= event->m_eedge.m_src->get_state ().m_region_model;
tree callee_var = callee_model->get_representative_tree (sval);
callsite_expr expr;
- tree caller_var = caller_model->get_representative_tree (sval);
+
+ tree caller_var;
+ if(event->m_sedge)
+ {
+ const callgraph_superedge& cg_superedge
+ = event->get_callgraph_superedge ();
+ if (cg_superedge.m_cedge)
+ caller_var
+ = cg_superedge.map_expr_from_callee_to_caller (callee_var,
+ &expr);
+ else
+ callee_var = callee_model->get_representative_tree (sval);
+ }
+ else
+ caller_var = caller_model->get_representative_tree (sval);
+
if (caller_var)
{
if (get_logger ())
if (sval)
{
return_event *event = (return_event *)base_event;
+ const region_model *caller_model
+ = event->m_eedge.m_dest->get_state ().m_region_model;
+ tree caller_var = caller_model->get_representative_tree (sval);
+ const region_model *callee_model
+ = event->m_eedge.m_src->get_state ().m_region_model;
callsite_expr expr;
- const region_model *callee_model
- = event->m_eedge.m_src->get_state ().m_region_model;
- tree callee_var = callee_model->get_representative_tree (sval);
+ tree callee_var;
+ if (event->m_sedge)
+ {
+ const callgraph_superedge& cg_superedge
+ = event->get_callgraph_superedge ();
+ if (cg_superedge.m_cedge)
+ callee_var
+ = cg_superedge.map_expr_from_caller_to_callee (caller_var,
+ &expr);
+ else
+ callee_var = callee_model->get_representative_tree (sval);
+ }
+ else
+ callee_var = callee_model->get_representative_tree (sval);
+
if (callee_var)
{
if (get_logger ())
Some example such calls are dynamically dispatched calls to virtual
functions or calls that happen via function pointer. */
-void
-exploded_graph::create_dynamic_call (const gcall *call,
- tree fn_decl,
- exploded_node *node,
- program_state next_state,
- program_point &next_point,
- uncertainty_t *uncertainty,
- logger *logger)
+bool
+exploded_graph::maybe_create_dynamic_call (const gcall *call,
+ tree fn_decl,
+ exploded_node *node,
+ program_state next_state,
+ program_point &next_point,
+ uncertainty_t *uncertainty,
+ logger *logger)
{
LOG_FUNC (logger);
if (fun)
{
const supergraph &sg = this->get_supergraph ();
- supernode * sn_entry = sg.get_node_for_function_entry (fun);
- supernode * sn_exit = sg.get_node_for_function_exit (fun);
+ supernode *sn_entry = sg.get_node_for_function_entry (fun);
+ supernode *sn_exit = sg.get_node_for_function_exit (fun);
program_point new_point
= program_point::before_supernode (sn_entry,
if (enode)
add_edge (node,enode, NULL,
new dynamic_call_info_t (call));
+ return true;
}
- }
+ }
+ return false;
}
/* The core of exploded_graph::process_worklist (the main analysis loop),
point.get_stmt());
region_model *model = state.m_region_model;
+ bool call_discovered = false;
if (tree fn_decl = model->get_fndecl_for_call(call,&ctxt))
- create_dynamic_call (call,
- fn_decl,
- node,
- next_state,
- next_point,
- &uncertainty,
- logger);
- else
+ call_discovered = maybe_create_dynamic_call (call,
+ fn_decl,
+ node,
+ next_state,
+ next_point,
+ &uncertainty,
+ logger);
+ if (!call_discovered)
{
- /* An unknown function was called at this point, in such
- case, don't terminate the analysis of the current
- function.
+ /* An unknown function or a special function was called
+ at this point, in such case, don't terminate the
+ analysis of the current function.
- The analyzer handles calls to unknown functions while
+ The analyzer handles calls to such functions while
analysing the stmt itself, so the the function call
must have been handled by the anlyzer till now. */
exploded_node *next
bool maybe_process_run_of_before_supernode_enodes (exploded_node *node);
void process_node (exploded_node *node);
- void create_dynamic_call (const gcall *call,
- tree fn_decl,
- exploded_node *node,
- program_state next_state,
- program_point &next_point,
- uncertainty_t *uncertainty,
- logger *logger);
+ bool maybe_create_dynamic_call (const gcall *call,
+ tree fn_decl,
+ exploded_node *node,
+ program_state next_state,
+ program_point &next_point,
+ uncertainty_t *uncertainty,
+ logger *logger);
exploded_node *get_or_create_node (const program_point &point,
const program_state &state,
void
region_model::update_for_gcall (const gcall *call_stmt,
- region_model_context *ctxt)
+ region_model_context *ctxt,
+ function *callee)
{
/* Build a vec of argument svalues, using the current top
frame for resolving tree expressions. */
arg_svals.quick_push (get_rvalue (arg, ctxt));
}
- /* Get the function * from the call. */
- tree fn_decl = get_fndecl_for_call (call_stmt,ctxt);
- function *fun = DECL_STRUCT_FUNCTION (fn_decl);
- push_frame (fun, &arg_svals, ctxt);
+ if(!callee)
+ {
+ /* Get the function * from the gcall. */
+ tree fn_decl = get_fndecl_for_call (call_stmt,ctxt);
+ callee = DECL_STRUCT_FUNCTION (fn_decl);
+ }
+
+ push_frame (callee, &arg_svals, ctxt);
}
/* Pop the top-most frame_region from the stack, and copy the return
region_model_context *ctxt)
{
const gcall *call_stmt = call_edge.get_call_stmt ();
- update_for_gcall (call_stmt,ctxt);
+ update_for_gcall (call_stmt, ctxt, call_edge.get_callee_function ());
}
/* Extract calling information from the return superedge and update the model
rejected_constraint **out);
void update_for_gcall (const gcall *call_stmt,
- region_model_context *ctxt);
+ region_model_context *ctxt,
+ function *callee = NULL);
void update_for_return_gcall (const gcall *call_stmt,
region_model_context *ctxt);
void
calls_free (void *victim)
{
- free (victim);
+ free (victim); /* { dg-warning "double-'free' of 'victim'" } */
}
+
void
no_op (void *ptr)
{
fn_ptr (ptr);
fn_ptr (ptr);
}
-// TODO: issue a double-'free' warning at 2nd call to fn_ptr.
/* As above, but with an extra indirection to try to thwart
the optimizer. */
(*fn_ptr) (ptr);
(*fn_ptr) (ptr);
}
-// TODO: issue a double-'free' warning at 2nd call to fn_ptr.
static void __attribute__((noinline))
called_by_test_6a (void *ptr)
{
- free (ptr); /* { dg-warning "double-'free'" "" { xfail *-*-* } } */
+ free (ptr); /* { dg-warning "double-'free'"} */
}
static deallocator_t __attribute__((noinline))