An object-sensitive pointer analysis method and device for generic programming
By mapping type variables to instantiation positions in generic programming code and performing pointer analysis in combination with context, the analysis accuracy problem of generic programming code is solved, and the accuracy of pointer analysis is improved.
Patent Information
- Application Number
- CN202210893348.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-27
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2042-07-27
AI Technical Summary
The lack of pointer analysis methods for generic programming in the prior art has led to poor analysis of generic programming codes.
It provides an object-sensitive pointer analysis method and device for generic programming. By obtaining type variables in generic programming statements and mapping them to instantiated positions, and performing pointer analysis in combination with context to improve analysis accuracy.
High accuracy analysis of pointer relationships in generic programming code is achieved by determining the instantiation location of type variables in generic programming code and mapping them to context.
Smart Images

Figure CN115658457B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of software testing, and in particular, to a pointer analysis method and device for generic programming. Background Art
[0002] Program Static Analysis refers to a code analysis technique that scans program code through techniques such as lexical analysis, syntax analysis, control flow, and data flow analysis without running the code, and verifies whether the code meets indicators such as normativity, security, reliability, and maintainability.
[0003] Pointer analysis is a type of program static analysis that answers the question of which memory a pointer in a program points to. On the one hand, taking the Java language as an example, pointer analysis in the Java language refers to the question of which object in the program a pointer points to. Usually, pointer analysis is a possibility analysis, and the result of the analysis is usually which objects a pointer may point to. On the other hand, generic programming has been widely adopted in modern programming methods. Using generics allows using type variables as parameters to define classes and methods, and then instantiating these classes or methods by assigning them specific actual types.
[0004] However, there is no pointer analysis method for generic programming in the prior art, resulting in poor analysis effects of conventional pointer analysis methods on the code obtained from generic programming. Summary of the Invention
[0005] This application provides an object-sensitive pointer analysis method, device, computer device, and storage medium for generic programming, which improves the accuracy of context-sensitive pointer analysis for generic programming. The technical solution is as follows.
[0006] On the one hand, an object-sensitive pointer analysis method for generic programming is provided. The method includes:
[0007] Obtain the target program code to be analyzed;
[0008] According to the type variables in the generic programming statements in the target program code, map the type variables to the instantiation positions, and put the mapping between the type variables and the instantiation positions into the context of the generic programming statements;
[0009] Based on the context of the generic programming statements, perform context-sensitive pointer analysis on the target program code to obtain the pointing relationships between the pointers in the target program code.
[0010] On the other hand, an object-sensitive pointer analysis device for generic programming is provided. The device includes:
[0011] A program code acquisition module, configured to acquire a target program code to be analyzed;
[0012] A variable mapping module, configured to map a type variable to an instantiation position in a generic programming statement in the target program code, and put the mapping between the type variable and the instantiation position into the context of the generic programming statement;
[0013] A pointer analysis module, configured to perform context-sensitive pointer analysis on the target program code based on the context of the generic programming statement to obtain the pointing relationship between each pointer in the target program code.
[0014] In a possible implementation manner, the variable mapping module is configured to map the type variable to an instantiation position in a generic programming statement in the target program code according to the type of the generic programming statement.
[0015] In a possible implementation manner, the variable mapping module includes:
[0016] A first mapping unit, configured to, when the type of the generic programming statement is a NEW statement, process the type variable in the generic programming statement in the target program code according to an object update function to map the type variable to the instantiation position;
[0017] The object update function is configured to map the type variable according to the instantiation type in the NEW statement to determine the instantiation position of the type variable.
[0018] In a possible implementation manner, the first mapping unit is configured to, when detecting that an object is instantiated with a type variable in the NEW statement, find the initialization point of the mapping of the type variable and determine the initialization point as the instantiation position of the type variable.
[0019] In a possible implementation manner, the variable mapping module further includes:
[0020] A second mapping unit, configured to, when the type of the generic programming statement is a CALL statement, process the type variable in the generic programming statement in the target program code according to an object append function to map the type variable to the instantiation position;
[0021] The object append function is configured to map the type variable according to the call type in the CALL statement to determine the instantiation position of the type variable.
[0022] In a possible implementation, the variable mapping module is configured to, when the call type in the CALL statement is a generic call of a specific type, determine the mapping relationship between the type variable and the call object in the CALL statement as the mapping relationship between the type variable and the instantiation location.
[0023] In a possible implementation, the variable mapping module is configured to, when the call type in the CALL statement is a generic call of a type variable, determine the mapping relationship between the type variable and the actual instantiation site as the mapping relationship between the type variable and the instantiation location;
[0024] The actual instantiation site includes the receiving object of the target method in the CALL statement and the method invoker of the target method.
[0025] In another aspect, a computer device is provided. The computer device includes a processor and a memory. At least one instruction is stored in the memory, and the at least one instruction is loaded and executed by the processor to implement the above-mentioned object-sensitive pointer analysis method for generic programming.
[0026] In yet another aspect, a computer-readable storage medium is provided. At least one instruction is stored in the storage medium, and the at least one instruction is loaded and executed by a processor to implement the above-mentioned object-sensitive pointer analysis method for generic programming.
[0027] In yet another aspect, a computer program product or a computer program is provided. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the above-mentioned object-sensitive pointer analysis method for generic programming.
[0028] The technical solution provided by this application may include the following beneficial effects:
[0029] When performing pointer analysis on the target program code obtained through generic programming, the type variables in the generic programming statements in the target program code can be obtained first, so as to determine the instantiation positions corresponding to the type variables. Then, the mapping relationship between the type variables and the instantiation positions is put into the context corresponding to the generic programming statements, and then context-sensitive pointer analysis is performed to obtain the pointing relationships between the pointers in the target program code. In the above solution for the target program code obtained through generic programming, by first analyzing the type variables in the generic programming statements to obtain the generic instantiation positions, and the positions where the generics are instantiated with specific types are key context elements. Therefore, the mapping relationship between the generic instantiation positions and the type variables is put into the context for context-sensitive pointer analysis to obtain the pointing relationships between the pointers, improving the accuracy of context-sensitive pointer analysis for generic programming. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] In order to more clearly illustrate the specific embodiments of the present application or the technical solutions in the prior art, the following will briefly introduce the drawings required for the description of the specific embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0031] Figure 1 FIG. is a schematic structural diagram of a software analysis system shown according to an exemplary embodiment.
[0032] Figure 2 FIG. shows a schematic diagram of software program code.
[0033] Figure 3 FIG. shows a schematic diagram of generic programming code.
[0034] Figure 4 FIG. is a flowchart of an object-sensitive pointer analysis method for generic programming shown according to an exemplary embodiment.
[0035] Figure 5 FIG. is a flowchart of an object-sensitive pointer analysis method for generic programming shown according to an exemplary embodiment.
[0036] Figure 6 FIG. shows a schematic diagram of explicit type and missing type instantiation.
[0037] Figure 7 FIG. shows a schematic diagram of labeled statements of five types.
[0038] Figure 8 FIG. is a schematic block diagram of a structure of an object-sensitive pointer analysis device for generic programming shown according to an exemplary embodiment.
[0039] Figure 9 The block diagram of a computer device shown in an exemplary embodiment of the present application is illustrated. Detailed implementation manners
[0040] The technical solutions of the present application will be clearly and completely described below with reference to the accompanying drawings. Apparently, the described embodiments are some but not all of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.
[0041] It should be understood that the "indication" mentioned in the embodiments of the present application can be a direct indication, an indirect indication, or a representation of an associated relationship. For example, A indicates B, which can mean that A directly indicates B, for example, B can be obtained through A; it can also mean that A indirectly indicates B, for example, A indicates C, and B can be obtained through C; it can also mean that there is an associated relationship between A and B.
[0042] In the description of the embodiments of the present application, the term "corresponding" can represent a direct or indirect corresponding relationship between two parties, can also represent an associated relationship between two parties, or can be a relationship such as indication and being indicated, configuration and being configured, etc.
[0043] In the embodiments of the present application, "predefined" can be implemented by pre-saving corresponding codes, tables or other means that can be used to indicate relevant information in a device (for example, including a terminal device and a network device). The present application does not limit its specific implementation manner.
[0044] To facilitate the understanding of the present application, before describing the various embodiments shown in the present application, several concepts related to the present application will be introduced first.
[0045] 1) Program Static Analysis
[0046] Program Static Analysis refers to a code analysis technique that scans program code through techniques such as lexical analysis, syntax analysis, control flow, and data flow analysis without running the code, and verifies whether the code meets indicators such as normativity, security, reliability, and maintainability. Static analysis techniques are developing towards techniques of simulated execution to be able to discover more defects that can only be discovered by traditional dynamic testing, such as symbolic execution, abstract interpretation, value dependence analysis, etc., and use mathematical constraint solving tools for path reduction or reachability analysis to reduce false positives and increase efficiency.
[0047] 2) Pointer analysis
[0048] Pointer analysis is a difficult point in static analysis. For any pointer / reference, can we know at the compilation stage which memory location it will point to (the location here is not a specific location like 0xFFFF, but which local / object on the stack / heap it points to)? However, the pointer problem is undecidable, that is, it is impossible to accurately analyze which exact location any pointer will point to. But this does not prevent finding approximate solutions, so that optimizations can be carried out in some cases. Therefore, pointer analysis is to statically calculate the possible runtime values (abstract memory addresses) that pointer variables in a program may point to.
[0049] Context-sensitive pointer analysis has different values that pointer variables point to in different call contexts, thus effectively reducing false positives introduced by infeasible interprocedural control flow paths and greatly improving accuracy. Generally speaking, a context is represented by a sequence of k context elements, where the context elements can be call sites (k-call-site-sensitive), initialization points of the receiving object (k-object-sensitive), or types of the receiving object (k-type-sensitive). For object-oriented programs, in terms of accuracy and efficiency in practice, object sensitivity is considered superior to call-site sensitivity, and type sensitivity is regarded as a more efficient but less accurate alternative to object sensitivity.
[0050] 3) Generic programming
[0051] Generic programming means that it can operate on multiple data types. Different from object-oriented programming, it does not require an additional indirection layer to call functions, but uses completely generalized and reusable algorithms, and the algorithm efficiency is the same as that of algorithms designed for a specific data type. Generic programming has been widely adopted and applied in modern programming languages, including C++, Java, C#, etc.
[0052] Figure 1 It is a schematic structural diagram of a software analysis system shown according to an exemplary embodiment. As Figure 1 shown, the software analysis system includes a computer device 110 and a server 120, and the computer device and the server 120 can be communicatively connected through a wired or wireless network.
[0053] Optionally, the computer device 110 can be a terminal device, that is, a developer can input corresponding software program code in the computer device 110, and the computer device 110 can send the software program code to the server 120 so that the server 120 can perform context-sensitive pointer analysis on the software program code.
[0054] Optionally, the above software program code is software program code for generic programming.
[0055] Alternatively, various software programs for generic programming are pre-stored in the computer device 110. When a developer needs to perform pointer analysis on any one of the above software programs, the computer device can send the software program to the server 120 so that the server 120 can perform context-sensitive pointer analysis based on generic programming on any one of the software programs.
[0056] Optionally, the above server can be a server cluster or a distributed system composed of multiple physical servers, or can also be a cloud server providing technical cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms.
[0057] Optionally, the system can further include a management device for managing the system (such as managing the connection status between each module and the server), and the management device is connected to the server through a communication network. Optionally, the communication network is a wired network or a wireless network.
[0058] Optionally, the above wireless network or wired network uses standard communication technologies and / or protocols. The network is usually the Internet, but can also be any other network, including but not limited to any combination of local area networks, metropolitan area networks, wide area networks, mobile, limited or wireless networks, private networks or virtual private networks. In some embodiments, technologies and / or formats including Hypertext Markup Language, Extensible Markup Language, etc. are used to represent data exchanged through the network. In addition, conventional encryption technologies such as Secure Sockets Layer, Transport Layer Security, Virtual Private Network, Internet Protocol Security, etc. can be used to encrypt all or some of the links. In other embodiments, customized and / or dedicated data communication technologies can also be used to replace or supplement the above data communication technologies.
[0059] The pointer analysis calculates the pointing set of program variables, that is, the set of abstract addresses that can be pointed to by variable v, and the set of abstract addresses is represented as pts(v). Generally, the abstract address is represented as an initialization point (the instruction that initializes an object, for example, new in Java), representing all dynamic object instances initialized by the instruction at runtime. In context-sensitive analysis, both variable v and abstract address o have context qualifiers, so as to effectively distinguish their different dynamic instances. Therefore, different from calculating whether o ∈ pts(v) in context-insensitive analysis, context-sensitive analysis calculates the relationship (co, o) ∈ pts(cv, v), where co and cv are the contexts of abstract address o and variable v respectively.
[0060] Call-site sensitivity, object sensitivity, and type sensitivity are the three main variants of context sensitivity, where the call site, the initialization point of the receiving object, and the type of the receiving object are considered context elements respectively. To ensure termination, k-limiting is applied to limit the number of context elements to k. In practice, for scalability, k is usually set to be less than 2.
[0061] Among the above three variants, object sensitivity and type sensitivity (as a less costly alternative) are considered more suitable for analyzing object-oriented programs. Specifically, object sensitivity is more accurate and efficient than call-site sensitivity and is considered the most accurate context-sensitive variant for analyzing Java programs. In k-object sensitivity, the object o0 is cloned multiple times, and each object has a different context of length k - 1, called the heap context. The heap context has the form [o k-1 ,..., o1], where o i (1 < i < k - 1) is the initialization point of o i-1 , that is, o i-1 is initialized in the method with o i as the receiving object. Therefore, the method o0.m (where o0 is the receiving object) will be analyzed multiple times: for each different heap context c0, the method is analyzed once under the method context [o0, c0].
[0062] Please refer to Figure 2 , which shows a schematic diagram of software program code. As Figure 2 shown, the example uses the generic class java.util.HashMap. Thereafter, we only discuss two mainstream context-sensitive variants of object-oriented programs: object sensitivity and type sensitivity.
[0063] In the main method, there are two HashMap objects: O1 (line 2) and O2 (line 7). The object O A is created in line 3 and put into O1, and then retrieved in line 4 through the get method. Similarly, the object O B is created in line 8 and put into O2, and then retrieved in line 9. As a result, the two cast operations (lines 5 and 10) will never fail.
[0064] A simplified code snippet of HashMap is given in lines 13 - 38. HashMap stores data in a table, which is an array of Node objects (line 15). The put method creates a Node object and stores it in the table (lines 16 - 19). The get method retrieves the corresponding Node object from the table and then returns its value through the getValue interface (lines 20 - 23). Note that the Node class (lines 24 - 38) is implemented as an inner generic class and is instantiated with the type variables of its outer class HashMap (i.e., K and V) when creating a Node object.
[0065] For object sensitivity, in 1 - object - sensitive analysis (abbreviated as 1 - obj), the receiving objects of the put / get methods called in lines 3 / 4 and 8 / 9 are O1 and O2 respectively. Therefore, the contexts [O1] and [O2] can be used to distinguish the calls to the put / get methods at different call sites. In put (line 17), through 1 - obj analysis, we get pts(O1, n) = {O4} and pts(O2, n) = O4. Then in the constructor of Node (lines 27 - 30), since O4 is the only receiving object, we get pts (O4, key) = {"A", "B"} and pts(O4, value) = {O A , O B}. Thus, calling O1.get and O2.get will return values pointing to O A and O B , resulting in false alarms of cast - may - fail at lines 5 and 10.
[0066] This example can be accurately analyzed only when the context depth is set to be greater than 2. In put (line 17), through 2 - obj analysis, we get pts(O1, n) = {(O1, O4)} and pts(O2, n) = {(O2, O4)}, where the object O4 is qualified by the heap context. Therefore, the constructor of class Node (lines 27 - 30) is analyzed twice using 2 different contexts: [O1, O4] and [O2, O4]. Thus, we can accurately calculate the pointer values of key and value: pts([O1, O4], key) = {"A"}, pts([O2, O4], key) = {"B"}, pts([O1, O4], value) = {O A}, and pts([O1, O4], value) = {O B}. Finally, we can correctly analyze that pts(v1) = O A and pts(v2) = OB , thus avoiding cast-may-fail false positives.
[0067] Please refer to Figure 3 , which shows a schematic diagram of generic programming code. As Figure 3 shown, for generics, the key to ensuring precision is to retain the instantiation location as part of the context, i.e., the location where the generic type parameter is instantiated with a concrete type. Thus, different pointer values flowing in / out of generic methods and generic objects can be effectively identified. In Figure 3 the example of A}, and pts(O1, value) = {O B}.
[0068] For Figure 3 the example in Figure 3 shown, the omit-generics scheme can work effectively by simply omitting all call contexts in the generic class. However, this scheme is not effective for generic methods. As
[0069] shown in the solution of this application, by using the generic instantiation location to actualize the context, the propagation of type variables is accurately tracked, and these instantiation locations are efficiently updated in a context-sensitive manner during the analysis process. Figure 4 is a flowchart of an object-sensitive pointer analysis method for generic programming shown according to an exemplary embodiment. This method is executed by a computer device, which can be a server in a software analysis system such as Figure 1 shown in Figure 4As shown, the object-sensitive pointer analysis method for generic programming may include the following steps:
[0070] Step 401: Obtain the target program code to be analyzed.
[0071] When pointer analysis needs to be performed on a computer program, the computer device can obtain the target program code corresponding to the computer program. And in the embodiments of this application, the computer program is obtained through generic programming, that is to say, the target program code is the program code obtained through generic programming.
[0072] Step 402: In the generic programming statements in the target program code, map the type variables to the instantiation positions, and put the mapping between the type variables and the instantiation positions into the context of the generic programming statements.
[0073] Since the target program code is obtained through generic programming, there are various types of generic programming statements in the target program code. And because in generic programming, type variables are directly used as parameters to define classes and methods in generic programming statements, when performing context-sensitive pointer analysis on generic programming statements, the positions where specific types instantiate generics should also be key context elements. At this time, putting the mapping relationship between type variables and instantiation positions into the context elements of the corresponding generic programming statements enhances the context information and improves the completeness of the context information.
[0074] Step 403: Based on the context of the generic programming statements, perform context-sensitive pointer analysis on the target program code to obtain the pointing relationships between the pointers in the target program code.
[0075] When the mapping relationship between type variables and instantiation positions is added to the context corresponding to the generic programming statements, the pointing relationships between the pointers in the target program code can be obtained through the context of the generic programming statements by means of context-sensitive pointer analysis, so as to statically calculate the possible running values pointed to by the pointer variables in the program.
[0076] In summary, when performing pointer analysis on the target program code obtained through generic programming, the type variables in the generic programming statements in the target program code can be obtained first, so as to determine the instantiation positions corresponding to the type variables. Then, the mapping relationship between the type variables and the instantiation positions is put into the context corresponding to the generic programming statements, and then context-sensitive pointer analysis is performed to obtain the pointing relationships between the various pointers in the target program code. In the target program code obtained through generic programming, the above solution first analyzes the type variables in the generic programming statements to obtain the generic instantiation positions, and the positions where the generics are instantiated with specific types are key context elements. Therefore, the mapping relationship between the generic instantiation positions and the type variables is put into the context for context-sensitive pointer analysis to obtain the pointing relationships between the various pointers, improving the accuracy of context-sensitive pointer analysis for generic programming.
[0077] Figure 5 is a flowchart of an object-sensitive pointer analysis method for generic programming shown according to an exemplary embodiment. This method is executed by a computer device, and the computer device can be a server in a software analysis system such as Figure 1 as shown. Figure 5 As shown, the object-sensitive pointer analysis method for generic programming may include the following steps:
[0078] Step 501, obtain the target program code to be analyzed.
[0079] In traditional context-sensitive pointer analysis, the context c is extended to a tuple <c, G>, where G records the instantiation points of all available type variables. For non-generic-related methods, G is θ. The size of G is limited by the number of available type variables.
[0080] In Java, developers can use explicit types ( Figure 6 (a)) or not provide any actual type parameters to instantiate generic classes. In the latter case, the omission is to instantiate the generic class with the type Object. For example, in Figure 6 (b), s is of type HashSet at line 3 <object>Created. At line 5, an object of type A is first created and implicitly cast to Object, and then it is put into s.
[0081] Step 502, in the generic programming statement in the target program code, according to the type of the generic programming statement, map the type variable to the instantiation position, and put the mapping between the type variable and the instantiation position into the context of the generic programming statement.
[0082] In the embodiment of the present application, it is necessary to infer the type parameter (that is, the type variable). In the target program code of the embodiment of the present application, if the generic object O of the generic class instantiated with the type formal parameter T has not escaped its scope, and all its uses of T can be resolved to the type C, C can be safely regarded as the type actual parameter for instantiating T.
[0083] As in Figure 6 (b), if s is not returned (that is, it has not escaped the scope foo where it is declared), then we can infer that s instantiates HashSet with the type A, that is, s has the type HashSet 。
[0084] Finally, if the type actual arguments for instantiating a generic class cannot be resolved, we use the instantiation location as a pseudo type. In the example Figure 6 (b), introduce a pseudo-type T3 to instantiate s, that is, in our analysis, the statement on line 3 is regarded as Set <t3>s = new HashSet(); Thus, we effectively apply object sensitivity when analyzing generics because each instantiation site is considered a different type.
[0085] Without loss of generality, we consider a simplified subset of Java with Figure 7 five types of labeled statements. We write "x = new C<T:A>" for object allocation. If C is a generic class, then T is its type formal parameter and A is the type actual parameter that instantiates T. Otherwise, both T and A are Nil. Similarly, the generic method call "x = v0.m'<T:A>(v1)" instantiates its type formal parameter T with type actual parameter A. For non-generic method calls, both T and A are Nil. For simplicity, our formalization only considers NEW and CALL statements with a single type parameter. The general form of NEW and CALL statements with multiple parameters can be analyzed in the same way.
[0086] The statement "x = new C(...)" in Java is modeled as "x = new C; x. <init>(...)", where <init>() is the corresponding constructor called. Control flow statements are not important for context-insensitive flow analysis and are thus skipped. Accesses to array elements are modeled by folding all elements into a special field of the array. Additionally, it is assumed that each method returns via a variable ret. Since we formalize method calls with only one argument, each method also has only one formal parameter p.
[0087] In one possible implementation, when the type of the generic programming statement is a NEW statement, the type variables in the generic programming statement in the target program code are processed according to the object update function to map the type variables to the instantiation location.
[0088] The object update function is used to map the type variables according to the instantiation type in the NEW statement to determine the instantiation location of the type variables.
[0089] In one possible implementation, when it is detected that an object is instantiated with a type variable in a NEW statement, the initialization point of the mapping of the type variable is found and the initialization point is determined as the instantiation location of the type variable.
[0090] Assume a program, and let M, F, H, V, L, T be the sets of its methods, fields, initialization points, local variables, statement labels, and types respectively. We use the symbol C to represent the context. The following auxiliary functions are used in our rules:
[0091] · methodOf:
[0092] · methodCtx:
[0093] · dispatch:
[0094] · pts:
[0095] · typeOf:
[0096] Among them, methodOf gives the containing method of the statement, methodCtx maintains the context for method analysis, dispatch parses the call to the target method, pts records the context-sensitive pointing information of variables or fields, and typeOf returns the variable of the declared type.
[0097] Assume a list of context elements c = [e1,..., en] and a context element e. We use the symbol e++c to denote [e, e1,..., en] and ck to denote [e1,..., ek], where k < n.
[0098] In the object-sensitive scheme shown in the embodiments of the present application, let That is, map the type variable T ∈ T to the allocation point O l ∈ H (identified by the label l). The extended context C = H* × G. The object update function we define is as follows:
[0099]
[0100] Where the function G(A) looks up the initialization point of the mapping of the type variable A.
[0101] When the type of the generic programming statement is the NEW type, the following rules can be used to perform object-sensitive analysis on the generic programming statement:
[0102] l:x = newC <t:a>m = methodOf(l)
[0103] ctx = <c:g>∈methodCtx(m)
[0104]
[0105] In the NEW statement, O l ∈H is an abstract heap object created by the initialization point at l, identified by its heap context ctx. Given the method context ctx = <c, G>, the heap context of O l is constructed as <[c]k-1, G′>, where, as in the standard k-obj analysis, [c] k-1 selects the first k - 1 context elements by c and G′ is updated by the Update function (i.e., the object update function) as follows.
[0106] If O l is a non-generic object, i.e., the type formal parameter T is Nil, then G′ is set to Therefore, analyzing a method call with a non-generic object as its receiving object is the same as in the standard object-sensitive analysis.
[0107] If it is instantiated with a concrete type, i.e., then G′ is set to l . Therefore, the instantiation location l is regarded as part of the context when analyzing a method call with O l as the receiving object.
[0108] Finally, if it is instantiated with a type variable, i.e., T ≠ Nil ∧ A ∈ G, then we determine the actual instantiation location of A by looking up the context containing the method at l. G′ is updated to l , thus forcing the actual generic instantiation location to always be part of this context.
[0109] In a possible implementation, when the generic programming statement type is a CALL statement, according to the object append function, the type variables in the generic programming statement in the target program code are processed to map the type variables to the instantiation locations;
[0110] The object append function is used to map the type variables according to the call type in the CALL statement to determine the instantiation locations of the type variables.
[0111] In the embodiments of the present application, the object append function can be as follows:
[0112]
[0113] In the Append function, if f is a non-generic call, i.e., T ≡ Nil, then G remains unchanged.
[0114] If f is a generic call instantiated with a concrete type, i.e., then G′ is updated by adding a new mapping to G.
[0115] If f is a generic call instantiated with a type variable, i.e., then G′ is updated by introducing the following mapping into G: from T to its actual instantiation site Note that the available type variables can be propagated from the receiving object (in this case A ∈ G) or from the invoker method (in this case A ∈ Gm).
[0116] In one possible implementation, when the call type in the CALL statement is a generic call with a concrete type, the mapping relationship between the type variable and the call object in the CALL statement is determined as the mapping relationship between the type variable and the instantiation location.
[0117] In one possible implementation, when the call type in the CALL statement is a generic call with a type variable, the mapping relationship between the type variable and the actual instantiation site is determined as the mapping relationship between the type variable and the instantiation location;
[0118] The actual instantiation site includes the receiving object of the target method in the CALL statement and the method invoker of the target method.
[0119] When the generic programming statement type is CALL type, the following rules can be used for object-sensitive analysis of the generic programming statement:
[0120] l: x = a0.f<T: A>(a1) m = mehtodOf(l)
[0121] ctx = <c m : G m > ∈ mehtodCtx(m)
[0122] (O o , hctx) ∈ pts(a o , ctx) (O1, -) ∈ pts(a1, ctx)
[0123] hctx = <c: G> G′ = Append(G, G l , T, A, O l )
[0124]
[0125]
[0126]
[0127] In the [CALL] statement, the call to the instance method x = a0.f<T:A> is analyzed. Let m' be the target method, and we write tis for the "this" variable parameter m′ , p m′ , ret m′ and are respectively the formal parameters and return value of m'. Let O0 be the receiving object of the method call and the heap context ctx = <c, G>, and let ctx = <cm, Gm> be the context of m. Similar to [NEW], when analyzing m', the context ctx' = <O0++c, G'> is constructed, where O0++c appends the heap context of O0 to the receiving object O0 in a standard way. In the conclusion of the rule, ctx' ∈ methodCtx(m') shows how to introduce the context of the method.
[0128] Revisit the example in Figure 3 at this time. A generic object O1 is created in line 2. Therefore, ∈ pts(g, <<[], >)(NEW statement). The generic method foo is called in line 4 <e>, where O1 is the receiving object and O2 is the actual parameter, i.e., g.foo<E:B>(b). Therefore, we use the updated context <[O1], >(CALL statement) to analyze the target method foo. In foo, the object created at line 8 (O3) is instantiated using the type variable T. Therefore, it has the updated heap context <[O1], Similarly, O4 at line 10 has the heap context <[O1], Then, the two method calls at lines 9 and 10 are analyzed using different contexts. In summary, G always maps the available type variables to their actual instantiation locations to encode the actual instantiation locations of generics as part of the context.
[0129] Step 503, based on the context of the generic programming statement, perform context-sensitive pointer analysis on the target program code to obtain the pointing relationships between the various pointers in the target program code.
[0130] After mapping the type variables in the NEW statement and the CALL statement through the context-sensitive pointer analysis rules corresponding to the NEW statement and the CALL statement, the obtained mapping relationships can be added to the context of the generic programming statement (i.e., the NEW statement and the CALL statement). And through the context-sensitive pointer analysis rules corresponding to the NEW statement and the CALL statement, the pointing relationships between the pointers can also be analyzed based on the updated context.
[0131] As Figure 6 shown, in JAVA generic programming, in addition to the NEW statement and the CALL statement, context-sensitive pointer analysis can also be performed on the ASSIGN statement, the LOAD statement, and the STORE statement through the following rules:
[0132]
[0133] l: x = y.f m = methodOf(l)
[0134]
[0135] l: x.f = y m = methodOf(l)
[0136]
[0137] And since the context-sensitive pointer analysis of the above statements is similar to the analysis method of the existing object-sensitive pointer analysis, it will not be elaborated here.
[0138] That is to say, in the solution shown in the embodiments of the present application, for the generic programming statements (i.e., CALL statements and NEW statements) involving type variables in generic programming, specific context-sensitive pointer analysis rules are set, and the correspondence between the type variables and the instantiation positions in the CALL statements and NEW statements is used to augment the context of the CALL statements and NEW statements, thereby improving the analysis accuracy of generic programming.
[0139] In summary, when performing pointer analysis on the target program code obtained from generic programming, the type variables in the generic programming statements in the target program code can be first obtained to determine the instantiation positions corresponding to the type variables, and then the mapping relationship between the type variables and the instantiation positions is placed into the context corresponding to the generic programming statements, and then context-sensitive pointer analysis is performed to obtain the pointing relationships between the various pointers in the target program code. In the above solution, in the target program code obtained from generic programming, by first analyzing the type variables in the generic programming statements, the generic instantiation positions are obtained, and the positions where the generics are instantiated with specific types are key context elements. Therefore, the mapping relationship between the generic instantiation positions and the type variables is placed into the context for context-sensitive pointer analysis to obtain the pointing relationships between the various pointers, improving the accuracy of context-sensitive pointer analysis for generic programming.
[0140] Figure 8 It is a structural block diagram of an object-sensitive pointer analysis device for generic programming shown according to an exemplary embodiment. The device includes:
[0141] A program code acquisition module 801, configured to acquire the target program code to be analyzed;
[0142] A variable mapping module 802, configured to map type variables to instantiation positions in the generic programming statements in the target program code, and place the mapping of the type variables and the instantiation positions into the context of the generic programming statements;
[0143] A pointer analysis module 803, configured to perform context-sensitive pointer analysis on the target program code based on the context of the generic programming statements to obtain the pointing relationships between the various pointers in the target program code.
[0144] In a possible implementation manner, the variable mapping module is configured to map the type variables to instantiation positions according to the type of the generic programming statements in the target program code.
[0145] In a possible implementation manner, the variable mapping module includes:
[0146] A first mapping unit, configured to, when the generic programming statement type is a NEW statement, process type variables in the generic programming statement in the target program code according to an object update function, so as to map the type variables to the instantiation positions;
[0147] The object update function is configured to map the type variables according to the instantiation types in the NEW statement, so as to determine the instantiation positions of the type variables.
[0148] In a possible implementation, the first mapping unit is configured to, when it is detected that an object is instantiated with a type variable in a NEW statement, find an initialization point of the mapping of the type variable, and determine the initialization point as the instantiation position of the type variable.
[0149] In a possible implementation, the variable mapping module further includes:
[0150] A second mapping unit, configured to, when the generic programming statement type is a CALL statement, process type variables in the generic programming statement in the target program code according to an object append function, so as to map the type variables to instantiation positions;
[0151] The object append function is configured to map the type variables according to the call types in the CALL statement, so as to determine the instantiation positions of the type variables.
[0152] In a possible implementation, the variable mapping module is configured to, when the call type in the CALL statement is a generic call of a specific type, determine the mapping relationship between the type variable and the call object in the CALL statement as the mapping relationship between the type variable and the instantiation position.
[0153] In a possible implementation, the variable mapping module is configured to, when the call type in the CALL statement is a generic call of a type variable, determine the mapping relationship between the type variable and the actual instantiation site as the mapping relationship between the type variable and the instantiation position;
[0154] The actual instantiation site includes a receiving object of a target method in the CALL statement and a method invoker of the target method.
[0155] In summary, when performing pointer analysis on the target program code obtained through generic programming, the type variables in the generic programming statements in the target program code can be obtained first, so as to determine the instantiation positions corresponding to the type variables. Then, the mapping relationship between the type variables and the instantiation positions is placed into the context corresponding to the generic programming statements, and then context-sensitive pointer analysis is performed to obtain the pointing relationships between the various pointers in the target program code. In the target program code obtained through generic programming, the above solution first analyzes the type variables in the generic programming statements to obtain the generic instantiation positions, and the positions where the generics are instantiated with specific types are key context elements. Therefore, the mapping relationship between the generic instantiation positions and the type variables is placed into the context for context-sensitive pointer analysis to obtain the pointing relationships between the various pointers, improving the accuracy of context-sensitive pointer analysis for generic programming.
[0156] Figure 9 FIG. shows a block diagram of a computer device 900 according to an exemplary embodiment of the present application. The computer device may be implemented as the server in the above solution of the present application. The computer device 900 includes a central processing unit (CPU) 901, a system memory 904 including a random access memory (RAM) 902 and a read-only memory (ROM) 903, and a system bus 905 connecting the system memory 904 and the central processing unit 901. The computer device 900 also includes a mass storage device 906 for storing an operating system 909, application programs 910, and other program modules 911.
[0157] The mass storage device 906 is connected to the central processing unit 901 through a mass storage controller (not shown) connected to the system bus 905. The mass storage device 906 and its associated computer-readable medium provide non-volatile storage for the computer device 900. That is to say, the mass storage device 906 may include a computer-readable medium (not shown) such as a hard disk or a compact disc read-only memory (CD-ROM) drive.
[0158] Without loss of generality, the computer-readable medium may include a computer storage medium and a communication medium. The computer storage medium includes volatile and non-volatile, removable and non-removable media implemented by any method or technology for storing information such as computer-readable instructions, data structures, program modules, or other data. The computer storage medium includes RAM, ROM, erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other solid-state storage technologies, CD-ROM, digital versatile disc (DVD) or other optical storage, magnetic tape cartridges, tapes, magnetic disk storage or other magnetic storage devices. Of course, those skilled in the art will know that the computer storage medium is not limited to the above several types. The above system memory 904 and mass storage device 906 can be collectively referred to as memory.
[0159] According to various embodiments of the present disclosure, the computer device 900 may also run on a remote computer on the network connected through a network such as the Internet. That is, the computer device 900 may be connected to the network 908 through the network interface unit 907 connected to the system bus 905, or rather, the network interface unit 907 may also be used to connect to other types of networks or remote computer systems (not shown).
[0160] The memory further includes at least one computer program, the at least one computer program is stored in the memory, and the central processing unit 901 implements all or part of the steps in the methods shown in the above various embodiments by executing the at least one computer program.
[0161] In an exemplary embodiment, there is also provided a computer-readable storage medium for storing at least one computer program, the at least one computer program is loaded and executed by a processor to implement all or part of the steps in the above method. For example, the computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a compact disc read-only memory (CD-ROM), magnetic tape, floppy disk, and optical data storage device, etc.
[0162] In an exemplary embodiment, a computer program product or a computer program is further provided. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes all or part of the steps of the method shown in any of the above Figure 2 or Figure 3 embodiments.
[0163] After considering the specification and practicing the invention disclosed herein, those skilled in the art will readily conceive of other embodiments of the present application. The present application is intended to cover any variations, uses, or adaptations of the present application, which follow the general principles of the present application and include known common knowledge or conventional technical means in the technical field not disclosed in the present application. The specification and embodiments are only regarded as exemplary, and the true scope and spirit of the present application are pointed out by the following claims.
[0164] It should be understood that the present application is not limited to the exact structures already described and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present application is only limited by the appended claims.< / e> < / c:g> < / t:a> < / init> < / init> < / object>
Claims
1. An object-sensitive pointer analysis method for generic programming, characterized in that, The method includes: Obtaining target program code to be analyzed; In the generic programming statements in the target program code, according to the type of the generic programming statement, mapping type variables to instantiation positions, and putting the mapping between the type variables and the instantiation positions into the context of the generic programming statement; Based on the context of the generic programming statement, performing context-sensitive pointer analysis on the target program code to obtain the pointing relationships between various pointers in the target program code; The mapping of type variables to instantiation positions according to the type of the generic programming statement includes: When the type of the generic programming statement is a NEW statement, processing the type variables in the generic programming statement in the target program code according to an object update function to map the type variables to the instantiation positions; the object update function is used to map the type variables according to the instantiation type in the NEW statement to determine the instantiation positions of the type variables; When the type of the generic programming statement is a CALL statement, processing the type variables in the generic programming statement in the target program code according to an object append function to map the type variables to instantiation positions; the object append function is used to map the type variables according to the call type in the CALL statement to determine the instantiation positions of the type variables.
2. The method according to claim 1, wherein The processing of the type variables in the generic programming statement in the target program code according to the object update function to map the type variables to the instantiation positions includes: When it is detected that an object is instantiated with a type variable in the NEW statement, finding the initialization point of the mapping of the type variable and determining the initialization point as the instantiation position of the type variable.
3. The method according to claim 1, wherein The processing of the type variables in the generic programming statement in the target program code according to the object append function to map the type variables to instantiation positions includes: When the call type in the CALL statement is a generic call of a specific type, determining the mapping relationship between the type variable and the call object in the CALL statement as the mapping relationship between the type variable and the instantiation position.
4. The method according to claim 3, characterized in that, The processing of the type variables in the generic programming statement in the target program code according to the object append function to map the type variables to instantiation positions includes: When the call type in the CALL statement is a generic call of a type variable, determining the mapping relationship between the type variable and the actual instantiation site as the mapping relationship between the type variable and the instantiation position; The actual instantiation site includes the receiving object of the target method in the CALL statement and the method invoker of the target method.
5. An object-sensitive pointer analysis device for generic programming, characterized in that The device includes: A program code acquisition module, configured to obtain target program code to be analyzed; A variable mapping module, which is used to map type variables to instantiation positions according to the type of the generic programming statement in the target program code, and put the mapping between the type variables and the instantiation positions into the context of the generic programming statement; A pointer analysis module, which is used to perform context-sensitive pointer analysis on the target program code based on the context of the generic programming statement to obtain the pointing relationships between the pointers in the target program code; The mapping of type variables to instantiation positions according to the type of the generic programming statement includes: When the type of the generic programming statement is a NEW statement, the type variables in the generic programming statement in the target program code are processed according to the object update function to map the type variables to the instantiation positions; the object update function is used to map the type variables according to the instantiation type in the NEW statement to determine the instantiation positions of the type variables; When the type of the generic programming statement is a CALL statement, the type variables in the generic programming statement in the target program code are processed according to the object append function to map the type variables to instantiation positions; the object append function is used to map the type variables according to the call type in the CALL statement to determine the instantiation positions of the type variables.
6. A computer device, characterized in that, The computer device includes a processor and a memory, and at least one instruction is stored in the memory, and the at least one instruction is loaded and executed by the processor to implement the object-sensitive pointer analysis method for generic programming according to any one of claims 1 to 4.
7. A computer-readable storage medium, characterized in that, At least one instruction is stored in the storage medium, and the at least one instruction is loaded and executed by a processor to implement the object-sensitive pointer analysis method for generic programming according to any one of claims 1 to 4.