analyzer: decls are not on the heap
authorDavid Malcolm <dmalcolm@redhat.com>
Fri, 18 Sep 2020 21:34:50 +0000 (17:34 -0400)
committerDavid Malcolm <dmalcolm@redhat.com>
Mon, 21 Sep 2020 22:49:22 +0000 (18:49 -0400)
commit15e7b93ba4256884c90198c678ed7eded4e73464
tree5fa02aa000936608becc8567a32f9542cec512fb
parent7db5967f1050eb2b45e920b13d495d92ba4f16f4
analyzer: decls are not on the heap

Whilst debugging the remaining state explosion in PR analyzer/93355
I noticed that half of the states at an exploding program point had:
  'malloc': {'&buf': 'non-heap'}
whereas the other half didn't, presumably depending on whether the path
to each enode had used this local buffer:
  char buf[400];

This patch tweaks malloc_state_machine::get_default_state to be smarter
about this, so that we can implicitly treat pointers to decls as
non-heap, preventing pointless differences between sm_state_map
instances.  With that, all of the states in question have equal (empty)
malloc sm-state - though the state explosion continues for other reasons.

gcc/analyzer/ChangeLog:
PR analyzer/93355
* sm-malloc.cc (malloc_state_machine::get_default_state): Look at
the base region when considering pointers.  Treat pointers to
decls as being non-heap.
gcc/analyzer/sm-malloc.cc