Static Value-Flow Analysis
Loading...
Searching...
No Matches
Public Types | Public Member Functions | Static Public Member Functions | Protected Types | Protected Member Functions | Protected Attributes | Static Protected Attributes | Friends | List of all members
SVF::FlowSensitive Class Reference

#include <FlowSensitive.h>

Inheritance diagram for SVF::FlowSensitive:
SVF::WPAFSSolver< GraphType > SVF::BVDataPTAImpl SVF::WPASolver< GraphType > SVF::PointerAnalysis SVF::FSMPTA< SVFGGraph > SVF::VersionedFlowSensitive

Public Types

typedef BVDataPTAImpl::MutDFPTDataTy MutDFPTDataTy
 
typedef BVDataPTAImpl::MutDFPTDataTy::DFPtsMap DFInOutMap
 
typedef BVDataPTAImpl::MutDFPTDataTy::PtsMap PtsMap
 
- Public Types inherited from SVF::WPASolver< GraphType >
typedef SVF::GenericGraphTraits< GraphType > GTraits
 Define the GTraits and node iterator for printing.
 
typedef GTraits::NodeRef GNODE
 
typedef GTraits::EdgeType GEDGE
 
typedef GTraits::ChildIteratorType child_iterator
 
typedef SCCDetection< GraphType > SCC
 
typedef FIFOWorkList< NodeID > WorkList
 
- Public Types inherited from SVF::BVDataPTAImpl
typedef PTData< NodeID, NodeSet, NodeID, PointsTo > PTDataTy
 
typedef DiffPTData< NodeID, NodeSet, NodeID, PointsTo > DiffPTDataTy
 
typedef DFPTData< NodeID, NodeSet, NodeID, PointsTo > DFPTDataTy
 
typedef VersionedPTData< NodeID, NodeSet, NodeID, PointsTo, VersionedVar, Set< VersionedVar > > VersionedPTDataTy
 
typedef MutablePTData< NodeID, NodeSet, NodeID, PointsTo > MutPTDataTy
 
typedef MutableDiffPTData< NodeID, NodeSet, NodeID, PointsTo > MutDiffPTDataTy
 
typedef MutableDFPTData< NodeID, NodeSet, NodeID, PointsTo > MutDFPTDataTy
 
typedef MutableIncDFPTData< NodeID, NodeSet, NodeID, PointsTo > MutIncDFPTDataTy
 
typedef MutableVersionedPTData< NodeID, NodeSet, NodeID, PointsTo, VersionedVar, Set< VersionedVar > > MutVersionedPTDataTy
 
typedef PersistentPTData< NodeID, NodeSet, NodeID, PointsTo > PersPTDataTy
 
typedef PersistentDiffPTData< NodeID, NodeSet, NodeID, PointsTo > PersDiffPTDataTy
 
typedef PersistentDFPTData< NodeID, NodeSet, NodeID, PointsTo > PersDFPTDataTy
 
typedef PersistentIncDFPTData< NodeID, NodeSet, NodeID, PointsTo > PersIncDFPTDataTy
 
typedef PersistentVersionedPTData< NodeID, NodeSet, NodeID, PointsTo, VersionedVar, Set< VersionedVar > > PersVersionedPTDataTy
 
- Public Types inherited from SVF::PointerAnalysis
typedef Set< const CallICFGNode * > CallSiteSet
 Indirect call edges type, map a callsite to a set of callees.
 
typedef SVFIR::CallSiteToFunPtrMap CallSiteToFunPtrMap
 
typedef Set< const FunObjVar * > FunctionSet
 
typedef OrderedMap< const CallICFGNode *, FunctionSet > CallEdgeMap
 
typedef SCCDetection< CallGraph * > CallGraphSCC
 
typedef Set< const GlobalObjVar * > VTableSet
 
typedef Set< const FunObjVar * > VFunSet
 

Public Member Functions

 FlowSensitive (SVFIR *_pag, PTATY type=PTATY::FSSPARSE_WPA)
 Constructor.
 
 ~FlowSensitive () override=default
 Destructor.
 
virtual bool runOnModule ()
 We start from here.
 
void analyze () override
 Flow sensitive analysis.
 
virtual void solveAndwritePtsToFile (const std::string &filename)
 
virtual void readPtsFromFile (const std::string &filename)
 
virtual void solveConstraints ()
 
void initialize () override
 Initialize analysis.
 
void finalize () override
 Finalize analysis.
 
const std::string PTAName () const override
 Get PTA name.
 
SVFG * getSVFG () const
 Return SVFG.
 
- Public Member Functions inherited from SVF::WPAFSSolver< GraphType >
 WPAFSSolver ()
 Constructor.
 
virtual ~WPAFSSolver ()
 Destructor.
 
virtual NodeID sccRepNode (NodeID id) const
 SCC methods.
 
- Public Member Functions inherited from SVF::BVDataPTAImpl
 BVDataPTAImpl (SVFIR *pag, PTATY type, bool alias_check=true)
 Constructor.
 
 ~BVDataPTAImpl () override=default
 Destructor.
 
PersistentPointsToCache< PointsTo > & getPtCache ()
 
const PointsTo & getPts (NodeID id) override
 
const NodeSet & getRevPts (NodeID nodeId) override
 
virtual void clearPts (NodeID id, NodeID element)
 Remove element from the points-to set of id.
 
virtual void clearFullPts (NodeID id)
 Clear points-to set of id.
 
virtual bool unionPts (NodeID id, const PointsTo &target)
 
virtual bool unionPts (NodeID id, NodeID ptd)
 
virtual bool addPts (NodeID id, NodeID ptd)
 
virtual void clearAllPts ()
 Clear all data.
 
virtual void expandFIObjs (const PointsTo &pts, PointsTo &expandedPts)
 Expand FI objects.
 
virtual void expandFIObjs (const NodeBS &pts, NodeBS &expandedPts)
 TODO: remove repetition.
 
void remapPointsToSets (void)
 Remap all points-to sets to use the current mapping.
 
virtual void writeToFile (const std::string &filename)
 Interface for analysis result storage on filesystem.
 
virtual void writeObjVarToFile (const std::string &filename)
 
virtual void writePtsResultToFile (std::fstream &f)
 
virtual void writeGepObjVarMapToFile (std::fstream &f)
 
virtual bool readFromFile (const std::string &filename)
 
virtual void readPtsResultFromFile (std::ifstream &f)
 
virtual void readGepObjVarMapFromFile (std::ifstream &f)
 
virtual void readAndSetObjFieldSensitivity (std::ifstream &f, const std::string &delimiterStr)
 
AliasResult alias (const SVFVar *V1, const SVFVar *V2) override
 Interface expose to users of our pointer analysis, given Value infos.
 
AliasResult alias (NodeID node1, NodeID node2) override
 Interface expose to users of our pointer analysis, given PAGNodeID.
 
virtual AliasResult alias (const PointsTo &pts1, const PointsTo &pts2)
 Interface expose to users of our pointer analysis, given two pts.
 
bool mayAlias (const PointsTo &pts1, const PointsTo &pts2)
 Convenience bool wrappers: return true if the two operands may/must/partial alias.
 
void dumpCPts () override
 dump and debug, print out conditional pts
 
void dumpTopLevelPtsTo () override
 
void dumpAllPts () override
 
bool mayAlias (const SVFVar *V1, const SVFVar *V2)
 
bool mayAlias (NodeID node1, NodeID node2)
 
- Public Member Functions inherited from SVF::PointerAnalysis
ICFG * getICFG () const
 Get ICFG.
 
u32_t getNumOfResolvedIndCallEdge () const
 Return number of resolved indirect call edges.
 
CallGraph * getCallGraph () const
 Return call graph.
 
CallGraphSCC * getCallGraphSCC () const
 Return call graph SCC.
 
 PointerAnalysis (SVFIR *pag, PTATY ty=PTATY::Default_PTA, bool alias_check=true)
 Constructor.
 
PTATY getAnalysisTy () const
 Type of pointer analysis.
 
PTAImplTy getImplTy () const
 Return implementation type of the pointer analysis.
 
bool printStat ()
 Whether print statistics.
 
void disablePrintStat ()
 Whether print statistics.
 
CallEdgeMap & getIndCallMap ()
 Get callees from an indirect callsite.
 
bool hasIndCSCallees (const CallICFGNode *cs) const
 
const FunctionSet & getIndCSCallees (const CallICFGNode *cs) const
 
virtual void resolveIndCalls (const CallICFGNode *cs, const PointsTo &target, CallEdgeMap &newEdges)
 Resolve indirect call edges.
 
void callGraphSCCDetection ()
 PTACallGraph SCC related methods.
 
NodeID getCallGraphSCCRepNode (NodeID id) const
 Get SCC rep node of a SVFG node.
 
bool inSameCallGraphSCC (const FunObjVar *fun1, const FunObjVar *fun2)
 Return TRUE if this edge is inside a PTACallGraph SCC, i.e., src node and dst node are in the same SCC on the SVFG.
 
bool isInRecursion (const FunObjVar *fun) const
 
bool isLocalVarInRecursiveFun (NodeID id) const
 Whether a local variable is in function recursions.
 
CommonCHGraph * getCHGraph () const
 get CHGraph
 
void getVFnsFromCHA (const CallICFGNode *cs, VFunSet &vfns)
 
void getVFnsFromPts (const CallICFGNode *cs, const PointsTo &target, VFunSet &vfns)
 
void connectVCallToVFns (const CallICFGNode *cs, const VFunSet &vfns, CallEdgeMap &newEdges)
 
virtual void resolveCPPIndCalls (const CallICFGNode *cs, const PointsTo &target, CallEdgeMap &newEdges)
 Resolve cpp indirect call edges.
 
SVFIR * getPAG () const
 
PTAStat * getStat () const
 Get PTA stat.
 
OrderedNodeSet & getAllValidPtrs ()
 Get all Valid Pointers for resolution.
 
virtual void computeDDAPts (NodeID)
 Compute points-to results on-demand, overridden by derived classes.
 
virtual NodeBS getMayAliases (NodeID node)
 
bool mayAlias (const SVFVar *V1, const SVFVar *V2)
 Convenience bool wrappers: return true if the two operands may/must/partial alias.
 
bool mayAlias (NodeID node1, NodeID node2)
 
void printIndCSTargets (const CallICFGNode *cs, const FunctionSet &targets)
 Print targets of a function pointer.
 
virtual void dumpPts (NodeID ptr, const PointsTo &pts)
 
void printIndCSTargets ()
 
void dumpAllTypes ()
 
void dumpStat ()
 Dump the statistics.
 
bool containBlackHoleNode (const PointsTo &pts)
 Determine whether a points-to contains a black hole or constant node.
 
bool containConstantNode (const PointsTo &pts)
 
virtual bool isBlkObjOrConstantObj (NodeID ptd) const
 
bool isHeapMemObj (NodeID id) const
 Whether this object is heap or array.
 
bool isArrayMemObj (NodeID id) const
 
bool isFIObjNode (NodeID id) const
 
NodeID getBaseObjVarID (NodeID id)
 
NodeID getFIObjVar (NodeID id)
 
NodeID getGepObjVar (NodeID id, const APOffset &ap)
 
virtual const NodeBS & getAllFieldsObjVars (NodeID id)
 
void setObjFieldInsensitive (NodeID id)
 
bool isFieldInsensitive (NodeID id) const
 

Static Public Member Functions

static FlowSensitive * createFSWPA (SVFIR *_pag)
 Create single instance of flow-sensitive pointer analysis.
 
static void releaseFSWPA ()
 Release flow-sensitive pointer analysis.
 
static bool classof (const FlowSensitive *)
 Methods for support type inquiry through isa, cast, and dyn_cast.
 
static bool classof (const PointerAnalysis *pta)
 
- Static Public Member Functions inherited from SVF::BVDataPTAImpl
static bool classof (const PointerAnalysis *pta)
 

Protected Types

typedef SVFG::SVFGEdgeSetTy SVFGEdgeSetTy
 

Protected Member Functions

NodeStack & SCCDetect () override
 SCC detection.
 
bool propFromSrcToDst (SVFGEdge *edge) override
 Propagation.
 
virtual bool propAlongDirectEdge (const DirectSVFGEdge *edge)
 Propagate points-to information along a DIRECT SVFG edge.
 
virtual bool propAlongIndirectEdge (const IndirectSVFGEdge *edge)
 Propagate points-to information along an INDIRECT SVFG edge.
 
virtual bool propVarPtsFromSrcToDst (NodeID var, const SVFGNode *src, const SVFGNode *dst)
 Propagate points-to information of a certain variable from src to dst.
 
virtual bool propagateFromAPToFP (const ActualParmSVFGNode *ap, const SVFGNode *dst)
 
virtual bool propagateFromFRToAR (const FormalRetSVFGNode *fr, const SVFGNode *dst)
 
virtual bool weakUpdateOutFromIn (const SVFGNode *node)
 Handle weak updates.
 
virtual bool strongUpdateOutFromIn (const SVFGNode *node, NodeID singleton)
 Handle strong updates.
 
bool propVarPtsAfterCGUpdated (NodeID var, const SVFGNode *src, const SVFGNode *dst)
 
virtual bool propDFOutToIn (const SVFGNode *srcStmt, NodeID srcVar, const SVFGNode *dstStmt, NodeID dstVar)
 
virtual bool propDFInToIn (const SVFGNode *srcStmt, NodeID srcVar, const SVFGNode *dstStmt, NodeID dstVar)
 
bool updateOutFromIn (const SVFGNode *srcStmt, NodeID srcVar, const SVFGNode *dstStmt, NodeID dstVar)
 Update data-flow points-to data.
 
virtual bool updateInFromIn (const SVFGNode *srcStmt, NodeID srcVar, const SVFGNode *dstStmt, NodeID dstVar)
 
virtual bool updateInFromOut (const SVFGNode *srcStmt, NodeID srcVar, const SVFGNode *dstStmt, NodeID dstVar)
 
virtual bool unionPtsFromIn (const SVFGNode *stmt, NodeID srcVar, NodeID dstVar)
 
virtual bool unionPtsFromTop (const SVFGNode *stmt, NodeID srcVar, NodeID dstVar)
 
void clearAllDFOutVarFlag (const SVFGNode *stmt)
 
void processNode (NodeID nodeId) override
 Handle various constraints.
 
bool processSVFGNode (SVFGNode *node)
 
virtual bool processAddr (const AddrSVFGNode *addr)
 
virtual bool processCopy (const CopySVFGNode *copy)
 
virtual bool processPhi (const PHISVFGNode *phi)
 
virtual bool processGep (const GepSVFGNode *edge)
 
virtual bool processLoad (const LoadSVFGNode *load)
 
virtual bool processStore (const StoreSVFGNode *store)
 
bool updateCallGraph (const CallSiteToFunPtrMap &callsites) override
 Update call graph.
 
void connectCallerAndCallee (const CallEdgeMap &newEdges, SVFGEdgeSetTy &edges)
 Connect nodes in SVFG.
 
virtual void updateConnectedNodes (const SVFGEdgeSetTy &edges)
 Update nodes connected during updating call graph.
 
bool isStrongUpdate (const SVFGNode *node, NodeID &singleton)
 Return TRUE if this is a strong update STORE statement.
 
virtual void countAliases (Set< std::pair< NodeID, NodeID > > cmp, unsigned *mayAliases, unsigned *noAliases)
 Fills may/noAliases for the location/pointer pairs in cmp.
 
const PointsTo & getDFInPtsSet (const SVFGNode *stmt, const NodeID node)
 Get points-to set for a node from data flow IN/OUT set at a statement.
 
const PointsTo & getDFOutPtsSet (const SVFGNode *stmt, const NodeID node)
 
virtual void cluster (void)
 
virtual void plainMap (void) const
 Sets the global best mapping as a plain mapping, i.e. n -> n.
 
void svfgStat ()
 
const DFInOutMap & getDFInputMap () const
 
const DFInOutMap & getDFOutputMap () const
 
- Protected Member Functions inherited from SVF::WPASolver< GraphType >
 WPASolver ()
 Constructor.
 
virtual ~WPASolver ()=default
 Destructor.
 
SCC * getSCCDetector () const
 Get SCC detector.
 
const GraphType graph ()
 Get/Set graph methods.
 
void setGraph (GraphType g)
 
virtual NodeStack & SCCDetect (NodeSet &candidates)
 
virtual void initWorklist ()
 
virtual void solveWorklist ()
 
virtual void collapseFields ()
 collapse positive weight cycles of a graph
 
virtual void propagate (GNODE *v)
 
virtual bool propFromSrcToDst (GEDGE *)
 Propagate information from source to destination node, to be implemented in the child class.
 
NodeID popFromWorklist ()
 Worklist operations.
 
virtual void pushIntoWorklist (NodeID id)
 
bool isWorklistEmpty ()
 
bool isInWorklist (NodeID id)
 
GNODE * Node (NodeID id)
 Get node on the graph.
 
NodeID Node_Index (GNODE node)
 Get node ID.
 
- Protected Member Functions inherited from SVF::BVDataPTAImpl
PTDataTy * getPTDataTy () const
 Get points-to data structure.
 
DiffPTDataTy * getDiffPTDataTy () const
 
DFPTDataTy * getDFPTDataTy () const
 
MutDFPTDataTy * getMutDFPTDataTy () const
 
VersionedPTDataTy * getVersionedPTDataTy () const
 
virtual void onTheFlyCallGraphSolve (const CallSiteToFunPtrMap &callsites, CallEdgeMap &newEdges)
 On the fly call graph construction.
 
virtual void onTheFlyThreadCallGraphSolve (const CallSiteToFunPtrMap &callsites, CallEdgeMap &newForkEdges)
 On the fly thread call graph construction respecting forksite.
 
virtual void normalizePointsTo ()
 
- Protected Member Functions inherited from SVF::PointerAnalysis
const CallSiteToFunPtrMap & getIndirectCallsites () const
 Return all indirect callsites.
 
NodeID getFunPtr (const CallICFGNode *cs) const
 Return function pointer PAGNode at a callsite cs.
 
virtual void validateTests ()
 Alias check functions to verify correctness of pointer analysis.
 
virtual void validateSuccessTests (std::string fun)
 
virtual void validateExpectedFailureTests (std::string fun)
 
void resetObjFieldSensitive ()
 Reset all object node as field-sensitive.
 

Protected Attributes

SVFG * svfg
 
SVFGBuilder memSSA
 
AndersenWaveDiff * ander
 
std::vector< std::pair< hclust_fast_methods, std::vector< NodeID > > > candidateMappings
 Save candidate mappings for evaluation's sake.
 
u32_t numOfProcessedAddr
 Statistics.
 
u32_t numOfProcessedCopy
 Number of processed Addr node.
 
u32_t numOfProcessedGep
 Number of processed Copy node.
 
u32_t numOfProcessedPhi
 Number of processed Gep node.
 
u32_t numOfProcessedLoad
 Number of processed Phi node.
 
u32_t numOfProcessedStore
 Number of processed Load node.
 
u32_t numOfProcessedActualParam
 Number of processed Store node.
 
u32_t numOfProcessedFormalRet
 Number of processed actual param node.
 
u32_t numOfProcessedMSSANode
 Number of processed formal ret node.
 
u32_t maxSCCSize
 Number of processed mssa node.
 
u32_t numOfSCC
 
u32_t numOfNodesInSCC
 
double solveTime
 time of solve.
 
double sccTime
 time of SCC detection.
 
double processTime
 time of processNode.
 
double propagationTime
 time of points-to propagation.
 
double directPropaTime
 time of points-to propagation of address-taken objects
 
double indirectPropaTime
 time of points-to propagation of top-level pointers
 
double updateTime
 time of strong/weak updates.
 
double addrTime
 time of handling address edges
 
double copyTime
 time of handling copy edges
 
double gepTime
 time of handling gep edges
 
double loadTime
 time of load edges
 
double storeTime
 time of store edges
 
double phiTime
 time of phi nodes.
 
double updateCallGraphTime
 time of updating call graph
 
NodeBS svfgHasSU
 
- Protected Attributes inherited from SVF::WPAFSSolver< GraphType >
NodeStack nodeStack
 stack used for processing nodes.
 
- Protected Attributes inherited from SVF::WPASolver< GraphType >
bool reanalyze
 Reanalyze if any constraint value changed.
 
u32_t iterationForPrintStat
 print out statistics for i-th iteration
 
GraphType _graph
 Graph.
 
std::unique_ptr< SCC > scc
 SCC.
 
WorkList worklist
 Worklist for resolution.
 
- Protected Attributes inherited from SVF::PointerAnalysis
bool print_stat
 User input flags.
 
bool alias_validation
 Flag for validating points-to/alias results.
 
u32_t OnTheFlyIterBudgetForStat
 Flag for iteration budget for on-the-fly statistics.
 
PTATY ptaTy
 Pointer analysis Type.
 
PTAImplTy ptaImplTy
 PTA implementation type.
 
PTAStat * stat
 Statistics.
 
CallGraph * callgraph
 Call graph used for pointer analysis.
 
CallGraphSCC * callGraphSCC
 SCC for PTACallGraph.
 
ICFG * icfg
 Interprocedural control-flow graph.
 
CommonCHGraph * chgraph
 CHGraph.
 

Static Protected Attributes

static std::unique_ptr< FlowSensitive > fspta
 
- Static Protected Attributes inherited from SVF::PointerAnalysis
static SVFIR * pag = nullptr
 SVFIR.
 

Friends

class FlowSensitiveStat
 

Additional Inherited Members

- Public Attributes inherited from SVF::WPASolver< GraphType >
u32_t numOfIteration
 num of iterations during constraint solving
 
- Static Public Attributes inherited from SVF::PointerAnalysis
static const std::string aliasTestMayAlias = "MAYALIAS"
 
static const std::string aliasTestMayAliasMangled = "_Z8MAYALIASPvS_"
 
static const std::string aliasTestNoAlias = "NOALIAS"
 
static const std::string aliasTestNoAliasMangled = "_Z7NOALIASPvS_"
 
static const std::string aliasTestPartialAlias = "PARTIALALIAS"
 
static const std::string aliasTestPartialAliasMangled = "_Z12PARTIALALIASPvS_"
 
static const std::string aliasTestMustAlias = "MUSTALIAS"
 
static const std::string aliasTestMustAliasMangled = "_Z9MUSTALIASPvS_"
 
static const std::string aliasTestFailMayAlias = "EXPECTEDFAIL_MAYALIAS"
 
static const std::string aliasTestFailMayAliasMangled = "_Z21EXPECTEDFAIL_MAYALIASPvS_"
 
static const std::string aliasTestFailNoAlias = "EXPECTEDFAIL_NOALIAS"
 
static const std::string aliasTestFailNoAliasMangled = "_Z20EXPECTEDFAIL_NOALIASPvS_"
 

Detailed Description

Definition at line 47 of file FlowSensitive.h.

Member Typedef Documentation

◆ DFInOutMap

Definition at line 55 of file FlowSensitive.h.

◆ MutDFPTDataTy

Definition at line 54 of file FlowSensitive.h.

◆ PtsMap

Definition at line 56 of file FlowSensitive.h.

◆ SVFGEdgeSetTy

Definition at line 51 of file FlowSensitive.h.

Constructor & Destructor Documentation

◆ FlowSensitive()

SVF::FlowSensitive::FlowSensitive ( SVFIR *  _pag,
PTATY  type = PTATY::FSSPARSE_WPA 
)
inlineexplicit

Constructor.

Definition at line 59 of file FlowSensitive.h.

60 {
61 svfg = nullptr;
71 }
newitem type
Definition cJSON.cpp:2739
BVDataPTAImpl(SVFIR *pag, PTATY type, bool alias_check=true)
Constructor.
u32_t numOfProcessedLoad
Number of processed Phi node.
u32_t numOfProcessedCopy
Number of processed Addr node.
double gepTime
time of handling gep edges
double indirectPropaTime
time of points-to propagation of top-level pointers
double addrTime
time of handling address edges
double solveTime
time of solve.
u32_t numOfProcessedStore
Number of processed Load node.
double storeTime
time of store edges
double copyTime
time of handling copy edges
u32_t numOfProcessedGep
Number of processed Copy node.
u32_t maxSCCSize
Number of processed mssa node.
double loadTime
time of load edges
u32_t numOfProcessedActualParam
Number of processed Store node.
u32_t numOfProcessedPhi
Number of processed Gep node.
double propagationTime
time of points-to propagation.
u32_t numOfProcessedFormalRet
Number of processed actual param node.
double directPropaTime
time of points-to propagation of address-taken objects
double processTime
time of processNode.
u32_t numOfProcessedAddr
Statistics.
double phiTime
time of phi nodes.
double sccTime
time of SCC detection.
double updateTime
time of strong/weak updates.
u32_t numOfProcessedMSSANode
Number of processed formal ret node.
double updateCallGraphTime
time of updating call graph
u32_t OnTheFlyIterBudgetForStat
Flag for iteration budget for on-the-fly statistics.
u32_t iterationForPrintStat
print out statistics for i-th iteration
Definition WPASolver.h:174
WPAFSSolver< SVFG * > WPASVFGFSSolver

◆ ~FlowSensitive()

SVF::FlowSensitive::~FlowSensitive ( )
overridedefault

Destructor.

Member Function Documentation

◆ analyze()

void FlowSensitive::analyze ( )
overridevirtual

Flow sensitive analysis.

Start analysis

Implements SVF::PointerAnalysis.

Definition at line 134 of file FlowSensitive.cpp.

135{
136 if(!Options::ReadAnder().empty())
137 {
139 }
140 else
141 {
142 if(Options::WriteAnder().empty())
143 {
144 initialize();
146 finalize();
147 }
148 else
149 {
151 }
152 }
153}
virtual void solveConstraints()
virtual void readPtsFromFile(const std::string &filename)
void finalize() override
Finalize analysis.
void initialize() override
Initialize analysis.
virtual void solveAndwritePtsToFile(const std::string &filename)
static const Option< std::string > ReadAnder
Definition Options.h:204
static const Option< std::string > WriteAnder
Definition Options.h:202

◆ classof() [1/2]

static bool SVF::FlowSensitive::classof ( const FlowSensitive *  )
inlinestatic

Methods for support type inquiry through isa, cast, and dyn_cast.

Definition at line 122 of file FlowSensitive.h.

123 {
124 return true;
125 }

◆ classof() [2/2]

static bool SVF::FlowSensitive::classof ( const PointerAnalysis *  pta)
inlinestatic

Definition at line 126 of file FlowSensitive.h.

127 {
128 return pta->getAnalysisTy() == PTATY::FSSPARSE_WPA;
129 }
@ FSSPARSE_WPA
Sparse flow sensitive WPA.
Definition PTATY.h:20

◆ clearAllDFOutVarFlag()

void SVF::FlowSensitive::clearAllDFOutVarFlag ( const SVFGNode *  stmt)
inlineprotected

Definition at line 209 of file FlowSensitive.h.

210 {
211 getDFPTDataTy()->clearAllDFOutUpdatedVar(stmt->getId());
212 }
DFPTDataTy * getDFPTDataTy() const

◆ cluster()

void FlowSensitive::cluster ( void  )
protectedvirtual

Performs clustering based on ander, setting the global best mapping accordingly.

Reimplemented in SVF::VersionedFlowSensitive.

Definition at line 829 of file FlowSensitive.cpp.

830{
831 std::vector<std::pair<unsigned, unsigned>> keys;
832 for (const auto& pair : *pag)
833 keys.emplace_back(pair.first, 1);
834
835 PointsTo::MappingPtr nodeMapping =
836 std::make_shared<std::vector<NodeID>>(
838 );
839 PointsTo::MappingPtr reverseNodeMapping =
840 std::make_shared<std::vector<NodeID>>(NodeIDAllocator::Clusterer::getReverseNodeMapping(*nodeMapping));
841
842 PointsTo::setCurrentBestNodeMapping(nodeMapping, reverseNodeMapping);
843}
AndersenWaveDiff * ander
std::vector< std::pair< hclust_fast_methods, std::vector< NodeID > > > candidateMappings
Save candidate mappings for evaluation's sake.
static std::vector< NodeID > getReverseNodeMapping(const std::vector< NodeID > &nodeMapping)
static std::vector< NodeID > cluster(BVDataPTAImpl *pta, const std::vector< std::pair< NodeID, unsigned > > keys, std::vector< std::pair< hclust_fast_methods, std::vector< NodeID > > > &candidates, std::string evalSubtitle="", bool printStat=true)
bool print_stat
User input flags.
static SVFIR * pag
SVFIR.
std::shared_ptr< std::vector< NodeID > > MappingPtr
Definition PointsTo.h:43
static void setCurrentBestNodeMapping(MappingPtr newCurrentBestNodeMapping, MappingPtr newCurrentBestReverseNodeMapping)
Definition PointsTo.cpp:383
llvm::IRBuilder IRBuilder
Definition BasicTypes.h:76

◆ connectCallerAndCallee()

void FlowSensitive::connectCallerAndCallee ( const CallEdgeMap &  newEdges,
SVFGEdgeSetTy &  edges 
)
protected

Connect nodes in SVFG.

Handle parameter passing in SVFG

Definition at line 744 of file FlowSensitive.cpp.

745{
746 CallEdgeMap::const_iterator iter = newEdges.begin();
747 CallEdgeMap::const_iterator eiter = newEdges.end();
748 for (; iter != eiter; iter++)
749 {
750 const CallICFGNode* cs = iter->first;
751 const FunctionSet & functions = iter->second;
752 for (FunctionSet::const_iterator func_iter = functions.begin(); func_iter != functions.end(); func_iter++)
753 {
754 const FunObjVar* func = *func_iter;
756 }
757 }
758}
Set< const FunObjVar * > FunctionSet
virtual void connectCallerAndCallee(const CallICFGNode *cs, const FunObjVar *callee, SVFGEdgeSetTy &edges)
Connect SVFG nodes between caller and callee for indirect call site.
Definition SVFG.cpp:658

◆ countAliases()

void FlowSensitive::countAliases ( Set< std::pair< NodeID, NodeID > >  cmp,
unsigned *  mayAliases,
unsigned *  noAliases 
)
protectedvirtual

Fills may/noAliases for the location/pointer pairs in cmp.

Definition at line 862 of file FlowSensitive.cpp.

863{
864 for (std::pair<NodeID, NodeID> locPA : cmp)
865 {
866 // loc doesn't make a difference for FSPTA.
867 NodeID p = locPA.second;
868 for (std::pair<NodeID, NodeID> locPB : cmp)
869 {
870 if (locPB == locPA) continue;
871
872 NodeID q = locPB.second;
873
874 switch (alias(p, q))
875 {
877 ++(*noAliases);
878 break;
880 ++(*mayAliases);
881 break;
882 default:
883 assert("Not May/NoAlias?");
884 }
885 }
886 }
887
888}
cJSON * p
Definition cJSON.cpp:2559
AliasResult alias(const SVFVar *V1, const SVFVar *V2) override
Interface expose to users of our pointer analysis, given Value infos.
u32_t NodeID
Definition GeneralType.h:76
@ MayAlias
Definition SVFType.h:621
@ NoAlias
Definition SVFType.h:620

◆ createFSWPA()

static FlowSensitive * SVF::FlowSensitive::createFSWPA ( SVFIR *  _pag)
inlinestatic

Create single instance of flow-sensitive pointer analysis.

Definition at line 77 of file FlowSensitive.h.

78 {
79 if (fspta == nullptr)
80 {
81 fspta = std::unique_ptr<FlowSensitive>(new FlowSensitive(_pag));
82 fspta->analyze();
83 }
84 return fspta.get();
85 }
static std::unique_ptr< FlowSensitive > fspta
FlowSensitive(SVFIR *_pag, PTATY type=PTATY::FSSPARSE_WPA)
Constructor.

◆ finalize()

void FlowSensitive::finalize ( )
overridevirtual

Finalize analysis.

Finalize analysis

Reimplemented from SVF::BVDataPTAImpl.

Reimplemented in SVF::FSMPTA< SVFGGraph >, and SVF::VersionedFlowSensitive.

Definition at line 169 of file FlowSensitive.cpp.

170{
171 if(Options::DumpVFG())
172 svfg->dump("fs_solved", true);
173
175 while (nodeStack.empty() == false)
176 {
177 NodeID rep = nodeStack.top();
178 nodeStack.pop();
179 const NodeBS& subNodes = getSCCDetector()->subNodes(rep);
180 if (subNodes.count() > maxSCCSize)
181 maxSCCSize = subNodes.count();
182 if (subNodes.count() > 1)
183 {
184 numOfNodesInSCC += subNodes.count();
185 numOfSCC++;
186 }
187 }
188
189 // TODO: check -stat too.
190 if (Options::ClusterFs())
191 {
193 const PTDataTy *ptd = getPTDataTy();
194 // TODO: should we use liveOnly?
195 Map<PointsTo, unsigned> allPts = ptd->getAllPts(true);
196 // TODO: parameterise final arg.
198 if (print_stat)
199 {
201 }
202 }
203
205}
void finalize() override
Finalization of pointer analysis, and normalize points-to information to Bit Vector representation.
PTData< NodeID, NodeSet, NodeID, PointsTo > PTDataTy
PTDataTy * getPTDataTy() const
Get points-to data structure.
static void printStats(std::string title, Map< std::string, std::string > &stats)
static void evaluate(const std::vector< NodeID > &nodeMap, const Map< PointsTo, unsigned > pointsToSets, Map< std::string, std::string > &stats, bool accountForOcc)
Fills in *NumWords statistics in stats..
static const Option< bool > ClusterFs
Whether to cluster FS or VFS with the auxiliary Andersen's.
Definition Options.h:40
static const Option< bool > DumpVFG
Definition Options.h:107
static MappingPtr getCurrentBestNodeMapping()
Definition PointsTo.cpp:373
void dump(const std::string &file, bool simple=false)
Dump graph into dot file.
Definition SVFG.cpp:576
unsigned count() const
NodeStack nodeStack
stack used for processing nodes.
Definition WPAFSSolver.h:65
SCC * getSCCDetector() const
Get SCC detector.
Definition WPASolver.h:68
virtual NodeStack & SCCDetect()
SCC detection.
Definition WPASolver.h:87
std::stack< NodeID > NodeStack
Definition GeneralType.h:92

◆ getDFInPtsSet()

const PointsTo & SVF::FlowSensitive::getDFInPtsSet ( const SVFGNode *  stmt,
const NodeID  node 
)
inlineprotected

Get points-to set for a node from data flow IN/OUT set at a statement.

Definition at line 246 of file FlowSensitive.h.

247 {
248 return getDFPTDataTy()->getDFInPtsSet(stmt->getId(),node);
249 }

◆ getDFInputMap()

const DFInOutMap & SVF::FlowSensitive::getDFInputMap ( ) const
inlineprotected

Get IN/OUT data flow map. May only be called when the backing is MUTABLE.

Definition at line 259 of file FlowSensitive.h.

260 {
261 return getMutDFPTDataTy()->getDFIn();
262 }
MutDFPTDataTy * getMutDFPTDataTy() const
const DFPtsMap & getDFIn()

◆ getDFOutPtsSet()

const PointsTo & SVF::FlowSensitive::getDFOutPtsSet ( const SVFGNode *  stmt,
const NodeID  node 
)
inlineprotected

Definition at line 250 of file FlowSensitive.h.

251 {
252 return getDFPTDataTy()->getDFOutPtsSet(stmt->getId(),node);
253 }

◆ getDFOutputMap()

const DFInOutMap & SVF::FlowSensitive::getDFOutputMap ( ) const
inlineprotected

Definition at line 263 of file FlowSensitive.h.

264 {
265 return getMutDFPTDataTy()->getDFOut();
266 }
const DFPtsMap & getDFOut()

◆ getSVFG()

SVFG * SVF::FlowSensitive::getSVFG ( ) const
inline

Return SVFG.

Definition at line 133 of file FlowSensitive.h.

134 {
135 return svfg;
136 }

◆ initialize()

void FlowSensitive::initialize ( )
overridevirtual

Initialize analysis.

Initialize analysis

Reimplemented from SVF::PointerAnalysis.

Reimplemented in SVF::FSMPTA< SVFGGraph >, and SVF::VersionedFlowSensitive.

Definition at line 44 of file FlowSensitive.cpp.

45{
47
48 stat = new FlowSensitiveStat(this);
49
50 // TODO: support clustered aux. Andersen's.
51 assert(!Options::ClusterAnder() && "FlowSensitive::initialize: clustering auxiliary Andersen's unsupported.");
53
54 // If cluster option is not set, it will give us a no-mapping points-to set.
56 && "FS::init: plain-mapping and cluster-fs are mutually exclusive.");
58 {
59 cluster();
60 // Reset the points-to cache although empty so the new mapping could
61 // be applied to the inserted empty set.
62 getPtCache().reset();
63 }
64 else if (Options::PlainMappingFs())
65 {
66 plainMap();
67 // As above.
68 getPtCache().reset();
69 }
70
72
74 //AndersenWaveDiff::releaseAndersenWaveDiff();
75}
static AndersenWaveDiff * createAndersenWaveDiff(SVFIR *_pag)
Create an singleton instance directly instead of invoking llvm pass manager.
Definition Andersen.h:420
PersistentPointsToCache< PointsTo > & getPtCache()
virtual void plainMap(void) const
Sets the global best mapping as a plain mapping, i.e. n -> n.
friend class FlowSensitiveStat
virtual void cluster(void)
static const Option< bool > PlainMappingFs
Use an explicitly plain mapping with flow-sensitive (not null).
Definition Options.h:43
static const Option< bool > ClusterAnder
Whether to stage Andersen's with Steensgaard and cluster based on that data.
Definition Options.h:37
virtual void initialize()
Initialization of a pointer analysis, including building symbol table and SVFIR etc.
PTAStat * stat
Statistics.
SVFIR * getPAG() const
SVFG * buildPTROnlySVFG(BVDataPTAImpl *pta)
void setGraph(GraphType g)
Definition WPASolver.h:79

◆ isStrongUpdate()

bool FlowSensitive::isStrongUpdate ( const SVFGNode *  node,
NodeID &  singleton 
)
protected

Return TRUE if this is a strong update STORE statement.

Return TRUE if this is a strong update STORE statement.

Find the unique element in cpts

Definition at line 661 of file FlowSensitive.cpp.

662{
663 bool isSU = false;
664 if (const StoreSVFGNode* store = SVFUtil::dyn_cast<StoreSVFGNode>(node))
665 {
666 const PointsTo& dstCPSet = getPts(store->getDstNodeID());
667 if (dstCPSet.count() == 1)
668 {
670 PointsTo::iterator it = dstCPSet.begin();
671 singleton = *it;
672
673 // Strong update can be made if this points-to target is not heap, array or field-insensitive.
675 {
679 {
680 isSU = true;
681 }
682 }
683 }
684 }
685 return isSU;
686}
const PointsTo & getPts(NodeID id) override
bool isFieldInsensitive() const
Return true if its field limit is 0.
bool isLocalVarInRecursiveFun(NodeID id) const
Whether a local variable is in function recursions.
bool isArrayMemObj(NodeID id) const
bool isHeapMemObj(NodeID id) const
Whether this object is heap or array.
const BaseObjVar * getBaseObject(NodeID id) const
Definition SVFIR.h:498

◆ plainMap()

void FlowSensitive::plainMap ( void  ) const
protectedvirtual

Sets the global best mapping as a plain mapping, i.e. n -> n.

Definition at line 845 of file FlowSensitive.cpp.

846{
848 && "FS::cluster: plain mapping requires dense allocation strategy.");
849
850 const size_t numObjects = NodeIDAllocator::get()->getNumObjects();
851 PointsTo::MappingPtr plainMapping = std::make_shared<std::vector<NodeID>>(numObjects);
852 PointsTo::MappingPtr reversePlainMapping = std::make_shared<std::vector<NodeID>>(numObjects);
853 for (NodeID i = 0; i < plainMapping->size(); ++i)
854 {
855 plainMapping->at(i) = i;
856 reversePlainMapping->at(i) = i;
857 }
858
860}
static NodeIDAllocator * get(void)
Return (singleton) allocator.
NodeID getNumObjects(void) const
Returns the total number of memory objects.
static const OptionMap< SVF::NodeIDAllocator::Strategy > NodeAllocStrat
Definition Options.h:31

◆ processAddr()

bool FlowSensitive::processAddr ( const AddrSVFGNode *  addr)
protectedvirtual

Process address node

TODO: If this object has been set as field-insensitive, just add the insensitive object node into dst pointer's pts.

Definition at line 451 of file FlowSensitive.cpp.

452{
453 double start = stat->getClk();
454 NodeID srcID = addr->getSrcNodeID();
459 bool changed = addPts(addr->getDstNodeID(), srcID);
460 double end = stat->getClk();
461 addrTime += (end - start) / TIMEINTERVAL;
462 return changed;
463}
#define TIMEINTERVAL
Definition SVFType.h:604
virtual bool addPts(NodeID id, NodeID ptd)
bool isFieldInsensitive(NodeID id) const
NodeID getFIObjVar(NodeID id)
static double getClk(bool mark=false)
Definition SVFStat.cpp:51

◆ processCopy()

bool FlowSensitive::processCopy ( const CopySVFGNode *  copy)
protectedvirtual

Process copy node

Definition at line 468 of file FlowSensitive.cpp.

469{
470 double start = stat->getClk();
471 bool changed = unionPts(copy->getDstNodeID(), copy->getSrcNodeID());
472 double end = stat->getClk();
473 copyTime += (end - start) / TIMEINTERVAL;
474 return changed;
475}
copy
Definition cJSON.cpp:414
virtual bool unionPts(NodeID id, const PointsTo &target)

◆ processGep()

bool FlowSensitive::processGep ( const GepSVFGNode *  edge)
protectedvirtual

Process gep node

Definition at line 501 of file FlowSensitive.cpp.

502{
503 double start = stat->getClk();
504 bool changed = false;
505 const PointsTo& srcPts = getPts(edge->getSrcNodeID());
506
508 const GepStmt* gepStmt = SVFUtil::cast<GepStmt>(edge->getSVFStmt());
509 if (gepStmt->isVariantFieldGep())
510 {
511 for (NodeID o : srcPts)
512 {
514 {
515 tmpDstPts.set(o);
516 continue;
517 }
518
520 tmpDstPts.set(getFIObjVar(o));
521 }
522 }
523 else
524 {
525 for (NodeID o : srcPts)
526 {
528 {
529 tmpDstPts.set(o);
530 continue;
531 }
532
533 NodeID fieldSrcPtdNode = getGepObjVar(o, gepStmt->getAccessPath().getConstantStructFldIdx());
535 }
536 }
537
538 if (unionPts(edge->getDstNodeID(), tmpDstPts))
539 changed = true;
540
541 double end = stat->getClk();
542 gepTime += (end - start) / TIMEINTERVAL;
543 return changed;
544}
virtual bool isBlkObjOrConstantObj(NodeID ptd) const
NodeID getGepObjVar(NodeID id, const APOffset &ap)
void setObjFieldInsensitive(NodeID id)

◆ processLoad()

bool FlowSensitive::processLoad ( const LoadSVFGNode *  load)
protectedvirtual

Process load node

Foreach node \in src pts(dst) = union pts(node)

If the ptd is a field-insensitive node, we should also get all field nodes' points-to sets and pass them to pagDst.

Reimplemented in SVF::VersionedFlowSensitive.

Definition at line 553 of file FlowSensitive.cpp.

554{
555 double start = stat->getClk();
556 bool changed = false;
557
558 NodeID dstVar = load->getDstNodeID();
559
560 const PointsTo& srcPts = getPts(load->getSrcNodeID());
561
562 // p = *q, the type of p must be a pointer
563 if(load->getDstNode()->isPointer())
564 {
565 for (PointsTo::iterator ptdIt = srcPts.begin(); ptdIt != srcPts.end(); ++ptdIt)
566 {
567 NodeID ptd = *ptdIt;
568
569 if (pag->isConstantObj(ptd))
570 continue;
571
572 if (unionPtsFromIn(load, ptd, dstVar))
573 changed = true;
574
576 {
580 for (NodeBS::iterator fieldIt = allFields.begin(), fieldEit = allFields.end();
582 {
583 if (unionPtsFromIn(load, *fieldIt, dstVar))
584 changed = true;
585 }
586 }
587 }
588 }
589 double end = stat->getClk();
590 loadTime += (end - start) / TIMEINTERVAL;
591 return changed;
592}
virtual bool unionPtsFromIn(const SVFGNode *stmt, NodeID srcVar, NodeID dstVar)
const ValVar * getDstNode() const
Definition VFGNode.h:217
virtual const NodeBS & getAllFieldsObjVars(NodeID id)
bool isConstantObj(NodeID id) const
Definition SVFIR.h:542
virtual bool isPointer() const
Check if this variable represents a pointer.
NodeID getSrcNodeID() const
Definition VFGNode.h:152
NodeID getDstNodeID() const
Definition VFGNode.h:157

◆ processNode()

void FlowSensitive::processNode ( NodeID  nodeId)
overrideprotectedvirtual

Handle various constraints.

Process each SVFG node

Reimplemented from SVF::WPASolver< GraphType >.

Reimplemented in SVF::VersionedFlowSensitive, and SVF::FSMPTA< SVFGGraph >.

Definition at line 222 of file FlowSensitive.cpp.

223{
225 if (processSVFGNode(node))
226 propagate(&node);
227
229}
void clearAllDFOutVarFlag(const SVFGNode *stmt)
bool processSVFGNode(SVFGNode *node)
SVFGNode * getSVFGNode(NodeID id) const
Get a SVFG node.
Definition SVFG.h:150
virtual void propagate(GNODE *v)
Definition WPASolver.h:128

◆ processPhi()

bool FlowSensitive::processPhi ( const PHISVFGNode *  phi)
protectedvirtual

Process mssa phi node

Definition at line 480 of file FlowSensitive.cpp.

481{
482 double start = stat->getClk();
483 bool changed = false;
484 NodeID pagDst = phi->getRes()->getId();
485 for (PHISVFGNode::OPVers::const_iterator it = phi->opVerBegin(), eit = phi->opVerEnd(); it != eit; ++it)
486 {
487 NodeID src = it->second->getId();
488 const PointsTo& srcPts = getPts(src);
489 if (unionPts(pagDst, srcPts))
490 changed = true;
491 }
492
493 double end = stat->getClk();
494 phiTime += (end - start) / TIMEINTERVAL;
495 return changed;
496}
GEdgeSetTy::const_iterator const_iterator

◆ processStore()

bool FlowSensitive::processStore ( const StoreSVFGNode *  store)
protectedvirtual

Process store node

foreach node \in dst pts(node) = union pts(src)

STORE statement can only be processed if the pointer on the LHS points to something. If we handle STORE with an empty points-to set, the OUT set will be updated from IN set. Then if LHS pointer points-to one target and it has been identified as a strong update, we can't remove those points-to information computed before this strong update from the OUT set.

check if this is a strong updates store

Reimplemented in SVF::VersionedFlowSensitive.

Definition at line 600 of file FlowSensitive.cpp.

601{
602
603 const PointsTo & dstPts = getPts(store->getDstNodeID());
604
611 if (dstPts.empty())
612 return false;
613
614 double start = stat->getClk();
615 bool changed = false;
616
617 // *p = q, the type of q must be a pointer
618 if(getPts(store->getSrcNodeID()).empty() == false && store->getSrcNode()->isPointer())
619 {
620 for (PointsTo::iterator it = dstPts.begin(), eit = dstPts.end(); it != eit; ++it)
621 {
622 NodeID ptd = *it;
623
624 if (pag->isConstantObj(ptd))
625 continue;
626
627 if (unionPtsFromTop(store, store->getSrcNodeID(), ptd))
628 changed = true;
629 }
630 }
631
632 double end = stat->getClk();
633 storeTime += (end - start) / TIMEINTERVAL;
634
635 double updateStart = stat->getClk();
636 // also merge the DFInSet to DFOutSet.
639 bool isSU = isStrongUpdate(store, singleton);
640 if (isSU)
641 {
642 svfgHasSU.set(store->getId());
644 changed = true;
645 }
646 else
647 {
648 svfgHasSU.reset(store->getId());
649 if (weakUpdateOutFromIn(store))
650 changed = true;
651 }
652 double updateEnd = stat->getClk();
654
655 return changed;
656}
bool isStrongUpdate(const SVFGNode *node, NodeID &singleton)
Return TRUE if this is a strong update STORE statement.
virtual bool unionPtsFromTop(const SVFGNode *stmt, NodeID srcVar, NodeID dstVar)
virtual bool strongUpdateOutFromIn(const SVFGNode *node, NodeID singleton)
Handle strong updates.
virtual bool weakUpdateOutFromIn(const SVFGNode *node)
Handle weak updates.
bool empty() const
Returns true if set is empty.
Definition PointsTo.cpp:110
NodeID getId() const
Get ID.
Definition SVFValue.h:158
void set(unsigned Idx)
void reset(unsigned Idx)
const ValVar * getSrcNode() const
Definition VFGNode.h:274

◆ processSVFGNode()

bool FlowSensitive::processSVFGNode ( SVFGNode *  node)
protected

Process each SVFG node

Definition at line 234 of file FlowSensitive.cpp.

235{
236 double start = stat->getClk();
237 bool changed = false;
238 if (AddrSVFGNode* addr = SVFUtil::dyn_cast<AddrSVFGNode>(node))
239 {
241 if (processAddr(addr))
242 changed = true;
243 }
244 else if (CopySVFGNode* copy = SVFUtil::dyn_cast<CopySVFGNode>(node))
245 {
247 if (processCopy(copy))
248 changed = true;
249 }
250 else if (GepSVFGNode* gep = SVFUtil::dyn_cast<GepSVFGNode>(node))
251 {
253 if(processGep(gep))
254 changed = true;
255 }
256 else if (LoadSVFGNode* load = SVFUtil::dyn_cast<LoadSVFGNode>(node))
257 {
259 if(processLoad(load))
260 changed = true;
261 }
262 else if (StoreSVFGNode* store = SVFUtil::dyn_cast<StoreSVFGNode>(node))
263 {
265 if (processStore(store))
266 changed = true;
267 }
268 else if (PHISVFGNode* phi = SVFUtil::dyn_cast<PHISVFGNode>(node))
269 {
271 if (processPhi(phi))
272 changed = true;
273 }
276 ActualOUTSVFGNode>(node))
277 {
279 changed = true;
280 }
283 NullPtrSVFGNode>(node))
284 {
285 changed = true;
286 }
287 else if (SVFUtil::isa<CmpVFGNode, BinaryOPVFGNode>(node) ||
288 SVFUtil::dyn_cast<UnaryOPVFGNode>(node))
289 {
290 }
291 else
292 {
293 assert(false && "unexpected kind of SVFG nodes");
294 }
295
296 double end = stat->getClk();
297 processTime += (end - start) / TIMEINTERVAL;
298
299 return changed;
300}
virtual bool processLoad(const LoadSVFGNode *load)
virtual bool processPhi(const PHISVFGNode *phi)
virtual bool processStore(const StoreSVFGNode *store)
virtual bool processCopy(const CopySVFGNode *copy)
virtual bool processAddr(const AddrSVFGNode *addr)
virtual bool processGep(const GepSVFGNode *edge)
LLVM_NODISCARD bool isa(const Y &Val)
Definition Casting.h:241

◆ propagateFromAPToFP()

bool FlowSensitive::propagateFromAPToFP ( const ActualParmSVFGNode *  ap,
const SVFGNode *  dst 
)
protectedvirtual

Propagate points-to information from an actual-param to a formal-param. Not necessary if SVFGOPT is used instead of original SVFG.

Propagate points-to information from actual-param to formal-param. Not necessary if SVFGOPT is used instead of original SVFG.

Definition at line 361 of file FlowSensitive.cpp.

362{
363 const FormalParmSVFGNode* fp = SVFUtil::dyn_cast<FormalParmSVFGNode>(dst);
364 assert(fp && "expecting a formal param node");
365
366 NodeID pagDst = fp->getParam()->getId();
367 const PointsTo &srcCPts = getPts(ap->getParam()->getId());
369
370 return changed;
371}
const ValVar * getParam() const
Return parameter.
Definition VFGNode.h:989

◆ propagateFromFRToAR()

bool FlowSensitive::propagateFromFRToAR ( const FormalRetSVFGNode *  fr,
const SVFGNode *  dst 
)
protectedvirtual

Propagate points-to information from a formal-ret to an actual-ret. Not necessary if SVFGOPT is used instead of original SVFG.

Propagate points-to information from formal-ret to actual-ret. Not necessary if SVFGOPT is used instead of original SVFG.

Definition at line 377 of file FlowSensitive.cpp.

378{
379 const ActualRetSVFGNode* ar = SVFUtil::dyn_cast<ActualRetSVFGNode>(dst);
380 assert(ar && "expecting an actual return node");
381
382 NodeID pagDst = ar->getRev()->getId();
383 const PointsTo & srcCPts = getPts(fr->getRet()->getId());
385
386 return changed;
387}

◆ propAlongDirectEdge()

bool FlowSensitive::propAlongDirectEdge ( const DirectSVFGEdge *  edge)
protectedvirtual

Propagate points-to information along a DIRECT SVFG edge.

Propagate points-to information along DIRECT SVFG edge.

Definition at line 330 of file FlowSensitive.cpp.

331{
332 double start = stat->getClk();
333 bool changed = false;
334
335 SVFGNode* src = edge->getSrcNode();
336 SVFGNode* dst = edge->getDstNode();
337 // If this is an actual-param or formal-ret, top-level pointer's pts must be
338 // propagated from src to dst.
339 if (ActualParmSVFGNode* ap = SVFUtil::dyn_cast<ActualParmSVFGNode>(src))
340 changed = propagateFromAPToFP(ap, dst);
341 else if (FormalRetSVFGNode* fp = SVFUtil::dyn_cast<FormalRetSVFGNode>(src))
343 else
344 {
345 // Direct SVFG edge links between def and use of a top-level pointer.
346 // There's no points-to information propagated along direct edge.
347 // Since the top-level pointer's value has been changed at src node,
348 // return TRUE to put dst node into the work list.
349 changed = true;
350 }
351
352 double end = stat->getClk();
353 directPropaTime += (end - start) / TIMEINTERVAL;
354 return changed;
355}
virtual bool propagateFromAPToFP(const ActualParmSVFGNode *ap, const SVFGNode *dst)
virtual bool propagateFromFRToAR(const FormalRetSVFGNode *fr, const SVFGNode *dst)

◆ propAlongIndirectEdge()

bool FlowSensitive::propAlongIndirectEdge ( const IndirectSVFGEdge *  edge)
protectedvirtual

Propagate points-to information along an INDIRECT SVFG edge.

Propagate points-to information along INDIRECT SVFG edge.

If this is a field-insensitive obj, propagate all field node's pts

Reimplemented in SVF::VersionedFlowSensitive.

Definition at line 392 of file FlowSensitive.cpp.

393{
394 double start = stat->getClk();
395
396 SVFGNode* src = edge->getSrcNode();
397 SVFGNode* dst = edge->getDstNode();
398
399 bool changed = false;
400
401 // Get points-to targets may be used by next SVFG node.
402 // Propagate points-to set for node used in dst.
403 const NodeBS& pts = edge->getPointsTo();
404 for (NodeBS::iterator ptdIt = pts.begin(), ptdEit = pts.end(); ptdIt != ptdEit; ++ptdIt)
405 {
406 NodeID ptd = *ptdIt;
407
408 if (propVarPtsFromSrcToDst(ptd, src, dst))
409 changed = true;
410
412 {
415 for (NodeBS::iterator fieldIt = allFields.begin(), fieldEit = allFields.end();
417 {
418 if (propVarPtsFromSrcToDst(*fieldIt, src, dst))
419 changed = true;
420 }
421 }
422 }
423
424 double end = stat->getClk();
425 indirectPropaTime += (end - start) / TIMEINTERVAL;
426 return changed;
427}
virtual bool propVarPtsFromSrcToDst(NodeID var, const SVFGNode *src, const SVFGNode *dst)
Propagate points-to information of a certain variable from src to dst.

◆ propDFInToIn()

virtual bool SVF::FlowSensitive::propDFInToIn ( const SVFGNode *  srcStmt,
NodeID  srcVar,
const SVFGNode *  dstStmt,
NodeID  dstVar 
)
inlineprotectedvirtual

Definition at line 179 of file FlowSensitive.h.

180 {
181 return getDFPTDataTy()->updateAllDFInFromIn(srcStmt->getId(), srcVar, dstStmt->getId(),dstVar);
182 }

◆ propDFOutToIn()

virtual bool SVF::FlowSensitive::propDFOutToIn ( const SVFGNode *  srcStmt,
NodeID  srcVar,
const SVFGNode *  dstStmt,
NodeID  dstVar 
)
inlineprotectedvirtual

Definition at line 175 of file FlowSensitive.h.

176 {
177 return getDFPTDataTy()->updateAllDFInFromOut(srcStmt->getId(), srcVar, dstStmt->getId(),dstVar);
178 }

◆ propFromSrcToDst()

bool FlowSensitive::propFromSrcToDst ( SVFGEdge *  edge)
overrideprotected

Propagation.

Propagate points-to information from an edge's src node to its dst node.

Propagate points-to information from source to destination node Union dfOutput of src to dfInput of dst. Only propagate points-to set of node which exists on the SVFG edge.

  1. propagation along direct edge will always return TRUE.
  2. propagation along indirect edge will return TRUE if destination node's IN set has been updated.

Definition at line 310 of file FlowSensitive.cpp.

311{
312 double start = stat->getClk();
313 bool changed = false;
314
315 if (DirectSVFGEdge* dirEdge = SVFUtil::dyn_cast<DirectSVFGEdge>(edge))
317 else if (IndirectSVFGEdge* indEdge = SVFUtil::dyn_cast<IndirectSVFGEdge>(edge))
319 else
320 assert(false && "new kind of svfg edge?");
321
322 double end = stat->getClk();
323 propagationTime += (end - start) /TIMEINTERVAL;
324 return changed;
325}
virtual bool propAlongDirectEdge(const DirectSVFGEdge *edge)
Propagate points-to information along a DIRECT SVFG edge.
virtual bool propAlongIndirectEdge(const IndirectSVFGEdge *edge)
Propagate points-to information along an INDIRECT SVFG edge.

◆ propVarPtsAfterCGUpdated()

bool FlowSensitive::propVarPtsAfterCGUpdated ( NodeID  var,
const SVFGNode *  src,
const SVFGNode *  dst 
)
protected

Propagation between newly connected SVFG nodes during updateCallGraph. Can only be used during updateCallGraph.

Propagate points-to information of a certain variable from src to dst.

Definition at line 814 of file FlowSensitive.cpp.

815{
816 if (SVFUtil::isa<StoreSVFGNode>(src))
817 {
818 if (propDFOutToIn(src, var, dst, var))
819 return true;
820 }
821 else
822 {
823 if (propDFInToIn(src, var, dst, var))
824 return true;
825 }
826 return false;
827}
virtual bool propDFInToIn(const SVFGNode *srcStmt, NodeID srcVar, const SVFGNode *dstStmt, NodeID dstVar)
virtual bool propDFOutToIn(const SVFGNode *srcStmt, NodeID srcVar, const SVFGNode *dstStmt, NodeID dstVar)

◆ propVarPtsFromSrcToDst()

bool FlowSensitive::propVarPtsFromSrcToDst ( NodeID  var,
const SVFGNode *  src,
const SVFGNode *  dst 
)
protectedvirtual

Propagate points-to information of a certain variable from src to dst.

Propagate points-to information of a certain variable from src to dst.

Definition at line 432 of file FlowSensitive.cpp.

433{
434 bool changed = false;
435 if (SVFUtil::isa<StoreSVFGNode>(src))
436 {
437 if (updateInFromOut(src, var, dst, var))
438 changed = true;
439 }
440 else
441 {
442 if (updateInFromIn(src, var, dst, var))
443 changed = true;
444 }
445 return changed;
446}
virtual bool updateInFromIn(const SVFGNode *srcStmt, NodeID srcVar, const SVFGNode *dstStmt, NodeID dstVar)
virtual bool updateInFromOut(const SVFGNode *srcStmt, NodeID srcVar, const SVFGNode *dstStmt, NodeID dstVar)

◆ PTAName()

const std::string SVF::FlowSensitive::PTAName ( ) const
inlineoverridevirtual

Get PTA name.

Reimplemented from SVF::PointerAnalysis.

Reimplemented in SVF::VersionedFlowSensitive.

Definition at line 115 of file FlowSensitive.h.

116 {
117 return "FlowSensitive";
118 }

◆ readPtsFromFile()

void FlowSensitive::readPtsFromFile ( const std::string &  filename)
virtual

Initialization for the Solver

Load the pts from file

finalize the analysis

Reimplemented in SVF::VersionedFlowSensitive.

Definition at line 155 of file FlowSensitive.cpp.

156{
158 initialize();
160 if(!filename.empty())
161 this->readFromFile(filename);
163 finalize();
164}
virtual bool readFromFile(const std::string &filename)

◆ releaseFSWPA()

static void SVF::FlowSensitive::releaseFSWPA ( )
inlinestatic

Release flow-sensitive pointer analysis.

Definition at line 88 of file FlowSensitive.h.

89 {
90 fspta = nullptr;
91 }

◆ runOnModule()

virtual bool SVF::FlowSensitive::runOnModule ( )
inlinevirtual

We start from here.

Definition at line 94 of file FlowSensitive.h.

95 {
96 return false;
97 }

◆ SCCDetect()

NodeStack & FlowSensitive::SCCDetect ( )
overrideprotectedvirtual

SCC detection.

SCC detection

Reimplemented from SVF::WPAFSSolver< GraphType >.

Reimplemented in SVF::FSMPTA< SVFGGraph >.

Definition at line 210 of file FlowSensitive.cpp.

211{
212 double start = stat->getClk();
214 double end = stat->getClk();
215 sccTime += (end - start) / TIMEINTERVAL;
216 return nodeStack;
217}
virtual NodeStack & SCCDetect()
SCC detection.
Definition WPAFSSolver.h:68

◆ solveAndwritePtsToFile()

void FlowSensitive::solveAndwritePtsToFile ( const std::string &  filename)
virtual

Start analysis

Initialization for the Solver

finalize the analysis

Reimplemented in SVF::VersionedFlowSensitive.

Definition at line 118 of file FlowSensitive.cpp.

119{
121 initialize();
122 if(!filename.empty())
125 if(!filename.empty())
128 finalize();
129}
virtual void writeToFile(const std::string &filename)
Interface for analysis result storage on filesystem.
virtual void writeObjVarToFile(const std::string &filename)

◆ solveConstraints()

void FlowSensitive::solveConstraints ( )
virtual

Start solving constraints

Definition at line 76 of file FlowSensitive.cpp.

77{
79 if (timeLimited)
80 {
82 }
83
84 double start = stat->getClk(true);
86 DBOUT(DGENERAL, outs() << SVFUtil::pasMsg("Start Solving Constraints\n"));
87
88 do
89 {
91
93 dumpStat();
94
95 callGraphSCC->find();
96
99 }
101
102 DBOUT(DGENERAL, outs() << SVFUtil::pasMsg("Finish Solving Constraints\n"));
103
104 // Reset the time-up alarm; analysis is done.
105 if (timeLimited)
106 {
108 }
109
110 double end = stat->getClk(true);
111 solveTime += (end - start) / TIMEINTERVAL;
112
113}
#define DBOUT(TYPE, X)
LLVM debug macros, define type of your DBUG model of each pass.
Definition SVFType.h:576
#define DGENERAL
Definition SVFType.h:582
bool updateCallGraph(const CallSiteToFunPtrMap &callsites) override
Update call graph.
static const Option< u32_t > FsTimeLimit
Time limit for the main phase (i.e., the actual solving) of FS analyses.
Definition Options.h:68
const CallSiteToFunPtrMap & getIndirectCallsites() const
Return all indirect callsites.
void dumpStat()
Dump the statistics.
CallGraphSCC * callGraphSCC
SCC for PTACallGraph.
virtual void initWorklist()
Definition WPASolver.h:98
u32_t numOfIteration
num of iterations during constraint solving
Definition WPASolver.h:201
virtual void solveWorklist()
Definition WPASolver.h:109
std::string pasMsg(const std::string &msg)
Print each pass/phase message by converting a string into blue string output.
Definition SVFUtil.cpp:105
void stopAnalysisLimitTimer(void)
Stops analysis timer.
Definition SVFUtil.cpp:295
void startAnalysisLimitTimer(unsigned timeLimit)
Starts analysis timer. timeLimit must be non-0. Timer must not be already set.
Definition SVFUtil.cpp:281
std::ostream & outs()
Overwrite llvm::outs()
Definition SVFUtil.h:52

◆ strongUpdateOutFromIn()

virtual bool SVF::FlowSensitive::strongUpdateOutFromIn ( const SVFGNode *  node,
NodeID  singleton 
)
inlineprotectedvirtual

Handle strong updates.

Definition at line 164 of file FlowSensitive.h.

165 {
166 return getDFPTDataTy()->updateAllDFOutFromIn(node->getId(),singleton,true);
167 }

◆ svfgStat()

void SVF::FlowSensitive::svfgStat ( )
protected

◆ unionPtsFromIn()

virtual bool SVF::FlowSensitive::unionPtsFromIn ( const SVFGNode *  stmt,
NodeID  srcVar,
NodeID  dstVar 
)
inlineprotectedvirtual

Definition at line 200 of file FlowSensitive.h.

201 {
202 return getDFPTDataTy()->updateTLVPts(stmt->getId(),srcVar,dstVar);
203 }

◆ unionPtsFromTop()

virtual bool SVF::FlowSensitive::unionPtsFromTop ( const SVFGNode *  stmt,
NodeID  srcVar,
NodeID  dstVar 
)
inlineprotectedvirtual

Definition at line 204 of file FlowSensitive.h.

205 {
206 return getDFPTDataTy()->updateATVPts(srcVar,stmt->getId(),dstVar);
207 }

◆ updateCallGraph()

bool FlowSensitive::updateCallGraph ( const CallSiteToFunPtrMap &  callsites)
overrideprotectedvirtual

Update call graph.

Update call graph.

Update call graph

Reimplemented from SVF::BVDataPTAImpl.

Definition at line 691 of file FlowSensitive.cpp.

692{
693 double start = stat->getClk();
696
697 // Bound the new edges by the Andersen's call graph.
698 // TODO: we want this to be an assertion eventually.
700 for (typename CallEdgeMap::value_type &csfs : newEdges)
701 {
702 const CallICFGNode *potentialCallSite = csfs.first;
704
705 // Check this callsite even calls anything per Andersen's.
706 typename CallEdgeMap::const_iterator andersFunctionSetIt
709 {
710 potentialFunctionSet.clear();
711 }
712
714 for (FunctionSet::iterator potentialFunctionIt = potentialFunctionSet.begin();
716 {
719 {
720 // potentialFunction is not in the Andersen's call graph -- remove it.
722 }
723 else
724 {
725 // potentialFunction is in the Andersen's call graph -- keep it..
727 }
728 }
729 }
730
733
735
736 double end = stat->getClk();
737 updateCallGraphTime += (end - start) / TIMEINTERVAL;
738 return (!newEdges.empty());
739}
virtual void onTheFlyCallGraphSolve(const CallSiteToFunPtrMap &callsites, CallEdgeMap &newEdges)
On the fly call graph construction.
virtual void updateConnectedNodes(const SVFGEdgeSetTy &edges)
Update nodes connected during updating call graph.
SVFG::SVFGEdgeSetTy SVFGEdgeSetTy
void connectCallerAndCallee(const CallEdgeMap &newEdges, SVFGEdgeSetTy &edges)
Connect nodes in SVFG.
OrderedMap< const CallICFGNode *, FunctionSet > CallEdgeMap
CallEdgeMap & getIndCallMap()
Get callees from an indirect callsite.

◆ updateConnectedNodes()

void FlowSensitive::updateConnectedNodes ( const SVFGEdgeSetTy &  edges)
protectedvirtual

Update nodes connected during updating call graph.

Push nodes connected during update call graph into worklist so they will be solved during next iteration.

If this is a formal-param or actual-ret node, we need to solve this phi node in next iteration

If this is a formal-in or actual-out node, we need to propagate points-to information from its predecessor node.

If this is a field-insensitive obj, propagate all field node's pts

Reimplemented in SVF::FSMPTA< SVFGGraph >, and SVF::VersionedFlowSensitive.

Definition at line 764 of file FlowSensitive.cpp.

765{
766 for (const SVFGEdge* edge : edges)
767 {
768 SVFGNode* dstNode = edge->getDstNode();
769 if (SVFUtil::isa<PHISVFGNode>(dstNode))
770 {
773 pushIntoWorklist(dstNode->getId());
774 }
775 else if (SVFUtil::isa<FormalINSVFGNode, ActualOUTSVFGNode>(dstNode))
776 {
779 bool changed = false;
780
781 SVFGNode* srcNode = edge->getSrcNode();
782
783 const NodeBS& pts = SVFUtil::cast<IndirectSVFGEdge>(edge)->getPointsTo();
784 for (NodeBS::iterator ptdIt = pts.begin(), ptdEit = pts.end(); ptdIt != ptdEit; ++ptdIt)
785 {
786 NodeID ptd = *ptdIt;
787
789 changed = true;
790
792 {
795 for (NodeBS::iterator fieldIt = allFields.begin(), fieldEit = allFields.end();
797 {
799 changed = true;
800 }
801 }
802 }
803
804 if (changed)
805 pushIntoWorklist(dstNode->getId());
806 }
807 }
808}
bool propVarPtsAfterCGUpdated(NodeID var, const SVFGNode *src, const SVFGNode *dst)
virtual void pushIntoWorklist(NodeID id)
Definition WPASolver.h:157

◆ updateInFromIn()

virtual bool SVF::FlowSensitive::updateInFromIn ( const SVFGNode *  srcStmt,
NodeID  srcVar,
const SVFGNode *  dstStmt,
NodeID  dstVar 
)
inlineprotectedvirtual

Definition at line 191 of file FlowSensitive.h.

192 {
193 return getDFPTDataTy()->updateDFInFromIn(srcStmt->getId(),srcVar, dstStmt->getId(),dstVar);
194 }

◆ updateInFromOut()

virtual bool SVF::FlowSensitive::updateInFromOut ( const SVFGNode *  srcStmt,
NodeID  srcVar,
const SVFGNode *  dstStmt,
NodeID  dstVar 
)
inlineprotectedvirtual

Definition at line 195 of file FlowSensitive.h.

196 {
197 return getDFPTDataTy()->updateDFInFromOut(srcStmt->getId(),srcVar, dstStmt->getId(),dstVar);
198 }

◆ updateOutFromIn()

bool SVF::FlowSensitive::updateOutFromIn ( const SVFGNode *  srcStmt,
NodeID  srcVar,
const SVFGNode *  dstStmt,
NodeID  dstVar 
)
inlineprotected

Update data-flow points-to data.

Definition at line 187 of file FlowSensitive.h.

188 {
189 return getDFPTDataTy()->updateDFOutFromIn(srcStmt->getId(),srcVar, dstStmt->getId(),dstVar);
190 }

◆ weakUpdateOutFromIn()

virtual bool SVF::FlowSensitive::weakUpdateOutFromIn ( const SVFGNode *  node)
inlineprotectedvirtual

Handle weak updates.

Definition at line 159 of file FlowSensitive.h.

160 {
161 return getDFPTDataTy()->updateAllDFOutFromIn(node->getId(),0,false);
162 }

Friends And Related Symbol Documentation

◆ FlowSensitiveStat

Definition at line 49 of file FlowSensitive.h.

Member Data Documentation

◆ addrTime

double SVF::FlowSensitive::addrTime
protected

time of handling address edges

Definition at line 305 of file FlowSensitive.h.

◆ ander

AndersenWaveDiff* SVF::FlowSensitive::ander
protected

Definition at line 277 of file FlowSensitive.h.

◆ candidateMappings

std::vector<std::pair<hclust_fast_methods, std::vector<NodeID> > > SVF::FlowSensitive::candidateMappings
protected

Save candidate mappings for evaluation's sake.

Definition at line 280 of file FlowSensitive.h.

◆ copyTime

double SVF::FlowSensitive::copyTime
protected

time of handling copy edges

Definition at line 306 of file FlowSensitive.h.

◆ directPropaTime

double SVF::FlowSensitive::directPropaTime
protected

time of points-to propagation of address-taken objects

Definition at line 302 of file FlowSensitive.h.

◆ fspta

std::unique_ptr< FlowSensitive > FlowSensitive::fspta
staticprotected

Definition at line 275 of file FlowSensitive.h.

◆ gepTime

double SVF::FlowSensitive::gepTime
protected

time of handling gep edges

Definition at line 307 of file FlowSensitive.h.

◆ indirectPropaTime

double SVF::FlowSensitive::indirectPropaTime
protected

time of points-to propagation of top-level pointers

Definition at line 303 of file FlowSensitive.h.

◆ loadTime

double SVF::FlowSensitive::loadTime
protected

time of load edges

Definition at line 308 of file FlowSensitive.h.

◆ maxSCCSize

u32_t SVF::FlowSensitive::maxSCCSize
protected

Number of processed mssa node.

Definition at line 294 of file FlowSensitive.h.

◆ memSSA

SVFGBuilder SVF::FlowSensitive::memSSA
protected

Definition at line 276 of file FlowSensitive.h.

◆ numOfNodesInSCC

u32_t SVF::FlowSensitive::numOfNodesInSCC
protected

Definition at line 296 of file FlowSensitive.h.

◆ numOfProcessedActualParam

u32_t SVF::FlowSensitive::numOfProcessedActualParam
protected

Number of processed Store node.

Definition at line 290 of file FlowSensitive.h.

◆ numOfProcessedAddr

u32_t SVF::FlowSensitive::numOfProcessedAddr
protected

Statistics.

Definition at line 284 of file FlowSensitive.h.

◆ numOfProcessedCopy

u32_t SVF::FlowSensitive::numOfProcessedCopy
protected

Number of processed Addr node.

Definition at line 285 of file FlowSensitive.h.

◆ numOfProcessedFormalRet

u32_t SVF::FlowSensitive::numOfProcessedFormalRet
protected

Number of processed actual param node.

Definition at line 291 of file FlowSensitive.h.

◆ numOfProcessedGep

u32_t SVF::FlowSensitive::numOfProcessedGep
protected

Number of processed Copy node.

Definition at line 286 of file FlowSensitive.h.

◆ numOfProcessedLoad

u32_t SVF::FlowSensitive::numOfProcessedLoad
protected

Number of processed Phi node.

Definition at line 288 of file FlowSensitive.h.

◆ numOfProcessedMSSANode

u32_t SVF::FlowSensitive::numOfProcessedMSSANode
protected

Number of processed formal ret node.

Definition at line 292 of file FlowSensitive.h.

◆ numOfProcessedPhi

u32_t SVF::FlowSensitive::numOfProcessedPhi
protected

Number of processed Gep node.

Definition at line 287 of file FlowSensitive.h.

◆ numOfProcessedStore

u32_t SVF::FlowSensitive::numOfProcessedStore
protected

Number of processed Load node.

Definition at line 289 of file FlowSensitive.h.

◆ numOfSCC

u32_t SVF::FlowSensitive::numOfSCC
protected

Definition at line 295 of file FlowSensitive.h.

◆ phiTime

double SVF::FlowSensitive::phiTime
protected

time of phi nodes.

Definition at line 310 of file FlowSensitive.h.

◆ processTime

double SVF::FlowSensitive::processTime
protected

time of processNode.

Definition at line 300 of file FlowSensitive.h.

◆ propagationTime

double SVF::FlowSensitive::propagationTime
protected

time of points-to propagation.

Definition at line 301 of file FlowSensitive.h.

◆ sccTime

double SVF::FlowSensitive::sccTime
protected

time of SCC detection.

Definition at line 299 of file FlowSensitive.h.

◆ solveTime

double SVF::FlowSensitive::solveTime
protected

time of solve.

Definition at line 298 of file FlowSensitive.h.

◆ storeTime

double SVF::FlowSensitive::storeTime
protected

time of store edges

Definition at line 309 of file FlowSensitive.h.

◆ svfg

SVFG* SVF::FlowSensitive::svfg
protected

Definition at line 243 of file FlowSensitive.h.

◆ svfgHasSU

NodeBS SVF::FlowSensitive::svfgHasSU
protected

Definition at line 313 of file FlowSensitive.h.

◆ updateCallGraphTime

double SVF::FlowSensitive::updateCallGraphTime
protected

time of updating call graph

Definition at line 311 of file FlowSensitive.h.

◆ updateTime

double SVF::FlowSensitive::updateTime
protected

time of strong/weak updates.

Definition at line 304 of file FlowSensitive.h.


The documentation for this class was generated from the following files: