#include <AEDetector.h>
Definition at line 331 of file AEDetector.h.
◆ NullptrDerefDetector()
| SVF::NullptrDerefDetector::NullptrDerefDetector |
( |
| ) |
|
|
inline |
Definition at line 335 of file AEDetector.h.
336 {
338 }
@ NULL_DEREF
Detector for nullptr dereference issues.
DetectorKind kind
The kind of the detector.
◆ ~NullptrDerefDetector()
| SVF::NullptrDerefDetector::~NullptrDerefDetector |
( |
| ) |
|
|
default |
◆ addBugToReporter()
Adds a bug to the reporter based on an exception.
- Parameters
-
| e | The exception that was thrown. |
| node | Pointer to the ICFG node where the bug was detected. |
Definition at line 377 of file AEDetector.h.
378 {
382
384 {
385 return;
386 }
388
389
391 {
392 return;
393 }
394 else
395 {
397 }
400 }
std::vector< SVFBugEvent > EventStack
Set< std::string > bugLoc
Set of locations where bugs have been reported.
SVFBugReport recoder
Recorder for abstract execution bugs.
Map< const ICFGNode *, std::string > nodeToBugInfo
Maps ICFG nodes to bug information.
void addAbsExecBug(GenericBug::BugType bugType, const GenericBug::EventStack &eventStack, s64_t allocLowerBound, s64_t allocUpperBound, s64_t accessLowerBound, s64_t accessUpperBound)
llvm::IRBuilder IRBuilder
◆ canSafelyDerefPtr()
Definition at line 678 of file AEDetector.cpp.
679{
683 if (!
AbsVal.isAddr())
return true;
685 {
686
688 ae.getAbsState(node).isFreedMem(
addr))
689 return false;
690 }
691 return true;
692}
static AbstractInterpretation & getAEInstance()
static bool isNullOrBlackHoleAddr(u32_t addr)
Whether addr has no concrete backing memory object.
bool isUninit(AbstractValue v)
Checks if an Abstract Value is uninitialized.
◆ classof()
◆ detect()
Detects nullptr dereferences issues within a node.
- Parameters
-
| as | Reference to the abstract state. |
| node | Pointer to the ICFG node. |
Implements SVF::AEDetector.
Definition at line 523 of file AEDetector.cpp.
524{
525 if (SVFUtil::isa<CallICFGNode>(node))
526 {
527
528
531 {
533 }
534 }
535 else
536 {
537 for (const auto& stmt: node->getSVFStmts())
538 {
539 if (
const GepStmt*
gep = SVFUtil::dyn_cast<GepStmt>(stmt))
540 {
541
542
545 {
548 }
549 }
550 else if (
const LoadStmt* load = SVFUtil::dyn_cast<LoadStmt>(stmt))
551 {
552
553
556 {
559 }
560 }
561 }
562 }
563}
Exception class for handling errors in Abstract Execution.
bool canSafelyDerefPtr(const ValVar *ptr, const ICFGNode *node)
void addBugToReporter(const AEException &e, const ICFGNode *node)
Adds a bug to the reporter based on an exception.
void detectExtAPI(const CallICFGNode *call)
Handle external API calls related to nullptr dereferences.
bool isExtCall(const FunObjVar *fun)
◆ detectExtAPI()
Handle external API calls related to nullptr dereferences.
- Parameters
-
| as | Reference to the abstract state. |
| call | Pointer to the call ICFG node. |
Definition at line 619 of file AEDetector.cpp.
620{
622
623
625 for (
const std::string &
annotation:
ExtAPI::getExtAPI()->getExtFuncAnnotations(call->getCalledFunction()))
626 {
627 if (
annotation.find(
"MEMCPY") != std::string::npos)
628 {
630 {
631
634 }
635 else
636 {
637
642 }
643 }
644 else if (
annotation.find(
"MEMSET") != std::string::npos)
645 {
646
648 }
649 else if (
annotation.find(
"STRCPY") != std::string::npos)
650 {
651
654 }
655 else if (
annotation.find(
"STRCAT") != std::string::npos)
656 {
657
658
661 }
662 }
663
665 {
667 continue;
670 {
673 }
674 }
675}
const std::string toString() const override
const ValVar * getArgument(u32_t ArgNo) const
Parameter operations.
const FunObjVar * getCalledFunction() const
◆ handleStubFunctions()
Handles external API calls related to nullptr dereferences.
- Parameters
-
| call | Pointer to the call ICFG node. |
Implements SVF::AEDetector.
Definition at line 566 of file AEDetector.cpp.
567{
568 std::string funcName =
callNode->getCalledFunction()->getName();
570 if (funcName == "UNSAFE_LOAD")
571 {
572
573 ae.getUtils()->checkpoints.erase(
callNode);
575 return;
576
578
582 << "\n";
584 {
586 <<
" — " <<
callNode->toString() <<
"\n";
587 return;
588 }
589 else
590 {
592 <<
" — Position: " <<
callNode->getSourceLoc() <<
"\n";
594 }
595 }
596 else if (funcName == "SAFE_LOAD")
597 {
598
599 ae.getUtils()->checkpoints.erase(
callNode);
600 if (
callNode->arg_size() < 1)
return;
602
605 {
607 <<
" — " <<
callNode->toString() <<
"\n";
608 return;
609 }
610 else
611 {
613 <<
" — Position: " <<
callNode->getSourceLoc() <<
"\n";
615 }
616 }
617}
NodeID getId() const
Get ID.
std::string sucMsg(const std::string &msg)
Returns successful message by converting a string into green string output.
std::string errMsg(const std::string &msg)
Print error message by converting a string into red string output.
std::ostream & outs()
Overwrite llvm::outs()
◆ isNull()
Check if an Abstract Value is NULL (or uninitialized).
- Parameters
-
| v | An Abstract Value of loaded from an address in an Abstract State. |
Definition at line 432 of file AEDetector.h.
433 {
434 return !
v.isAddr() && !
v.isInterval();
435 }
◆ isUninit()
Checks if an Abstract Value is uninitialized.
- Parameters
-
| v | The Abstract Value to check. |
- Returns
- True if the value is uninitialized, false otherwise.
Definition at line 365 of file AEDetector.h.
366 {
367
368 bool is =
v.getAddrs().isBottom() &&
v.getInterval().isBottom();
370 }
◆ reportBug()
| void SVF::NullptrDerefDetector::reportBug |
( |
| ) |
|
|
inlineoverridevirtual |
Reports all detected nullptr dereference bugs.
Implements SVF::AEDetector.
Definition at line 405 of file AEDetector.h.
406 {
408 {
409 std::cerr <<
"###################### Nullptr Dereference (" + std::to_string(
nodeToBugInfo.size())
410 + " found)######################\n";
411 std::cerr << "---------------------------------------------\n";
413 {
414 std::cerr << it.second << "\n---------------------------------------------\n";
415 }
416 }
417 }
◆ AbstractInterpretation
◆ bugLoc
| Set<std::string> SVF::NullptrDerefDetector::bugLoc |
|
private |
Set of locations where bugs have been reported.
Definition at line 440 of file AEDetector.h.
◆ nodeToBugInfo
◆ recoder
Recorder for abstract execution bugs.
Definition at line 441 of file AEDetector.h.
The documentation for this class was generated from the following files: