Search in sources :

Example 1 with LocalVarNode

use of soot.jimple.spark.pag.LocalVarNode in project soot by Sable.

the class GeomPointsTo method finalizeInternalData.

 * 1. Update the call graph;
 * 2. Eliminate the pointers, objects, and constraints related to the unreachable code.
private void finalizeInternalData() {
    // Compute the set of reachable functions after the points-to analysis
    // Clean the unreachable objects
    for (Iterator<IVarAbstraction> it = allocations.iterator(); it.hasNext(); ) {
        IVarAbstraction po =;
        AllocNode obj = (AllocNode) po.getWrappedNode();
        SootMethod sm = obj.getMethod();
        if (sm != null && func2int.containsKey(sm) == false)
    // Clean the unreachable pointers
    final Vector<AllocNode> removeSet = new Vector<AllocNode>();
    for (Iterator<IVarAbstraction> it = pointers.iterator(); it.hasNext(); ) {
        IVarAbstraction pn =;
        // Is this pointer obsoleted?
        Node vn = pn.getWrappedNode();
        SootMethod sm = null;
        if (vn instanceof LocalVarNode) {
            sm = ((LocalVarNode) vn).getMethod();
        } else if (vn instanceof AllocDotField) {
            sm = ((AllocDotField) vn).getBase().getMethod();
        if (sm != null) {
            if (func2int.containsKey(sm) == false) {
        if (pn.getRepresentative() != pn)
        if (pn.hasPTResult()) {
            // We remove the useless shapes or objects
            Set<AllocNode> objSet = pn.get_all_points_to_objects();
            for (Iterator<AllocNode> oit = objSet.iterator(); oit.hasNext(); ) {
                AllocNode obj =;
                IVarAbstraction po = consG.get(obj);
                if (!po.reachable() || pn.isDeadObject(obj)) {
            for (AllocNode obj : removeSet) pn.remove_points_to(obj);
        } else {
            // We also remove unreachable objects for SPARK nodes
            PointsToSetInternal pts = vn.getP2Set();
            pts.forall(new P2SetVisitor() {

                public void visit(Node n) {
                    IVarAbstraction pan = findInternalNode(n);
                    // The removeSet is misused as a contains set
                    if (pan.reachable())
                        removeSet.add((AllocNode) n);
            pts = vn.makeP2Set();
            for (AllocNode an : removeSet) pts.add(an);
    // Clean the useless constraints
    for (Iterator<PlainConstraint> cIt = constraints.iterator(); cIt.hasNext(); ) {
        PlainConstraint cons =;
        IVarAbstraction lhs = cons.getLHS();
        IVarAbstraction rhs = cons.getRHS();
        if (!lhs.reachable() || !rhs.reachable() || getMethodIDFromPtr(lhs) == Constants.UNKNOWN_FUNCTION || getMethodIDFromPtr(rhs) == Constants.UNKNOWN_FUNCTION) {
    // We reassign the IDs to the pointers, objects and constraints
Also used : AllocDotField(soot.jimple.spark.pag.AllocDotField) PlainConstraint(soot.jimple.spark.geom.dataRep.PlainConstraint) PointsToSetInternal(soot.jimple.spark.sets.PointsToSetInternal) FieldRefNode(soot.jimple.spark.pag.FieldRefNode) ContextVarNode(soot.jimple.spark.pag.ContextVarNode) LocalVarNode(soot.jimple.spark.pag.LocalVarNode) Node(soot.jimple.spark.pag.Node) VarNode(soot.jimple.spark.pag.VarNode) AllocNode(soot.jimple.spark.pag.AllocNode) AllocNode(soot.jimple.spark.pag.AllocNode) SootMethod(soot.SootMethod) Vector(java.util.Vector) LocalVarNode(soot.jimple.spark.pag.LocalVarNode) P2SetVisitor(soot.jimple.spark.sets.P2SetVisitor)

Example 2 with LocalVarNode

use of soot.jimple.spark.pag.LocalVarNode in project soot by Sable.

the class GeomPointsTo method reachingObjects.

public PointsToSet reachingObjects(Local l) {
    if (!hasExecuted)
        return super.reachingObjects(l);
    LocalVarNode vn = findLocalVarNode(l);
    if (vn == null)
        return EmptyPointsToSet.v();
    IVarAbstraction pn = consG.get(vn);
    // This is perhaps a bug
    if (pn == null)
        return vn.getP2Set();
    // Return the cached result
    if (hasTransformed || vn.getP2Set() != EmptyPointsToSet.v())
        return vn.getP2Set();
    // Compute and cache the result
    pn = pn.getRepresentative();
    PointsToSetInternal ptSet = vn.makeP2Set();
    for (AllocNode obj : pn.get_all_points_to_objects()) {
    return ptSet;
Also used : AllocNode(soot.jimple.spark.pag.AllocNode) PointsToSetInternal(soot.jimple.spark.sets.PointsToSetInternal) LocalVarNode(soot.jimple.spark.pag.LocalVarNode)

Example 3 with LocalVarNode

use of soot.jimple.spark.pag.LocalVarNode in project soot by Sable.

the class GeomPointsTo method reachingObjects.

	 * Currently, we only accept one call unit context (1CFA).
	 * For querying K-CFA (K >1), please see GeomQueries.contextsByCallChain
public PointsToSet reachingObjects(Context c, Local l) {
    if (!hasExecuted)
        return super.reachingObjects(c, l);
    if (hasTransformed || !(c instanceof Unit))
        return reachingObjects(l);
    LocalVarNode vn = findLocalVarNode(l);
    if (vn == null)
        return EmptyPointsToSet.v();
    // Lookup the context sensitive points-to information for this pointer
    IVarAbstraction pn = consG.get(vn);
    if (pn == null)
        return vn.getP2Set();
    pn = pn.getRepresentative();
    // Obtain the context sensitive points-to result
    SootMethod callee = vn.getMethod();
    Edge e = Scene.v().getCallGraph().findEdge((Unit) c, callee);
    if (e == null)
        return vn.getP2Set();
    // Compute the contexts interval
    CgEdge myEdge = getInternalEdgeFromSootEdge(e);
    if (myEdge == null)
        return vn.getP2Set();
    long low = myEdge.map_offset;
    long high = low + max_context_size_block[myEdge.s];
    // Lookup the cache
    ContextVarNode cvn = vn.context(c);
    if (cvn != null) {
        PointsToSetInternal ans = cvn.getP2Set();
        if (ans != EmptyPointsToSet.v())
            return ans;
    } else {
        // Create a new context sensitive variable
        // The points-to vector is set to empty at start
        cvn = makeContextVarNode(vn, c);
    // Fill
    PointsToSetInternal ptset = cvn.makeP2Set();
    for (AllocNode an : pn.get_all_points_to_objects()) {
        if (pn.pointer_interval_points_to(low, high, an))
    return ptset;
Also used : CgEdge(soot.jimple.spark.geom.dataRep.CgEdge) AllocNode(soot.jimple.spark.pag.AllocNode) PointsToSetInternal(soot.jimple.spark.sets.PointsToSetInternal) SootMethod(soot.SootMethod) ContextVarNode(soot.jimple.spark.pag.ContextVarNode) Unit(soot.Unit) LocalVarNode(soot.jimple.spark.pag.LocalVarNode) Edge(soot.jimple.toolkits.callgraph.Edge) CgEdge(soot.jimple.spark.geom.dataRep.CgEdge)

Example 4 with LocalVarNode

use of soot.jimple.spark.pag.LocalVarNode in project soot by Sable.

the class GeomPointsTo method mergeLocalVariables.

 * As pointed out by the single entry graph contraction, temporary variables incur high redundancy in points-to relations.
 * Find and eliminate the redundancies as early as possible.
 * Methodology:
 * If q has unique incoming edge p -> q, p and q are both local to the same function, and they have the same type, we merge them.
private void mergeLocalVariables() {
    IVarAbstraction my_lhs, my_rhs;
    Node lhs, rhs;
    int[] count = new int[pointers.size()];
    // We count how many ways a local pointer can be assigned
    for (PlainConstraint cons : constraints) {
        my_lhs = cons.getLHS();
        my_rhs = cons.getRHS();
        switch(cons.type) {
            case Constants.NEW_CONS:
            case Constants.ASSIGN_CONS:
            case Constants.LOAD_CONS:
                lhs = my_lhs.getWrappedNode();
                count[] += lhs.getP2Set().size();
    // Second time scan, we delete those constraints that only duplicate points-to information
    for (Iterator<PlainConstraint> cons_it = constraints.iterator(); cons_it.hasNext(); ) {
        PlainConstraint cons =;
        if (cons.type == Constants.ASSIGN_CONS) {
            my_lhs = cons.getLHS();
            my_rhs = cons.getRHS();
            lhs = my_lhs.getWrappedNode();
            rhs = my_rhs.getWrappedNode();
            if ((lhs instanceof LocalVarNode) && (rhs instanceof LocalVarNode)) {
                SootMethod sm1 = ((LocalVarNode) lhs).getMethod();
                SootMethod sm2 = ((LocalVarNode) rhs).getMethod();
                if (sm1 == sm2 && count[] == 1 && lhs.getType() == rhs.getType()) {
                    // They are local to the same function and the receiver pointer has unique incoming edge
                    // More importantly, they have the same type.
    // Third scan, update the constraints with the representatives
    for (PlainConstraint cons : constraints) {
        my_lhs = cons.getLHS();
        my_rhs = cons.getRHS();
        switch(cons.type) {
            case Constants.NEW_CONS:
            case Constants.ASSIGN_CONS:
            case Constants.LOAD_CONS:
            case Constants.STORE_CONS:
Also used : PlainConstraint(soot.jimple.spark.geom.dataRep.PlainConstraint) FieldRefNode(soot.jimple.spark.pag.FieldRefNode) ContextVarNode(soot.jimple.spark.pag.ContextVarNode) LocalVarNode(soot.jimple.spark.pag.LocalVarNode) Node(soot.jimple.spark.pag.Node) VarNode(soot.jimple.spark.pag.VarNode) AllocNode(soot.jimple.spark.pag.AllocNode) SootMethod(soot.SootMethod) LocalVarNode(soot.jimple.spark.pag.LocalVarNode)

Example 5 with LocalVarNode

use of soot.jimple.spark.pag.LocalVarNode in project soot by Sable.

the class OfflineProcessor method setAllUserCodeVariablesUseful.

 * All the pointers that we need their points-to information are marked.
 * @param virtualBaseSet
protected void setAllUserCodeVariablesUseful() {
    for (int i = 0; i < n_var; ++i) {
        IVarAbstraction pn = int2var.get(i);
        if (pn != pn.getRepresentative())
        Node node = pn.getWrappedNode();
        int sm_id = geomPTA.getMethodIDFromPtr(pn);
        if (!geomPTA.isReachableMethod(sm_id))
        if (node instanceof VarNode) {
            // flag == true if node is defined in the Java library
            boolean defined_in_lib = false;
            if (node instanceof LocalVarNode) {
                defined_in_lib = ((LocalVarNode) node).getMethod().isJavaLibraryMethod();
            } else if (node instanceof GlobalVarNode) {
                SootClass sc = ((GlobalVarNode) node).getDeclaringClass();
                if (sc != null)
                    defined_in_lib = sc.isJavaLibraryClass();
            if (!defined_in_lib && !geomPTA.isExceptionPointer(node)) {
                // Defined in the user code
                pn.willUpdate = true;
Also used : GlobalVarNode(soot.jimple.spark.pag.GlobalVarNode) LocalVarNode(soot.jimple.spark.pag.LocalVarNode) VarNode(soot.jimple.spark.pag.VarNode) GlobalVarNode(soot.jimple.spark.pag.GlobalVarNode) GlobalVarNode(soot.jimple.spark.pag.GlobalVarNode) LocalVarNode(soot.jimple.spark.pag.LocalVarNode) Node(soot.jimple.spark.pag.Node) VarNode(soot.jimple.spark.pag.VarNode) AllocNode(soot.jimple.spark.pag.AllocNode) SootClass(soot.SootClass) LocalVarNode(soot.jimple.spark.pag.LocalVarNode) PlainConstraint(soot.jimple.spark.geom.dataRep.PlainConstraint)


LocalVarNode (soot.jimple.spark.pag.LocalVarNode)22 SootMethod (soot.SootMethod)16 AllocNode (soot.jimple.spark.pag.AllocNode)15 Node (soot.jimple.spark.pag.Node)13 VarNode (soot.jimple.spark.pag.VarNode)11 FieldRefNode (soot.jimple.spark.pag.FieldRefNode)8 PointsToSetInternal (soot.jimple.spark.sets.PointsToSetInternal)6 RefType (soot.RefType)5 GlobalVarNode (soot.jimple.spark.pag.GlobalVarNode)5 SootClass (soot.SootClass)4 CgEdge (soot.jimple.spark.geom.dataRep.CgEdge)4 PlainConstraint (soot.jimple.spark.geom.dataRep.PlainConstraint)4 AssignEdge (soot.jimple.spark.ondemand.pautil.AssignEdge)4 ContextVarNode (soot.jimple.spark.pag.ContextVarNode)4 SparkField (soot.jimple.spark.pag.SparkField)4 StringConstantNode (soot.jimple.spark.pag.StringConstantNode)4 HashSet (java.util.HashSet)3 Hierarchy (soot.Hierarchy)3 Unit (soot.Unit)3 AssignStmt (soot.jimple.AssignStmt)3