50 if(lhs.
id()==ID_symbol)
52 if(lhs.
type().
id()==ID_pointer)
60 get_rec(rhs_set, rhs, loc_info_src);
63 for(object_sett::const_iterator
72 else if(lhs.
id()==ID_dereference)
77 if(lhs.
type().
id()==ID_pointer)
95 else if(lhs.
id()==ID_index)
99 else if(lhs.
id()==ID_member)
102 to_member_expr(lhs).struct_op(), rhs, loc_info_src, loc_info_dest);
104 else if(lhs.
id()==ID_typecast)
108 else if(lhs.
id()==ID_if)
117 const exprt &rhs)
const
119 local_cfgt::loc_mapt::const_iterator loc_it=
cfg.
loc_map.find(t);
126 get_rec(result_tmp, rhs, loc_info_src);
128 std::set<exprt> result;
130 for(object_sett::const_iterator
131 it=result_tmp.begin();
132 it!=result_tmp.end();
145 local_cfgt::loc_mapt::const_iterator loc_it=
cfg.
loc_map.find(t);
152 get_rec(tmp1, src1, loc_info_src);
153 get_rec(tmp2, src2, loc_info_src);
159 std::list<unsigned> result;
161 std::set_intersection(
162 tmp1.begin(), tmp1.end(),
163 tmp2.begin(), tmp2.end(),
164 std::back_inserter(result));
166 return !result.empty();
174 if(rhs.
id()==ID_constant)
181 else if(rhs.
id()==ID_symbol)
183 if(rhs.
type().
id()==ID_pointer)
187 dest.insert(src_pointer);
189 for(std::size_t i=0; i<loc_info_src.
aliases.
size(); i++)
196 else if(rhs.
id()==ID_if)
201 else if(rhs.
id()==ID_address_of)
205 if(
object.
id()==ID_symbol)
208 dest.insert(object_nr);
210 for(std::size_t i=0; i<loc_info_src.
aliases.
size(); i++)
214 else if(
object.
id()==ID_index)
217 if(index_expr.
array().
id()==ID_symbol)
223 dest.insert(object_nr);
225 for(std::size_t i=0; i<loc_info_src.
aliases.
size(); i++)
229 else if(index_expr.
array().
id()==ID_string_constant)
235 dest.insert(object_nr);
237 for(std::size_t i=0; i<loc_info_src.
aliases.
size(); i++)
247 else if(rhs.
id()==ID_typecast)
251 else if(rhs.
id()==ID_plus)
255 if(plus_expr.operands().size() >= 3)
258 plus_expr.op0().type().id() == ID_pointer,
259 "pointer in pointer-typed sum must be op0");
260 get_rec(dest, plus_expr.op0(), loc_info_src);
262 else if(plus_expr.operands().size() == 2)
265 if(plus_expr.op0().type().id() == ID_pointer)
267 get_rec(dest, plus_expr.op0(), loc_info_src);
269 else if(plus_expr.op1().type().id() == ID_pointer)
271 get_rec(dest, plus_expr.op1(), loc_info_src);
279 else if(rhs.
id()==ID_minus)
283 if(op0.type().id() == ID_pointer)
285 get_rec(dest, op0, loc_info_src);
290 else if(rhs.
id()==ID_member)
294 else if(rhs.
id()==ID_index)
298 else if(rhs.
id()==ID_dereference)
302 else if(rhs.
id()==ID_side_effect)
307 if(statement==ID_allocate)
340 for(code_typet::parameterst::const_iterator
341 it=goto_function.type.parameters().begin();
342 it!=goto_function.type.parameters().end();
345 const irep_idt &identifier=it->get_identifier();
346 if(is_tracked(identifier))
353 for(localst::locals_mapt::const_iterator
354 l_it=
locals.locals_map.begin();
355 l_it!=
locals.locals_map.end();
358 if(is_tracked(l_it->first))
364 while(!work_queue.empty())
374 switch(instruction.
type())
398 const auto &lhs = instruction.
call_lhs();
407 if(
objects[i].
id() == ID_symbol)
424 DATA_INVARIANT(
false,
"Exceptions must be removed before analysis");
428 DATA_INVARIANT(
false,
"SET_RETURN_VALUE must be removed before analysis");
445 false,
"Unclear what is a safe over-approximation of OTHER");
450 DATA_INVARIANT(
false,
"Only complete instructions can be analyzed");
454 for(local_cfgt::successorst::const_iterator
460 work_queue.push(*it);
474 out <<
"**** " << instruction.source_location() <<
"\n";
478 for(std::size_t i=0; i<loc_info.
aliases.
size(); i++)
484 for(std::size_t j=0; j<loc_info.
aliases.
size(); j++)
489 if(
objects[j].
id() == ID_symbol)
bitvector_typet c_index_type()
Operator to return the address of an object.
dstringt has one field, an unsigned integer no which is an index into a static table of strings.
Base class for all expressions.
bool is_zero() const
Return whether the expression is a constant representing 0.
typet & type()
Return the type of the expression.
A goto function, consisting of function body (see body) and parameter identifiers (see parameter_iden...
This class represents an instruction in the GOTO intermediate representation.
const exprt & call_lhs() const
Get the lhs of a FUNCTION_CALL (may be nil)
const exprt & assign_rhs() const
Get the rhs of the assignment for ASSIGN.
const symbol_exprt & dead_symbol() const
Get the symbol for DEAD.
const symbol_exprt & decl_symbol() const
Get the declared symbol for DECL.
const exprt & assign_lhs() const
Get the lhs of the assignment for ASSIGN.
goto_program_instruction_typet type() const
What kind of instruction?
instructionst instructions
The list of instructions in the goto program.
instructionst::const_iterator const_targett
std::ostream & output_instruction(const namespacet &ns, const irep_idt &identifier, std::ostream &out, const instructionst::value_type &instruction) const
Output a single instruction.
const irep_idt & id() const
goto_programt::const_targett t
bool merge(const loc_infot &src)
void output(std::ostream &out, const goto_functiont &goto_function, const namespacet &ns) const
void assign_lhs(const exprt &lhs, const exprt &rhs, const loc_infot &loc_info_src, loc_infot &loc_info_dest)
void build(const goto_functiont &goto_function)
numberingt< exprt, irep_hash > objects
std::set< exprt > get(const goto_programt::const_targett t, const exprt &src) const
void get_rec(object_sett &dest, const exprt &rhs, const loc_infot &loc_info_src) const
std::stack< local_cfgt::node_nrt > work_queuet
bool aliases(const goto_programt::const_targett t, const exprt &src1, const exprt &src2) const
std::set< unsigned > object_sett
bool is_local(const irep_idt &identifier) const
A namespacet is essentially one or two symbol tables bound together, to allow for symbol lookups in t...
number_type number(const key_type &a)
An expression containing a side effect.
const irep_idt & get_statement() const
const irep_idt & get_identifier() const
size_type find(size_type a) const
size_type count(size_type a) const
void make_union(size_type a, size_type b)
bool same_set(size_type a, size_type b) const
void isolate(size_type a)
std::string from_expr(const namespacet &ns, const irep_idt &identifier, const exprt &expr)
Field-insensitive, location-sensitive may-alias analysis.
API to expression classes for Pointers.
const address_of_exprt & to_address_of_expr(const exprt &expr)
Cast an exprt to an address_of_exprt.
#define DATA_INVARIANT(CONDITION, REASON)
This condition should be used to document that assumptions that are made on goto_functions,...
side_effect_exprt & to_side_effect_expr(exprt &expr)
const if_exprt & to_if_expr(const exprt &expr)
Cast an exprt to an if_exprt.
const symbol_exprt & to_symbol_expr(const exprt &expr)
Cast an exprt to a symbol_exprt.
const typecast_exprt & to_typecast_expr(const exprt &expr)
Cast an exprt to a typecast_exprt.
const minus_exprt & to_minus_expr(const exprt &expr)
Cast an exprt to a minus_exprt.
const plus_exprt & to_plus_expr(const exprt &expr)
Cast an exprt to a plus_exprt.
const member_exprt & to_member_expr(const exprt &expr)
Cast an exprt to a member_exprt.
const index_exprt & to_index_expr(const exprt &expr)
Cast an exprt to an index_exprt.
void merge(string_constraintst &result, string_constraintst other)
Merge two sets of constraints by appending to the first one.