cprover
reaching_definitions.cpp
Go to the documentation of this file.
1 /*******************************************************************\
2 
3 Module: Range-based reaching definitions analysis (following Field-
4  Sensitive Program Dependence Analysis, Litvak et al., FSE 2010)
5 
6 Author: Michael Tautschnig
7 
8 Date: February 2013
9 
10 \*******************************************************************/
11 
15 
16 #include "reaching_definitions.h"
17 
18 #include <memory>
19 
21 #include <util/prefix.h>
22 #include <util/make_unique.h>
23 
25 
26 #include "is_threaded.h"
27 #include "dirty.h"
28 
32 class rd_range_domain_factoryt : public ai_domain_factoryt<rd_range_domaint>
33 {
34 public:
37  : bv_container(_bv_container)
38  {
39  PRECONDITION(bv_container != nullptr);
40  }
41 
42  std::unique_ptr<statet> make(locationt) const override
43  {
44  auto p = util_make_unique<rd_range_domaint>(bv_container);
45  CHECK_RETURN(p->is_bottom());
46  return std::unique_ptr<statet>(p.release());
47  }
48 
49 private:
51 };
52 
54  const namespacet &_ns)
57  ns(_ns)
58 {
59 }
60 
62 
71 void rd_range_domaint::populate_cache(const irep_idt &identifier) const
72 {
73  assert(bv_container);
74 
75  valuest::const_iterator v_entry=values.find(identifier);
76  if(v_entry==values.end() ||
77  v_entry->second.empty())
78  return;
79 
80  ranges_at_loct &export_entry=export_cache[identifier];
81 
82  for(const auto &id : v_entry->second)
83  {
85 
86  export_entry[v.definition_at].insert(
87  std::make_pair(v.bit_begin, v.bit_end));
88  }
89 }
90 
92  const irep_idt &function_from,
93  trace_ptrt trace_from,
94  const irep_idt &function_to,
95  trace_ptrt trace_to,
96  ai_baset &ai,
97  const namespacet &ns)
98 {
99  locationt from{trace_from->current_location()};
100  locationt to{trace_to->current_location()};
101 
103  dynamic_cast<reaching_definitions_analysist*>(&ai);
105  rd!=nullptr,
107  "ai has type reaching_definitions_analysist");
108 
109  assert(bv_container);
110 
111  // kill values
112  if(from->is_dead())
113  transform_dead(ns, from);
114  // kill thread-local values
115  else if(from->is_start_thread())
116  transform_start_thread(ns, *rd);
117  // do argument-to-parameter assignments
118  else if(from->is_function_call())
119  transform_function_call(ns, function_from, from, function_to, *rd);
120  // cleanup parameters
121  else if(from->is_end_function())
122  transform_end_function(ns, function_from, from, function_to, to, *rd);
123  // lhs assignments
124  else if(from->is_assign())
125  transform_assign(ns, from, function_from, from, *rd);
126  // initial (non-deterministic) value
127  else if(from->is_decl())
128  transform_assign(ns, from, function_from, from, *rd);
129 
130 #if 0
131  // handle return values
132  if(to->is_function_call())
133  {
134  const code_function_callt &code=to_code_function_call(to->code);
135 
136  if(code.lhs().is_not_nil())
137  {
138  rw_range_set_value_sett rw_set(ns, rd->get_value_sets());
139  goto_rw(to, rw_set);
140  const bool is_must_alias=rw_set.get_w_set().size()==1;
141 
142  for(const auto &written_object_entry : rw_set.get_w_set())
143  {
144  const irep_idt &identifier = written_object_entry.first;
145  // ignore symex::invalid_object
146  const symbolt *symbol_ptr;
147  if(ns.lookup(identifier, symbol_ptr))
148  continue;
149  assert(symbol_ptr!=0);
150 
151  const range_domaint &ranges =
152  rw_set.get_ranges(written_object_entry.second);
153 
154  if(is_must_alias &&
155  (!rd->get_is_threaded()(from) ||
156  (!symbol_ptr->is_shared() &&
157  !rd->get_is_dirty()(identifier))))
158  for(const auto &range : ranges)
159  kill(identifier, range.first, range.second);
160  }
161  }
162  }
163 #endif
164 }
165 
169  const namespacet &,
170  locationt from)
171 {
172  const irep_idt &identifier = from->dead_symbol().get_identifier();
173 
174  valuest::iterator entry=values.find(identifier);
175 
176  if(entry!=values.end())
177  {
178  values.erase(entry);
179  export_cache.erase(identifier);
180  }
181 }
182 
184  const namespacet &ns,
186 {
187  for(valuest::iterator it=values.begin();
188  it!=values.end();
189  ) // no ++it
190  {
191  const irep_idt &identifier=it->first;
192 
193  if(!ns.lookup(identifier).is_shared() &&
194  !rd.get_is_dirty()(identifier))
195  {
196  export_cache.erase(identifier);
197 
198  valuest::iterator next=it;
199  ++next;
200  values.erase(it);
201  it=next;
202  }
203  else
204  ++it;
205  }
206 }
207 
209  const namespacet &ns,
210  const irep_idt &function_from,
211  locationt from,
212  const irep_idt &function_to,
214 {
215  const code_function_callt &code=to_code_function_call(from->code);
216 
217  // only if there is an actual call, i.e., we have a body
218  if(function_from != function_to)
219  {
220  for(valuest::iterator it=values.begin();
221  it!=values.end();
222  ) // no ++it
223  {
224  const irep_idt &identifier=it->first;
225 
226  // dereferencing may introduce extra symbols
227  const symbolt *sym;
228  if((ns.lookup(identifier, sym) ||
229  !sym->is_shared()) &&
230  !rd.get_is_dirty()(identifier))
231  {
232  export_cache.erase(identifier);
233 
234  valuest::iterator next=it;
235  ++next;
236  values.erase(it);
237  it=next;
238  }
239  else
240  ++it;
241  }
242 
243  const symbol_exprt &fn_symbol_expr=to_symbol_expr(code.function());
244  const code_typet &code_type=
245  to_code_type(ns.lookup(fn_symbol_expr.get_identifier()).type);
246 
247  for(const auto &param : code_type.parameters())
248  {
249  const irep_idt &identifier=param.get_identifier();
250 
251  if(identifier.empty())
252  continue;
253 
254  auto param_bits = pointer_offset_bits(param.type(), ns);
255  if(param_bits.has_value())
256  gen(from, identifier, 0, to_range_spect(*param_bits));
257  else
258  gen(from, identifier, 0, -1);
259  }
260  }
261  else
262  {
263  // handle return values of undefined functions
264  if(to_code_function_call(from->code).lhs().is_not_nil())
265  transform_assign(ns, from, function_from, from, rd);
266  }
267 }
268 
270  const namespacet &ns,
271  const irep_idt &function_from,
272  locationt from,
273  const irep_idt &function_to,
274  locationt to,
276 {
277  locationt call = to;
278  --call;
279  const code_function_callt &code=to_code_function_call(call->code);
280 
281  valuest new_values;
282  new_values.swap(values);
283  values=rd[call].values;
284 
285  for(const auto &new_value : new_values)
286  {
287  const irep_idt &identifier=new_value.first;
288 
289  if(!rd.get_is_threaded()(call) ||
290  (!ns.lookup(identifier).is_shared() &&
291  !rd.get_is_dirty()(identifier)))
292  {
293  for(const auto &id : new_value.second)
294  {
295  const reaching_definitiont &v=bv_container->get(id);
296  kill(v.identifier, v.bit_begin, v.bit_end);
297  }
298  }
299 
300  for(const auto &id : new_value.second)
301  {
302  const reaching_definitiont &v=bv_container->get(id);
304  }
305  }
306 
307  const code_typet &code_type = to_code_type(ns.lookup(function_from).type);
308 
309  for(const auto &param : code_type.parameters())
310  {
311  const irep_idt &identifier=param.get_identifier();
312 
313  if(identifier.empty())
314  continue;
315 
316  valuest::iterator entry=values.find(identifier);
317 
318  if(entry!=values.end())
319  {
320  values.erase(entry);
321  export_cache.erase(identifier);
322  }
323  }
324 
325  // handle return values
326  if(code.lhs().is_not_nil())
327  {
328 #if 0
329  rd_range_domaint *rd_state=
330  dynamic_cast<rd_range_domaint*>(&(rd.get_state(call)));
331  assert(rd_state!=0);
332  rd_state->
333 #endif
334  transform_assign(ns, from, function_to, call, rd);
335  }
336 }
337 
339  const namespacet &ns,
340  locationt from,
341  const irep_idt &function_to,
342  locationt to,
344 {
345  rw_range_set_value_sett rw_set(ns, rd.get_value_sets());
346  goto_rw(function_to, to, rw_set);
347  const bool is_must_alias=rw_set.get_w_set().size()==1;
348 
349  for(const auto &written_object_entry : rw_set.get_w_set())
350  {
351  const irep_idt &identifier = written_object_entry.first;
352  // ignore symex::invalid_object
353  const symbolt *symbol_ptr;
354  if(ns.lookup(identifier, symbol_ptr))
355  continue;
357  symbol_ptr!=nullptr,
359  "Symbol is in symbol table");
360 
361  const range_domaint &ranges =
362  rw_set.get_ranges(written_object_entry.second);
363 
364  if(is_must_alias &&
365  (!rd.get_is_threaded()(from) ||
366  (!symbol_ptr->is_shared() &&
367  !rd.get_is_dirty()(identifier))))
368  for(const auto &range : ranges)
369  kill(identifier, range.first, range.second);
370 
371  for(const auto &range : ranges)
372  gen(from, identifier, range.first, range.second);
373  }
374 }
375 
377  const irep_idt &identifier,
378  const range_spect &range_start,
379  const range_spect &range_end)
380 {
381  assert(range_start>=0);
382  // -1 for objects of infinite/unknown size
383  if(range_end==-1)
384  {
385  kill_inf(identifier, range_start);
386  return;
387  }
388 
389  assert(range_end>range_start);
390 
391  valuest::iterator entry=values.find(identifier);
392  if(entry==values.end())
393  return;
394 
395  bool clear_export_cache=false;
396  values_innert new_values;
397 
398  for(values_innert::iterator
399  it=entry->second.begin();
400  it!=entry->second.end();
401  ) // no ++it
402  {
403  const reaching_definitiont &v=bv_container->get(*it);
404 
405  if(v.bit_begin >= range_end)
406  ++it;
407  else if(v.bit_end!=-1 &&
408  v.bit_end <= range_start)
409  ++it;
410  else if(v.bit_begin >= range_start &&
411  v.bit_end!=-1 &&
412  v.bit_end <= range_end) // rs <= a < b <= re
413  {
414  clear_export_cache=true;
415 
416  entry->second.erase(it++);
417  }
418  else if(v.bit_begin >= range_start) // rs <= a <= re < b
419  {
420  clear_export_cache=true;
421 
422  reaching_definitiont v_new=v;
423  v_new.bit_begin=range_end;
424  new_values.insert(bv_container->add(v_new));
425 
426  entry->second.erase(it++);
427  }
428  else if(v.bit_end==-1 ||
429  v.bit_end > range_end) // a <= rs < re < b
430  {
431  clear_export_cache=true;
432 
433  reaching_definitiont v_new=v;
434  v_new.bit_end=range_start;
435 
436  reaching_definitiont v_new2=v;
437  v_new2.bit_begin=range_end;
438 
439  new_values.insert(bv_container->add(v_new));
440  new_values.insert(bv_container->add(v_new2));
441 
442  entry->second.erase(it++);
443  }
444  else // a <= rs < b <= re
445  {
446  clear_export_cache=true;
447 
448  reaching_definitiont v_new=v;
449  v_new.bit_end=range_start;
450  new_values.insert(bv_container->add(v_new));
451 
452  entry->second.erase(it++);
453  }
454  }
455 
456  if(clear_export_cache)
457  export_cache.erase(identifier);
458 
459  values_innert::iterator it=entry->second.begin();
460  for(const auto &id : new_values)
461  {
462  while(it!=entry->second.end() && *it<id)
463  ++it;
464  if(it==entry->second.end() || id<*it)
465  {
466  entry->second.insert(it, id);
467  }
468  else if(it!=entry->second.end())
469  {
470  assert(*it==id);
471  ++it;
472  }
473  }
474 }
475 
477  const irep_idt &,
478  const range_spect &range_start)
479 {
480  assert(range_start>=0);
481 
482 #if 0
483  valuest::iterator entry=values.find(identifier);
484  if(entry==values.end())
485  return;
486 
487  XXX export_cache_available=false;
488 
489  // makes the analysis underapproximating
490  rangest &ranges=entry->second;
491 
492  for(rangest::iterator it=ranges.begin();
493  it!=ranges.end();
494  ) // no ++it
495  if(it->second.first!=-1 &&
496  it->second.first <= range_start)
497  ++it;
498  else if(it->first >= range_start) // rs <= a < b <= re
499  {
500  ranges.erase(it++);
501  }
502  else // a <= rs < b < re
503  {
504  it->second.first=range_start;
505  ++it;
506  }
507 #endif
508 }
509 
515  locationt from,
516  const irep_idt &identifier,
517  const range_spect &range_start,
518  const range_spect &range_end)
519 {
520  // objects of size 0 like union U { signed : 0; };
521  if(range_start==0 && range_end==0)
522  return false;
523 
524  assert(range_start>=0);
525 
526  // -1 for objects of infinite/unknown size
527  assert(range_end>range_start || range_end==-1);
528 
530  v.identifier=identifier;
531  v.definition_at=from;
532  v.bit_begin=range_start;
533  v.bit_end=range_end;
534 
535  if(!values[identifier].insert(bv_container->add(v)).second)
536  return false;
537 
538  export_cache.erase(identifier);
539 
540 #if 0
541  range_spect merged_range_end=range_end;
542 
543  std::pair<valuest::iterator, bool> entry=
544  values.insert(std::make_pair(identifier, rangest()));
545  rangest &ranges=entry.first->second;
546 
547  if(!entry.second)
548  {
549  for(rangest::iterator it=ranges.begin();
550  it!=ranges.end();
551  ) // no ++it
552  {
553  if(it->second.second!=from ||
554  (it->second.first!=-1 && it->second.first <= range_start) ||
555  (range_end!=-1 && it->first >= range_end))
556  ++it;
557  else if(it->first > range_start) // rs < a < b,re
558  {
559  if(range_end!=-1)
560  merged_range_end=std::max(range_end, it->second.first);
561  ranges.erase(it++);
562  }
563  else if(it->second.first==-1 ||
564  (range_end!=-1 &&
565  it->second.first >= range_end)) // a <= rs < re <= b
566  {
567  // nothing to do
568  return false;
569  }
570  else // a <= rs < b < re
571  {
572  it->second.first=range_end;
573  return true;
574  }
575  }
576  }
577 
578  ranges.insert(std::make_pair(
579  range_start,
580  std::make_pair(merged_range_end, from)));
581 #endif
582 
583  return true;
584 }
585 
586 void rd_range_domaint::output(std::ostream &out) const
587 {
588  out << "Reaching definitions:\n";
589 
590  if(has_values.is_known())
591  {
592  out << has_values.to_string() << '\n';
593  return;
594  }
595 
596  for(const auto &value : values)
597  {
598  const irep_idt &identifier=value.first;
599 
600  const ranges_at_loct &ranges=get(identifier);
601 
602  out << " " << identifier << "[";
603 
604  for(ranges_at_loct::const_iterator itl=ranges.begin();
605  itl!=ranges.end();
606  ++itl)
607  for(rangest::const_iterator itr=itl->second.begin();
608  itr!=itl->second.end();
609  ++itr)
610  {
611  if(itr!=itl->second.begin() ||
612  itl!=ranges.begin())
613  out << ";";
614 
615  out << itr->first << ":" << itr->second;
616  out << "@" << itl->first->location_number;
617  }
618 
619  out << "]\n";
620 
621  clear_cache(identifier);
622  }
623 }
624 
627  values_innert &dest,
628  const values_innert &other)
629 {
630  bool more=false;
631 
632 #if 0
633  ranges_at_loct::iterator itr=it->second.begin();
634  for(const auto &o : ito->second)
635  {
636  while(itr!=it->second.end() && itr->first<o.first)
637  ++itr;
638  if(itr==it->second.end() || o.first<itr->first)
639  {
640  it->second.insert(o);
641  more=true;
642  }
643  else if(itr!=it->second.end())
644  {
645  assert(itr->first==o.first);
646 
647  for(const auto &o_range : o.second)
648  more=gen(itr->second, o_range.first, o_range.second) ||
649  more;
650 
651  ++itr;
652  }
653  }
654 #else
655  values_innert::iterator itr=dest.begin();
656  for(const auto &id : other)
657  {
658  while(itr!=dest.end() && *itr<id)
659  ++itr;
660  if(itr==dest.end() || id<*itr)
661  {
662  dest.insert(itr, id);
663  more=true;
664  }
665  else if(itr!=dest.end())
666  {
667  assert(*itr==id);
668  ++itr;
669  }
670  }
671 #endif
672 
673  return more;
674 }
675 
678  const rd_range_domaint &other,
679  locationt,
680  locationt)
681 {
682  bool changed=has_values.is_false();
684 
685  valuest::iterator it=values.begin();
686  for(const auto &value : other.values)
687  {
688  while(it!=values.end() && it->first<value.first)
689  ++it;
690  if(it==values.end() || value.first<it->first)
691  {
692  values.insert(value);
693  changed=true;
694  }
695  else if(it!=values.end())
696  {
697  assert(it->first==value.first);
698 
699  if(merge_inner(it->second, value.second))
700  {
701  changed=true;
702  export_cache.erase(it->first);
703  }
704 
705  ++it;
706  }
707  }
708 
709  return changed;
710 }
711 
714  const rd_range_domaint &other,
715  locationt,
716  locationt,
717  const namespacet &ns)
718 {
719  // TODO: dirty vars
720 #if 0
722  dynamic_cast<reaching_definitions_analysist*>(&ai);
723  assert(rd!=0);
724 #endif
725 
726  bool changed=has_values.is_false();
728 
729  valuest::iterator it=values.begin();
730  for(const auto &value : other.values)
731  {
732  const irep_idt &identifier=value.first;
733 
734  if(!ns.lookup(identifier).is_shared()
735  /*&& !rd.get_is_dirty()(identifier)*/)
736  continue;
737 
738  while(it!=values.end() && it->first<value.first)
739  ++it;
740  if(it==values.end() || value.first<it->first)
741  {
742  values.insert(value);
743  changed=true;
744  }
745  else if(it!=values.end())
746  {
747  assert(it->first==value.first);
748 
749  if(merge_inner(it->second, value.second))
750  {
751  changed=true;
752  export_cache.erase(it->first);
753  }
754 
755  ++it;
756  }
757  }
758 
759  return changed;
760 }
761 
763  const irep_idt &identifier) const
764 {
765  populate_cache(identifier);
766 
767  static ranges_at_loct empty;
768 
769  export_cachet::const_iterator entry=export_cache.find(identifier);
770 
771  if(entry==export_cache.end())
772  return empty;
773  else
774  return entry->second;
775 }
776 
778  const goto_functionst &goto_functions)
779 {
780  auto value_sets_=util_make_unique<value_set_analysis_fit>(ns);
781  (*value_sets_)(goto_functions);
782  value_sets=std::move(value_sets_);
783 
784  is_threaded=util_make_unique<is_threadedt>(goto_functions);
785 
786  is_dirty=util_make_unique<dirtyt>(goto_functions);
787 
789 }
dstringt
dstringt has one field, an unsigned integer no which is an index into a static table of strings.
Definition: dstring.h:37
pointer_offset_size.h
Pointer Logic.
rd_range_domaint::values
valuest values
It is an ordered map from program variable names to IDs of reaching_definitiont instances stored in m...
Definition: reaching_definitions.h:268
bad_cast_exceptiont
Definition: base_exceptions.h:18
dirty.h
Variables whose address is taken.
rd_range_domaint::populate_cache
void populate_cache(const irep_idt &identifier) const
Given the passed variable name identifier it collects data from bv_container for each ID in values[id...
Definition: reaching_definitions.cpp:71
reaching_definitions_analysist::reaching_definitions_analysist
reaching_definitions_analysist(const namespacet &_ns)
Definition: reaching_definitions.cpp:53
CHECK_RETURN
#define CHECK_RETURN(CONDITION)
Definition: invariant.h:496
reaching_definitions_analysist::get_value_sets
value_setst & get_value_sets() const
Definition: reaching_definitions.h:348
rw_range_sett::get_ranges
const range_domaint & get_ranges(const std::unique_ptr< range_domain_baset > &ranges) const
Definition: goto_rw.h:132
sparse_bitvector_analysist< reaching_definitiont >
reaching_definitiont::definition_at
ai_domain_baset::locationt definition_at
The iterator to the GOTO instruction where the variable has been written to.
Definition: reaching_definitions.h:92
rd_range_domaint::transform_assign
void transform_assign(const namespacet &ns, locationt from, const irep_idt &function_to, locationt to, reaching_definitions_analysist &rd)
Definition: reaching_definitions.cpp:338
prefix.h
goto_rw
static void goto_rw(const irep_idt &function, goto_programt::const_targett target, const code_assignt &assign, rw_range_sett &rw_set)
Definition: goto_rw.cpp:723
rd_range_domaint::ranges_at_loct
std::map< locationt, rangest > ranges_at_loct
Definition: reaching_definitions.h:234
nullptr_exceptiont
Definition: base_exceptions.h:30
reaching_definitions_analysist::get_is_threaded
const is_threadedt & get_is_threaded() const
Definition: reaching_definitions.h:354
sparse_bitvector_analysist::values
std::vector< typename inner_mapt::const_iterator > values
It is a map from an ID to the corresponding reaching_definitiont instance inside the map value_map.
Definition: reaching_definitions.h:77
rd_range_domaint::values_innert
std::set< std::size_t > values_innert
Definition: reaching_definitions.h:257
rd_range_domaint::has_values
tvt has_values
This (three value logic) flag determines, whether the instance represents top, bottom,...
Definition: reaching_definitions.h:246
rd_range_domaint::merge
bool merge(const rd_range_domaint &other, locationt from, locationt to)
Implements the join operation of two instances *this and other.
Definition: reaching_definitions.cpp:677
rw_range_set_value_sett
Definition: goto_rw.h:264
rd_range_domaint::bv_container
sparse_bitvector_analysist< reaching_definitiont > *const bv_container
It points to the actual reaching definitions data of individual program variables.
Definition: reaching_definitions.h:255
symbol_exprt
Expression to hold a symbol (variable)
Definition: std_expr.h:81
reaching_definitiont::bit_begin
range_spect bit_begin
The two integers below define a range of bits (i.e.
Definition: reaching_definitions.h:98
rd_range_domaint::get
const ranges_at_loct & get(const irep_idt &identifier) const
Definition: reaching_definitions.cpp:762
code_function_callt::lhs
exprt & lhs()
Definition: std_code.h:1240
ai_domain_baset::trace_ptrt
ai_history_baset::trace_ptrt trace_ptrt
Definition: ai_domain.h:78
reaching_definitions_analysist
Definition: reaching_definitions.h:339
to_range_spect
range_spect to_range_spect(const mp_integer &size)
Definition: goto_rw.h:59
tvt::is_known
bool is_known() const
Definition: threeval.h:28
sparse_bitvector_analysist::add
std::size_t add(const V &value)
Definition: reaching_definitions.h:52
rd_range_domaint::transform_function_call
void transform_function_call(const namespacet &ns, const irep_idt &function_from, locationt from, const irep_idt &function_to, reaching_definitions_analysist &rd)
Definition: reaching_definitions.cpp:208
namespacet
A namespacet is essentially one or two symbol tables bound together, to allow for symbol lookups in t...
Definition: namespace.h:92
util_make_unique
std::unique_ptr< T > util_make_unique(Ts &&... ts)
Definition: make_unique.h:19
namespacet::lookup
bool lookup(const irep_idt &name, const symbolt *&symbol) const override
See documentation for namespace_baset::lookup().
Definition: namespace.cpp:140
code_function_callt
codet representation of a function call statement.
Definition: std_code.h:1215
irept::is_not_nil
bool is_not_nil() const
Definition: irep.h:391
to_code_type
const code_typet & to_code_type(const typet &type)
Cast a typet to a code_typet.
Definition: std_types.h:949
make_unique.h
reaching_definitions_analysist::is_threaded
std::unique_ptr< is_threadedt > is_threaded
Definition: reaching_definitions.h:369
reaching_definitiont::identifier
irep_idt identifier
The name of the variable which was defined.
Definition: reaching_definitions.h:89
PRECONDITION
#define PRECONDITION(CONDITION)
Definition: invariant.h:464
symbol_exprt::get_identifier
const irep_idt & get_identifier() const
Definition: std_expr.h:110
pointer_offset_bits
optionalt< mp_integer > pointer_offset_bits(const typet &type, const namespacet &ns)
Definition: pointer_offset_size.cpp:100
is_threaded.h
Over-approximate Concurrency for Threaded Goto Programs.
rd_range_domaint
Because the class is inherited from ai_domain_baset, its instance represents an element of a domain o...
Definition: reaching_definitions.h:137
to_symbol_expr
const symbol_exprt & to_symbol_expr(const exprt &expr)
Cast an exprt to a symbol_exprt.
Definition: std_expr.h:190
code_typet
Base type of functions.
Definition: std_types.h:744
rd_range_domaint::transform
void transform(const irep_idt &function_from, trace_ptrt trace_from, const irep_idt &function_to, trace_ptrt trace_to, ai_baset &ai, const namespacet &ns) final override
Computes an instance obtained from the instance *this by transformation over a GOTO instruction refer...
Definition: reaching_definitions.cpp:91
rd_range_domaint::gen
bool gen(locationt from, const irep_idt &identifier, const range_spect &range_start, const range_spect &range_end)
A utility function which updates internal data structures by inserting a new reaching definition reco...
Definition: reaching_definitions.cpp:514
symbolt::is_shared
bool is_shared() const
Definition: symbol.h:95
tvt::unknown
static tvt unknown()
Definition: threeval.h:33
to_code_function_call
const code_function_callt & to_code_function_call(const codet &code)
Definition: std_code.h:1326
dstringt::empty
bool empty() const
Definition: dstring.h:88
tvt::to_string
const char * to_string() const
Definition: threeval.cpp:13
reaching_definitions.h
Range-based reaching definitions analysis (following Field- Sensitive Program Dependence Analysis,...
value_set_analysis_fi.h
Value Set Propagation (flow insensitive)
code_typet::parameters
const parameterst & parameters() const
Definition: std_types.h:860
tvt::is_false
bool is_false() const
Definition: threeval.h:26
rd_range_domaint::rangest
std::multimap< range_spect, range_spect > rangest
Definition: reaching_definitions.h:233
rd_range_domaint::merge_inner
bool merge_inner(values_innert &dest, const values_innert &other)
Definition: reaching_definitions.cpp:626
rd_range_domain_factoryt::bv_container
sparse_bitvector_analysist< reaching_definitiont > *const bv_container
Definition: reaching_definitions.cpp:50
rd_range_domaint::transform_dead
void transform_dead(const namespacet &ns, locationt from)
Computes an instance obtained from a *this by transformation over DEAD v GOTO instruction.
Definition: reaching_definitions.cpp:168
range_spect
int range_spect
Definition: goto_rw.h:57
reaching_definitions_analysist::~reaching_definitions_analysist
virtual ~reaching_definitions_analysist()
ai_baset::initialize
virtual void initialize(const irep_idt &function_id, const goto_programt &goto_program)
Initialize all the abstract states for a single function.
Definition: ai.cpp:190
goto_functionst
A collection of goto functions.
Definition: goto_functions.h:23
ai_domain_baset::locationt
goto_programt::const_targett locationt
Definition: ai_domain.h:77
rd_range_domain_factoryt::make
std::unique_ptr< statet > make(locationt) const override
Definition: reaching_definitions.cpp:42
ai_domain_factoryt
Definition: ai_domain.h:201
rd_range_domaint::transform_start_thread
void transform_start_thread(const namespacet &ns, reaching_definitions_analysist &rd)
Definition: reaching_definitions.cpp:183
reaching_definitions_analysist::get_is_dirty
const dirtyt & get_is_dirty() const
Definition: reaching_definitions.h:360
rd_range_domaint::merge_shared
bool merge_shared(const rd_range_domaint &other, locationt from, locationt to, const namespacet &ns)
Definition: reaching_definitions.cpp:713
symbolt
Symbol table entry.
Definition: symbol.h:28
concurrency_aware_ait
Base class for concurrency-aware abstract interpretation.
Definition: ai.h:643
ai_baset
This is the basic interface of the abstract interpreter with default implementations of the core func...
Definition: ai.h:120
rd_range_domain_factoryt::rd_range_domain_factoryt
rd_range_domain_factoryt(sparse_bitvector_analysist< reaching_definitiont > *_bv_container)
Definition: reaching_definitions.cpp:35
INVARIANT_STRUCTURED
#define INVARIANT_STRUCTURED(CONDITION, TYPENAME,...)
Definition: invariant.h:408
reaching_definitions_analysist::initialize
void initialize(const goto_functionst &goto_functions) override
Initialize all the abstract states for a whole program.
Definition: reaching_definitions.cpp:777
reaching_definitiont::bit_end
range_spect bit_end
Definition: reaching_definitions.h:99
ai_domain_factory_baset::locationt
ai_domain_baset::locationt locationt
Definition: ai_domain.h:175
rd_range_domaint::export_cache
export_cachet export_cache
It is a helper data structure.
Definition: reaching_definitions.h:286
rd_range_domaint::kill_inf
void kill_inf(const irep_idt &identifier, const range_spect &range_start)
Definition: reaching_definitions.cpp:476
reaching_definitiont
Identifies a GOTO instruction where a given variable is defined (i.e.
Definition: reaching_definitions.h:87
reaching_definitions_analysist::ns
const namespacet & ns
Definition: reaching_definitions.h:367
rd_range_domaint::kill
void kill(const irep_idt &identifier, const range_spect &range_start, const range_spect &range_end)
Definition: reaching_definitions.cpp:376
rd_range_domaint::output
void output(std::ostream &out, const ai_baset &, const namespacet &) const final override
Definition: reaching_definitions.h:166
rd_range_domaint::transform_end_function
void transform_end_function(const namespacet &ns, const irep_idt &function_from, locationt from, const irep_idt &function_to, locationt to, reaching_definitions_analysist &rd)
Definition: reaching_definitions.cpp:269
reaching_definitions_analysist::is_dirty
std::unique_ptr< dirtyt > is_dirty
Definition: reaching_definitions.h:370
rd_range_domain_factoryt
This ensures that all domains are constructed with the appropriate pointer back to the analysis engin...
Definition: reaching_definitions.cpp:33
rd_range_domaint::clear_cache
void clear_cache(const irep_idt &identifier) const
Definition: reaching_definitions.h:237
rd_range_domaint::valuest
std::map< irep_idt, values_innert > valuest
Definition: reaching_definitions.h:259
ait::get_state
virtual statet & get_state(locationt l)
Definition: ai.h:606
sparse_bitvector_analysist::get
const V & get(const std::size_t value_index) const
Definition: reaching_definitions.h:46
reaching_definitions_analysist::value_sets
std::unique_ptr< value_setst > value_sets
Definition: reaching_definitions.h:368
rw_range_sett::get_w_set
const objectst & get_w_set() const
Definition: goto_rw.h:126
code_function_callt::function
exprt & function()
Definition: std_code.h:1250
range_domaint
Definition: goto_rw.h:70