m_src_to_dst[src.as_int ()];
96}
97
98/* Dump this map to PP. */
99
100template <typename T>
101inline void
103{
104 pp_string (pp, "src to dst: {");
105 unsigned i;
106 T *dst;
108 {
109 if (i > 0)
110 pp_string (pp, ", ");
111 T src (T::from_int (i));
112 src.print (pp);
113 pp_string (pp, " -> ");
114 dst->print (pp);
115 }
116 pp_string (pp, "}");
117 pp_newline (pp);
118}
119
120/* Dump this map to stderr. */
121
122template <typename T>
123DEBUG_FUNCTION inline void
125{
127 pp.set_output_stream (stderr);
128 dump_to_pp (&pp);
129 pp_flush (&pp);
130}
131
132/* Update *ID from the old value to its new value in this map. */
133
134template <typename T>
135inline void
137{
138 *id = get_dst_for_src (*id);
139}
140
141/* A mapping from region to svalue for use when tracking state. */
142
144{
145public:
147 typedef hash_map_t::iterator iterator;
148
153
154 bool operator== (const region_to_value_map &other) const;
155 bool operator!= (const region_to_value_map &other) const
156 {
157 return !(*this == other);
158 }
159
160 iterator begin () const { return m_hash_map.begin (); }
161 iterator end () const { return m_hash_map.end (); }
162
163 const svalue * const *get (const region *reg) const
164 {
165 return const_cast <hash_map_t &> (m_hash_map).get (reg);
166 }
167 void put (const region *reg, const svalue *sval)
168 {
169 m_hash_map.put (reg, sval);
170 }
171 void remove (const region *reg)
172 {
173 m_hash_map.remove (reg);
174 }
175
176 bool is_empty () const { return m_hash_map.is_empty (); }
177
178 void dump_to_pp (pretty_printer *pp, bool simple, bool multiline) const;
179 void dump (bool simple) const;
180
181 std::unique_ptr<json::object> to_json () const;
182
183 std::unique_ptr<text_art::tree_widget>
185
187 region_to_value_map *out) const;
188
189 void purge_state_involving (const svalue *sval);
190
191private:
193};
194
195/* Various operations delete information from a region_model.
196
197 This struct tracks how many of each kind of entity were purged (e.g.
198 for selftests, and for debugging). */
199
218
219/* A base class for visiting regions and svalues, with do-nothing
220 base implementations of the per-subclass vfuncs. */
221
223{
224public:
225 virtual void visit_region_svalue (const region_svalue *) {}
226 virtual void visit_constant_svalue (const constant_svalue *) {}
227 virtual void visit_unknown_svalue (const unknown_svalue *) {}
228 virtual void visit_poisoned_svalue (const poisoned_svalue *) {}
229 virtual void visit_setjmp_svalue (const setjmp_svalue *) {}
230 virtual void visit_initial_svalue (const initial_svalue *) {}
231 virtual void visit_unaryop_svalue (const unaryop_svalue *) {}
232 virtual void visit_binop_svalue (const binop_svalue *) {}
233 virtual void visit_sub_svalue (const sub_svalue *) {}
234 virtual void visit_repeated_svalue (const repeated_svalue *) {}
238 virtual void visit_widening_svalue (const widening_svalue *) {}
239 virtual void visit_compound_svalue (const compound_svalue *) {}
240 virtual void visit_conjured_svalue (const conjured_svalue *) {}
243
244 virtual void visit_region (const region *) {}
245};
246
247struct append_regions_cb_data;
248
249/* Roughly equivalent to a struct __cxa_exception, except we store a std::vector
250 rather than a linked list. */
251
253{
254 exception_node (const svalue *exception_sval,
255 const svalue *typeinfo_sval,
256 const svalue *destructor_sval)
257 : m_exception_sval (exception_sval),
258 m_typeinfo_sval (typeinfo_sval),
259 m_destructor_sval (destructor_sval)
260 {
261 }
262
263 bool operator== (const exception_node &other) const;
264
265 void dump_to_pp (pretty_printer *pp, bool simple) const;
266 void dump (FILE *fp, bool simple) const;
267 void dump (bool simple) const;
268 void dump () const;
269
270 std::unique_ptr<json::object> to_json () const;
271
272 std::unique_ptr<text_art::tree_widget>
274
276
278
282};
283
284/* A region_model encapsulates a representation of the state of memory, with
285 a tree of regions, along with their associated values.
286 The representation is graph-like because values can be pointers to
287 regions.
288 It also stores:
289 - a constraint_manager, capturing relationships between the values, and
290 - dynamic extents, mapping dynamically-allocated regions to svalues (their
291 capacities). */
292
294{
295 public:
297
302
303 bool operator== (const region_model &other) const;
304 bool operator!= (const region_model &other) const
305 {
306 return !(*this == other);
307 }
308
309 hashval_t hash () const;
310
311 void print (pretty_printer *pp) const;
312
313 void dump_to_pp (pretty_printer *pp, bool simple, bool multiline) const;
314 void dump (FILE *fp, bool simple, bool multiline) const;
315 void dump (bool simple) const;
316 void dump () const;
317
318 void debug () const;
319
320 std::unique_ptr<json::object> to_json () const;
321
322 std::unique_ptr<text_art::tree_widget>
324
325 void validate () const;
326
328 bool canonicalized_p () const;
329
330 void
332 bool *out_unknown_side_effects,
334
336 const svalue *get_gassign_result (const gassign *assign,
338 void on_asm_stmt (const gasm *asm_stmt, region_model_context *ctxt);
340 void on_call_post (const gcall &stmt,
341 bool unknown_side_effects,
343
345
347
348 const svalue *maybe_get_copy_bounds (const region *src_reg,
349 const svalue *num_bytes_sval);
351 int retval,
352 bool unmergeable);
354 bool unmergeable);
356 bool unmergeable);
358
362 const svalue *extra_sval,
363 const uncertainty_t *uncertainty);
364
366 void on_setjmp (const gcall &stmt,
367 const exploded_node &enode,
368 const superedge &sedge,
370 void on_longjmp (const gcall &longjmp_call, const gcall &setjmp_call,
371 int setjmp_stack_depth, region_model_context *ctxt);
372
373 void update_for_gcall (const gcall &call_stmt,
375 function *callee = nullptr);
376
377 void update_for_return_gcall (const gcall &call_stmt,
379
380 const region *push_frame (const function &fun,
381 const gcall *call_stmt,
382 const vec<const svalue *> *arg_sids,
386 void pop_frame (tree result_lvalue,
387 const svalue **out_result,
389 const gcall *call_stmt,
390 bool eval_return_svalue = true);
391 int get_stack_depth () const;
392 const frame_region *get_frame_at_index (int index) const;
393
398
399 const region *deref_rvalue (const svalue *ptr_sval, tree ptr_tree,
401 bool add_nonnull_constraint = true) const;
402
404 const region *reg,
405 const bit_range &bits,
406 region_model_context *ctxt) const;
407
408 void set_value (const region *lhs_reg, const svalue *rhs_sval,
410 void set_value (tree lhs, tree rhs, region_model_context *ctxt);
411 void clobber_region (const region *reg);
412 void purge_region (const region *reg);
413 void fill_region (const region *reg,
414 const svalue *sval,
416 void zero_fill_region (const region *reg,
418 void write_bytes (const region *dest_reg,
419 const svalue *num_bytes_sval,
420 const svalue *sval,
422 const svalue *read_bytes (const region *src_reg,
423 tree src_ptr_expr,
424 const svalue *num_bytes_sval,
425 region_model_context *ctxt) const;
426 void copy_bytes (const region *dest_reg,
427 const region *src_reg,
428 tree src_ptr_expr,
429 const svalue *num_bytes_sval,
431 void mark_region_as_unknown (const region *reg, uncertainty_t *uncertainty);
432
434 enum tree_code op,
435 const svalue *rhs) const;
437 const region_svalue *ptr) const;
439 const svalue *b) const;
440 tristate structural_equality (const svalue *a, const svalue *b) const;
442 enum tree_code op,
443 tree rhs,
444 region_model_context *ctxt) const;
445 bool add_constraint (tree lhs, enum tree_code op, tree rhs,
447 bool add_constraint (tree lhs, enum tree_code op, tree rhs,
449 std::unique_ptr<rejected_constraint> *out);
450
451 const region *
454 bool update_state_machine = false,
455 const call_details *cd = nullptr);
456
460
462 logger *logger = nullptr) const;
464 logger *logger = nullptr) const;
468 logger *logger) const;
472 logger *logger) const;
473
474 /* For selftests. */
479
480 store *get_store () { return &m_store; }
481 const store *get_store () const { return &m_store; }
482
483 const dynamic_extents_t &
485 {
486 return m_dynamic_extents;
487 }
488 const svalue *get_dynamic_extents (const region *reg) const;
489 void set_dynamic_extents (const region *reg,
490 const svalue *size_in_bytes,
492 void unset_dynamic_extents (const region *reg);
493
496 {
497 return m_mgr->get_range_manager ();
498 }
499
501 enum poison_kind pkind);
502
503 bool can_merge_with_p (const region_model &other_model,
504 const program_point &point,
505 region_model *out_model,
506 const extrinsic_state *ext_state = nullptr,
507 const program_state *state_a = nullptr,
508 const program_state *state_b = nullptr) const;
509
514
516 static void append_regions_cb (const region *base_reg,
517 struct append_regions_cb_data *data);
518
519 const svalue *get_store_value (const region *reg,
520 region_model_context *ctxt) const;
521 const svalue *get_store_bytes (const region *base_reg,
522 const byte_range &bytes,
523 region_model_context *ctxt) const;
525 tree expr,
526 const svalue **out_sval,
527 region_model_context *ctxt) const;
529 tree expr,
530 const svalue **out_sval,
531 region_model_context *ctxt) const;
532
533 bool region_exists_p (const region *reg) const;
534
535 void loop_replay_fixup (const region_model *dst_state);
536
537 const svalue *get_capacity (const region *reg) const;
538
540 const region_model &summary);
541
543 const svalue *copied_sval,
544 const region *src_reg,
546
547 void set_errno (const call_details &cd);
548
549 /* Implemented in sm-fd.cc */
551
552 /* Implemented in sm-malloc.cc */
554 const svalue *old_ptr_sval,
555 const svalue *new_ptr_sval);
556
557 /* Implemented in sm-malloc.cc. */
558 void
560 const svalue *new_ptr_sval);
561
562 /* Implemented in sm-taint.cc. */
563 void mark_as_tainted (const svalue *sval,
565
566 bool add_constraint (const svalue *lhs,
567 enum tree_code op,
568 const svalue *rhs,
570
571 const svalue *check_for_poison (const svalue *sval,
572 tree expr,
573 const region *src_region,
574 region_model_context *ctxt) const;
575
576 void check_region_for_write (const region *dest_reg,
577 const svalue *sval_hint,
578 region_model_context *ctxt) const;
579
580 const svalue *
582 unsigned idx) const;
583 const svalue *
585 unsigned idx,
586 bool include_terminator,
587 const svalue **out_sval) const;
588
590 get_builtin_kf (const gcall &call,
591 region_model_context *ctxt = nullptr) const;
592
593 bool called_from_main_p () const;
594
596 {
598 }
600 {
601 if (m_thrown_exceptions_stack.empty ())
602 return nullptr;
603 return &m_thrown_exceptions_stack.back ();
604 }
606 {
608 const exception_node retval = m_thrown_exceptions_stack.back ();
609 m_thrown_exceptions_stack.pop_back ();
610 return retval;
611 }
612
614 {
616 }
618 {
619 if (m_caught_exceptions_stack.empty ())
620 return nullptr;
621 return &m_caught_exceptions_stack.back ();
622 }
624 {
626 const exception_node retval = m_caught_exceptions_stack.back ();
627 m_caught_exceptions_stack.pop_back ();
628 return retval;
629 }
630
631private:
634
638 logger *logger) const;
642 logger *logger) const;
643
645 const call_details &cd) const;
647
648 bool add_constraints_from_binop (const svalue *outer_lhs,
649 enum tree_code outer_op,
650 const svalue *outer_rhs,
651 bool *out,
653
655 enum poison_kind pkind);
656
658 bool nonnull,
660
661 const svalue *get_initial_value_for_global (const region *reg) const;
662
664
666 const svalue *size_in_bytes,
667 region_model_context *ctxt) const;
669 region_model_context *ctxt) const;
670
672 enum access_direction dir,
673 region_model_context *ctxt) const;
674
675 void check_for_writable_region (const region* dest_reg,
676 region_model_context *ctxt) const;
677 bool check_region_access (const region *reg,
678 enum access_direction dir,
679 const svalue *sval_hint,
680 region_model_context *ctxt) const;
681 bool check_region_for_read (const region *src_reg,
682 region_model_context *ctxt) const;
683 void check_region_size (const region *lhs_reg, const svalue *rhs_sval,
684 region_model_context *ctxt) const;
685
686 /* Implemented in bounds-checking.cc */
687 bool check_symbolic_bounds (const region *base_reg,
688 const svalue *sym_byte_offset,
689 const svalue *num_bytes_sval,
690 const svalue *capacity,
691 enum access_direction dir,
692 const svalue *sval_hint,
693 region_model_context *ctxt) const;
694 bool check_region_bounds (const region *reg, enum access_direction dir,
695 const svalue *sval_hint,
696 region_model_context *ctxt) const;
697
698 void check_call_args (const call_details &cd) const;
700 tree format_attr) const;
702 tree callee_fndecl,
704 rdwr_map &rdwr_idx) const;
706 tree callee_fndecl,
708 rdwr_map &rdwr_idx);
710 tree callee_fndecl,
712 rdwr_map &rdwr_idx,
713 tree attr);
714 void check_function_attrs (const gcall &call,
715 tree callee_fndecl,
717
719 tree fndecl,
721
722 /* Storing this here to avoid passing it around everywhere. */
724
726
727 constraint_manager *m_constraints; // TODO: embed, rather than dynalloc?
728
730
731 std::vector<exception_node> m_thrown_exceptions_stack;
732 std::vector<exception_node> m_caught_exceptions_stack;
733
734 /* Map from base region to size in bytes, for tracking the sizes of
735 dynamically-allocated regions.
736 This is part of the region_model rather than the region to allow for
737 memory regions to be resized (e.g. by realloc). */
739};
740
741/* Some region_model activity could lead to warnings (e.g. attempts to use an
742 uninitialized value). This abstract base class encapsulates an interface
743 for the region model to use when emitting such warnings.
744
745 Having this as an abstract base class allows us to support the various
746 operations needed by program_state in the analyzer within region_model,
747 whilst keeping them somewhat modularized. */
748
750{
751 public:
752 bool
753 warn (std::unique_ptr<pending_diagnostic> d,
754 std::unique_ptr<pending_location::fixer_for_epath> ploc_fixer = nullptr);
755
756 /* Hook for determining where diagnostics are to currently be emitted. */
757 virtual pending_location
759
760 /* Hook for clients to store pending diagnostics.
761 Return true if the diagnostic was stored, or false if it was deleted. */
762 virtual bool
763 warn_at (std::unique_ptr<pending_diagnostic> d,
764 pending_location &&ploc) = 0;
765
766 /* Hook for clients to add a note to the last previously stored
767 pending diagnostic. */
768 virtual void add_note (std::unique_ptr<pending_note> pn) = 0;
769
770 /* Hook for clients to add an event to the last previously stored
771 pending diagnostic. */
772 virtual void add_event (std::unique_ptr<checker_event> event) = 0;
773
774 /* Hook for clients to be notified when an SVAL that was reachable
775 in a previous state is no longer live, so that clients can emit warnings
776 about leaks. */
777 virtual void on_svalue_leak (const svalue *sval) = 0;
778
779 /* Hook for clients to be notified when the set of explicitly live
780 svalues changes, so that they can purge state relating to dead
781 svalues. */
782 virtual void on_liveness_change (const svalue_set &live_svalues,
783 const region_model *model) = 0;
784
785 virtual logger *get_logger () = 0;
786
787 /* Hook for clients to be notified when the condition
788 "LHS OP RHS" is added to the region model.
789 This exists so that state machines can detect tests on edges,
790 and use them to trigger sm-state transitions (e.g. transitions due
791 to ptrs becoming known to be NULL or non-NULL, rather than just
792 "unchecked") */
793 virtual void on_condition (const svalue *lhs,
794 enum tree_code op,
795 const svalue *rhs) = 0;
796
797 /* Hook for clients to be notified when the condition that
798 SVAL is within RANGES is added to the region model.
799 Similar to on_condition, but for use when handling switch statements.
800 RANGES is non-empty. */
801 virtual void on_bounded_ranges (const svalue &sval,
802 const bounded_ranges &ranges) = 0;
803
804 /* Hook for clients to be notified when a frame is popped from the stack. */
805 virtual void on_pop_frame (const frame_region *) = 0;
806
807 /* Hooks for clients to be notified when an unknown change happens
808 to SVAL (in response to a call to an unknown function). */
809 virtual void on_unknown_change (const svalue *sval, bool is_mutable) = 0;
810
811 /* Hooks for clients to be notified when a phi node is handled,
812 where RHS is the pertinent argument. */
813 virtual void on_phi (const gphi *phi, tree rhs) = 0;
814
815 /* Hooks for clients to be notified when the region model doesn't
816 know how to handle the tree code of T at LOC. */
818 const dump_location_t &loc) = 0;
819
820 /* Hook for clients to be notified when a function_decl escapes. */
821 virtual void on_escaped_function (tree fndecl) = 0;
822
824
825 /* Hook for clients to purge state involving SVAL. */
826 virtual void purge_state_involving (const svalue *sval) = 0;
827
828 /* Hook for clients to split state with a non-standard path. */
829 virtual void bifurcate (std::unique_ptr<custom_edge_info> info) = 0;
830
831 /* Hook for clients to terminate the standard path. */
832 virtual void terminate_path () = 0;
833
834 virtual const extrinsic_state *get_ext_state () const = 0;
835
836 /* Hook for clients to access the a specific state machine in
837 any underlying program_state. */
838 virtual bool
839 get_state_map_by_name (const char *name,
840 sm_state_map **out_smap,
841 const state_machine **out_sm,
842 unsigned *out_sm_idx,
843 std::unique_ptr<sm_context> *out_sm_context) = 0;
844
845 /* Precanned ways for clients to access specific state machines. */
846 bool get_fd_map (sm_state_map **out_smap,
847 const state_machine **out_sm,
848 unsigned *out_sm_idx,
849 std::unique_ptr<sm_context> *out_sm_context)
850 {
851 return get_state_map_by_name ("file-descriptor", out_smap, out_sm,
852 out_sm_idx, out_sm_context);
853 }
854 bool get_malloc_map (sm_state_map **out_smap,
855 const state_machine **out_sm,
856 unsigned *out_sm_idx)
857 {
858 return get_state_map_by_name ("malloc", out_smap, out_sm, out_sm_idx,
859 nullptr);
860 }
861 bool get_taint_map (sm_state_map **out_smap,
862 const state_machine **out_sm,
863 unsigned *out_sm_idx)
864 {
865 return get_state_map_by_name ("taint", out_smap, out_sm, out_sm_idx,
866 nullptr);
867 }
868
869 bool possibly_tainted_p (const svalue *sval);
870
871 /* Get the current statement, if any. */
872 virtual const gimple *get_stmt () const = 0;
873
874 virtual const exploded_graph *get_eg () const = 0;
875
876 virtual const program_state *get_state () const = 0;
877
878 /* Hooks for detecting infinite loops. */
879 virtual void maybe_did_work () = 0;
880 virtual bool checking_for_infinite_loop_p () const = 0;
881 virtual void on_unusable_in_infinite_loop () = 0;
882};
883
884/* A "do nothing" subclass of region_model_context. */
885
887{
888public:
891 {
892 return pending_location ();
893 }
894 bool
895 warn_at (std::unique_ptr<pending_diagnostic>,
896 pending_location &&) override
897 {
898 return false;
899 }
900 void add_note (std::unique_ptr<pending_note>) override;
901 void add_event (std::unique_ptr<checker_event>) override;
902 void on_svalue_leak (const svalue *) override {}
904 const region_model *) override {}
905 logger *get_logger () override { return nullptr; }
906 void on_condition (const svalue *lhs ATTRIBUTE_UNUSED,
907 enum tree_code op ATTRIBUTE_UNUSED,
908 const svalue *rhs ATTRIBUTE_UNUSED) override
909 {
910 }
912 const bounded_ranges &) override
913 {
914 }
915 void on_pop_frame (const frame_region *) override {}
916 void on_unknown_change (const svalue *sval ATTRIBUTE_UNUSED,
917 bool is_mutable ATTRIBUTE_UNUSED) override
918 {
919 }
920 void on_phi (const gphi *phi ATTRIBUTE_UNUSED,
921 tree rhs ATTRIBUTE_UNUSED) override
922 {
923 }
924 void on_unexpected_tree_code (tree, const dump_location_t &) override {}
925
926 void on_escaped_function (tree) override {}
927
928 uncertainty_t *get_uncertainty () override { return nullptr; }
929
930 void purge_state_involving (const svalue *sval ATTRIBUTE_UNUSED) override {}
931
932 void bifurcate (std::unique_ptr<custom_edge_info> info) override;
933 void terminate_path () override;
934
935 const extrinsic_state *get_ext_state () const override { return nullptr; }
936
937 bool get_state_map_by_name (const char *,
938 sm_state_map **,
939 const state_machine **,
940 unsigned *,
941 std::unique_ptr<sm_context> *) override
942 {
943 return false;
944 }
945
946 const gimple *get_stmt () const override { return nullptr; }
947 const exploded_graph *get_eg () const override { return nullptr; }
948 const program_state *get_state () const override { return nullptr; }
949
950 void maybe_did_work () override {}
951 bool checking_for_infinite_loop_p () const override { return false; }
953};
954
955/* A subclass of region_model_context for determining if operations fail
956 e.g. "can we generate a region for the lvalue of EXPR?". */
957
959{
960public:
962
964 final override
965 {
967 }
968
969 bool had_errors_p () const { return m_num_unexpected_codes > 0; }
970
971private:
973};
974
975/* Subclass of region_model_context that wraps another context, allowing
976 for extra code to be added to the various hooks. */
977
979{
980 public:
983 {
984 if (m_inner)
985 return m_inner->get_pending_location_for_diag ();
986 else
987 return pending_location ();
988 }
989
990 bool
991 warn_at (std::unique_ptr<pending_diagnostic> d,
992 pending_location &&ploc) override
993 {
994 if (m_inner)
995 return m_inner->warn_at (std::move (d), std::move (ploc));
996 else
997 return false;
998 }
999
1000 void add_note (std::unique_ptr<pending_note> pn) override
1001 {
1002 if (m_inner)
1003 m_inner->add_note (std::move (pn));
1004 }
1005 void add_event (std::unique_ptr<checker_event> event) override;
1006
1007 void on_svalue_leak (const svalue *sval) override
1008 {
1009 if (m_inner)
1010 m_inner->on_svalue_leak (sval);
1011 }
1012
1013 void on_liveness_change (const svalue_set &live_svalues,
1014 const region_model *model) override
1015 {
1016 if (m_inner)
1017 m_inner->on_liveness_change (live_svalues, model);
1018 }
1019
1020 logger *get_logger () override
1021 {
1022 if (m_inner)
1023 return m_inner->get_logger ();
1024 else
1025 return nullptr;
1026 }
1027
1028 void on_condition (const svalue *lhs,
1029 enum tree_code op,
1030 const svalue *rhs) override
1031 {
1032 if (m_inner)
1033 m_inner->on_condition (lhs, op, rhs);
1034 }
1035
1036 void on_bounded_ranges (const svalue &sval,
1037 const bounded_ranges &ranges) override
1038 {
1039 if (m_inner)
1040 m_inner->on_bounded_ranges (sval, ranges);
1041 }
1042
1043 void on_pop_frame (const frame_region *frame_reg) override
1044 {
1045 if (m_inner)
1046 m_inner->on_pop_frame (frame_reg);
1047 }
1048
1049 void on_unknown_change (const svalue *sval, bool is_mutable) override
1050 {
1051 if (m_inner)
1052 m_inner->on_unknown_change (sval, is_mutable);
1053 }
1054
1055 void on_phi (const gphi *phi, tree rhs) override
1056 {
1057 if (m_inner)
1058 m_inner->on_phi (phi, rhs);
1059 }
1060
1062 const dump_location_t &loc) override
1063 {
1064 if (m_inner)
1065 m_inner->on_unexpected_tree_code (t, loc);
1066 }
1067
1068 void on_escaped_function (tree fndecl) override
1069 {
1070 if (m_inner)
1071 m_inner->on_escaped_function (fndecl);
1072 }
1073
1075 {
1076 if (m_inner)
1077 return m_inner->get_uncertainty ();
1078 else
1079 return nullptr;
1080 }
1081
1082 void purge_state_involving (const svalue *sval) override
1083 {
1084 if (m_inner)
1085 m_inner->purge_state_involving (sval);
1086 }
1087
1088 void bifurcate (std::unique_ptr<custom_edge_info> info) override
1089 {
1090 if (m_inner)
1091 m_inner->bifurcate (std::move (info));
1092 }
1093
1094 void terminate_path () override
1095 {
1096 if (m_inner)
1097 m_inner->terminate_path ();
1098 }
1099
1100 const extrinsic_state *get_ext_state () const override
1101 {
1102 if (m_inner)
1103 return m_inner->get_ext_state ();
1104 else
1105 return nullptr;
1106 }
1107
1108 bool get_state_map_by_name (const char *name,
1109 sm_state_map **out_smap,
1110 const state_machine **out_sm,
1111 unsigned *out_sm_idx,
1112 std::unique_ptr<sm_context> *out_sm_context)
1113 override
1114 {
1115 if (m_inner)
1116 return m_inner->get_state_map_by_name (name, out_smap, out_sm, out_sm_idx,
1117 out_sm_context);
1118 else
1119 return false;
1120 }
1121
1122 const gimple *get_stmt () const override
1123 {
1124 if (m_inner)
1125 return m_inner->get_stmt ();
1126 else
1127 return nullptr;
1128 }
1129
1130 const exploded_graph *get_eg () const override
1131 {
1132 if (m_inner)
1133 return m_inner->get_eg ();
1134 else
1135 return nullptr;
1136 }
1137
1138 const program_state *get_state () const override
1139 {
1140 if (m_inner)
1141 return m_inner->get_state ();
1142 else
1143 return nullptr;
1144 }
1145
1146 void maybe_did_work () override
1147 {
1148 if (m_inner)
1149 m_inner->maybe_did_work ();
1150 }
1151
1152 bool checking_for_infinite_loop_p () const override
1153 {
1154 if (m_inner)
1155 return m_inner->checking_for_infinite_loop_p ();
1156 return false;
1157 }
1159 {
1160 if (m_inner)
1161 m_inner->on_unusable_in_infinite_loop ();
1162 }
1163
1164protected:
1166 : m_inner (inner)
1167 {
1168 }
1169
1171};
1172
1173/* Subclass of region_model_context_decorator with a hook for adding
1174 notes/events when saving diagnostics. */
1175
1177{
1178public:
1179 bool
1180 warn_at (std::unique_ptr<pending_diagnostic> d,
1181 pending_location &&ploc) override
1182 {
1183 if (m_inner)
1184 if (m_inner->warn_at (std::move (d), std::move (ploc)))
1185 {
1186 add_annotations ();
1187 return true;
1188 }
1189 return false;
1190 }
1191
1192 /* Hook to add new event(s)/note(s) */
1193 virtual void add_annotations () = 0;
1194
1195protected:
1200};
1201
1202/* A bundle of data for use when attempting to merge two region_model
1203 instances to make a third. */
1204
1206{
1208 const region_model *model_b,
1209 const program_point &point,
1210 region_model *merged_model,
1212 const program_state *state_a,
1213 const program_state *state_b)
1214 : m_model_a (model_a), m_model_b (model_b),
1215 m_point (point),
1216 m_merged_model (merged_model),
1218 m_state_a (state_a), m_state_b (state_b)
1219 {
1220 }
1221
1222 void dump_to_pp (pretty_printer *pp, bool simple) const;
1223 void dump (FILE *fp, bool simple) const;
1224 void dump (bool simple) const;
1225
1227 {
1228 return m_model_a->get_manager ();
1229 }
1230
1231 bool mergeable_svalue_p (const svalue *) const;
1232
1233 const supernode *get_supernode () const
1234 {
1235 return m_point.get_supernode ();
1236 }
1237
1238 void on_widening_reuse (const widening_svalue *widening_sval);
1239
1244
1248
1250};
1251
1252/* A record that can (optionally) be written out when
1253 region_model::add_constraint fails. */
1254
1256{
1257public:
1259 virtual void dump_to_pp (pretty_printer *pp) const = 0;
1260
1261 const region_model &get_model () const { return m_model; }
1262
1263protected:
1265 : m_model (model)
1266 {}
1267
1269};
1270
1272{
1273public:
1275 const svalue *lhs, enum tree_code op, const svalue *rhs)
1276 : rejected_constraint (model),
1277 m_lhs (lhs), m_op (op), m_rhs (rhs)
1278 {}
1279
1280 void dump_to_pp (pretty_printer *pp) const final override;
1281
1285};
1286
1288{
1289public:
1291 : rejected_constraint (model)
1292 {}
1293
1294 void dump_to_pp (pretty_printer *pp) const final override;
1295};
1296
1298{
1299public:
1301 tree expr, const bounded_ranges *ranges)
1302 : rejected_constraint (model),
1303 m_expr (expr), m_ranges (ranges)
1304 {}
1305
1306 void dump_to_pp (pretty_printer *pp) const final override;
1307
1308private:
1311};
1312
1313/* A bundle of state. */
1314
1316{
1317public:
1319 const supergraph *sg = nullptr);
1320 const supergraph *get_supergraph () { return m_sg; }
1323 {
1324 return m_mgr.get_known_function_manager ();
1325 }
1326
1327 void log_stats (logger *logger) const;
1328
1329private:
1332};
1333
1334/* Factory functions for various diagnostics. */
1335
1336extern std::unique_ptr<pending_diagnostic>
1338 const region *src_region,
1339 tree check_expr);
1340
1341extern std::unique_ptr<pending_diagnostic>
1343 tree count_cst,
1344 const region *src_region);
1345
1346extern std::unique_ptr<pending_diagnostic>
1348 int operand_precision,
1349 tree count_cst,
1350 const region *src_region);
1351
1352extern std::unique_ptr<pending_diagnostic>
1354
1355extern std::unique_ptr<pending_diagnostic>
1357
1358} // namespace ana
1359
1360extern void debug (const region_model &rmodel);
1361
1362namespace ana {
1363
1364#if CHECKING_P
1365
1366namespace selftest {
1367
1368using namespace ::selftest;
1369
1370/* An implementation of region_model_context for use in selftests, which
1371 stores any pending_diagnostic instances passed to it. */
1372
1373class test_region_model_context : public noop_region_model_context
1374{
1375public:
1376 bool
1377 warn_at (std::unique_ptr<pending_diagnostic> d,
1378 pending_location &&) final override
1379 {
1380 m_diagnostics.safe_push (d.release ());
1381 return true;
1382 }
1383
1384 unsigned get_num_diagnostics () const { return m_diagnostics.length (); }
1385
1386 void on_unexpected_tree_code (tree t, const dump_location_t &)
1387 final override
1388 {
1389 internal_error ("unhandled tree code: %qs",
1391 }
1392
1393private:
1394 /* Implicitly delete any diagnostics in the dtor. */
1395 auto_delete_vec<pending_diagnostic> m_diagnostics;
1396};
1397
1398/* Attempt to add the constraint (LHS OP RHS) to MODEL.
1399 Verify that MODEL remains satisfiable. */
1400
1401#define ADD_SAT_CONSTRAINT(MODEL, LHS, OP, RHS) \
1402 SELFTEST_BEGIN_STMT \
1403 bool sat = (MODEL).add_constraint (LHS, OP, RHS, nullptr); \
1404 ASSERT_TRUE (sat); \
1405 SELFTEST_END_STMT
1406
1407/* Attempt to add the constraint (LHS OP RHS) to MODEL.
1408 Verify that the result is not satisfiable. */
1409
1410#define ADD_UNSAT_CONSTRAINT(MODEL, LHS, OP, RHS) \
1411 SELFTEST_BEGIN_STMT \
1412 bool sat = (MODEL).add_constraint (LHS, OP, RHS, nullptr); \
1413 ASSERT_FALSE (sat); \
1414 SELFTEST_END_STMT
1415
1416/* Implementation detail of the ASSERT_CONDITION_* macros. */
1417
1418void assert_condition (const location &loc,
1419 region_model &model,
1420 const svalue *lhs, tree_code op, const svalue *rhs,
1421 tristate expected);
1422
1423void assert_condition (const location &loc,
1424 region_model &model,
1425 tree lhs, tree_code op, tree rhs,
1426 tristate expected);
1427
1428/* Assert that REGION_MODEL evaluates the condition "LHS OP RHS"
1429 as "true". */
1430
1431#define ASSERT_CONDITION_TRUE(REGION_MODEL, LHS, OP, RHS) \
1432 SELFTEST_BEGIN_STMT \
1433 assert_condition (SELFTEST_LOCATION, REGION_MODEL, LHS, OP, RHS, \
1434 tristate (tristate::TS_TRUE)); \
1435 SELFTEST_END_STMT
1436
1437/* Assert that REGION_MODEL evaluates the condition "LHS OP RHS"
1438 as "false". */
1439
1440#define ASSERT_CONDITION_FALSE(REGION_MODEL, LHS, OP, RHS) \
1441 SELFTEST_BEGIN_STMT \
1442 assert_condition (SELFTEST_LOCATION, REGION_MODEL, LHS, OP, RHS, \
1443 tristate (tristate::TS_FALSE)); \
1444 SELFTEST_END_STMT
1445
1446/* Assert that REGION_MODEL evaluates the condition "LHS OP RHS"
1447 as "unknown". */
1448
1449#define ASSERT_CONDITION_UNKNOWN(REGION_MODEL, LHS, OP, RHS) \
1450 SELFTEST_BEGIN_STMT \
1451 assert_condition (SELFTEST_LOCATION, REGION_MODEL, LHS, OP, RHS, \
1452 tristate (tristate::TS_UNKNOWN)); \
1453 SELFTEST_END_STMT
1454
1455} /* end of namespace selftest. */
1456
1457#endif /* #if CHECKING_P */
1458
1459} // namespace ana
1460
1461#endif /* GCC_ANALYZER_REGION_MODEL_H */
hash_map< rdwr_access_hash, attr_access > rdwr_map
Definition attribs.h:402
bool warn_at(std::unique_ptr< pending_diagnostic > d, pending_location &&ploc) override
Definition region-model.h:1180
virtual void add_annotations()=0
annotating_context(region_model_context *inner)
Definition region-model.h:1196
Definition svalue.h:1655
Definition svalue.h:815
Definition svalue.h:1101
Definition constraint-manager.h:178
Definition common.h:343
Definition call-details.h:31
Definition call-summary.h:68
Definition svalue.h:1418
Definition svalue.h:1553
Definition svalue.h:1801
Definition svalue.h:317
Definition constraint-manager.h:410
known_function_manager * get_known_function_manager()
Definition region-model.h:1322
const supergraph * get_supergraph()
Definition region-model.h:1320
const supergraph * m_sg
Definition region-model.h:1331
region_model_manager * get_model_manager()
Definition region-model.h:1321
void log_stats(logger *logger) const
engine(region_model_manager &mgr, const supergraph *sg=nullptr)
region_model_manager & m_mgr
Definition region-model.h:1330
Definition exploded-graph.h:790
Definition exploded-graph.h:206
Definition program-state.h:34
Definition region.h:320
Definition svalue.h:672
Definition known-function-manager.h:41
Definition common.h:314
Definition analyzer-logging.h:36
Definition region-model.h:887
const program_state * get_state() const override
Definition region-model.h:948
bool get_state_map_by_name(const char *, sm_state_map **, const state_machine **, unsigned *, std::unique_ptr< sm_context > *) override
Definition region-model.h:937
bool checking_for_infinite_loop_p() const override
Definition region-model.h:951
void maybe_did_work() override
Definition region-model.h:950
uncertainty_t * get_uncertainty() override
Definition region-model.h:928
void on_unexpected_tree_code(tree, const dump_location_t &) override
Definition region-model.h:924
void on_unknown_change(const svalue *sval, bool is_mutable) override
Definition region-model.h:916
void on_pop_frame(const frame_region *) override
Definition region-model.h:915
void on_phi(const gphi *phi, tree rhs) override
Definition region-model.h:920
void on_condition(const svalue *lhs, enum tree_code op, const svalue *rhs) override
Definition region-model.h:906
void add_event(std::unique_ptr< checker_event >) override
void on_liveness_change(const svalue_set &, const region_model *) override
Definition region-model.h:903
logger * get_logger() override
Definition region-model.h:905
void on_escaped_function(tree) override
Definition region-model.h:926
const exploded_graph * get_eg() const override
Definition region-model.h:947
const gimple * get_stmt() const override
Definition region-model.h:946
pending_location get_pending_location_for_diag() const override
Definition region-model.h:890
void on_unusable_in_infinite_loop() override
Definition region-model.h:952
bool warn_at(std::unique_ptr< pending_diagnostic >, pending_location &&) override
Definition region-model.h:895
void on_svalue_leak(const svalue *) override
Definition region-model.h:902
void add_note(std::unique_ptr< pending_note >) override
void purge_state_involving(const svalue *sval) override
Definition region-model.h:930
const extrinsic_state * get_ext_state() const override
Definition region-model.h:935
void on_bounded_ranges(const svalue &, const bounded_ranges &) override
Definition region-model.h:911
void bifurcate(std::unique_ptr< custom_edge_info > info) override
void put(T src, T dst)
Definition region-model.h:82
void dump() const
Definition region-model.h:124
T get_dst_for_src(T src) const
Definition region-model.h:91
void dump_to_pp(pretty_printer *pp) const
Definition region-model.h:102
auto_vec< T > m_src_to_dst
Definition region-model.h:63
void update(T *) const
Definition region-model.h:136
one_way_id_map(int num_ids)
Definition region-model.h:71
Definition common.h:179
Definition svalue.h:1250
Definition svalue.h:467
Definition program-point.h:54
Definition program-state.h:224
Definition region-model-reachability.h:36
region_model_context * m_inner
Definition region-model.h:1170
const exploded_graph * get_eg() const override
Definition region-model.h:1130
void on_bounded_ranges(const svalue &sval, const bounded_ranges &ranges) override
Definition region-model.h:1036
void on_phi(const gphi *phi, tree rhs) override
Definition region-model.h:1055
void add_event(std::unique_ptr< checker_event > event) override
const extrinsic_state * get_ext_state() const override
Definition region-model.h:1100
void on_condition(const svalue *lhs, enum tree_code op, const svalue *rhs) override
Definition region-model.h:1028
const gimple * get_stmt() const override
Definition region-model.h:1122
void maybe_did_work() override
Definition region-model.h:1146
const program_state * get_state() const override
Definition region-model.h:1138
void on_pop_frame(const frame_region *frame_reg) override
Definition region-model.h:1043
uncertainty_t * get_uncertainty() override
Definition region-model.h:1074
void bifurcate(std::unique_ptr< custom_edge_info > info) override
Definition region-model.h:1088
void add_note(std::unique_ptr< pending_note > pn) override
Definition region-model.h:1000
void on_svalue_leak(const svalue *sval) override
Definition region-model.h:1007
pending_location get_pending_location_for_diag() const override
Definition region-model.h:982
bool checking_for_infinite_loop_p() const override
Definition region-model.h:1152
logger * get_logger() override
Definition region-model.h:1020
region_model_context_decorator(region_model_context *inner)
Definition region-model.h:1165
void purge_state_involving(const svalue *sval) override
Definition region-model.h:1082
void on_liveness_change(const svalue_set &live_svalues, const region_model *model) override
Definition region-model.h:1013
void on_unexpected_tree_code(tree t, const dump_location_t &loc) override
Definition region-model.h:1061
void on_escaped_function(tree fndecl) override
Definition region-model.h:1068
bool warn_at(std::unique_ptr< pending_diagnostic > d, pending_location &&ploc) override
Definition region-model.h:991
void terminate_path() override
Definition region-model.h:1094
void on_unknown_change(const svalue *sval, bool is_mutable) override
Definition region-model.h:1049
void on_unusable_in_infinite_loop() override
Definition region-model.h:1158
bool get_state_map_by_name(const char *name, sm_state_map **out_smap, const state_machine **out_sm, unsigned *out_sm_idx, std::unique_ptr< sm_context > *out_sm_context) override
Definition region-model.h:1108
Definition region-model.h:750
virtual void on_bounded_ranges(const svalue &sval, const bounded_ranges &ranges)=0
virtual bool warn_at(std::unique_ptr< pending_diagnostic > d, pending_location &&ploc)=0
virtual void bifurcate(std::unique_ptr< custom_edge_info > info)=0
virtual void purge_state_involving(const svalue *sval)=0
virtual void on_escaped_function(tree fndecl)=0
bool get_malloc_map(sm_state_map **out_smap, const state_machine **out_sm, unsigned *out_sm_idx)
Definition region-model.h:854
virtual void on_pop_frame(const frame_region *)=0
virtual void on_liveness_change(const svalue_set &live_svalues, const region_model *model)=0
bool get_fd_map(sm_state_map **out_smap, const state_machine **out_sm, unsigned *out_sm_idx, std::unique_ptr< sm_context > *out_sm_context)
Definition region-model.h:846
virtual void add_note(std::unique_ptr< pending_note > pn)=0
virtual pending_location get_pending_location_for_diag() const =0
virtual logger * get_logger()=0
virtual const extrinsic_state * get_ext_state() const =0
bool possibly_tainted_p(const svalue *sval)
virtual const program_state * get_state() const =0
virtual void on_unexpected_tree_code(tree t, const dump_location_t &loc)=0
virtual void on_phi(const gphi *phi, tree rhs)=0
bool get_taint_map(sm_state_map **out_smap, const state_machine **out_sm, unsigned *out_sm_idx)
Definition region-model.h:861
virtual void on_svalue_leak(const svalue *sval)=0
virtual void on_condition(const svalue *lhs, enum tree_code op, const svalue *rhs)=0
virtual void on_unusable_in_infinite_loop()=0
bool warn(std::unique_ptr< pending_diagnostic > d, std::unique_ptr< pending_location::fixer_for_epath > ploc_fixer=nullptr)
virtual const exploded_graph * get_eg() const =0
virtual void on_unknown_change(const svalue *sval, bool is_mutable)=0
virtual const gimple * get_stmt() const =0
virtual uncertainty_t * get_uncertainty()=0
virtual bool checking_for_infinite_loop_p() const =0
virtual void terminate_path()=0
virtual bool get_state_map_by_name(const char *name, sm_state_map **out_smap, const state_machine **out_sm, unsigned *out_sm_idx, std::unique_ptr< sm_context > *out_sm_context)=0
virtual void add_event(std::unique_ptr< checker_event > event)=0
virtual void maybe_did_work()=0
Definition region-model-manager.h:32
Definition region-model.h:294
path_var get_representative_path_var(const svalue *sval, svalue_set *visited, logger *logger) const
region_model(const region_model &other)
void impl_deallocation_call(const call_details &cd)
void update_for_zero_return(const call_details &cd, bool unmergeable)
bool add_constraint(tree lhs, enum tree_code op, tree rhs, region_model_context *ctxt)
store * get_store()
Definition region-model.h:480
constraint_manager * get_constraints()
Definition region-model.h:475
void update_for_nonzero_return(const call_details &cd)
bool add_constraint(tree lhs, enum tree_code op, tree rhs, region_model_context *ctxt, std::unique_ptr< rejected_constraint > *out)
void dump(FILE *fp, bool simple, bool multiline) const
bool replay_call_summary(call_summary_replay &r, const region_model &summary)
void check_region_size(const region *lhs_reg, const svalue *rhs_sval, region_model_context *ctxt) const
void zero_fill_region(const region *reg, region_model_context *ctxt)
void on_asm_stmt(const gasm *asm_stmt, region_model_context *ctxt)
bool check_region_access(const region *reg, enum access_direction dir, const svalue *sval_hint, region_model_context *ctxt) const
void update_for_return_gcall(const gcall &call_stmt, region_model_context *ctxt)
bounded_ranges_manager * get_range_manager() const
Definition region-model.h:495
void dump(bool simple) const
path_var get_representative_path_var_1(const svalue *sval, svalue_set *visited, logger *logger) const
static void append_regions_cb(const region *base_reg, struct append_regions_cb_data *data)
const region * deref_rvalue(const svalue *ptr_sval, tree ptr_tree, region_model_context *ctxt, bool add_nonnull_constraint=true) const
void debug() const
const builtin_known_function * get_builtin_kf(const gcall &call, region_model_context *ctxt=nullptr) const
void on_realloc_with_move(const call_details &cd, const svalue *old_ptr_sval, const svalue *new_ptr_sval)
constraint_manager * m_constraints
Definition region-model.h:727
const exception_node * get_current_thrown_exception() const
Definition region-model.h:599
const svalue * check_for_null_terminated_string_arg(const call_details &cd, unsigned idx) const
void set_errno(const call_details &cd)
void set_dynamic_extents(const region *reg, const svalue *size_in_bytes, region_model_context *ctxt)
void check_region_for_write(const region *dest_reg, const svalue *sval_hint, region_model_context *ctxt) const
const svalue * get_dynamic_extents(const region *reg) const
void clobber_region(const region *reg)
void dump_to_pp(pretty_printer *pp, bool simple, bool multiline) const
void transition_ptr_sval_non_null(region_model_context *ctxt, const svalue *new_ptr_sval)
const svalue * get_rvalue_1(path_var pv, region_model_context *ctxt) const
tristate eval_condition(const svalue *lhs, enum tree_code op, const svalue *rhs) const
const svalue * check_for_null_terminated_string_arg(const call_details &cd, unsigned idx, bool include_terminator, const svalue **out_sval) const
void mark_as_tainted(const svalue *sval, region_model_context *ctxt)
const svalue * get_capacity(const region *reg) const
bool add_constraint(const svalue *lhs, enum tree_code op, const svalue *rhs, region_model_context *ctxt)
void on_assignment(const gassign *stmt, region_model_context *ctxt)
tristate symbolic_greater_than(const binop_svalue *a, const svalue *b) const
region_model & operator=(const region_model &other)
const frame_region * get_frame_at_index(int index) const
store m_store
Definition region-model.h:725
void print(pretty_printer *pp) const
const region * create_region_for_alloca(const svalue *size_in_bytes, region_model_context *ctxt)
void purge_region(const region *reg)
void validate() const
const region * push_frame(const function &fun, const gcall *call_stmt, const vec< const svalue * > *arg_sids, region_model_context *ctxt)
bool operator!=(const region_model &other) const
Definition region-model.h:304
const svalue * get_store_value(const region *reg, region_model_context *ctxt) const
const region * get_region_for_poisoned_expr(tree expr) const
void push_caught_exception(const exception_node &node)
Definition region-model.h:613
void poison_any_pointers_to_descendents(const region *reg, enum poison_kind pkind)
void update_for_gcall(const gcall &call_stmt, region_model_context *ctxt, function *callee=nullptr)
hashval_t hash() const
void check_function_attrs(const gcall &call, tree callee_fndecl, region_model_context *ctxt)
void get_regions_for_current_frame(auto_vec< const decl_region * > *out) const
std::unique_ptr< text_art::tree_widget > make_dump_widget(const text_art::dump_widget_info &dwi) const
const svalue * get_rvalue_for_bits(tree type, const region *reg, const bit_range &bits, region_model_context *ctxt) const
const svalue * get_initial_value_for_global(const region *reg) const
std::vector< exception_node > m_caught_exceptions_stack
Definition region-model.h:732
tristate compare_initial_and_pointer(const initial_svalue *init, const region_svalue *ptr) const
exception_node pop_thrown_exception()
Definition region-model.h:605
const function * get_current_function() const
const svalue * get_store_bytes(const region *base_reg, const byte_range &bytes, region_model_context *ctxt) const
bool can_merge_with_p(const region_model &other_model, const program_point &point, region_model *out_model, const extrinsic_state *ext_state=nullptr, const program_state *state_a=nullptr, const program_state *state_b=nullptr) const
bool on_call_pre(const gcall &stmt, region_model_context *ctxt)
void loop_replay_fixup(const region_model *dst_state)
void check_dynamic_size_for_floats(const svalue *size_in_bytes, region_model_context *ctxt) const
bool operator==(const region_model &other) const
tree get_fndecl_for_call(const gcall &call, region_model_context *ctxt)
bool region_exists_p(const region *reg) const
tree get_representative_tree(const svalue *sval, logger *logger=nullptr) const
void check_function_attr_access(const gcall &call, tree callee_fndecl, region_model_context *ctxt, rdwr_map &rdwr_idx) const
region_model(region_model_manager *mgr)
void handle_unrecognized_call(const gcall &call, region_model_context *ctxt)
void push_thrown_exception(const exception_node &node)
Definition region-model.h:595
const svalue * maybe_get_copy_bounds(const region *src_reg, const svalue *num_bytes_sval)
region_to_value_map dynamic_extents_t
Definition region-model.h:296
tristate eval_condition(tree lhs, enum tree_code op, tree rhs, region_model_context *ctxt) const
const svalue * scan_for_null_terminator_1(const region *reg, tree expr, const svalue **out_sval, region_model_context *ctxt) const
bool called_from_main_p() const
bool add_constraints_from_binop(const svalue *outer_lhs, enum tree_code outer_op, const svalue *outer_rhs, bool *out, region_model_context *ctxt)
void check_one_function_attr_null_terminated_string_arg(const gcall &call, tree callee_fndecl, region_model_context *ctxt, rdwr_map &rdwr_idx, tree attr)
void set_value(const region *lhs_reg, const svalue *rhs_sval, region_model_context *ctxt)
void on_return(const greturn *stmt, region_model_context *ctxt)
void get_reachable_svalues(svalue_set *out, const svalue *extra_sval, const uncertainty_t *uncertainty)
tristate structural_equality(const svalue *a, const svalue *b) const
void copy_bytes(const region *dest_reg, const region *src_reg, tree src_ptr_expr, const svalue *num_bytes_sval, region_model_context *ctxt)
const frame_region * get_current_frame() const
Definition region-model.h:384
std::unique_ptr< json::object > to_json() const
region_model_manager *const m_mgr
Definition region-model.h:723
const frame_region * m_current_frame
Definition region-model.h:729
void dump() const
void check_region_for_taint(const region *reg, enum access_direction dir, region_model_context *ctxt) const
void on_top_level_param(tree param, bool nonnull, region_model_context *ctxt)
tree get_fndecl_for_virtual_call(const_tree fn_ptr, region_model_context *ctxt)
void check_function_attr_null_terminated_string_arg(const gcall &call, tree callee_fndecl, region_model_context *ctxt, rdwr_map &rdwr_idx)
void mark_region_as_unknown(const region *reg, uncertainty_t *uncertainty)
void on_stmt_pre(const gimple *stmt, bool *out_unknown_side_effects, region_model_context *ctxt)
void check_call_format_attr(const call_details &cd, tree format_attr) const
void check_for_throw_inside_call(const gcall &call, tree fndecl, region_model_context *ctxt)
void set_value(tree lhs, tree rhs, region_model_context *ctxt)
bool check_region_for_read(const region *src_reg, region_model_context *ctxt) const
void maybe_complain_about_infoleak(const region *dst_reg, const svalue *copied_sval, const region *src_reg, region_model_context *ctxt)
region_model_manager * get_manager() const
Definition region-model.h:494
const known_function * get_known_function(tree fndecl, const call_details &cd) const
const exception_node * get_current_caught_exception() const
Definition region-model.h:617
void write_bytes(const region *dest_reg, const svalue *num_bytes_sval, const svalue *sval, region_model_context *ctxt)
void on_longjmp(const gcall &longjmp_call, const gcall &setjmp_call, int setjmp_stack_depth, region_model_context *ctxt)
void unset_dynamic_extents(const region *reg)
void on_setjmp(const gcall &stmt, const exploded_node &enode, const superedge &sedge, region_model_context *ctxt)
void check_for_writable_region(const region *dest_reg, region_model_context *ctxt) const
void update_for_null_return(const call_details &cd, bool unmergeable)
const region * get_lvalue_1(path_var pv, region_model_context *ctxt) const
const known_function * get_known_function(enum internal_fn) const
path_var get_representative_path_var(const region *reg, svalue_set *visited, logger *logger) const
const region * get_lvalue(path_var pv, region_model_context *ctxt) const
void get_referenced_base_regions(auto_bitmap &out_ids) const
void update_for_int_cst_return(const call_details &cd, int retval, bool unmergeable)
const svalue * check_for_poison(const svalue *sval, tree expr, const region *src_region, region_model_context *ctxt) const
int get_stack_depth() const
std::vector< exception_node > m_thrown_exceptions_stack
Definition region-model.h:731
bool check_region_bounds(const region *reg, enum access_direction dir, const svalue *sval_hint, region_model_context *ctxt) const
tree get_representative_tree(const region *reg, logger *logger=nullptr) const
void on_call_post(const gcall &stmt, bool unknown_side_effects, region_model_context *ctxt)
void check_call_args(const call_details &cd) const
void fill_region(const region *reg, const svalue *sval, region_model_context *ctxt)
void check_dynamic_size_for_taint(enum memory_space mem_space, const svalue *size_in_bytes, region_model_context *ctxt) const
bool check_symbolic_bounds(const region *base_reg, const svalue *sym_byte_offset, const svalue *num_bytes_sval, const svalue *capacity, enum access_direction dir, const svalue *sval_hint, region_model_context *ctxt) const
void mark_as_valid_fd(const svalue *sval, region_model_context *ctxt)
const svalue * get_rvalue(path_var pv, region_model_context *ctxt) const
path_var get_representative_path_var_1(const region *reg, svalue_set *visited, logger *logger) const
const store * get_store() const
Definition region-model.h:481
dynamic_extents_t m_dynamic_extents
Definition region-model.h:738
const region * get_lvalue(tree expr, region_model_context *ctxt) const
const svalue * get_gassign_result(const gassign *assign, region_model_context *ctxt)
const svalue * read_bytes(const region *src_reg, tree src_ptr_expr, const svalue *num_bytes_sval, region_model_context *ctxt) const
void pop_frame(tree result_lvalue, const svalue **out_result, region_model_context *ctxt, const gcall *call_stmt, bool eval_return_svalue=true)
const svalue * scan_for_null_terminator(const region *reg, tree expr, const svalue **out_sval, region_model_context *ctxt) const
const region * get_or_create_region_for_heap_alloc(const svalue *size_in_bytes, region_model_context *ctxt, bool update_state_machine=false, const call_details *cd=nullptr)
exception_node pop_caught_exception()
Definition region-model.h:623
const svalue * get_rvalue(tree expr, region_model_context *ctxt) const
bool canonicalized_p() const
void purge_state_involving(const svalue *sval, region_model_context *ctxt)
void unbind_region_and_descendents(const region *reg, enum poison_kind pkind)
const dynamic_extents_t & get_dynamic_extents() const
Definition region-model.h:484
Definition svalue.h:229
Definition region-model.h:144
void remove(const region *reg)
Definition region-model.h:171
iterator begin() const
Definition region-model.h:160
const svalue *const * get(const region *reg) const
Definition region-model.h:163
hash_map_t::iterator iterator
Definition region-model.h:147
hash_map_t m_hash_map
Definition region-model.h:192
std::unique_ptr< text_art::tree_widget > make_dump_widget(const text_art::dump_widget_info &dwi) const
void purge_state_involving(const svalue *sval)
std::unique_ptr< json::object > to_json() const
hash_map< const region *, const svalue * > hash_map_t
Definition region-model.h:146
bool operator==(const region_to_value_map &other) const
iterator end() const
Definition region-model.h:161
void put(const region *reg, const svalue *sval)
Definition region-model.h:167
bool is_empty() const
Definition region-model.h:176
region_to_value_map & operator=(const region_to_value_map &other)
region_to_value_map()
Definition region-model.h:149
void dump_to_pp(pretty_printer *pp, bool simple, bool multiline) const
bool operator!=(const region_to_value_map &other) const
Definition region-model.h:155
void dump(bool simple) const
bool can_merge_with_p(const region_to_value_map &other, region_to_value_map *out) const
region_to_value_map(const region_to_value_map &other)
Definition region-model.h:150
Definition region.h:127
virtual ~rejected_constraint()
Definition region-model.h:1258
virtual void dump_to_pp(pretty_printer *pp) const =0
rejected_constraint(const region_model &model)
Definition region-model.h:1264
const region_model & get_model() const
Definition region-model.h:1261
region_model m_model
Definition region-model.h:1268
void dump_to_pp(pretty_printer *pp) const final override
rejected_default_case(const region_model &model)
Definition region-model.h:1290
const svalue * m_lhs
Definition region-model.h:1282
void dump_to_pp(pretty_printer *pp) const final override
enum tree_code m_op
Definition region-model.h:1283
rejected_op_constraint(const region_model &model, const svalue *lhs, enum tree_code op, const svalue *rhs)
Definition region-model.h:1274
const svalue * m_rhs
Definition region-model.h:1284
void dump_to_pp(pretty_printer *pp) const final override
tree m_expr
Definition region-model.h:1309
const bounded_ranges * m_ranges
Definition region-model.h:1310
rejected_ranges_constraint(const region_model &model, tree expr, const bounded_ranges *ranges)
Definition region-model.h:1300
Definition svalue.h:1005
Definition svalue.h:586
Definition program-state.h:92
Definition sm.h:43
Definition store.h:923
Definition svalue.h:919
Definition supergraph.h:281
Definition supergraph.h:105
Definition supergraph.h:224
Definition svalue.h:92
int m_num_unexpected_codes
Definition region-model.h:972
bool had_errors_p() const
Definition region-model.h:969
void on_unexpected_tree_code(tree, const dump_location_t &) final override
Definition region-model.h:963
tentative_region_model_context()
Definition region-model.h:961
Definition svalue.h:720
Definition store.h:162
Definition svalue.h:415
Definition svalue.h:1203
Definition region-model.h:223
virtual void visit_unknown_svalue(const unknown_svalue *)
Definition region-model.h:227
virtual void visit_poisoned_svalue(const poisoned_svalue *)
Definition region-model.h:228
virtual void visit_asm_output_svalue(const asm_output_svalue *)
Definition region-model.h:241
virtual void visit_unaryop_svalue(const unaryop_svalue *)
Definition region-model.h:231
virtual void visit_region_svalue(const region_svalue *)
Definition region-model.h:225
virtual void visit_initial_svalue(const initial_svalue *)
Definition region-model.h:230
virtual void visit_sub_svalue(const sub_svalue *)
Definition region-model.h:233
virtual void visit_setjmp_svalue(const setjmp_svalue *)
Definition region-model.h:229
virtual void visit_conjured_svalue(const conjured_svalue *)
Definition region-model.h:240
virtual void visit_placeholder_svalue(const placeholder_svalue *)
Definition region-model.h:237
virtual void visit_binop_svalue(const binop_svalue *)
Definition region-model.h:232
virtual void visit_const_fn_result_svalue(const const_fn_result_svalue *)
Definition region-model.h:242
virtual void visit_compound_svalue(const compound_svalue *)
Definition region-model.h:239
virtual void visit_unmergeable_svalue(const unmergeable_svalue *)
Definition region-model.h:236
virtual void visit_widening_svalue(const widening_svalue *)
Definition region-model.h:238
virtual void visit_bits_within_svalue(const bits_within_svalue *)
Definition region-model.h:235
virtual void visit_constant_svalue(const constant_svalue *)
Definition region-model.h:226
virtual void visit_region(const region *)
Definition region-model.h:244
virtual void visit_repeated_svalue(const repeated_svalue *)
Definition region-model.h:234
Definition svalue.h:1298
Definition bitmap.h:953
Definition vec.h:1667
Definition genoutput.cc:150
Definition dumpfile.h:446
Definition genmatch.cc:1507
Definition ree.cc:583
Definition hash-map.h:40
Definition hash-set.h:37
Definition inchash.h:38
Definition pretty-print.h:241
void set_output_stream(FILE *outfile)
Definition pretty-print.h:274
Definition tristate.h:26
bool debug
Definition collect-utils.cc:34
const union tree_node * const_tree
Definition coretypes.h:98
union tree_node * tree
Definition coretypes.h:97
void internal_error(const char *,...) ATTRIBUTE_GCC_DIAG(1
void final(rtx_insn *first, FILE *file, int optimize_p)
Definition final.cc:2009
internal_fn
Definition genmatch.cc:1015
tree_code
Definition genmatch.cc:1002
Definition access-diagram.h:30
std::unique_ptr< pending_diagnostic > make_write_to_const_diagnostic(const region *dest_reg, tree decl)
@ stmt
Definition checker-event.h:38
std::unique_ptr< pending_diagnostic > make_shift_count_negative_diagnostic(const gassign *assign, tree count_cst, const region *src_region)
access_direction
Definition common.h:388
std::unique_ptr< pending_diagnostic > make_poisoned_value_diagnostic(tree expr, enum poison_kind pkind, const region *src_region, tree check_expr)
std::unique_ptr< pending_diagnostic > make_write_to_string_literal_diagnostic(const region *reg)
poison_kind
Definition svalue.h:447
std::unique_ptr< pending_diagnostic > make_shift_count_overflow_diagnostic(const gassign *assign, int operand_precision, tree count_cst, const region *src_region)
hash_set< const svalue * > svalue_set
Definition common.h:76
memory_space
Definition region.h:33
Definition custom-sarif-properties/state-graphs.h:33
Definition fold-const.cc:4268
void add_path_var(path_var pv, hash &hstate)
Definition dump-context.h:31
poly_int< N, C > r
Definition poly-int.h:774
i
Definition poly-int.h:776
Ca const poly_int< N, Cb > & b
Definition poly-int.h:771
Ca & a
Definition poly-int.h:770
void pp_flush(pretty_printer *pp)
Definition pretty-print.cc:2462
void pp_newline(pretty_printer *pp)
Definition pretty-print.cc:2737
void pp_string(pretty_printer *pp, const char *str)
Definition pretty-print.cc:2764
Definition store.h:234
Definition constraint-manager.h:123
Definition store.h:328
Definition region-model.h:253
void dump() const
exception_node(const svalue *exception_sval, const svalue *typeinfo_sval, const svalue *destructor_sval)
Definition region-model.h:254
const svalue * m_exception_sval
Definition region-model.h:279
bool operator==(const exception_node &other) const
tree maybe_get_type() const
void dump(bool simple) const
const svalue * m_typeinfo_sval
Definition region-model.h:280
const svalue * m_destructor_sval
Definition region-model.h:281
void dump(FILE *fp, bool simple) const
std::unique_ptr< text_art::tree_widget > make_dump_widget(const text_art::dump_widget_info &dwi) const
void dump_to_pp(pretty_printer *pp, bool simple) const
std::unique_ptr< json::object > to_json() const
void add_to_reachable_regions(reachable_regions &) const
const program_point & m_point
Definition region-model.h:1242
const program_state * m_state_a
Definition region-model.h:1246
const region_model * m_model_a
Definition region-model.h:1240
const extrinsic_state * m_ext_state
Definition region-model.h:1245
hash_set< const svalue * > m_svals_changing_meaning
Definition region-model.h:1249
void dump_to_pp(pretty_printer *pp, bool simple) const
model_merger(const region_model *model_a, const region_model *model_b, const program_point &point, region_model *merged_model, const extrinsic_state *ext_state, const program_state *state_a, const program_state *state_b)
Definition region-model.h:1207
const program_state * m_state_b
Definition region-model.h:1247
const supernode * get_supernode() const
Definition region-model.h:1233
bool mergeable_svalue_p(const svalue *) const
void dump(bool simple) const
region_model_manager * get_manager() const
Definition region-model.h:1226
void on_widening_reuse(const widening_svalue *widening_sval)
region_model * m_merged_model
Definition region-model.h:1243
void dump(FILE *fp, bool simple) const
const region_model * m_model_b
Definition region-model.h:1241
Definition diagnostic-manager.h:35
int m_num_equiv_classes
Definition region-model.h:213
int m_num_bounded_ranges_constraints
Definition region-model.h:215
int m_num_client_items
Definition region-model.h:216
int m_num_svalues
Definition region-model.h:211
purge_stats()
Definition region-model.h:202
int m_num_constraints
Definition region-model.h:214
int m_num_regions
Definition region-model.h:212
Definition genautomata.cc:499
Definition function.h:249
Definition gimple.h:552
Definition gimple.h:910
Definition gimple.h:355
Definition gimple.h:224
Definition gimple.h:464
Definition gimple.h:920
Definition dump-widget-info.h:31
Definition gengtype.h:252
Definition vec.h:450
#define gcc_assert(EXPR)
Definition system.h:820
#define DEBUG_FUNCTION
Definition system.h:1192
static bitmap visited
Definition tree-ssa-dce.cc:664
static control_dependences * cd
Definition tree-ssa-dce.cc:105
const char * get_tree_code_name(enum tree_code code)
Definition tree.cc:13069
#define TREE_CODE(NODE)
Definition tree.h:325
tree size_in_bytes(const_tree t)
Definition tree.h:5327
#define FOR_EACH_VEC_ELT(V, I, P)
Definition vec.h:1895