44#define SSE_FUNC_PROCESS(LLVM_NAME ,FUNC_NAME) \
45 auto sse_##FUNC_NAME = [this](const CallICFGNode *callNode) { \
47 assert(callNode->arg_size() >= 1 && "external function expects one argument"); \
48 const SVFVar* argVar = callNode->getArgument(0); \
49 const AbstractValue& argVal = ae->getAbsValue(argVar, callNode); \
50 IntervalValue result = IntervalValue::top(); \
51 if (argVal.isInterval() && argVal.getInterval().is_numeral()) { \
52 u32_t rhs = argVal.getInterval().lb().getIntNumeral(); \
53 result = IntervalValue(FUNC_NAME(rhs)); \
55 const SVFVar* retVar = callNode->getRetICFGNode()->getActualRet(); \
56 ae->updateAbsValue(retVar, result, callNode); \
58 func_map[#FUNC_NAME] = sse_##FUNC_NAME;
115 assert(
callNode->arg_size() >= 2 &&
"svf_print expects two arguments");
119 <<
", PrintVal: " <<
itv.toString() <<
", Loc:" <<
callNode->getSourceLoc() << std::endl;
126 assert(
callNode->arg_size() >= 3 &&
"set_value expects three arguments");
130 assert(
lbVal.getInterval().is_numeral() &&
ubVal.getInterval().is_numeral());
135 const ICFGNode* node = SVFUtil::cast<ValVar>(
callNode->getArgument(0))->getICFGNode();
138 if (SVFUtil::isa<LoadStmt>(stmt))
140 const LoadStmt* load = SVFUtil::cast<LoadStmt>(stmt);
152 assert(
callNode->arg_size() >= 3 &&
"fread expects at least three arguments");
168 "formatted-output function expects at least two arguments");
171 callNode->getArgument(2)->getType()->isArrayTy())
173 elemSize = SVFUtil::cast<SVFArrayType>(
174 callNode->getArgument(2)->getType())
175 ->getTypeOfElement()->getByteSize();
195 assert(
callNode->arg_size() >= 3 &&
"itoa expects three arguments");
197 std::string
snum = std::to_string(
num);
205 assert(
callNode->arg_size() >= 1 &&
"strlen expects one argument");
219 assert(
callNode->arg_size() >= 4 &&
"recv expects four arguments");
241 "VOS_MemFree",
"cfree",
"free",
"free_all_mem",
"freeaddrinfo",
242 "gcry_mpi_release",
"gcry_sexp_release",
"globfree",
"nhfree",
243 "obstack_free",
"safe_cfree",
"safe_free",
"safefree",
"safexfree",
244 "sm_free",
"vim_free",
"xfree",
"SSL_CTX_free",
"SSL_free",
"XFree"
268 if (
const CallICFGNode *call = SVFUtil::dyn_cast<CallICFGNode>(node))
270 if (
const FunObjVar *fun = call->getCalledFunction())
324 if (!
val.getInterval().is_numeral())
328 if ((
char)
val.getInterval().getIntNumeral() ==
'\0')
332 str0.push_back((
char)
val.getInterval().getIntNumeral());
340 assert(fun &&
"FunObjVar* is nullptr");
345 if (
annotation.find(
"MEMCPY") != std::string::npos)
347 if (
annotation.find(
"MEMSET") != std::string::npos)
349 if (
annotation.find(
"STRCPY") != std::string::npos)
351 if (
annotation.find(
"STRCAT") != std::string::npos)
390 if (
name.find(
"ncat") != std::string::npos)
410 if (
var->getType()->isArrayTy())
412 return SVFUtil::dyn_cast<SVFArrayType>(
var->getType())
413 ->getTypeOfElement()->getByteSize();
415 if (
var->getType()->isPointerTy())
417 assert(
false &&
"unsupported type for element size");
426 return !
len.isBottom() && !
len.lb().is_minus_infinity();
483 if (
val.getInterval().is_numeral() &&
484 (
char)
val.getInterval().getIntNumeral() ==
'\0')
582 ->getTypeOfElement()->getByteSize();
590 assert(
false &&
"unsupported type for element size");
601 if (
as.inAddrToValTable(
objId))
637 ub =
static_cast<s64_t>(std::numeric_limits<s32_t>::max());
638 lb =
static_cast<s64_t>(std::numeric_limits<s32_t>::min());
642 ub =
static_cast<s64_t>(std::numeric_limits<u32_t>::max());
643 lb =
static_cast<s64_t>(std::numeric_limits<u32_t>::min());
650 ub =
static_cast<s64_t>(std::numeric_limits<s16_t>::max());
651 lb =
static_cast<s64_t>(std::numeric_limits<s16_t>::min());
655 ub =
static_cast<s64_t>(std::numeric_limits<u16_t>::max());
656 lb =
static_cast<s64_t>(std::numeric_limits<u16_t>::min());
663 ub =
static_cast<s64_t>(std::numeric_limits<int8_t>::max());
664 lb =
static_cast<s64_t>(std::numeric_limits<int8_t>::min());
668 ub =
static_cast<s64_t>(std::numeric_limits<uint8_t>::max());
669 lb =
static_cast<s64_t>(std::numeric_limits<uint8_t>::min());
674 else if (SVFUtil::isa<SVFOtherType>(
type))
677 s64_t ub =
static_cast<s64_t>(std::numeric_limits<s32_t>::max());
678 s64_t lb =
static_cast<s64_t>(std::numeric_limits<s32_t>::min());
#define SSE_FUNC_PROCESS(LLVM_NAME,FUNC_NAME)
AbstractInterpretation * ae
Owning AbstractInterpretation; provides state access.
AbstractState & getAbsState(const ICFGNode *node)
Retrieves the abstract state from the trace for a given ICFG node.
void initExtFunMap()
Initializes the external function map.
IntervalValue getStrlen(const ValVar *strValue, const ICFGNode *node)
Calculate the length of a null-terminated string in abstract state.
void handleMemcpy(const ValVar *dst, const ValVar *src, const IntervalValue &len, u32_t start_idx, const ICFGNode *node)
Core memcpy: copy len bytes from src to dst starting at dst[start_idx].
void handleExtAPI(const CallICFGNode *call)
Handles an external API call.
void handleStrncat(const CallICFGNode *call)
static bool isValidLength(const IntervalValue &len)
Check if an interval length is usable (not bottom, not unbounded).
Set< const CallICFGNode * > checkpoints
std::string strRead(const ValVar *rhs, const ICFGNode *node)
Reads a string from the abstract state.
u32_t getElementSize(const ValVar *var)
Get the byte size of each element for a pointer/array variable.
void handleMemset(const ValVar *dst, const IntervalValue &elem, const IntervalValue &len, const ICFGNode *node)
AbsExtAPI(AbstractInterpretation *ae)
Constructor for AbsExtAPI.
SVFIR * svfir
Pointer to the SVF intermediate representation.
ExtAPIType
Enumeration of external API types.
static u32_t getBoundedMinimumByteCount(const IntervalValue &len)
Return the lower bound of len, capped by the field limit.
IntervalValue getRangeLimitFromType(const SVFType *type)
Gets the range limit from a type.
ICFG * icfg
Pointer to the interprocedural control flow graph.
void handleStrcat(const CallICFGNode *call)
void handleStrcpy(const CallICFGNode *call)
Map< std::string, std::function< void(const CallICFGNode *)> > func_map
Map of function names to handlers.
AbstractState & getAbsState(const ICFGNode *node)
u32_t getAllocaInstByteSize(const AddrStmt *addr)
AddressValue getGepObjAddrs(const ValVar *pointer, IntervalValue offset)
virtual const AbstractValue & getAbsValue(const ValVar *var, const ICFGNode *node)
virtual void updateAbsValue(const ValVar *var, const AbstractValue &val, const ICFGNode *node)
static bool isNullOrBlackHoleAddr(u32_t addr)
Whether addr has no concrete backing memory object.
void join_with(const AbstractValue &other)
IntervalValue & getInterval()
const ICFGNode * getICFGNode() const
Get the ICFGNode related to the creation of this object.
bool isConstantByteSize() const
Check if byte size is a const value.
u32_t getByteSizeOfObj() const
Get the byte size of this object.
const ValVar * getArgument(u32_t ArgNo) const
Parameter operations.
const FunObjVar * getCalledFunction() const
const RetICFGNode * getRetICFGNode() const
Return callsite.
static ExtAPI * getExtAPI()
const std::vector< std::string > & getExtFuncAnnotations(const FunObjVar *fun)
iterator begin()
Iterators.
virtual const std::string toString() const
const SVFStmtList & getSVFStmts() const
const std::string toString() const
void set_to_top()
Set current IntervalValue as top.
static IntervalValue top()
Create the IntervalValue [-inf, +inf].
const ValVar * getRHSVar() const
static const Option< u32_t > MaxFieldLimit
Maximum number of field derivations for an object.
static const Option< bool > NullDerefCheck
nullptr dereference checker, Default: false
static const Option< bool > BufferOverflowCheck
buffer overflow checker, Default: false
const SVFVar * getActualRet() const
Return actual return parameter.
const BaseObjVar * getBaseObject(NodeID id) const
static SVFIR * getPAG(bool buildFromFile=false)
Singleton design here to make sure we only have one instance during any analysis.
virtual const SVFType * getType() const
virtual const std::string & getName() const
int ispunct(int argument)
int isblank(int character)
int isalnum(int character)
int isalpha(int character)
std::string sucMsg(const std::string &msg)
Returns successful message by converting a string into green string output.
std::string errMsg(const std::string &msg)
Print error message by converting a string into red string output.
std::ostream & errs()
Overwrite llvm::errs()
llvm::IRBuilder IRBuilder