-
Notifications
You must be signed in to change notification settings - Fork 5
/
Copy pathsmatch.h
1719 lines (1544 loc) · 63.9 KB
/
smatch.h
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
/*
* Copyright (C) 2006 Dan Carpenter.
*
* This program is free software; you can redistribute it and/or
* modify it under the terms of the GNU General Public License
* as published by the Free Software Foundation; either version 2
* of the License, or (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program; if not, see http://www.gnu.org/copyleft/gpl.txt
*/
#ifndef SMATCH_H_
# define SMATCH_H_
#include <stdio.h>
#include <string.h>
#include <limits.h>
#include <float.h>
#include <sys/time.h>
#include <sqlite3.h>
#include "lib.h"
#include "allocate.h"
#include "scope.h"
#include "parse.h"
#include "expression.h"
#include "avl.h"
#include "smatch_constants.h"
typedef long long mtag_t;
struct smatch_state {
const char *name;
void *data;
};
#define STATE(_x) static struct smatch_state _x = { .name = #_x }
#define GLOBAL_STATE(_x) struct smatch_state _x = { .name = #_x }
extern struct smatch_state undefined;
extern struct smatch_state merged;
extern struct smatch_state true_state;
extern struct smatch_state false_state;
extern struct smatch_state unit_bit;
extern struct smatch_state unit_byte;
extern struct smatch_state unit_array_size;
extern struct smatch_state unit_long;
extern struct smatch_state unit_page;
extern struct smatch_state unit_msec;
extern struct smatch_state unit_ns;
extern struct smatch_state unit_jiffy;
DECLARE_ALLOCATOR(smatch_state);
static inline void *INT_PTR(int i)
{
return (void *)(long)i;
}
static inline int PTR_INT(void *p)
{
return (int)(long)p;
}
struct tracker {
char *name;
struct symbol *sym;
unsigned short owner;
};
DECLARE_ALLOCATOR(tracker);
DECLARE_PTR_LIST(tracker_list, struct tracker);
DECLARE_PTR_LIST(stree_stack, struct stree);
/* The first 3 struct members must match struct tracker */
struct sm_state {
const char *name;
struct symbol *sym;
unsigned short owner;
unsigned short merged:1;
unsigned short leaf:1;
unsigned int line;
struct smatch_state *state;
struct stree *pool;
struct sm_state *left;
struct sm_state *right;
struct state_list *possible;
};
struct var_sym {
char *var;
struct symbol *sym;
};
DECLARE_ALLOCATOR(var_sym);
DECLARE_PTR_LIST(var_sym_list, struct var_sym);
struct constraint {
int op;
int id;
};
DECLARE_PTR_LIST(constraint_list, struct constraint);
struct alloc_info {
const char *fn;
int size_param, nr;
};
extern struct alloc_info *alloc_funcs;
struct bit_info {
unsigned long long set;
unsigned long long possible;
};
enum hook_type {
EXPR_HOOK,
EXPR_HOOK_AFTER,
STMT_HOOK,
STMT_HOOK_AFTER,
SYM_HOOK,
STRING_HOOK,
DECLARATION_HOOK,
DECLARATION_HOOK_AFTER,
ASSIGNMENT_HOOK,
ASSIGNMENT_HOOK_AFTER,
RAW_ASSIGNMENT_HOOK,
GLOBAL_ASSIGNMENT_HOOK,
LOGIC_HOOK,
CONDITION_HOOK,
PRELOOP_HOOK,
POSTLOOP_HOOK,
AFTER_LOOP_NO_BREAKS,
SELECT_HOOK,
WHOLE_CONDITION_HOOK,
FUNCTION_CALL_HOOK_BEFORE,
FUNCTION_CALL_HOOK,
CALL_HOOK_AFTER_INLINE,
FUNCTION_CALL_HOOK_AFTER_DB,
CALL_ASSIGNMENT_HOOK,
MACRO_ASSIGNMENT_HOOK,
BINOP_HOOK,
OP_HOOK,
DEREF_HOOK, /* DEREF_HOOK is junk. Better to use add_dereference_hook() */
CASE_HOOK,
ASM_HOOK,
CAST_HOOK,
SIZEOF_HOOK,
BASE_HOOK,
FUNC_DEF_HOOK,
AFTER_DEF_HOOK,
END_FUNC_HOOK,
AFTER_FUNC_HOOK,
RETURN_HOOK,
INLINE_FN_START,
INLINE_FN_END,
END_FILE_HOOK,
NUM_HOOKS,
};
#define TRUE 1
#define FALSE 0
struct range_list;
typedef void (void_fn)(void);
typedef void (expr_func)(struct expression *expr);
typedef void (stmt_func)(struct statement *stmt);
typedef bool (bool_stmt_func)(struct statement *stmt);
typedef void (sym_func)(struct symbol *sym);
typedef void (name_sym_hook)(struct expression *expr, const char *name, struct symbol *sym);
typedef void (sm_hook)(struct sm_state *sm, struct expression *mod_expr);
typedef void (string_hook)(struct expression *expr, const char *str);
DECLARE_PTR_LIST(void_fn_list, void_fn);
DECLARE_PTR_LIST(expr_fn_list, expr_func);
DECLARE_PTR_LIST(stmt_fn_list, stmt_func);
DECLARE_PTR_LIST(bool_stmt_fn_list, bool_stmt_func);
DECLARE_PTR_LIST(sym_fn_list, sym_func);
DECLARE_PTR_LIST(name_sym_fn_list, name_sym_hook);
DECLARE_PTR_LIST(string_hook_list, string_hook);
void call_void_fns(struct void_fn_list *list);
void call_expr_fns(struct expr_fn_list *list, struct expression *expr);
void call_stmt_fns(struct stmt_fn_list *list, struct statement *stmt);
void call_sym_fns(struct sym_fn_list *list, struct symbol *sym);
void call_name_sym_fns(struct name_sym_fn_list *list, struct expression *expr, const char *name, struct symbol *sym);
void call_string_hooks(struct string_hook_list *list, struct expression *expr, const char *str);
void add_dereference_hook(expr_func *fn);
struct allocation_info {
const char *fn_name;
const char *size_str;
struct expression *total_size;
struct expression *nr_elems;
struct expression *elem_size;
long min, max;
bool zeroed;
bool safe; /* safe from overflows */
};
typedef void (alloc_hook)(struct expression *expr, const char *name, struct symbol *sym, struct allocation_info *info);
void add_allocation_hook(alloc_hook *func);
void add_hook(void *func, enum hook_type type);
typedef struct smatch_state *(merge_func_t)(struct smatch_state *s1, struct smatch_state *s2);
typedef struct smatch_state *(unmatched_func_t)(struct sm_state *state);
void add_merge_hook(int client_id, merge_func_t *func);
void add_unmatched_state_hook(int client_id, unmatched_func_t *func);
void add_pre_merge_hook(int client_id, void (*hook)(struct sm_state *cur, struct sm_state *other));
typedef void (scope_hook)(void *data);
void add_scope_hook(scope_hook *hook, void *data);
void add_return_string_hook(string_hook *fn);
typedef void (param_key_hook)(struct expression *expr, const char *name, struct symbol *sym, void *data);
typedef void (func_hook)(const char *fn, struct expression *expr, void *data);
typedef void (implication_hook)(const char *fn, struct expression *call_expr,
struct expression *assign_expr, void *data);
typedef void (return_implies_hook)(struct expression *call_expr,
int param, char *key, char *value);
typedef int (implied_return_hook)(struct expression *call_expr, void *info, struct range_list **rl);
void add_function_hook_early(const char *look_for, func_hook *call_back, void *data);
void add_function_hook(const char *look_for, func_hook *call_back, void *data);
void add_function_hook_late(const char *look_for, func_hook *call_back, void *info);
void add_function_assign_hook(const char *look_for, func_hook *call_back,
void *info);
void register_func_hooks_from_file(const char *file,
func_hook *call_back, void *info);
void register_assign_hooks_from_file(const char *file,
func_hook *call_back, void *info);
void add_implied_return_hook(const char *look_for,
implied_return_hook *call_back,
void *info);
void add_macro_assign_hook(const char *look_for, func_hook *call_back,
void *info);
void add_macro_assign_hook_extra(const char *look_for, func_hook *call_back,
void *info);
void return_implies_state(const char *look_for, long long start, long long end,
implication_hook *call_back, void *info);
void return_implies_state_sval(const char *look_for, sval_t start, sval_t end,
implication_hook *call_back, void *info);
void return_implies_exact(const char *look_for, sval_t start, sval_t end,
implication_hook *call_back, void *info);
struct range_list *get_range_implications(const char *fn);
void select_return_states_hook(int type, return_implies_hook *callback);
void select_return_states_before(void (*fn)(void));
void select_return_states_after(void (*fn)(void));
void add_param_key_expr_hook(const char *look_for, expr_func *call_back,
int param, const char *key, void *info);
void add_function_param_key_hook(const char *look_for, param_key_hook *call_back,
int param, const char *key, void *info);
void add_function_param_key_hook_early(const char *look_for, param_key_hook *call_back,
int param, const char *key, void *info);
void add_function_param_key_hook_late(const char *look_for, param_key_hook *call_back,
int param, const char *key, void *info);
void return_implies_param_key(const char *look_for, sval_t start, sval_t end,
param_key_hook *call_back,
int param, const char *key, void *info);
void return_implies_param_key_exact(const char *look_for, sval_t start, sval_t end,
param_key_hook *call_back,
int param, const char *key, void *info);
void return_implies_param_key_expr(const char *look_for, sval_t start, sval_t end,
expr_func *call_back,
int param, const char *key, void *info);
void select_return_param_key(int type, param_key_hook *callback);
bool get_implied_return(struct expression *expr, struct range_list **rl);
void allocate_hook_memory(void);
void allocate_tracker_array(int num_checks);
struct modification_data {
struct smatch_state *prev;
struct expression *cur;
};
void allocate_modification_hooks(void);
bool is_sub_member(const char *name, struct symbol *sym, struct sm_state *sm);
void add_all_modifications_hook(int owner, name_sym_hook *hook);
void add_modification_hook(int owner, sm_hook *call_back);
void add_modification_hook_late(int owner, sm_hook *call_back);
struct smatch_state *get_modification_state(struct expression *expr);
int outside_of_function(void);
const char *get_filename(void);
extern int base_file_stream;
const char *get_base_file(void);
unsigned long long get_file_id(void);
unsigned long long get_base_file_id(void);
char *get_function(void);
extern int __smatch_lineno;
int get_lineno(void);
extern int final_pass;
extern struct symbol *cur_func_sym;
extern int option_debug;
extern int local_debug;
extern int debug_db;
extern bool implied_debug;
bool debug_implied(void);
bool debug_on(const char *check_name, const char *var);
extern int option_info;
extern int option_spammy;
extern int option_pedantic;
extern int option_print_names;
extern char *trace_variable;
extern struct stree *global_states;
void set_function_skipped(void);
int is_skipped_function(void);
int is_silenced_function(void);
extern bool implications_off;
/* smatch_impossible.c */
int is_impossible_path(void);
void set_true_path_impossible(void);
void set_false_path_impossible(void);
void set_path_impossible(void);
extern FILE *sm_outfd;
extern FILE *sql_outfd;
extern FILE *caller_info_fd;
extern int sm_nr_checks;
extern int sm_nr_errors;
/*
* How to use these routines:
*
* sm_fatal(): an internal error of some kind that should immediately exit
* sm_ierror(): an internal error
* sm_perror(): an internal error from parsing input source
* sm_error(): an error from input source
* sm_warning(): a warning from input source
* sm_info(): info message (from option_info)
* sm_debug(): debug message
* sm_msg(): other message (please avoid using this)
*/
#define sm_printf(msg...) do { \
if (final_pass || option_debug || local_debug || debug_db) \
fprintf(sm_outfd, msg); \
} while (0)
static inline void sm_prefix(void)
{
sm_printf("%s:%d %s() ", get_filename(), get_lineno(), get_function());
if (option_info || !option_print_names)
return;
sm_printf("[smatch.%s] ", __CHECKNAME__);
}
static inline void print_implied_debug_msg();
extern bool __silence_warnings_for_stmt;
#define sm_print_msg(type, msg...) \
do { \
print_implied_debug_msg(); \
if (!final_pass && !option_debug && !local_debug && !debug_db) \
break; \
if (__silence_warnings_for_stmt && !option_debug && !local_debug) \
break; \
if (!option_info && is_silenced_function()) \
break; \
sm_prefix(); \
if (type == 1) { \
sm_printf("warn: "); \
sm_nr_checks++; \
} else if (type == 2) { \
sm_printf("error: "); \
sm_nr_checks++; \
} else if (type == 3) { \
sm_printf("parse error: "); \
sm_nr_errors++; \
} else if (type == 4) { \
sm_printf("pedantic: "); \
} \
sm_printf(msg); \
sm_printf("\n"); \
} while (0)
#define sm_msg(msg...) do { sm_print_msg(0, msg); } while (0)
extern char *implied_debug_msg;
static inline void print_implied_debug_msg(void)
{
static struct symbol *last_printed = NULL;
if (!implied_debug_msg)
return;
if (last_printed == cur_func_sym)
return;
last_printed = cur_func_sym;
sm_msg("%s", implied_debug_msg);
}
#define sm_debug(msg...) do { if (option_debug) sm_printf(msg); } while (0)
#define db_debug(msg...) do { if (option_debug || debug_db) sm_printf(msg); } while (0)
#define sm_info(msg...) do { \
if (option_debug || (option_info && final_pass)) { \
sm_prefix(); \
sm_printf("info: "); \
sm_printf(msg); \
sm_printf("\n"); \
} \
} while(0)
#define sm_warning(msg...) do { sm_print_msg(1, msg); } while (0)
#define sm_warning_line(line, msg...) do { \
int __orig = __smatch_lineno; \
__smatch_lineno = line; \
sm_print_msg(1, msg); \
__smatch_lineno = __orig; \
} while (0)
#define sm_error(msg...) do { sm_print_msg(2, msg); } while (0)
#define sm_perror(msg...) do { sm_print_msg(3, msg); } while (0)
#define sm_pedantic(msg...) do { if (option_pedantic) sm_print_msg(4, msg); } while (0)
static inline void sm_fatal(const char *fmt, ...)
{
va_list args;
va_start(args, fmt);
vfprintf(sm_outfd, fmt, args);
va_end(args);
fprintf(sm_outfd, "\n");
exit(1);
}
static inline void sm_ierror(const char *fmt, ...)
{
va_list args;
sm_nr_errors++;
fprintf(sm_outfd, "internal error: ");
va_start(args, fmt);
vfprintf(sm_outfd, fmt, args);
va_end(args);
fprintf(sm_outfd, "\n");
}
#define ALIGN(x, a) (((x) + (a) - 1) & ~((a) - 1))
bool has_states(struct stree *stree, int owner);
struct smatch_state *__get_state(int owner, const char *name, struct symbol *sym);
struct smatch_state *get_state(int owner, const char *name, struct symbol *sym);
struct smatch_state *get_state_expr(int owner, struct expression *expr);
bool has_possible_state(int owner, const char *name, struct symbol *sym, struct smatch_state *state);
bool expr_has_possible_state(int owner, struct expression *expr, struct smatch_state *state);
struct state_list *get_possible_states(int owner, const char *name,
struct symbol *sym);
struct state_list *get_possible_states_expr(int owner, struct expression *expr);
struct sm_state *set_state(int owner, const char *name, struct symbol *sym,
struct smatch_state *state);
struct sm_state *set_state_expr(int owner, struct expression *expr,
struct smatch_state *state);
void preserve_out_of_scope(int owner);
void __delete_state(int owner, const char *name, struct symbol *sym);
void __delete_all_states_sym(struct symbol *sym);
void set_true_false_states(int owner, const char *name, struct symbol *sym,
struct smatch_state *true_state,
struct smatch_state *false_state);
void set_true_false_states_expr(int owner, struct expression *expr,
struct smatch_state *true_state,
struct smatch_state *false_state);
struct stree *get_all_states_from_stree(int owner, struct stree *source);
struct stree *get_all_states_stree(int id);
struct stree *__get_cur_stree(void);
int is_reachable(void);
void add_get_state_hook(void (*fn)(int owner, const char *name, struct symbol *sym));
static inline void set_undefined(struct sm_state *sm, struct expression *mod_expr)
{
set_state(sm->owner, sm->name, sm->sym, &undefined);
}
/* smatch_ssa.c */
char *ssa_name(const char *name);
void set_ssa_state(int owner, const char *name, struct symbol *sym, struct smatch_state *state);
void update_ssa_state(int owner, const char *name, struct symbol *sym,
struct smatch_state *state);
void update_ssa_sm(int owner, struct sm_state *sm, struct smatch_state *state);
void set_ssa_state_expr(int owner, struct expression *expr, struct smatch_state *state);
struct sm_state *get_ssa_sm_state(int owner, const char *name, struct symbol *sym);
struct sm_state *get_ssa_sm_state_expr(int owner, struct expression *expr);
struct smatch_state *get_ssa_state(int owner, const char *name, struct symbol *sym);
struct smatch_state *get_ssa_state_expr(int owner, struct expression *expr);
/* smatch_helper.c */
DECLARE_PTR_LIST(int_stack, int);
char *alloc_string(const char *str);
char *alloc_string_newline(const char *str);
void free_string(char *str);
void remove_parens(char *str);
struct smatch_state *alloc_state_num(int num);
struct smatch_state *alloc_state_str(const char *name);
struct smatch_state *merge_str_state(struct smatch_state *s1, struct smatch_state *s2);
struct smatch_state *alloc_state_expr(struct expression *expr);
struct expression *get_assigned_call(struct expression *expr);
struct expression *get_argument_from_call_expr(struct expression_list *args,
int num);
struct expression *get_array_expr(struct expression *expr);
char *expr_to_var(struct expression *expr);
struct symbol *expr_to_sym(struct expression *expr);
char *expr_to_str(struct expression *expr);
char *expr_to_str_sym(struct expression *expr,
struct symbol **sym_ptr);
char *expr_to_var_sym(struct expression *expr,
struct symbol **sym_ptr);
char *expr_to_known_chunk_sym(struct expression *expr, struct symbol **sym);
char *expr_to_chunk_sym_vsl(struct expression *expr, struct symbol **sym, struct var_sym_list **vsl);
int get_complication_score(struct expression *expr);
int sym_name_is(const char *name, struct expression *expr);
int get_const_value(struct expression *expr, sval_t *sval);
int get_value(struct expression *expr, sval_t *val);
int get_implied_value(struct expression *expr, sval_t *val);
int get_implied_value_fast(struct expression *expr, sval_t *sval);
int get_implied_min(struct expression *expr, sval_t *sval);
int get_implied_max(struct expression *expr, sval_t *val);
int get_hard_max(struct expression *expr, sval_t *sval);
int get_fuzzy_min(struct expression *expr, sval_t *min);
int get_fuzzy_max(struct expression *expr, sval_t *max);
int get_absolute_min(struct expression *expr, sval_t *sval);
int get_absolute_max(struct expression *expr, sval_t *sval);
int parse_call_math(struct expression *expr, char *math, sval_t *val);
int parse_call_math_rl(struct expression *call, const char *math, struct range_list **rl);
const char *get_allocation_math(struct expression *expr);
char *get_value_in_terms_of_parameter_math(struct expression *expr);
char *get_value_in_terms_of_parameter_math_var_sym(const char *var, struct symbol *sym);
int expr_is_zero(struct expression *expr);
int known_condition_true(struct expression *expr);
int known_condition_false(struct expression *expr);
int implied_condition_true(struct expression *expr);
int implied_condition_false(struct expression *expr);
int can_integer_overflow(struct symbol *type, struct expression *expr);
void clear_math_cache(void);
void clear_strip_cache(void);
void set_fast_math_only(void);
void clear_fast_math_only(void);
int is_array(struct expression *expr);
struct expression *get_array_base(struct expression *expr);
struct expression *get_array_offset(struct expression *expr);
const char *show_state(struct smatch_state *state);
struct statement *get_expression_statement(struct expression *expr);
struct expression *strip__builtin_choose_expr(struct expression *expr);
struct expression *strip_Generic(struct expression *expr);
struct expression *strip_parens(struct expression *expr);
struct expression *strip_expr(struct expression *expr);
struct expression *strip_no_cast(struct expression *expr);
struct expression *strip_expr_set_parent(struct expression *expr);
int is_error_return(struct expression *expr);
int getting_address(struct expression *expr);
int get_struct_and_member(struct expression *expr, const char **type, const char **member);
char *get_member_name(struct expression *expr);
char *get_fnptr_name(struct expression *expr);
int cmp_pos(struct position pos1, struct position pos2);
int positions_eq(struct position pos1, struct position pos2);
struct statement *get_current_statement(void);
struct statement *get_prev_statement(void);
struct expression *get_last_expr_from_expression_stmt(struct expression *expr);
enum { RET_SUCCESS, RET_FAIL, RET_UNKNOWN };
int success_fail_return(struct range_list *rl);
#define RETURN_VAR -1
#define LOCAL_SCOPE -2
#define FILE_SCOPE -3
#define GLOBAL_SCOPE -4
#define UNKNOWN_SCOPE -5
char *swap_names(const char *orig, const char *remove, const char *add);
char *get_param_var_sym_var_sym(const char *name, struct symbol *sym, struct expression *ret_expr, struct symbol **sym_p);
char *get_param_name_sym(struct expression *expr, struct symbol **sym_p);
int get_return_param_key_from_var_sym(const char *name, struct symbol *sym,
struct expression *ret_expr,
const char **key);
int get_param_key_from_var_sym(const char *name, struct symbol *sym,
struct expression *ret_expr,
const char **key);
int get_param_key_from_sm(struct sm_state *sm, struct expression *ret_expr,
const char **key);
int get_param_key_from_expr(struct expression *expr, struct expression *ret_expr,
const char **key);
const char *get_param_key_swap_dollar(struct expression *expr);
int map_to_param(const char *name, struct symbol *sym);
int get_param_num_from_sym(struct symbol *sym);
int get_param_num(struct expression *expr);
struct symbol *get_param_sym_from_num(int num);
struct expression *map_container_of_to_simpler_expr_key(struct expression *expr, const char *orig_key, char **new_key);
const char *get_container_of_str(struct expression *expr);
bool get_offset_param(const char *ret_str, int *offset, int *param);
/* smatch_points_to_container.c */
struct expression *get_stored_container(struct expression *expr, int offset);
int ms_since(struct timeval *start);
int parent_is_gone_var_sym(const char *name, struct symbol *sym);
int parent_is_gone(struct expression *expr);
bool is_noderef_ptr(struct expression *expr);
int invert_op(int op);
int op_remove_assign(int op);
int expr_equiv(struct expression *one, struct expression *two);
void push_int(struct int_stack **stack, int num);
int pop_int(struct int_stack **stack);
bool macro_to_ul(const char *macro, unsigned long *val);
bool has_cleanup(struct expression *expr);
/* smatch_type.c */
struct symbol *get_real_base_type(struct symbol *sym);
int type_bytes(struct symbol *type);
int array_bytes(struct symbol *type);
struct symbol *get_pointer_type(struct expression *expr);
struct symbol *get_type(struct expression *expr);
struct symbol *get_comparison_type(struct expression *expr);
struct symbol *get_final_type(struct expression *expr);
struct symbol *get_promoted_type(struct symbol *left, struct symbol *right);
int type_signed(struct symbol *base_type);
int expr_unsigned(struct expression *expr);
int expr_signed(struct expression *expr);
int returns_unsigned(struct symbol *base_type);
int is_pointer(struct expression *expr);
bool is_void_ptr(struct symbol *type);
int returns_pointer(struct symbol *base_type);
sval_t sval_type_max(struct symbol *base_type);
sval_t sval_type_min(struct symbol *base_type);
int nr_bits(struct expression *expr);
int is_void_pointer(struct expression *expr);
int is_char_pointer(struct expression *expr);
int is_string(struct expression *expr);
bool is_struct_ptr(struct symbol *type);
int is_static(struct expression *expr);
bool is_local_variable(struct expression *expr);
int types_equiv(struct symbol *one, struct symbol *two);
bool type_fits(struct symbol *type, struct symbol *test);
int fn_static(void);
const char *global_static();
struct symbol *cur_func_return_type(void);
struct symbol *get_arg_type(struct expression *fn, int arg);
struct symbol *get_member_type_from_key(struct expression *expr, const char *key);
struct symbol *get_arg_type_from_key(struct expression *fn, int param, struct expression *arg, const char *key);
int is_struct(struct expression *expr);
char *type_to_str(struct symbol *type);
/* smatch_ignore.c */
void add_ignore(int owner, const char *name, struct symbol *sym);
int is_ignored(int owner, const char *name, struct symbol *sym);
void add_ignore_expr(int owner, struct expression *expr);
int is_ignored_expr(int owner, struct expression *expr);
/* smatch_var_sym */
struct smatch_state *alloc_var_sym_state(const char *var, struct symbol *sym);
struct var_sym *alloc_var_sym(const char *var, struct symbol *sym);
struct var_sym_list *expr_to_vsl(struct expression *expr);
void add_var_sym(struct var_sym_list **list, const char *var, struct symbol *sym);
void add_var_sym_expr(struct var_sym_list **list, struct expression *expr);
void del_var_sym(struct var_sym_list **list, const char *var, struct symbol *sym);
int in_var_sym_list(struct var_sym_list *list, const char *var, struct symbol *sym);
struct var_sym_list *clone_var_sym_list(struct var_sym_list *from_vsl);
void merge_var_sym_list(struct var_sym_list **dest, struct var_sym_list *src);
struct var_sym_list *combine_var_sym_lists(struct var_sym_list *one, struct var_sym_list *two);
int var_sym_lists_equiv(struct var_sym_list *one, struct var_sym_list *two);
void free_var_sym_list(struct var_sym_list **list);
void free_var_syms_and_list(struct var_sym_list **list);
/* smatch_tracker */
struct tracker *alloc_tracker(int owner, const char *name, struct symbol *sym);
void add_tracker(struct tracker_list **list, int owner, const char *name,
struct symbol *sym);
void add_tracker_expr(struct tracker_list **list, int owner, struct expression *expr);
void del_tracker(struct tracker_list **list, int owner, const char *name,
struct symbol *sym);
int in_tracker_list(struct tracker_list *list, int owner, const char *name,
struct symbol *sym);
void free_tracker_list(struct tracker_list **list);
void free_trackers_and_list(struct tracker_list **list);
/* smatch_conditions */
int in_condition(void);
/* smatch_flow.c */
extern int __in_fake_assign;
extern int __in_fake_parameter_assign;
extern int __in_fake_struct_assign;
extern int __in_buf_clear;
extern int __in_fake_var_assign;
extern int __in_builtin_overflow_func;
extern int __fake_state_cnt;
extern int __debug_skip;
extern int in_fake_env;
bool is_fake_var_assign(struct expression *expr);
void smatch (struct string_list *filelist);
int inside_loop(void);
int definitely_inside_loop(void);
void add_once_through_hook(bool_stmt_func *fn);
struct expression *get_switch_expr(void);
int in_expression_statement(void);
void __process_post_op_stack(void);
void parse_assignment(struct expression *expr, bool shallow);
void __split_expr(struct expression *expr);
void __split_label_stmt(struct statement *stmt);
void __split_stmt(struct statement *stmt);
extern int __in_function_def;
extern int __in_unmatched_hook;
extern int option_assume_loops;
extern int option_two_passes;
extern int option_no_db;
extern int option_file_output;
extern int option_time;
extern int option_time_stmt;
extern struct expression_list *big_expression_stack;
extern struct expression_list *big_condition_stack;
extern struct statement_list *big_statement_stack;
int is_condition_call(struct expression *expr);
int is_assigned_call(struct expression *expr);
int is_fake_assigned_call(struct expression *expr);
void add_function_data(unsigned long *fn_data);
int inlinable(struct expression *expr);
extern int __inline_call;
extern struct expression *__inline_fn;
extern int __in_pre_condition;
extern int __bail_on_rest_of_function;
extern struct statement *__prev_stmt;
extern struct statement *__cur_stmt;
extern struct statement *__next_stmt;
void init_fake_env(void);
void end_fake_env(void);
int time_parsing_function(void);
bool taking_too_long(void);
struct statement *get_last_stmt(void);
int is_last_stmt(struct statement *cur_stmt);
/* smatch_struct_assignment.c */
struct expression *get_faked_expression(void);
void __fake_struct_member_assignments(struct expression *expr);
void create_recursive_fake_assignments(struct expression *expr,
void (*assign_handler)(struct expression *expr, void *data),
void *data);
/* smatch_project.c */
int is_no_inline_function(const char *function);
/* smatch_conditions */
void __set_confidence_implied(void);
void __unset_confidence();
void __split_whole_condition_tf(struct expression *expr, int *known_tf);
void __split_whole_condition(struct expression *expr);
void __handle_logic(struct expression *expr);
int is_condition(struct expression *expr);
int __handle_condition_assigns(struct expression *expr);
int __handle_select_assigns(struct expression *expr);
int __handle_expr_statement_assigns(struct expression *expr);
/* smatch_implied.c */
struct range_list_stack;
void turn_off_implications(int id);
void param_limit_implications(struct expression *expr, int param, char *key, char *value, struct stree **implied);
struct stree *__implied_case_stree(struct expression *switch_expr,
struct range_list *case_rl,
struct range_list_stack **remaining_cases,
struct stree **raw_stree);
void overwrite_states_using_pool(struct sm_state *gate_sm, struct sm_state *pool_sm);
int assume(struct expression *expr);
void end_assume(void);
int impossible_assumption(struct expression *left, int op, sval_t sval);
/* smatch_slist.h */
bool has_dynamic_states(unsigned short owner);
void set_dynamic_states(unsigned short owner);
/* smatch_extras.c */
int in_warn_on_macro(void);
extern int SMATCH_EXTRA;
extern int RETURN_ID;
struct data_range {
sval_t min;
sval_t max;
};
char *get_other_name_sym(const char *name, struct symbol *sym, struct symbol **new_sym);
char *map_call_to_other_name_sym(const char *name, struct symbol *sym, struct symbol **new_sym);
char *map_long_to_short_name_sym(const char *name, struct symbol *sym, struct symbol **new_sym, bool use_stack);
#define STRLEN_MAX_RET 1010101
/* smatch_absolute.c */
int get_absolute_min_helper(struct expression *expr, sval_t *sval);
int get_absolute_max_helper(struct expression *expr, sval_t *sval);
/* smatch_type_value.c */
void disable_type_val_lookups(void);
void enable_type_val_lookups(void);
void clear_type_value_cache(void);
int get_db_type_rl(struct expression *expr, struct range_list **rl);
/* smatch_data_val.c */
int get_mtag_rl(struct expression *expr, struct range_list **rl);
/* smatch_array_values.c */
void clear_array_values_cache(void);
int get_array_rl(struct expression *expr, struct range_list **rl);
/* smatch_states.c */
struct stree *__swap_cur_stree(struct stree *stree);
void __push_fake_cur_stree();
struct stree *__pop_fake_cur_stree();
void __free_fake_cur_stree();
void __set_fake_cur_stree_fast(struct stree *stree);
void __pop_fake_cur_stree_fast(void);
void __merge_stree_into_cur(struct stree *stree);
int unreachable(void);
void __set_cur_stree_readonly(void);
void __set_cur_stree_writable(void);
void __set_sm(struct sm_state *sm);
void __set_sm_cur_stree(struct sm_state *sm);
void __set_true_false_sm(struct sm_state *true_state,
struct sm_state *false_state);
void nullify_path(void);
void __match_nullify_path_hook(const char *fn, struct expression *expr,
void *unused);
void __unnullify_path(void);
int __path_is_null(void);
void save_all_states(void);
void restore_all_states(void);
void free_goto_stack(void);
void clear_all_states(void);
struct sm_state *get_sm_state(int owner, const char *name,
struct symbol *sym);
struct sm_state *get_sm_state_expr(int owner, struct expression *expr);
void __push_true_states(void);
void __use_false_states(void);
void __discard_false_states(void);
void __merge_false_states(void);
void __merge_true_states(void);
void __negate_cond_stacks(void);
void __use_pre_cond_states(void);
void __use_cond_true_states(void);
void __use_cond_false_states(void);
void __push_cond_stacks(void);
void __fold_in_set_states(void);
void __free_set_states(void);
struct stree *__copy_cond_true_states(void);
struct stree *__copy_cond_false_states(void);
struct stree *__pop_cond_true_stack(void);
struct stree *__pop_cond_false_stack(void);
void __and_cond_states(void);
void __or_cond_states(void);
void __save_pre_cond_states(void);
void __discard_pre_cond_states(void);
struct stree *__get_true_states(void);
struct stree *__get_false_states(void);
void __use_cond_states(void);
extern struct state_list *__last_base_slist;
void __push_continues(void);
void __discard_continues(void);
void __process_continues(void);
void __merge_continues(void);
void __push_breaks(void);
void __process_breaks(void);
int __has_breaks(void);
void __merge_breaks(void);
void __use_breaks(void);
void __save_switch_states(struct expression *switch_expr);
void __discard_switches(void);
int have_remaining_cases(void);
void __merge_switches(struct expression *switch_expr, struct range_list *case_rl);
void __push_default(void);
void __set_default(void);
bool __has_default_case(void);
int __pop_default(void);
void __push_conditions(void);
void __discard_conditions(void);
void __save_gotos(const char *name, struct symbol *sym);
void __merge_gotos(const char *name, struct symbol *sym);
void __discard_fake_states(struct expression *call);
void __print_cur_stree(void);
bool __print_states(const char *owner);
typedef void (check_tracker_hook)(int owner, const char *name, struct symbol *sym, struct smatch_state *state);
void add_check_tracker(const char *check_name, check_tracker_hook *fn);
/* smatch_hooks.c */
void __pass_to_client(void *data, enum hook_type type);
void __pass_case_to_client(struct expression *switch_expr,
struct range_list *rl);
int __has_merge_function(int client_id);
struct smatch_state *__client_merge_function(int owner,
struct smatch_state *s1,
struct smatch_state *s2);
struct smatch_state *__client_unmatched_state_function(struct sm_state *sm);
void call_pre_merge_hook(struct sm_state *cur, struct sm_state *other);
void __push_scope_hooks(void);
void __call_scope_hooks(void);
void __free_scope_hooks(void);
void __call_all_scope_hooks(void);
void add_array_initialized_hook(void (*hook)(struct expression *array, int nr));
void __call_array_initialized_hooks(struct expression *array, int nr);
/* smatch_function_hooks.c */
void add_fake_call_after_return(struct expression *call);
void create_function_hook_hash(void);
void __match_initializer_call(struct symbol *sym);
struct expression *get_unfaked_call(void);
void fake_param_assign_helper(struct expression *call, struct expression *fake_assign, bool shallow);
/* smatch_db.c */
enum info_type {
INTERNAL = 0,
/*
* Changing these numbers is a pain. Don't do it. If you ever use a
* number it can't be re-used right away so there may be gaps.
* We select these in order by type so if the order matters, then give
* it a number below 100-999,9000-9999 ranges. */
PARAM_LIMIT = 103,
PARAM_FILTER = 104,
RELEASE = 500,
BUF_CLEARED = 501,
BUF_ADD = 502,
PARAM_VALUE = 1001,
BUF_SIZE = 1002,
CAPPED_DATA = 1004,
RETURN_VALUE = 1005,
DEREFERENCE = 1006,
RANGE_CAP = 1007,
ABSOLUTE_LIMITS = 1010,
PARAM_ADD = 1012,
PARAM_FREED = 1013,
MAYBE_FREED = 2014,
DATA_SOURCE = 1014,
FUZZY_MAX = 1015,
HARD_MAX = 2015,
STR_LEN = 1016,
ARRAY_LEN = 1017,
CAPABLE = 1018,
NS_CAPABLE = 1019,
CONTAINER = 1020,
CASTED_CALL = 1021,
TYPE_LINK = 1022,
UNTRACKED_PARAM = 1023,
LOST_PARAM = 2023,
CULL_PATH = 1024,
PARAM_SET = 1025,
PARAM_USED = 1026,
BYTE_UNITS = 1027,
COMPARE_LIMIT = 1028,
PARAM_COMPARE = 1029,
CONSTRAINT = 1031,
PASSES_TYPE = 1032,
CONSTRAINT_REQUIRED = 1033,
BIT_INFO = 1034,
NOSPEC = 1035,
NOSPEC_WB = 1036,
STMT_CNT = 1037,
TERMINATED = 1038,
SLEEP = 1039,
FRESH_ALLOC = 1044,
ALLOCATOR = 1045,
FUNC_TIME = 1047,
POWER_OF_TWO = 1048,
POWER_OF_TWO_SET = 1049,
BIT_SET = 1051,
BIT_CLEAR = 1052,
BIT_IS_SET = 1053,
BIT_IS_CLEAR = 1054,
NEGATIVE_ERROR = 1057,
ERR_PTR = 1060,
PREEMPT_ADD = 2054,
PREEMPT_SUB = 2055,
FD_INSTALL = 2058,
FGET = 3059,
IRQ_CONTEXT = 2062,
TASK_RUNNING = 2063,
TASK_NOT_RUNNING = 2064,
/* put random temporary stuff in the 7000-7999 range for testing */
HOST_DATA = 7016,
HOST_DATA_SET = 7017,
HOST_PTR = 7018,
HOST_PTR_SET = 7019,
USER_DATA = 8017,
USER_DATA_SET = 9017,
USER_PTR = 9018,
USER_PTR_SET = 9019,
NO_OVERFLOW = 8018,
NO_OVERFLOW_SIMPLE = 8019,
LOCK = 8020,