Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix Unreached Fixpoint in Reluctant Incremental Analysis #950

Merged
merged 11 commits into from
Dec 21, 2022
Merged

Conversation

jerhard
Copy link
Member

@jerhard jerhard commented Dec 19, 2022

This PR targets issue #949. This PR changes the behavior of reluctant incremental analysis for in case the abstract value of a reluctantly analyzed unknown x changed.

The sets infl x from the previous analysis and the set infl x after the call to solve x by the reluctant analysis are joined before calling destabilize x. Unlike previously, this does not add x to the stable set after the call to destabilize.

@jerhard jerhard changed the title Issue 949 Fix Unreached Fixpoint in Reluctant Incremental Analysis Dec 19, 2022
@jerhard jerhard marked this pull request as draft December 19, 2022 22:25
@jerhard
Copy link
Member Author

jerhard commented Dec 19, 2022

Looking at the old and new infl ret_{foo} (ret_{foo} referring to the unknown at the return node of foo) sets occurring in the reluctant reanalyis of the test case in #949, in turns out that the sets are disjunct: the new set only records the new influence to the newly reachable bar function that calls foo. This is strange, since the infl ret_{foo} set should only grow during a call solve ret_{foo}, since the unknown is in called, and therefore should not be destabilized, and therefore its infl set should not be reset.

It is also not quite clear to me yet why the test case fails when adding the unknown (in this case ret_{foo}) back to the stable set, after destabilizing it.

@jerhard jerhard marked this pull request as ready for review December 21, 2022 14:48
@jerhard jerhard merged commit fc0d171 into master Dec 21, 2022
@jerhard jerhard deleted the issue_949 branch December 21, 2022 14:49
@sim642 sim642 added this to the v2.2.0 milestone Apr 5, 2023
sim642 added a commit to sim642/opam-repository that referenced this pull request Sep 13, 2023
CHANGES:

* Add `setjmp`/`longjmp` analysis (goblint/analyzer#887, goblint/analyzer#970, goblint/analyzer#1015, goblint/analyzer#1019).
* Refactor race analysis to lazy distribution (goblint/analyzer#1084, goblint/analyzer#1089, goblint/analyzer#1136, goblint/analyzer#1016).
* Add thread-unsafe library function call analysis (goblint/analyzer#723, goblint/analyzer#1082).
* Add mutex type analysis and mutex API analysis (goblint/analyzer#800, goblint/analyzer#839, goblint/analyzer#1073).
* Add interval set domain and string literals domain (goblint/analyzer#901, goblint/analyzer#966, goblint/analyzer#994, goblint/analyzer#1048).
* Add affine equalities analysis (goblint/analyzer#592).
* Add use-after-free analysis (goblint/analyzer#1050, goblint/analyzer#1114).
* Add dead code elimination transformation (goblint/analyzer#850, goblint/analyzer#979).
* Add taint analysis for partial contexts (goblint/analyzer#553, goblint/analyzer#952).
* Add YAML witness validation via unassume (goblint/analyzer#796, goblint/analyzer#977, goblint/analyzer#1044, goblint/analyzer#1045, goblint/analyzer#1124).
* Add incremental analysis rename detection (goblint/analyzer#774, goblint/analyzer#777).
* Fix address sets unsoundness (goblint/analyzer#822, goblint/analyzer#967, goblint/analyzer#564, goblint/analyzer#1032, goblint/analyzer#998, goblint/analyzer#1031).
* Fix thread escape analysis unsoundness (goblint/analyzer#939, goblint/analyzer#984, goblint/analyzer#1074, goblint/analyzer#1078).
* Fix many incremental analysis issues (goblint/analyzer#627, goblint/analyzer#836, goblint/analyzer#835, goblint/analyzer#841, goblint/analyzer#932, goblint/analyzer#678, goblint/analyzer#942, goblint/analyzer#949, goblint/analyzer#950, goblint/analyzer#957, goblint/analyzer#955, goblint/analyzer#954, goblint/analyzer#960, goblint/analyzer#959, goblint/analyzer#1004, goblint/analyzer#558, goblint/analyzer#1010, goblint/analyzer#1091).
* Fix server mode for abstract debugging (goblint/analyzer#983, goblint/analyzer#990, goblint/analyzer#997, goblint/analyzer#1000, goblint/analyzer#1001, goblint/analyzer#1013, goblint/analyzer#1018, goblint/analyzer#1017, goblint/analyzer#1026, goblint/analyzer#1027).
* Add documentation for configuration JSON schema and OCaml API (goblint/analyzer#999, goblint/analyzer#1054, goblint/analyzer#1055, goblint/analyzer#1053).
* Add many library function specifications (goblint/analyzer#962, goblint/analyzer#996, goblint/analyzer#1028, goblint/analyzer#1079, goblint/analyzer#1121, goblint/analyzer#1135, goblint/analyzer#1138).
* Add OCaml 5.0 support (goblint/analyzer#1003, goblint/analyzer#945, goblint/analyzer#1162).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Reluctant incremental analysis does not reach fixpoint and is unsound in some cases
4 participants