-
- Downloads
analyzer: fix taint false +ve due to overzealous state purging [PR112977]
gcc/analyzer/ChangeLog:
PR analyzer/112977
* engine.cc (impl_region_model_context::on_liveness_change): Pass
m_ext_state to sm_state_map::on_liveness_change.
* program-state.cc (sm_state_map::on_svalue_leak): Guard removal
of map entry based on can_purge_p.
(sm_state_map::on_liveness_change): Add ext_state param. Add
workaround for bad interaction between state purging and
alt-inherited sm-state.
* program-state.h (sm_state_map::on_liveness_change): Add
ext_state param.
* sm-taint.cc
(taint_state_machine::has_alt_get_inherited_state_p): New.
(taint_state_machine::can_purge_p): Return false for "has_lb" and
"has_ub".
* sm.h (state_machine::has_alt_get_inherited_state_p): New vfunc.
gcc/testsuite/ChangeLog:
PR analyzer/112977
* gcc.dg/plugin/plugin.exp: Add taint-pr112977.c.
* gcc.dg/plugin/taint-pr112977.c: New test.
Signed-off-by:
David Malcolm <dmalcolm@redhat.com>
Showing
- gcc/analyzer/engine.cc 1 addition, 1 deletiongcc/analyzer/engine.cc
- gcc/analyzer/program-state.cc 63 additions, 2 deletionsgcc/analyzer/program-state.cc
- gcc/analyzer/program-state.h 1 addition, 0 deletionsgcc/analyzer/program-state.h
- gcc/analyzer/sm-taint.cc 9 additions, 0 deletionsgcc/analyzer/sm-taint.cc
- gcc/analyzer/sm.h 6 additions, 0 deletionsgcc/analyzer/sm.h
- gcc/testsuite/gcc.dg/plugin/plugin.exp 2 additions, 1 deletiongcc/testsuite/gcc.dg/plugin/plugin.exp
- gcc/testsuite/gcc.dg/plugin/taint-pr112977.c 44 additions, 0 deletionsgcc/testsuite/gcc.dg/plugin/taint-pr112977.c
Loading
Please register or sign in to comment