Call graph construction method and device selectively based on pointer analysis

Through the call graph construction method selectively based on pointer analysis, the problems of high computing costs and slow analysis in traditional methods are solved, and the balance between high precision and fast analysis is achieved.

CN119938134APending Publication Date: 2025-05-06HANGZHOU HIGH-TECH ZONE (BINJIANG) INSTITUTE OF BLOCKCHAIN & DATA SECURITY +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411979712.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-30
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

Traditional pointer analysis methods are expensive to calculate when building call graphs, resulting in increased analysis time, especially in large code bases or frequent use of function pointers, the analysis speed is significantly slowed down.

Method used

A call graph construction method selectively based on pointer analysis is proposed. By obtaining the program's source code, determining the type information of the call point, building the initial call graph, and selectively updating the initial call graph based on the pointer analysis results, generating the target call graph.

Benefits of technology

This method can significantly improve the analysis speed while maintaining high accuracy, reduce calculation costs, and avoid increasing analysis time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119938134A_ABST
    Figure CN119938134A_ABST
Patent Text Reader

Abstract

The invention provides a call graph construction method and device selectively based on pointer analysis. The method comprises the following steps: acquiring a source code of a program; determining type information of each calling point based on the source code; constructing an initial call graph based on the type information of each call point; and performing pointer analysis on the program, and updating the initial call graph based on the analysis result to obtain the target call graph, so that the target call graph has relatively high precision, and the analysis speed can also be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the technical field of static program analysis, and in particular, relates to a method and device for constructing a call graph selectively based on pointer analysis. Background Art

[0002] Traditional pointer analysis methods typically rely on just-in-time call graph construction, where the call graph is incrementally built as the analysis proceeds. When new function pointer targets are discovered, the call graph is updated to reflect these new edges, and this process is iterated until a fixed point is reached (i.e., no new targets or edges are discovered). While this approach ensures high accuracy, it is computationally expensive, and each update to the call graph may require reprocessing parts of the program, resulting in increased analysis time. In large code bases or when function pointers are frequently used, this iterative refinement can become a significant bottleneck, slowing down the overall analysis. Summary of the invention

[0003] In response to the above-mentioned problems, an embodiment of the present application provides a method and device for constructing a call graph selectively based on pointer analysis to solve the problem of slow analysis speed in related technologies.

[0004] In a first aspect, an embodiment of the present application provides a method for constructing a call graph selectively based on pointer analysis, the method comprising:

[0005] Get the source code of the program;

[0006] Determine type information of each call point based on the source code;

[0007] Building an initial call graph based on the type information of each of the call points;

[0008] Pointer analysis is performed on the program, and based on the analysis result, the initial call graph is updated to obtain a target call graph.

[0009] In some embodiments, performing pointer analysis on the call points in the program and updating the initial call graph based on the analysis results to obtain the target call graph includes:

[0010] In the process of performing pointer analysis on the program, determining whether the analyzed target call point is in the initial call graph;

[0011] In the case where the target call point is not in the initial call graph, determining a function target of the target call point;

[0012] The target call site is added into the initial call graph based on the function target of the target call site.

[0013] In some embodiments, the method further comprises:

[0014] In the case where the target call point is in the initial call graph and the call point is an indirect call point, determining whether the target call point meets a preset condition, wherein the preset condition includes: the analysis convergence speed of the target call point is less than a convergence speed threshold, or the criticality of the target call point is less than a criticality threshold;

[0015] In the case that the target call point does not satisfy the preset condition, determining whether there is a newly discovered function pointer that is related to the target call point;

[0016] In the case that there is a newly discovered function pointer that has a relationship with the target call point, the calling relationship of the target call point in the initial call graph is updated based on the newly discovered function pointer.

[0017] In some embodiments, the method further comprises:

[0018] When the target call point satisfies the preset condition, the call relationship of the target call point in the initial call graph is maintained.

[0019] In some embodiments, performing pointer analysis on the program and updating the initial call graph based on the analysis result to obtain the target call graph includes:

[0020] In the process of performing pointer analysis on the program, when it is determined that a new function pointer points to a target function, the initial call graph is updated based on the target function pointed to by the newly discovered function pointer.

[0021] In some embodiments, the method further comprises:

[0022] Determining whether the updated initial call graph satisfies a convergence condition;

[0023] When the updated initial call graph meets the convergence condition, the target call graph is output.

[0024] In some embodiments, determining type information of each call point based on the source code includes:

[0025] Determining an abstract syntax tree or an intermediate representation based on the source code;

[0026] Type information of each call site is determined based on the abstract syntax tree or the intermediate representation.

[0027] In some embodiments, the call points include: direct call points and indirect call points, and the step of constructing an initial call graph based on type information of each of the call points includes:

[0028] Determine whether the function target can be matched in all call sites based on the type information of each indirect call site;

[0029] An indirect call site that can match a function target among all call sites is determined as a target indirect call site;

[0030] An initial call graph is constructed based on the type information of the direct call site and the type information of the target indirect call site.

[0031] In some embodiments, the method further comprises:

[0032] Determining optimization suggestions based on the target call graph;

[0033] The program is optimized based on the optimization suggestion.

[0034] In a second aspect, an embodiment of the present application provides a call graph construction device selectively based on pointer analysis, including:

[0035] Acquisition module, used to obtain the source code of the program;

[0036] A first determination module, configured to determine type information of each call point based on the source code;

[0037] A construction module, used to construct an initial call graph based on the type information of each of the call points;

[0038] The updating module is used to perform pointer analysis on the program and update the initial call graph based on the analysis result to obtain a target call graph.

[0039] In a third aspect, an embodiment of the present application provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method provided in the first aspect when executing the computer program.

[0040] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the method provided in the first aspect is implemented.

[0041] In a fifth aspect, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the method provided in the first aspect is implemented.

[0042] In a sixth aspect, an embodiment of the present application provides a computer program product, the computer program product comprising a computer program, which, when executed by a processor, is at least used to implement any method as in the first aspect.

[0043] Compared with the prior art, the embodiments of the present invention have the following beneficial effects:

[0044] The method for constructing a call graph selectively based on pointer analysis provided in an embodiment of the present application obtains the source code of a program; determines the type information of each call point based on the source code; constructs an initial call graph based on the type information of each call point; performs pointer analysis on the program, and updates the initial call graph based on the analysis result to obtain a target call graph, which can make the target call graph have higher accuracy and improve the speed of analysis.

[0045] It can be understood that the beneficial effects of the second to sixth aspects mentioned above can be found in the relevant description of the first aspect mentioned above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0047] Figure 1 A flowchart of a call graph construction method based on pointer analysis provided by the present application;

[0048] Figure 2 A schematic diagram of an implementation flow of step S104 provided in an embodiment of the present application;

[0049] Figure 3 A schematic diagram of the structure of a call graph construction device provided in an embodiment of the present application;

[0050] Figure 4 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0051] In the following description, specific details such as specific system structures, technologies, etc. are provided for the purpose of illustration rather than limitation, so as to provide a thorough understanding of the embodiments of the present application. However, it should be clear to those skilled in the art that the present application may also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to prevent unnecessary details from obstructing the description of the present application.

[0052] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, wholes, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or combinations thereof.

[0053] It should also be understood that the term “and / or” used in the specification and appended claims refers to any and all possible combinations of one or more of the associated listed items, and includes these combinations.

[0054] As used in the specification of this application and the appended claims, the term "if" can be interpreted as "when" or "uponce" or "in response to determining" or "in response to detecting" depending on the context. Similarly, the phrases "if it is determined" or "if it is detected" can be interpreted as meaning "uponce it is determined" or "in response to determining" or "uponce detected" or "in response to detecting" depending on the context.

[0055] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.

[0056] References to "one embodiment" or "some embodiments" etc. described in the specification of this application mean that one or more embodiments of the present application include specific features, structures or characteristics described in conjunction with the embodiment. Therefore, the phrases "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. appearing in different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways.

[0057] Before introducing the embodiment of the present application, the related art is briefly introduced. In static program analysis, pointer analysis plays a vital role. It is intended to calculate the set of all possible objects that each pointer may point to during program execution, i.e., the set of points (Points-To Sets, PTS). This information is essential for tasks such as compiler optimization, program verification, and error detection. However, when a function pointer (pointer to executable code) and a virtual function (dynamic parsing method) are included in the program, the complexity of pointer analysis increases significantly. These indirect references require special processing because they introduce additional dynamic behaviors, making accurate analysis more challenging.

[0058] Traditional call graph construction methods typically rely on just-in-time pointer analysis, where the call graph is incrementally built as the analysis proceeds. As new function pointer targets are discovered, the call graph is updated to reflect these new edges, and this process is iteratively performed until a fixed point is reached (i.e., no new targets or edges are discovered). While this approach ensures high accuracy, it is computationally expensive. Each update to the call graph may require reprocessing parts of the program, resulting in increased analysis time. In large code bases or where function pointers are frequently used, this iterative refinement can become a significant bottleneck, slowing down the overall analysis.

[0059] To solve this problem, researchers have proposed a variety of optimization methods, one of which is type-based call graph pre-construction. This method uses type information to identify potential function pointer targets, so that the call graph can be quickly constructed. However, this method may not be accurate enough because the call graph may contain many incorrect function targets.

[0060] Therefore, there is an urgent need for a method to construct call graphs that can maintain high accuracy while significantly improving the analysis speed.

[0061] Based on the technical problems of the related art, the embodiment of the present application provides a call graph construction method selectively based on pointer analysis, which can be applied to electronic devices. The electronic devices may include: mobile phones, tablet computers, wearable devices, augmented reality (AR) / virtual reality (VR) devices, laptops, ultra-mobile personal computers (UMPC), netbooks, personal digital assistants (PDA), and the embodiment of the present application does not impose any restrictions on the specific type of electronic devices. Of course, the electronic device can also be a smart device.

[0062] The present application embodiment provides a method for constructing a call graph selectively based on pointer analysis. Figure 1 The present application provides a flowchart of a method for constructing a call graph selectively based on pointer analysis, such as Figure 1 As shown, the method includes:

[0063] Step S101, obtaining the source code of the program.

[0064] In the embodiments of the present application, source code is the basic text representation of a program, which contains all instructions and data definitions written by a programmer. Source code files can be extracted from a source code management system (such as Git) or a development environment. The source code of a program can be C / C++ program source code.

[0065] Step S102: determining type information of each call point based on the source code.

[0066] In the embodiments of the present application, a call site refers to the location where a function call occurs. When a function is called by another function, the location of the call is a call site. A call site can be a direct call (explicitly specifying the function name) or an indirect call (through a function pointer, function object, or virtual function call). Type information is knowledge about the data types of variables, function parameters, return values, etc. Type information may include the signature of the called function (parameter type and quantity, return type), the context of the call site (e.g., the type of the caller function), type inheritance relationships, and conversion relationships between types.

[0067] In the embodiment of the present application, the type information of each call point can be determined by parsing the source code (for example, using a parser to generate an abstract syntax tree). The parser can identify function calls and extract information about the call point and the called function.

[0068] Step S103: construct an initial call graph based on the type information of each of the call points.

[0069] In an embodiment of the present application, a call graph is a graphical representation for displaying the call relationships between functions in a program. The initial call graph is constructed based on the call relationships directly visible in the source code, and may not include calls that occur in an indirect manner (such as a function pointer). The initial call graph can be constructed by traversing the parsed source code or abstract syntax tree. For each function call, an edge from the caller to the callee can be created in the call graph. The call points in the initial call graph include all direct call points, and in some embodiments, the initial call graph may also include some indirect call points.

[0070] In an embodiment of the present application, an empty call graph can be created to record the calling relationship between functions, and based on the type information, the call points are input into the empty call graph, so that an initial call graph can be obtained.

[0071] Step S104, performing pointer analysis on the program, and updating the initial call graph based on the analysis result to obtain a target call graph.

[0072] In the embodiments of the present application, pointer analysis is a form of program analysis that aims to determine the possible directions of pointer variables in a program. This includes function pointer pointing analysis to determine which functions may be called through a specific function pointer. The target call graph is a call graph updated after pointer analysis, which more accurately reflects the actual function call relationship in the program, including calls that occur indirectly.

[0073] In the embodiment of the present application, pointer analysis can use a variety of techniques, such as data flow analysis, control flow analysis, pointer alias analysis, etc. Pointer analysis can determine all possible locations that a pointer variable may point to during program execution.

[0074] In the embodiment of the present application, when the initial call graph is updated based on the analysis result to obtain the target call graph, the information in the initial call graph can be selectively updated.

[0075] In the embodiment of the present application, based on the pointer analysis, function calls that occur through indirect means (such as function pointers) can be identified. These calls can be added as new edges to the initial call graph to generate the target call graph.

[0076] The method for constructing a call graph selectively based on pointer analysis provided in an embodiment of the present application obtains the source code of a program; determines the type information of each call point based on the source code; constructs an initial call graph based on the type information of each call point; performs pointer analysis on the program, and updates the initial call graph based on the analysis result to obtain a target call graph, which can make the target call graph have higher accuracy and improve the speed of analysis.

[0077] In some embodiments, Figure 2 A schematic diagram of an implementation flow of step S104 provided in an embodiment of the present application is as follows: Figure 2 As shown, step S104 can be implemented by the following steps:

[0078] Step S1041, during the process of performing pointer analysis on the program, determining whether the analyzed target call point is in the initial call graph.

[0079] In the embodiments of the present application, pointer analysis generally involves analyzing the control flow and data flow of a program to determine the possible directions of a pointer variable, which can be achieved through static analysis.

[0080] In the embodiment of the present application, during the pointer analysis process, whenever a potential function call point (i.e., a target call point) is identified, it is necessary to check whether the call point is already in the initial call graph. Identifying whether the target call point is in the initial call graph can be achieved by searching for a node corresponding to the target call point in the initial call graph. If a node corresponding to the target call point is searched in the initial call graph, it is determined that the target call point is in the initial call graph. If it is not searched, it is considered that the target call point is not in the initial call graph. The target call point can be any call point identified during the pointer analysis process.

[0081] Step S1042: if the target call point is not in the initial call graph, determine the function target of the target call point.

[0082] In the embodiment of the present application, the function target is determined by parsing a function pointer or other indirect reference mechanism.

[0083] In the embodiment of the present application, if the target call point is not in the initial call graph, then the function target of the call point needs to be determined. The function target of the target call point can be determined by methods such as dynamic analysis or symbolic execution.

[0084] Step S1043: adding the target call point into the initial call graph based on the function target of the target call point.

[0085] In the embodiment of the present application, when the function target of the target call point is determined, the target call point and its corresponding function target can be added to the initial call graph. New nodes and edges can be created in the call graph to represent new call relationships.

[0086] The method provided by the embodiment of the present application can gradually build a more complete call graph by determining whether the analyzed target call point is in the initial call graph during pointer analysis of the program; if the target call point is not in the initial call graph, determining the function target of the target call point; and adding the target call point to the initial call graph based on the function target of the target call point, so that the updated call graph can more accurately reflect the calling relationship between functions in the program.

[0087] In some embodiments, after step S1041, the method further includes:

[0088] Step S1044, when the target call point is in the initial call graph and the call point is an indirect call point, determine whether the target call point meets a preset condition, wherein the preset condition includes: the analysis convergence speed of the target call point is less than a convergence speed threshold, or the criticality of the target call point is less than a criticality threshold.

[0089] In the embodiments of the present application, indirect call points refer to those function call points that are called through function pointers, function objects or other forms of indirect references. Unlike direct calls (explicitly specifying the function name), indirect calls may not be able to determine the specific called function at compile time. Convergence rate refers to the speed at which the analysis of a specific call point reaches a stable state during the pointer analysis process. If the analysis can quickly converge to a certain result (i.e., a specific function target is determined), the convergence rate of the call point is considered to be fast. Criticality is an indicator that measures the importance of a call point in a program. Call points with high criticality may have a significant impact on the execution results or performance of the program. Criticality can be measured in a variety of ways, such as call frequency, access to critical resources, parts involving system calls or whether sensitive data is processed.

[0090] In the embodiment of the present application, if the analysis convergence speed for a certain indirect call point is very slow, this may mean that the behavior of the call point is complex or difficult to predict. The repeated refinement of the call graph results in that if the criticality of a certain indirect call point is very low, it means that the call point has little impact on the execution result or performance of the program. In this case, even if a new function pointer related to the call point is found, it may not be necessary to update the call graph because the benefits of the update are limited.

[0091] In the embodiment of the present application, for the indirect call point that is already in the initial call graph, it is necessary to determine whether it meets the preset conditions.

[0092] Step S1045 , when the target call point does not satisfy a preset condition, determining whether there is a newly discovered function pointer that is related to the target call point.

[0093] In an embodiment of the present application, if the target call point does not meet the preset conditions, that is, the call point has a fast convergence speed or high criticality, the analysis result of the call point can be quickly obtained due to the fast convergence speed. At this time, the initial call graph can be directly updated through the newly discovered function pointer. If the criticality is high, the accuracy of the call point is crucial, and it is necessary to check whether there is a newly discovered function pointer that has a relationship with the call point. This can be achieved by analyzing the context, data flow and control flow of the call point.

[0094] Step S1046: When there is a newly discovered function pointer that has a relationship with the target call point, update the calling relationship of the target call point in the initial call graph based on the newly discovered function pointer.

[0095] In the embodiment of the present application, if there is a newly discovered function pointer that has a relationship with the target call point, it is necessary to update the call relationship of the initial call point in the initial call graph based on these newly discovered function pointers. New nodes and edges can be added to the initial call graph to represent the new call relationship.

[0096] In the embodiment of the present application, for call points with fast convergence speed or high criticality, the accuracy of the constructed target call graph can be ensured through real-time updating.

[0097] In some embodiments, after step S1044, the method further includes:

[0098] Step S1047, when the target call point meets the preset condition, the call relationship of the target call point in the initial call graph is maintained.

[0099] In an embodiment of the present application, if the target call point meets the preset conditions, it means that the call point converges slowly or is less important. If the target call point meets the preset conditions, it is decided to keep its call relationship in the initial call graph unchanged.

[0100] In the embodiment of the present application, when the convergence speed is slow due to repeated refinement of the initial call graph, the call relationship of the target call point in the initial call graph is maintained at the target call point to accelerate the convergence without significantly affecting the accuracy of the overall analysis; and if the criticality is low, the initial call graph is directly used to minimize the impact of the precision loss on the overall program behavior. For the target call point, the initial call graph is used instead, and no refinement is performed when performing pointer analysis, which can save computing resources.

[0101] In some embodiments, the method further comprises:

[0102] When the target call point is in the initial call graph and the call point is a direct call point, the call relationship of the target call point in the initial call graph is maintained.

[0103] In the embodiment of the present application, that is, for direct call points, the information in the call graph based on type information is directly used, and the initial call graph is used instead, and there is no need to refine it when performing pointer analysis, which can save computing resources.

[0104] In some embodiments, step S104 may be implemented by the following steps:

[0105] In the process of performing pointer analysis on the program, when it is determined that a new function pointer points to a target function, the initial call graph is updated based on the target function pointed to by the newly discovered function pointer.

[0106] In the embodiment of the present application, once the target function is determined, the initial call graph needs to be updated to reflect the new call relationship. The update process may include adding new nodes (representing the target function) and edges (representing the call relationship from the call point to the target function through the function pointer) in the call graph. If the target function already exists in the call graph, but the new call path is not previously identified, then the call graph also needs to be updated to include this new path.

[0107] The method provided by the embodiment of the present application can ensure that the call graph is continuously updated during the pointer analysis process to reflect the actual function call relationship in the program, which helps to improve the accuracy and completeness of program analysis.

[0108] In some embodiments, after step S104, the method further includes:

[0109] Step S105, determining whether the updated initial call graph meets a convergence condition.

[0110] In the embodiment of the present application, the convergence condition refers to a stable state reached by the updated initial call graph during the update process, that is, the updated initial call graph no longer changes significantly due to the discovery of new function targets or call relationships. This usually means that the pointer analysis has fully traversed the relevant parts of the program and has not found new indirect calls that have a significant impact on the call graph.

[0111] In the embodiment of the present application, the call graphs before and after the update can be compared to see if there are significant differences.

[0112] Step S106: when the updated initial call graph meets the convergence condition, output the target call graph.

[0113] In the embodiment of the present application, if there is no significant difference between the call graphs before and after the update, it can be considered that the convergence condition is met, and the final target call graph can be obtained.

[0114] In some embodiments, the call point includes: a direct call point and an indirect call point, and step S103 can be implemented by the following steps:

[0115] Step S1031 , determining whether a function target can be matched in all the call sites based on the type information of each indirect call site.

[0116] In the embodiment of the present application, all indirect call sites in the program can be traversed. For each indirect call site, its type information (such as the type of the function pointer) is used to try to match a possible function target.

[0117] Step S1032: determine the indirect call site that can match the function target among all call sites as the target indirect call site.

[0118] In the embodiment of the present application, if the type information of an indirect call site can be successfully matched to one or more function targets, it is regarded as a target indirect call site.

[0119] Step S1033: construct an initial call graph based on the type information of the direct call site and the type information of the target indirect call site.

[0120] In the embodiment of the present application, an empty call graph can be created to represent the function call relationship of the program. All direct call points are added as nodes to the call graph, and edges are added according to their call relationships. For each target indirect call point, the function target it points to is added as a node to the call graph, and an edge is added from the location of the indirect call point (which can be another function or a part of the program) to the function target.

[0121] The method provided in the embodiment of the present application constructs an accurate, complete and easy-to-understand initial call graph based on the type information of indirect call points and direct call points, which serves as the basis for subsequent optimization.

[0122] In some embodiments, the method further comprises:

[0123] Step S107: determining optimization suggestions based on the target call graph.

[0124] In the embodiment of the present application, the optimization suggestions are specific suggestions for improving program performance, reducing resource consumption or improving code readability based on the target call graph analysis. The target call graph can be analyzed to understand the calling relationship between each function. Identify frequently called functions, functions with potential performance bottlenecks, and parts with long call chains. Based on the analysis results of the call graph, identify possible problems in the program, such as excessive function call overhead, memory leaks, unnecessary repeated calculations, etc. Pay special attention to those functions that are frequently called and have long execution times, which are often the key to performance optimization.

[0125] In the embodiments of the present application, specific optimization suggestions can be made based on the identified problems. These suggestions may include: optimizing algorithms and data structures to reduce computational complexity; using more efficient data access methods, such as caching or pre-computation; merging or splitting functions to reduce function call overhead; eliminating unnecessary function calls, such as through inline functions or macro replacement. Improving memory management strategies to reduce the number of memory allocations and releases, etc.

[0126] Step S108: Optimize the program based on the optimization suggestion.

[0127] In the embodiments of the present application, the program code may be modified and adjusted according to the optimization suggestions.

[0128] The method provided in the embodiment of the present application can make effective optimization suggestions based on the target call graph, and optimize the program accordingly, thereby improving the performance of the program, reducing resource consumption and improving code quality.

[0129] Based on the foregoing embodiments, the present application further provides a method for constructing a call graph selectively based on pointer analysis, including:

[0130] Pre-analysis phase: Before pointer analysis begins, pre-analysis is performed to identify a set of call sites in the program where type information can be effectively used to build an initial call graph; these call sites are usually located where the function pointer target can be easily inferred from the type information or where accuracy is not required.

[0131] Initial call graph construction: Use type information to quickly build an initial call graph, which serves as the starting point and basis for subsequent immediate call graph construction;

[0132] Real-time call graph construction and selective optimization: During the pointer analysis process, the call graph is dynamically and instantly updated for newly discovered function pointer targets. At the same time, the preset heuristic rules (equivalent to preset conditions) are used to determine whether each call point meets the conditions for switching to the initial call graph. If the conditions are met, the information in the initial call graph is used to replace the real-time, step-by-step refinement of the call graph construction process for the call point to save computing resources.

[0133] Iterative refinement and convergence judgment: As the pointer analysis proceeds, the initial call graph is continuously updated iteratively, and the updated initial call graph is checked to see if it has reached a convergence state. In each iteration, the call graph construction process is judged and optimized based on heuristic rules.

[0134] Result output: When the pointer analysis converges, the final target call graph is output for subsequent compiler optimization, program verification, and error detection tasks.

[0135] In an embodiment of the present application, convergence behavior: if the analysis convergence speed of a certain call point is slow (i.e., the convergence speed is less than the convergence speed threshold) due to repeated refinement of the call graph, then the information in the initial call graph is maintained at the call point to accelerate convergence without significantly affecting the accuracy of the overall analysis.

[0136] In an embodiment of the present application, in performance-sensitive or security-critical code paths (equivalent to a criticality greater than a criticality threshold), such as parts involving system calls or sensitive data processing, accuracy is critical; in these areas, the analysis results from the immediate pointer analysis continue to be used to update the initial call graph to ensure that all potential call targets are correctly identified; in non-critical areas, the information in the initial call graph can be safely used to minimize the impact of precision loss on the overall program behavior.

[0137] In an embodiment of the present application, during the just-in-time pointer analysis process, the set of call points that can use the initial call graph is dynamically adjusted; as the analysis progresses, new information may reveal additional call points where the approximate call graph is sufficiently accurate, thereby reducing the need for expensive just-in-time updates.

[0138] In an embodiment of the present application, before pointer analysis begins, a preliminary analysis is performed to identify a set of call sites that can be effectively accelerated using an initial call graph; these call sites are typically locations where the function pointer target can be easily inferred through static type information, or locations where accuracy requirements are not high.

[0139] The method provided by the embodiment of the present application performs an offline detection phase before the pointer analysis begins, using type information and static analysis techniques to identify a subset of call points that can be effectively processed using an initial call graph based on type information. During the real-time pointer analysis process, online detection is performed dynamically, and the initial call graph is dynamically updated based on the newly discovered function pointer targets and call relationships.

[0140] The method provided by the embodiment of the present application selectively applies call graph construction based on type information and call graph construction in real time. For non-critical call points, an initial call graph based on type information is used for approximation processing to reduce computational costs. For critical call points, the call graph construction in real time is retained to ensure the accuracy of the analysis.

[0141] During the pointer analysis of the program, when new function pointer targets are found, the call graph is updated iteratively. A convergence judgment mechanism is introduced. When the call graph reaches a fixed point (i.e. no new targets or edges are found), the iterative update is stopped to improve the analysis efficiency.

[0142] The method provided in the embodiment of the present application significantly reduces the time required for pointer analysis and improves the analysis efficiency by constructing a selective instant call graph. Although the initial call graph based on type information is used for approximate processing, the method provided in the embodiment of the present application maintains a high degree of accuracy as a whole and has little effect on the overall correctness.

[0143] The method provided in the embodiment of the present application is not only applicable to C and C++ programs, but its principles can also be extended to other programming languages ​​with similar characteristics, and has wide applicability.

[0144] Based on the foregoing embodiments, the present application further provides an example of a method for constructing a call graph selectively based on pointer analysis, including:

[0145] Step 1: Initialization phase:

[0146] Read the source code of the program: First, read the source code of the C / C++ program to be analyzed and parse it into an abstract syntax tree (AST) or intermediate representation (IR) form for subsequent analysis.

[0147] Build a type system: Based on the parsed source code, build the type system of the program, including type definitions, type inheritance relationships, and conversion relationships between types.

[0148] Initialize the call graph: Create an empty call graph to record the calling relationship between functions. At the same time, initialize a function call stack to track the current function call path.

[0149] Step 2: Offline detection phase:

[0150] Static analysis: Perform static analysis on the program source code to identify all function call sites, including direct calls and indirect calls (through function pointers or virtual functions).

[0151] Type matching: For each indirect call site, try to match possible function targets according to the type system. If a function target can be determined based on the type information, it is added to the call graph and marked as a call based on type information.

[0152] Generate pre-built call graph: Based on the result of type matching, a pre-built call graph is generated. The call graph only contains type-based call relationships.

[0153] Step 3: Online detection and instant call graph construction phase:

[0154] Start real-time pointer analysis: Start real-time pointer analysis from the program entry point. During the analysis, the call graph is dynamically updated according to the current function call path and function call stack.

[0155] Detect indirect call sites: Whenever an indirect call site is encountered, check if it is already in the initial call graph. If not, perform an immediate refinement step.

[0156] On-the-fly refinement: For indirect call points that are not in the initial call graph, their possible function targets are determined through methods such as dynamic analysis or symbolic execution, and added to the call graph. At the same time, the function call stack and the current call path are updated.

[0157] Convergence judgment: After each call graph update, check whether a fixed point has been reached (i.e. no new function targets or edges have been found). If a fixed point has been reached, stop the immediate refinement and end the immediate pointer analysis.

[0158] Step 4: Result output and optimization:

[0159] Output call graph: Output the final constructed call graph to a file for subsequent analysis and optimization.

[0160] Optimization suggestions: Based on the analysis results of the call graph, possible optimization suggestions are proposed, such as function inlining, dead code elimination, etc., to improve the performance and maintainability of the program.

[0161] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0162] According to the aforementioned embodiments, the embodiments of the present application provide a call graph construction device selectively based on pointer analysis. The modules included in the device and the units included in the modules can be implemented by a processor in a computer device; of course, they can also be implemented by a specific logic circuit; in the implementation process, the processor can be a central processing unit (CPU, Central Processing Unit), a microprocessor (MPU, Microprocessor Unit), a digital signal processor (DSP, Digital Signal Processing) or a field programmable gate array (FPGA, Field ProgrammableGate Array), etc.

[0163] The embodiment of the present application provides a call graph construction device selectively based on pointer analysis, Figure 3 A schematic diagram of a structure of a call graph construction device provided in an embodiment of the present application, such as Figure 3 As shown, the call graph construction device 300 selectively based on pointer analysis includes:

[0164] An acquisition module 301 is used to acquire the source code of a program;

[0165] A first determination module 302, configured to determine type information of each call point based on the source code;

[0166] A construction module 303 is used to construct an initial call graph based on the type information of each of the call points;

[0167] The updating module 304 is used to perform pointer analysis on the program and update the initial call graph based on the analysis result to obtain a target call graph.

[0168] In some embodiments, the update module 304 includes:

[0169] A first determining unit is used to determine whether the analyzed target call point is in the initial call graph during the process of performing pointer analysis on the program;

[0170] A second determining unit is used to determine a function target of the target call point when the target call point is not in the initial call graph;

[0171] An adding unit is used to add the target call point into the initial call graph based on the function target of the target call point.

[0172] In some embodiments, the update module 304 includes:

[0173] A third determining unit is used to determine whether the target call point meets a preset condition when the target call point is in the initial call graph and the call point is an indirect call point, wherein the preset condition includes: the analysis convergence speed of the target call point is less than a convergence speed threshold, or the criticality of the target call point is less than a criticality threshold;

[0174] A fourth determining unit, configured to determine whether there is a newly discovered function pointer that is related to the target calling point when the target calling point does not satisfy a preset condition;

[0175] The first updating unit is used to update the calling relationship of the target calling point in the initial calling graph based on the newly discovered function pointer when there is a newly discovered function pointer that has a relationship with the target calling point.

[0176] In some embodiments, the update module 304 includes:

[0177] A maintaining unit is used to maintain the calling relationship of the target calling point in the initial calling graph when the target calling point meets the preset condition.

[0178] In some embodiments, the update module 304 includes:

[0179] The second updating unit is used to update the initial call graph based on the target function pointed to by the newly found function pointer when it is determined that a new function pointer points to a target function during the pointer analysis of the program.

[0180] In some embodiments, the call graph construction apparatus 300 selectively based on pointer analysis includes:

[0181] A second determination module is used to determine whether the updated initial call graph meets the convergence condition;

[0182] The output module is used to output the target call graph when the updated initial call graph meets the convergence condition.

[0183] In some embodiments, the first determining module includes:

[0184] a fifth determining unit, configured to determine an abstract syntax tree or an intermediate representation based on the source code;

[0185] A sixth determining unit is used to determine type information of each call point based on the abstract syntax tree or the intermediate representation.

[0186] In some embodiments, the call site includes: a direct call site and an indirect call site, and the building module includes:

[0187] a seventh determination unit, configured to determine whether a function target can be matched in all call sites based on type information of each indirect call site;

[0188] an eighth determining unit, configured to determine an indirect call point that can match a function target among all call points as a target indirect call point;

[0189] A construction unit is used to construct an initial call graph based on the type information of the direct call site and the type information of the target indirect call site.

[0190] In some embodiments, the call graph construction apparatus 300 selectively based on pointer analysis further includes:

[0191] A third determination module, configured to determine optimization suggestions based on the target call graph;

[0192] An optimization module is used to optimize the program based on the optimization suggestion.

[0193] in addition, Figure 3 The call graph construction shown may be a software unit, a hardware unit, or a combination of software and hardware units built into an existing electronic device, or may be integrated into an electronic device as an independent widget, or may exist as an independent terminal device.

[0194] It should be noted that the information interaction, execution process, etc. between the above-mentioned devices / units are based on the same concept as the method embodiment of the present application. Their specific functions and technical effects can be found in the method embodiment part and will not be repeated here.

[0195] The technicians in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In practical applications, the above-mentioned function allocation can be completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated in a processing unit, or each unit can exist physically separately, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, which will not be repeated here.

[0196] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. Figure 4 As shown, the electronic device 3 of this embodiment may include: at least one processor 30 ( Figure 4 Only one processor 30 is shown in the figure), a memory 31, and a computer program 32 stored in the memory 31 and executable on at least one processor 30. When the processor 30 executes the computer program 32, the steps in any of the above-mentioned method embodiments are implemented; or, when the processor 30 executes the computer program 32, the functions of the modules / units in the above-mentioned device embodiments are implemented.

[0197] Exemplarily, the computer program 32 may be divided into one or more modules / units, one or more modules / units are stored in the memory 31, and are executed by the processor 30 to complete the present application. One or more modules / units may be a series of computer program 32 instruction segments capable of completing specific functions, and the instruction segments are used to describe the execution process of the computer program 32 in the electronic device 3.

[0198] The embodiment of the present application further provides a computer-readable storage medium, which stores a computer program 32. When the computer program 32 is executed by the processor 30, the steps in the above-mentioned method embodiments can be implemented.

[0199] An embodiment of the present application provides a computer program product. When the computer program product runs on an electronic device, the electronic device can implement the steps in the above-mentioned method embodiments when executing the computer program product.

[0200] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. According to this understanding, the present application implements all or part of the processes in the above-mentioned embodiment method, which can be completed by instructing the relevant hardware through a computer program 32, and the computer program 32 can be stored in a computer-readable storage medium. When the computer program 32 is executed by the processor 30, the steps of the above-mentioned various method embodiments can be implemented. Among them, the computer program 32 includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may at least include: any entity or device capable of carrying the computer program code to the terminal, a recording medium, a computer memory, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), an electric carrier signal, a telecommunication signal and a software distribution medium. For example, a USB flash drive, a mobile hard disk, a magnetic disk or an optical disk. In some jurisdictions, according to legislation and patent practice, computer-readable media cannot be electric carrier signals and telecommunication signals.

[0201] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0202] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0203] In the embodiments provided in the present application, it should be understood that the disclosed devices / network equipment and methods can be implemented in other ways. For example, the device / network equipment embodiments described above are merely schematic. For example, the division of the modules or units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0204] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0205] The embodiments described above are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, a person skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.

[0206] The relevant user personal information that may be involved in the various embodiments of this application is strictly in accordance with the requirements of laws and regulations, following the principles of legality, legitimacy and necessity, based on the reasonable purposes of business scenarios, to process the personal information that users actively provide during the use of products / services or generated due to the use of products / services, as well as the personal information obtained with the user's authorization.

[0207] The user personal information processed by the applicant will vary depending on the specific product / service scenario, and shall be based on the specific scenario in which the user uses the product / service, which may involve the user's account information, device information, driving information, vehicle information or other related information. The applicant will treat the user's personal information and its processing with a high degree of diligence.

[0208] The Applicant attaches great importance to the security of user personal information and has adopted reasonable and feasible security protection measures that comply with industry standards to protect user information and prevent personal information from being accessed, disclosed, used, modified, damaged or lost without authorization.

Claims

1. A method for constructing a call graph selectively based on pointer analysis, characterized in that: include: Get the source code of the program; Determine type information of each call point based on the source code; Building an initial call graph based on the type information of each of the call points; Pointer analysis is performed on the program, and based on the analysis result, the initial call graph is updated to obtain a target call graph.

2. The method according to claim 1, characterized in that: The step of performing pointer analysis on the call points in the program and updating the initial call graph based on the analysis result to obtain a target call graph includes: In the process of performing pointer analysis on the program, determining whether the analyzed target call point is in the initial call graph; In the case where the target call point is not in the initial call graph, determining a function target of the target call point; The target call site is added into the initial call graph based on the function target of the target call site.

3. The method according to claim 2, characterized in that The method further comprises: In the case where the target call point is in the initial call graph and the call point is an indirect call point, determining whether the target call point meets a preset condition, wherein the preset condition includes: the analysis convergence speed of the target call point is less than a convergence speed threshold, or the criticality of the target call point is less than a criticality threshold; In the case where the target call point does not satisfy a preset condition, determining whether there is a newly discovered function pointer that has a relationship with the target call point; in the case where there is a newly discovered function pointer that has a relationship with the target call point, updating the calling relationship of the target call point in the initial call graph based on the newly discovered function pointer; When the target call point satisfies the preset condition, the call relationship of the target call point in the initial call graph is maintained.

4. The method according to claim 1, characterized in that: The performing pointer analysis on the program and updating the initial call graph based on the analysis result to obtain a target call graph includes: In the process of performing pointer analysis on the program, when it is determined that a new function pointer points to a target function, the initial call graph is updated based on the target function pointed to by the newly discovered function pointer.

5. The method according to claim 1, characterized in that The method further comprises: Determining whether the updated initial call graph satisfies a convergence condition; When the updated initial call graph meets the convergence condition, the target call graph is output.

6. The method according to claim 1, characterized in that The determining type information of each call point based on the source code includes: Determining an abstract syntax tree or an intermediate representation based on the source code; Type information of each call site is determined based on the abstract syntax tree or the intermediate representation.

7. The method according to claim 1, characterized in that The call points include: direct call points and indirect call points, and the initial call graph is constructed based on the type information of each of the call points, including: Determine whether the function target can be matched in all call sites based on the type information of each indirect call site; An indirect call site that can match a function target among all call sites is determined as a target indirect call site; An initial call graph is constructed based on the type information of the direct call site and the type information of the target indirect call site.

8. The method according to any one of claims 1 to 7, characterized in that: The method further comprises: Determining optimization suggestions based on the target call graph; The program is optimized based on the optimization suggestion.

9. A call graph construction device selectively based on pointer analysis, characterized in that: include: Acquisition module, used to obtain the source code of the program; A first determination module, configured to determine type information of each call point based on the source code; A construction module, used to construct an initial call graph based on the type information of each of the call points; The updating module is used to perform pointer analysis on the program and update the initial call graph based on the analysis result to obtain a target call graph.

10. An electronic device, characterized in that: include: The method comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method according to any one of claims 1 to 8 when executing the computer program.