49 if (!SVFUtil::isa<CallICFGNode>(node))
54 if (
const GepStmt*
gep = SVFUtil::dyn_cast<GepStmt>(stmt))
62 ae.getGepByteOffset(
gep));
82 size = ae.getAllocaInstByteSize(
addrStmt);
120 std::string funcName =
callNode->getCalledFunction()->getName();
122 if (funcName ==
"SAFE_BUFACCESS")
124 ae.getUtils()->checkpoints.erase(
callNode);
131 assert(
false &&
"SAFE_BUFACCESS size is bottom");
138 <<
" — " <<
callNode->toString() <<
"\n";
144 <<
" — Position: " <<
callNode->getSourceLoc() <<
"\n";
148 else if (funcName ==
"UNSAFE_BUFACCESS")
150 ae.getUtils()->checkpoints.erase(
callNode);
151 if (
callNode->arg_size() < 2)
return;
155 assert(
false &&
"UNSAFE_BUFACCESS size is bottom");
162 <<
" — " <<
callNode->toString() <<
"\n";
168 <<
" — Position: " <<
callNode->getSourceLoc() <<
"\n";
223 if (
annotation.find(
"MEMCPY") != std::string::npos)
225 if (
annotation.find(
"MEMSET") != std::string::npos)
227 if (
annotation.find(
"STRCPY") != std::string::npos)
229 if (
annotation.find(
"STRCAT") != std::string::npos)
241 std::vector<std::pair<u32_t, u32_t>>
args =
261 std::vector<std::pair<u32_t, u32_t>>
args =
312 if (SVFUtil::isa<BaseObjVar>(
obj))
314 return ae.getGepByteOffset(
gep);
316 else if (SVFUtil::isa<GepObjVar>(
obj))
322 assert(SVFUtil::isa<DummyObjVar>(
obj) &&
"Unknown object type");
348 if (SVFUtil::isa<BaseObjVar>(
obj))
363 "GEP object is neither a GepObjVar nor an address without a backing object");
367 else if (SVFUtil::isa<GepObjVar>(
obj))
389 "GEP RHS object has no offset from base");
395 "GEP object is neither a GepObjVar nor an address without a backing object");
424 const std::vector<std::string>
strcatGroup = {
"__strcat_chk",
"strcat",
"__wcscat_chk",
"wcscat"};
425 const std::vector<std::string>
strncatGroup = {
"__strncat_chk",
"strncat",
"__wcsncat_chk",
"wcsncat"};
447 assert(
false &&
"Unknown strcat function, please add it to strcatGroup or strncatGroup");
472 ae.updateAbsValue(value,
ptrVal, node);
497 size = ae.getAllocaInstByteSize(
addrStmt);
515 if (
offset.ub().getIntNumeral() >= size)
525 if (SVFUtil::isa<CallICFGNode>(node))
539 if (
const GepStmt*
gep = SVFUtil::dyn_cast<GepStmt>(stmt))
550 else if (
const LoadStmt* load = SVFUtil::dyn_cast<LoadStmt>(stmt))
568 std::string funcName =
callNode->getCalledFunction()->getName();
570 if (funcName ==
"UNSAFE_LOAD")
573 ae.getUtils()->checkpoints.erase(
callNode);
586 <<
" — " <<
callNode->toString() <<
"\n";
592 <<
" — Position: " <<
callNode->getSourceLoc() <<
"\n";
596 else if (funcName ==
"SAFE_LOAD")
599 ae.getUtils()->checkpoints.erase(
callNode);
600 if (
callNode->arg_size() < 1)
return;
607 <<
" — " <<
callNode->toString() <<
"\n";
613 <<
" — Position: " <<
callNode->getSourceLoc() <<
"\n";
627 if (
annotation.find(
"MEMCPY") != std::string::npos)
644 else if (
annotation.find(
"MEMSET") != std::string::npos)
649 else if (
annotation.find(
"STRCPY") != std::string::npos)
655 else if (
annotation.find(
"STRCAT") != std::string::npos)
683 if (!
AbsVal.isAddr())
return true;
688 ae.getAbsState(node).isFreedMem(
addr))
Exception class for handling errors in Abstract Execution.
ExtAPIType
Enumeration of external API types.
static AbstractInterpretation & getAEInstance()
u32_t getIDFromAddr(u32_t addr) const
Return the internal index if addr is an address otherwise return the value of idx.
static bool isNullOrBlackHoleAddr(u32_t addr)
Whether addr has no concrete backing memory object.
const ICFGNode * getICFGNode() const
Get the ICFGNode related to the creation of this object.
bool isConstantByteSize() const
Check if byte size is a const value.
u32_t getByteSizeOfObj() const
Get the byte size of this object.
void addToGepObjOffsetFromBase(const GepObjVar *obj, const IntervalValue &offset)
Adds an offset to a GEP object.
void detect(const ICFGNode *) override
Detect buffer overflow issues within a node.
Map< std::string, std::vector< std::pair< u32_t, u32_t > > > extAPIBufOverflowCheckRules
Rules for checking buffer overflows in external APIs.
IntervalValue getAccessOffset(NodeID objId, const GepStmt *gep)
Retrieves the access offset for a given object and GEP statement.
void updateGepObjOffsetFromBase(const ICFGNode *node, AddressValue gepAddrs, AddressValue objAddrs, IntervalValue offset)
Updates the offset of a GEP object from its base.
void detectExtAPI(const CallICFGNode *call)
Handles external API calls related to buffer overflow detection.
bool canSafelyAccessMemory(const ValVar *value, const IntervalValue &len, const ICFGNode *node)
Checks if memory can be safely accessed.
IntervalValue getGepObjOffsetFromBase(const GepObjVar *obj) const
Retrieves the offset of a GEP object from its base.
bool detectStrcpy(const CallICFGNode *call)
Detects buffer overflow in 'strcpy' function calls.
void handleStubFunctions(const CallICFGNode *) override
Handles external API calls related to buffer overflow detection.
bool hasGepObjOffsetFromBase(const GepObjVar *obj) const
Checks if a GEP object has an associated offset.
void initExtAPIBufOverflowCheckRules()
Initializes external API buffer overflow check rules.
bool detectStrcat(const CallICFGNode *call)
Detects buffer overflow in 'strcat' function calls.
void addBugToReporter(const AEException &e, const ICFGNode *node)
Adds a bug to the reporter based on an exception.
const std::string toString() const override
const ValVar * getArgument(u32_t ArgNo) const
Parameter operations.
const FunObjVar * getCalledFunction() const
static ExtAPI * getExtAPI()
const std::vector< std::string > & getExtFuncAnnotations(const FunObjVar *fun)
const SVFStmtList & getSVFStmts() const
static IntervalValue top()
Create the IntervalValue [-inf, +inf].
bool canSafelyDerefPtr(const ValVar *ptr, const ICFGNode *node)
bool isUninit(AbstractValue v)
Checks if an Abstract Value is uninitialized.
void handleStubFunctions(const CallICFGNode *call) override
Handles external API calls related to nullptr dereferences.
void detect(const ICFGNode *node) override
Detects nullptr dereferences issues within a node.
void addBugToReporter(const AEException &e, const ICFGNode *node)
Adds a bug to the reporter based on an exception.
void detectExtAPI(const CallICFGNode *call)
Handle external API calls related to nullptr dereferences.
const BaseObjVar * getBaseObject(NodeID id) const
const SVFVar * getSVFVar(NodeID id) const
ObjVar/GepObjVar/BaseObjVar.
static SVFIR * getPAG(bool buildFromFile=false)
Singleton design here to make sure we only have one instance during any analysis.
NodeID getId() const
Get ID.
virtual const std::string & getName() const
std::string sucMsg(const std::string &msg)
Returns successful message by converting a string into green string output.
std::string errMsg(const std::string &msg)
Print error message by converting a string into red string output.
std::ostream & errs()
Overwrite llvm::errs()
bool isExtCall(const FunObjVar *fun)
std::ostream & outs()
Overwrite llvm::outs()
llvm::IRBuilder IRBuilder