2015-11-10 19:48:55 +08:00
|
|
|
//===--- LoopWidening.cpp - Widen loops -------------------------*- C++ -*-===//
|
2015-10-30 23:23:57 +08:00
|
|
|
//
|
2019-01-19 16:50:56 +08:00
|
|
|
// Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
|
|
|
|
// See https://llvm.org/LICENSE.txt for license information.
|
|
|
|
// SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
|
2015-10-30 23:23:57 +08:00
|
|
|
//
|
|
|
|
//===----------------------------------------------------------------------===//
|
|
|
|
///
|
|
|
|
/// This file contains functions which are used to widen loops. A loop may be
|
|
|
|
/// widened to approximate the exit state(s), without analyzing every
|
|
|
|
/// iteration. The widening is done by invalidating anything which might be
|
|
|
|
/// modified by the body of the loop.
|
|
|
|
///
|
|
|
|
//===----------------------------------------------------------------------===//
|
|
|
|
|
2018-06-13 06:22:35 +08:00
|
|
|
#include "clang/AST/AST.h"
|
|
|
|
#include "clang/ASTMatchers/ASTMatchFinder.h"
|
|
|
|
#include "clang/StaticAnalyzer/Core/PathSensitive/ExplodedGraph.h"
|
2015-10-30 23:23:57 +08:00
|
|
|
#include "clang/StaticAnalyzer/Core/PathSensitive/LoopWidening.h"
|
|
|
|
|
|
|
|
using namespace clang;
|
|
|
|
using namespace ento;
|
2018-06-13 06:22:35 +08:00
|
|
|
using namespace clang::ast_matchers;
|
|
|
|
|
|
|
|
const auto MatchRef = "matchref";
|
2015-10-30 23:23:57 +08:00
|
|
|
|
|
|
|
/// Return the loops condition Stmt or NULL if LoopStmt is not a loop
|
|
|
|
static const Expr *getLoopCondition(const Stmt *LoopStmt) {
|
|
|
|
switch (LoopStmt->getStmtClass()) {
|
|
|
|
default:
|
2015-11-05 05:37:17 +08:00
|
|
|
return nullptr;
|
2015-10-30 23:23:57 +08:00
|
|
|
case Stmt::ForStmtClass:
|
|
|
|
return cast<ForStmt>(LoopStmt)->getCond();
|
|
|
|
case Stmt::WhileStmtClass:
|
|
|
|
return cast<WhileStmt>(LoopStmt)->getCond();
|
|
|
|
case Stmt::DoStmtClass:
|
|
|
|
return cast<DoStmt>(LoopStmt)->getCond();
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
namespace clang {
|
|
|
|
namespace ento {
|
|
|
|
|
|
|
|
ProgramStateRef getWidenedLoopState(ProgramStateRef PrevState,
|
|
|
|
const LocationContext *LCtx,
|
|
|
|
unsigned BlockCount, const Stmt *LoopStmt) {
|
|
|
|
|
|
|
|
assert(isa<ForStmt>(LoopStmt) || isa<WhileStmt>(LoopStmt) ||
|
|
|
|
isa<DoStmt>(LoopStmt));
|
|
|
|
|
|
|
|
// Invalidate values in the current state.
|
|
|
|
// TODO Make this more conservative by only invalidating values that might
|
|
|
|
// be modified by the body of the loop.
|
|
|
|
// TODO Nested loops are currently widened as a result of the invalidation
|
|
|
|
// being so inprecise. When the invalidation is improved, the handling
|
|
|
|
// of nested loops will also need to be improved.
|
2018-06-13 06:22:35 +08:00
|
|
|
ASTContext &ASTCtx = LCtx->getAnalysisDeclContext()->getASTContext();
|
2018-06-27 09:51:55 +08:00
|
|
|
const StackFrameContext *STC = LCtx->getStackFrame();
|
2015-10-30 23:23:57 +08:00
|
|
|
MemRegionManager &MRMgr = PrevState->getStateManager().getRegionManager();
|
|
|
|
const MemRegion *Regions[] = {MRMgr.getStackLocalsRegion(STC),
|
|
|
|
MRMgr.getStackArgumentsRegion(STC),
|
|
|
|
MRMgr.getGlobalsRegion()};
|
|
|
|
RegionAndSymbolInvalidationTraits ITraits;
|
|
|
|
for (auto *Region : Regions) {
|
|
|
|
ITraits.setTrait(Region,
|
|
|
|
RegionAndSymbolInvalidationTraits::TK_EntireMemSpace);
|
|
|
|
}
|
[analyzer] Do not invalidate the `this` pointer.
Summary:
`this` pointer is not an l-value, although we have modeled `CXXThisRegion` for `this` pointer, we can only bind it once, which is when we start to inline method. And this patch fixes https://bugs.llvm.org/show_bug.cgi?id=35506.
In addition, I didn't find any other cases other than loop-widen that could invalidate `this` pointer.
Reviewers: NoQ, george.karpenkov, a.sidorin, seaneveson, szepet
Reviewed By: NoQ
Subscribers: xazax.hun, rnkovacs, cfe-commits, MTC
Differential Revision: https://reviews.llvm.org/D45491
llvm-svn: 330095
2018-04-15 18:34:06 +08:00
|
|
|
|
2018-06-13 06:22:35 +08:00
|
|
|
// References should not be invalidated.
|
|
|
|
auto Matches = match(findAll(stmt(hasDescendant(varDecl(hasType(referenceType())).bind(MatchRef)))),
|
|
|
|
*LCtx->getDecl()->getBody(), ASTCtx);
|
|
|
|
for (BoundNodes Match : Matches) {
|
|
|
|
const VarDecl *VD = Match.getNodeAs<VarDecl>(MatchRef);
|
|
|
|
assert(VD);
|
|
|
|
const VarRegion *VarMem = MRMgr.getVarRegion(VD, LCtx);
|
|
|
|
ITraits.setTrait(VarMem,
|
|
|
|
RegionAndSymbolInvalidationTraits::TK_PreserveContents);
|
|
|
|
}
|
|
|
|
|
|
|
|
|
[analyzer] Do not invalidate the `this` pointer.
Summary:
`this` pointer is not an l-value, although we have modeled `CXXThisRegion` for `this` pointer, we can only bind it once, which is when we start to inline method. And this patch fixes https://bugs.llvm.org/show_bug.cgi?id=35506.
In addition, I didn't find any other cases other than loop-widen that could invalidate `this` pointer.
Reviewers: NoQ, george.karpenkov, a.sidorin, seaneveson, szepet
Reviewed By: NoQ
Subscribers: xazax.hun, rnkovacs, cfe-commits, MTC
Differential Revision: https://reviews.llvm.org/D45491
llvm-svn: 330095
2018-04-15 18:34:06 +08:00
|
|
|
// 'this' pointer is not an lvalue, we should not invalidate it. If the loop
|
|
|
|
// is located in a method, constructor or destructor, the value of 'this'
|
2018-08-08 07:13:28 +08:00
|
|
|
// pointer should remain unchanged. Ignore static methods, since they do not
|
|
|
|
// have 'this' pointers.
|
|
|
|
const CXXMethodDecl *CXXMD = dyn_cast<CXXMethodDecl>(STC->getDecl());
|
|
|
|
if (CXXMD && !CXXMD->isStatic()) {
|
2019-01-11 09:54:53 +08:00
|
|
|
const CXXThisRegion *ThisR =
|
|
|
|
MRMgr.getCXXThisRegion(CXXMD->getThisType(), STC);
|
[analyzer] Do not invalidate the `this` pointer.
Summary:
`this` pointer is not an l-value, although we have modeled `CXXThisRegion` for `this` pointer, we can only bind it once, which is when we start to inline method. And this patch fixes https://bugs.llvm.org/show_bug.cgi?id=35506.
In addition, I didn't find any other cases other than loop-widen that could invalidate `this` pointer.
Reviewers: NoQ, george.karpenkov, a.sidorin, seaneveson, szepet
Reviewed By: NoQ
Subscribers: xazax.hun, rnkovacs, cfe-commits, MTC
Differential Revision: https://reviews.llvm.org/D45491
llvm-svn: 330095
2018-04-15 18:34:06 +08:00
|
|
|
ITraits.setTrait(ThisR,
|
|
|
|
RegionAndSymbolInvalidationTraits::TK_PreserveContents);
|
|
|
|
}
|
|
|
|
|
2015-10-30 23:23:57 +08:00
|
|
|
return PrevState->invalidateRegions(Regions, getLoopCondition(LoopStmt),
|
|
|
|
BlockCount, LCtx, true, nullptr, nullptr,
|
|
|
|
&ITraits);
|
|
|
|
}
|
|
|
|
|
|
|
|
} // end namespace ento
|
|
|
|
} // end namespace clang
|