diff options
author | Anna Zaks <ganna@apple.com> | 2012-01-20 00:11:16 +0000 |
---|---|---|
committer | Anna Zaks <ganna@apple.com> | 2012-01-20 00:11:16 +0000 |
commit | be97b7edb112520d764c24e8b9a159cdc692bcb6 (patch) | |
tree | 3d69ea06279124bb2e66a5ba30ceb78d7f2214a1 /lib/StaticAnalyzer/Core/ProgramState.cpp | |
parent | 461af1e502c9bd88330bbf17d449a7593fc0d624 (diff) |
[analyzer] Skip casts when determining taint dependencies + pretty
printing.
git-svn-id: https://llvm.org/svn/llvm-project/cfe/trunk@148517 91177308-0d34-0410-b5e6-96231b3b80d8
Diffstat (limited to 'lib/StaticAnalyzer/Core/ProgramState.cpp')
-rw-r--r-- | lib/StaticAnalyzer/Core/ProgramState.cpp | 25 |
1 files changed, 25 insertions, 0 deletions
diff --git a/lib/StaticAnalyzer/Core/ProgramState.cpp b/lib/StaticAnalyzer/Core/ProgramState.cpp index 5eb0e06bca..a8061e1b40 100644 --- a/lib/StaticAnalyzer/Core/ProgramState.cpp +++ b/lib/StaticAnalyzer/Core/ProgramState.cpp @@ -413,6 +413,22 @@ void ProgramState::dump() const { print(llvm::errs()); } +void ProgramState::printTaint(raw_ostream &Out, + const char *NL, const char *Sep) const { + TaintMapImpl TM = get<TaintMap>(); + + if (!TM.isEmpty()) + Out <<"Tainted Symbols:" << NL; + + for (TaintMapImpl::iterator I = TM.begin(), E = TM.end(); I != E; ++I) { + Out << I->first << " : " << I->second << NL; + } +} + +void ProgramState::dumpTaint() const { + printTaint(llvm::errs()); +} + //===----------------------------------------------------------------------===// // Generic Data Map. //===----------------------------------------------------------------------===// @@ -602,6 +618,11 @@ const ProgramState* ProgramState::addTaint(const MemRegion *R, const ProgramState* ProgramState::addTaint(SymbolRef Sym, TaintTagType Kind) const { + // If this is a symbol cast, remove the cast before adding the taint. Taint + // is cast agnostic. + while (const SymbolCast *SC = dyn_cast<SymbolCast>(Sym)) + Sym = SC->getOperand(); + const ProgramState *NewState = set<TaintMap>(Sym, Kind); assert(NewState); return NewState; @@ -662,6 +683,10 @@ bool ProgramState::isTainted(SymbolRef Sym, TaintTagType Kind) const { if (const SymbolRegionValue *SRV = dyn_cast<SymbolRegionValue>(*SI)) Tainted = Tainted || isTainted(SRV->getRegion(), Kind); + // If If this is a SymbolCast from a tainted value, it's also tainted. + if (const SymbolCast *SC = dyn_cast<SymbolCast>(*SI)) + Tainted = Tainted || isTainted(SC->getOperand(), Kind); + if (Tainted) return true; } |