1 /* Copyright (c) 2008-2015. The SimGrid Team.
2 * All rights reserved. */
4 /* This program is free software; you can redistribute it and/or modify it
5 * under the terms of the license (GNU LGPL) which comes with this package. */
7 /* mc_diff - Memory snapshooting and comparison */
9 #include "src/xbt/ex_interface.h" /* internals of backtrace setup */
12 #include "xbt/mmalloc.h"
13 #include "src/mc/mc_object_info.h"
14 #include "mc/datatypes.h"
15 #include "src/mc/mc_private.h"
16 #include "src/mc/mc_snapshot.h"
17 #include "src/mc/mc_dwarf.hpp"
18 #include "src/mc/Type.hpp"
20 using simgrid::mc::remote;
24 XBT_LOG_NEW_DEFAULT_SUBCATEGORY(mc_diff, xbt,
25 "Logging specific to mc_diff in mc");
27 /*********************************** Heap comparison ***********************************/
28 /***************************************************************************************/
30 typedef char *type_name;
32 struct XBT_PRIVATE s_mc_diff {
33 s_xbt_mheap_t std_heap_copy;
34 std::size_t heaplimit;
35 // Number of blocks in the heaps:
36 std::size_t heapsize1, heapsize2;
37 std::vector<simgrid::mc::IgnoredHeapRegion>* to_ignore1;
38 std::vector<simgrid::mc::IgnoredHeapRegion>* to_ignore2;
39 s_heap_area_t *equals_to1, *equals_to2;
40 simgrid::mc::Type **types1;
41 simgrid::mc::Type **types2;
42 std::size_t available;
45 #define equals_to1_(i,j) equals_to1[ MAX_FRAGMENT_PER_BLOCK*(i) + (j)]
46 #define equals_to2_(i,j) equals_to2[ MAX_FRAGMENT_PER_BLOCK*(i) + (j)]
47 #define types1_(i,j) types1[ MAX_FRAGMENT_PER_BLOCK*(i) + (j)]
48 #define types2_(i,j) types2[ MAX_FRAGMENT_PER_BLOCK*(i) + (j)]
50 static __thread struct s_mc_diff *mc_diff_info = nullptr;
52 /*********************************** Free functions ************************************/
54 static void heap_area_pair_free(heap_area_pair_t pair)
60 static void heap_area_pair_free_voidp(void *d)
62 heap_area_pair_free((heap_area_pair_t) * (void **) d);
65 static void heap_area_free(heap_area_t area)
71 /************************************************************************************/
73 static s_heap_area_t make_heap_area(int block, int fragment)
78 area.fragment = fragment;
83 static int is_new_heap_area_pair(xbt_dynar_t list, int block1, int fragment1,
84 int block2, int fragment2)
87 unsigned int cursor = 0;
88 heap_area_pair_t current_pair;
90 xbt_dynar_foreach(list, cursor, current_pair) {
91 if (current_pair->block1 == block1 && current_pair->block2 == block2
92 && current_pair->fragment1 == fragment1
93 && current_pair->fragment2 == fragment2)
100 static int add_heap_area_pair(xbt_dynar_t list, int block1, int fragment1,
101 int block2, int fragment2)
104 if (is_new_heap_area_pair(list, block1, fragment1, block2, fragment2)) {
105 heap_area_pair_t pair = NULL;
106 pair = xbt_new0(s_heap_area_pair_t, 1);
107 pair->block1 = block1;
108 pair->fragment1 = fragment1;
109 pair->block2 = block2;
110 pair->fragment2 = fragment2;
112 xbt_dynar_push(list, &pair);
120 static ssize_t heap_comparison_ignore_size(
121 std::vector<simgrid::mc::IgnoredHeapRegion>* ignore_list,
125 int end = ignore_list->size() - 1;
127 while (start <= end) {
128 unsigned int cursor = (start + end) / 2;
129 simgrid::mc::IgnoredHeapRegion const& region = (*ignore_list)[cursor];
130 if (region.address == address)
132 if (region.address < address)
134 if (region.address > address)
141 static bool is_stack(const void *address)
143 for (auto const& stack : mc_model_checker->process().stack_areas())
144 if (address == stack.address)
149 // TODO, this should depend on the snapshot?
150 static bool is_block_stack(int block)
152 for (auto const& stack : mc_model_checker->process().stack_areas())
153 if (block == stack.block)
158 static void match_equals(struct s_mc_diff *state, xbt_dynar_t list)
161 unsigned int cursor = 0;
162 heap_area_pair_t current_pair;
164 xbt_dynar_foreach(list, cursor, current_pair) {
166 if (current_pair->fragment1 != -1) {
168 state->equals_to1_(current_pair->block1, current_pair->fragment1) =
169 make_heap_area(current_pair->block2, current_pair->fragment2);
170 state->equals_to2_(current_pair->block2, current_pair->fragment2) =
171 make_heap_area(current_pair->block1, current_pair->fragment1);
175 state->equals_to1_(current_pair->block1, 0) =
176 make_heap_area(current_pair->block2, current_pair->fragment2);
177 state->equals_to2_(current_pair->block2, 0) =
178 make_heap_area(current_pair->block1, current_pair->fragment1);
185 /** Check whether two blocks are known to be matching
187 * @param state State used
188 * @param b1 Block of state 1
189 * @param b2 Block of state 2
190 * @return if the blocks are known to be matching
192 static int equal_blocks(struct s_mc_diff *state, int b1, int b2)
195 if (state->equals_to1_(b1, 0).block == b2
196 && state->equals_to2_(b2, 0).block == b1)
202 /** Check whether two fragments are known to be matching
204 * @param state State used
205 * @param b1 Block of state 1
206 * @param f1 Fragment of state 1
207 * @param b2 Block of state 2
208 * @param f2 Fragment of state 2
209 * @return if the fragments are known to be matching
211 static int equal_fragments(struct s_mc_diff *state, int b1, int f1, int b2,
215 if (state->equals_to1_(b1, f1).block == b2
216 && state->equals_to1_(b1, f1).fragment == f2
217 && state->equals_to2_(b2, f2).block == b1
218 && state->equals_to2_(b2, f2).fragment == f1)
226 int init_heap_information(xbt_mheap_t heap1, xbt_mheap_t heap2,
227 std::vector<simgrid::mc::IgnoredHeapRegion>* i1,
228 std::vector<simgrid::mc::IgnoredHeapRegion>* i2)
230 if (mc_diff_info == NULL) {
231 mc_diff_info = xbt_new0(struct s_mc_diff, 1);
232 mc_diff_info->equals_to1 = NULL;
233 mc_diff_info->equals_to2 = NULL;
234 mc_diff_info->types1 = NULL;
235 mc_diff_info->types2 = NULL;
237 struct s_mc_diff *state = mc_diff_info;
239 if ((((struct mdesc *) heap1)->heaplimit !=
240 ((struct mdesc *) heap2)->heaplimit)
242 ((((struct mdesc *) heap1)->heapsize !=
243 ((struct mdesc *) heap2)->heapsize)))
246 state->heaplimit = ((struct mdesc *) heap1)->heaplimit;
248 state->std_heap_copy = *mc_model_checker->process().get_heap();
250 state->heapsize1 = heap1->heapsize;
251 state->heapsize2 = heap2->heapsize;
253 state->to_ignore1 = i1;
254 state->to_ignore2 = i2;
256 if (state->heaplimit > state->available) {
257 state->equals_to1 = (s_heap_area_t*)
258 realloc(state->equals_to1,
259 state->heaplimit * MAX_FRAGMENT_PER_BLOCK *
260 sizeof(s_heap_area_t));
261 state->types1 = (simgrid::mc::Type**)
262 realloc(state->types1,
263 state->heaplimit * MAX_FRAGMENT_PER_BLOCK *
264 sizeof(simgrid::mc::Type*));
265 state->equals_to2 = (s_heap_area_t*)
266 realloc(state->equals_to2,
267 state->heaplimit * MAX_FRAGMENT_PER_BLOCK *
268 sizeof(s_heap_area_t));
269 state->types2 = (simgrid::mc::Type**)
270 realloc(state->types2,
271 state->heaplimit * MAX_FRAGMENT_PER_BLOCK *
272 sizeof(simgrid::mc::Type*));
273 state->available = state->heaplimit;
276 memset(state->equals_to1, 0,
277 state->heaplimit * MAX_FRAGMENT_PER_BLOCK * sizeof(s_heap_area_t));
278 memset(state->equals_to2, 0,
279 state->heaplimit * MAX_FRAGMENT_PER_BLOCK * sizeof(s_heap_area_t));
280 memset(state->types1, 0,
281 state->heaplimit * MAX_FRAGMENT_PER_BLOCK * sizeof(type_name *));
282 memset(state->types2, 0,
283 state->heaplimit * MAX_FRAGMENT_PER_BLOCK * sizeof(type_name *));
291 void reset_heap_information()
296 // TODO, have a robust way to find it in O(1)
298 mc_mem_region_t MC_get_heap_region(mc_snapshot_t snapshot)
300 size_t n = snapshot->snapshot_regions.size();
301 for (size_t i=0; i!=n; ++i) {
302 mc_mem_region_t region = snapshot->snapshot_regions[i].get();
303 if (region->region_type() == simgrid::mc::RegionType::Heap)
306 xbt_die("No heap region");
309 int mmalloc_compare_heap(mc_snapshot_t snapshot1, mc_snapshot_t snapshot2)
311 simgrid::mc::Process* process = &mc_model_checker->process();
312 struct s_mc_diff *state = mc_diff_info;
314 /* Start comparison */
315 size_t i1, i2, j1, j2, k;
316 void *addr_block1, *addr_block2, *addr_frag1, *addr_frag2;
317 int nb_diff1 = 0, nb_diff2 = 0;
319 int equal, res_compare = 0;
321 /* Check busy blocks */
325 malloc_info heapinfo_temp1, heapinfo_temp2;
326 malloc_info heapinfo_temp2b;
328 mc_mem_region_t heap_region1 = MC_get_heap_region(snapshot1);
329 mc_mem_region_t heap_region2 = MC_get_heap_region(snapshot2);
331 // This is the address of std_heap->heapinfo in the application process:
332 void* heapinfo_address = &((xbt_mheap_t) process->heap_address)->heapinfo;
334 // This is in snapshot do not use them directly:
335 const malloc_info* heapinfos1 = snapshot1->read<malloc_info*>(
336 (std::uint64_t)heapinfo_address, simgrid::mc::ProcessIndexMissing);
337 const malloc_info* heapinfos2 = snapshot2->read<malloc_info*>(
338 (std::uint64_t)heapinfo_address, simgrid::mc::ProcessIndexMissing);
340 while (i1 <= state->heaplimit) {
342 const malloc_info* heapinfo1 = (const malloc_info*) MC_region_read(heap_region1, &heapinfo_temp1, &heapinfos1[i1], sizeof(malloc_info));
343 const malloc_info* heapinfo2 = (const malloc_info*) MC_region_read(heap_region2, &heapinfo_temp2, &heapinfos2[i1], sizeof(malloc_info));
345 if (heapinfo1->type == MMALLOC_TYPE_FREE || heapinfo1->type == MMALLOC_TYPE_HEAPINFO) { /* Free block */
350 if (heapinfo1->type < 0) {
351 fprintf(stderr, "Unkown mmalloc block type.\n");
356 ((void *) (((ADDR2UINT(i1)) - 1) * BLOCKSIZE +
357 (char *) state->std_heap_copy.heapbase));
359 if (heapinfo1->type == MMALLOC_TYPE_UNFRAGMENTED) { /* Large block */
361 if (is_stack(addr_block1)) {
362 for (k = 0; k < heapinfo1->busy_block.size; k++)
363 state->equals_to1_(i1 + k, 0) = make_heap_area(i1, -1);
364 for (k = 0; k < heapinfo2->busy_block.size; k++)
365 state->equals_to2_(i1 + k, 0) = make_heap_area(i1, -1);
366 i1 += heapinfo1->busy_block.size;
370 if (state->equals_to1_(i1, 0).valid) {
379 /* Try first to associate to same block in the other heap */
380 if (heapinfo2->type == heapinfo1->type) {
382 if (state->equals_to2_(i1, 0).valid == 0) {
384 addr_block2 = (ADDR2UINT(i1) - 1) * BLOCKSIZE +
385 (char *) state->std_heap_copy.heapbase;
388 compare_heap_area(simgrid::mc::ProcessIndexMissing, addr_block1, addr_block2, snapshot1, snapshot2,
391 if (res_compare != 1) {
392 for (k = 1; k < heapinfo2->busy_block.size; k++)
393 state->equals_to2_(i1 + k, 0) = make_heap_area(i1, -1);
394 for (k = 1; k < heapinfo1->busy_block.size; k++)
395 state->equals_to1_(i1 + k, 0) = make_heap_area(i1, -1);
397 i1 += heapinfo1->busy_block.size;
404 while (i2 <= state->heaplimit && !equal) {
406 addr_block2 = (ADDR2UINT(i2) - 1) * BLOCKSIZE +
407 (char *) state->std_heap_copy.heapbase;
414 const malloc_info* heapinfo2b = (const malloc_info*) MC_region_read(heap_region2, &heapinfo_temp2b, &heapinfos2[i2], sizeof(malloc_info));
416 if (heapinfo2b->type != MMALLOC_TYPE_UNFRAGMENTED) {
421 if (state->equals_to2_(i2, 0).valid) {
427 compare_heap_area(simgrid::mc::ProcessIndexMissing, addr_block1, addr_block2, snapshot1, snapshot2,
430 if (res_compare != 1) {
431 for (k = 1; k < heapinfo2b->busy_block.size; k++)
432 state->equals_to2_(i2 + k, 0) = make_heap_area(i1, -1);
433 for (k = 1; k < heapinfo1->busy_block.size; k++)
434 state->equals_to1_(i1 + k, 0) = make_heap_area(i2, -1);
436 i1 += heapinfo1->busy_block.size;
444 XBT_DEBUG("Block %zu not found (size_used = %zu, addr = %p)", i1,
445 heapinfo1->busy_block.busy_size, addr_block1);
446 i1 = state->heaplimit + 1;
451 } else { /* Fragmented block */
453 for (j1 = 0; j1 < (size_t) (BLOCKSIZE >> heapinfo1->type); j1++) {
455 if (heapinfo1->busy_frag.frag_size[j1] == -1) /* Free fragment */
458 if (state->equals_to1_(i1, j1).valid)
462 (void *) ((char *) addr_block1 + (j1 << heapinfo1->type));
467 /* Try first to associate to same fragment in the other heap */
468 if (heapinfo2->type == heapinfo1->type) {
470 if (state->equals_to2_(i1, j1).valid == 0) {
472 addr_block2 = (ADDR2UINT(i1) - 1) * BLOCKSIZE +
473 (char *) state->std_heap_copy.heapbase;
475 (void *) ((char *) addr_block2 +
476 (j1 << heapinfo2->type));
479 compare_heap_area(simgrid::mc::ProcessIndexMissing, addr_frag1, addr_frag2, snapshot1, snapshot2,
482 if (res_compare != 1)
489 while (i2 <= state->heaplimit && !equal) {
491 const malloc_info* heapinfo2b = (const malloc_info*) MC_region_read(
492 heap_region2, &heapinfo_temp2b, &heapinfos2[i2],
493 sizeof(malloc_info));
495 if (heapinfo2b->type == MMALLOC_TYPE_FREE || heapinfo2b->type == MMALLOC_TYPE_HEAPINFO) {
500 // We currently do not match fragments with unfragmented blocks (maybe we should).
501 if (heapinfo2b->type == MMALLOC_TYPE_UNFRAGMENTED) {
506 if (heapinfo2b->type < 0) {
507 fprintf(stderr, "Unkown mmalloc block type.\n");
511 for (j2 = 0; j2 < (size_t) (BLOCKSIZE >> heapinfo2b->type);
514 if (i2 == i1 && j2 == j1)
517 if (state->equals_to2_(i2, j2).valid)
520 addr_block2 = (ADDR2UINT(i2) - 1) * BLOCKSIZE +
521 (char *) state->std_heap_copy.heapbase;
523 (void *) ((char *) addr_block2 +
524 (j2 << heapinfo2b->type));
527 compare_heap_area(simgrid::mc::ProcessIndexMissing, addr_frag1, addr_frag2, snapshot2, snapshot2,
530 if (res_compare != 1) {
543 ("Block %zu, fragment %zu not found (size_used = %zd, address = %p)\n",
544 i1, j1, heapinfo1->busy_frag.frag_size[j1],
546 i2 = state->heaplimit + 1;
547 i1 = state->heaplimit + 1;
560 /* All blocks/fragments are equal to another block/fragment ? */
563 for(i = 1; i <= state->heaplimit; i++) {
564 const malloc_info* heapinfo1 = (const malloc_info*) MC_region_read(
565 heap_region1, &heapinfo_temp1, &heapinfos1[i], sizeof(malloc_info));
566 if (heapinfo1->type == MMALLOC_TYPE_UNFRAGMENTED) {
567 if (i1 == state->heaplimit) {
568 if (heapinfo1->busy_block.busy_size > 0) {
569 if (state->equals_to1_(i, 0).valid == 0) {
570 if (XBT_LOG_ISENABLED(mc_diff, xbt_log_priority_debug)) {
572 XBT_DEBUG("Block %zu not found (size used = %zu)", i,
573 heapinfo1->busy_block.busy_size);
574 //mmalloc_backtrace_block_display((void*)heapinfo1, i);
581 if (heapinfo1->type > 0) {
582 for (j = 0; j < (size_t) (BLOCKSIZE >> heapinfo1->type); j++) {
583 if (i1 == state->heaplimit) {
584 if (heapinfo1->busy_frag.frag_size[j] > 0) {
585 if (state->equals_to1_(i, j).valid == 0) {
586 if (XBT_LOG_ISENABLED(mc_diff, xbt_log_priority_debug)) {
587 // TODO, print fragment address
589 ("Block %zu, Fragment %zu not found (size used = %zd)",
591 heapinfo1->busy_frag.frag_size[j]);
592 //mmalloc_backtrace_fragment_display((void*)heapinfo1, i, j);
602 if (i1 == state->heaplimit)
603 XBT_DEBUG("Number of blocks/fragments not found in heap1 : %d", nb_diff1);
605 for (i=1; i <= state->heaplimit; i++) {
606 const malloc_info* heapinfo2 = (const malloc_info*) MC_region_read(
607 heap_region2, &heapinfo_temp2, &heapinfos2[i], sizeof(malloc_info));
608 if (heapinfo2->type == MMALLOC_TYPE_UNFRAGMENTED) {
609 if (i1 == state->heaplimit) {
610 if (heapinfo2->busy_block.busy_size > 0) {
611 if (state->equals_to2_(i, 0).valid == 0) {
612 if (XBT_LOG_ISENABLED(mc_diff, xbt_log_priority_debug)) {
613 // TODO, print address of the block
614 XBT_DEBUG("Block %zu not found (size used = %zu)", i,
615 heapinfo2->busy_block.busy_size);
616 //mmalloc_backtrace_block_display((void*)heapinfo2, i);
623 if (heapinfo2->type > 0) {
624 for (j = 0; j < (size_t) (BLOCKSIZE >> heapinfo2->type); j++) {
625 if (i1 == state->heaplimit) {
626 if (heapinfo2->busy_frag.frag_size[j] > 0) {
627 if (state->equals_to2_(i, j).valid == 0) {
628 if (XBT_LOG_ISENABLED(mc_diff, xbt_log_priority_debug)) {
629 // TODO, print address of the block
631 ("Block %zu, Fragment %zu not found (size used = %zd)",
633 heapinfo2->busy_frag.frag_size[j]);
634 //mmalloc_backtrace_fragment_display((void*)heapinfo2, i, j);
644 if (i1 == state->heaplimit)
645 XBT_DEBUG("Number of blocks/fragments not found in heap2 : %d", nb_diff2);
647 return ((nb_diff1 > 0) || (nb_diff2 > 0));
653 * @param real_area1 Process address for state 1
654 * @param real_area2 Process address for state 2
655 * @param snapshot1 Snapshot of state 1
656 * @param snapshot2 Snapshot of state 2
659 * @param check_ignore
661 static int compare_heap_area_without_type(struct s_mc_diff *state, int process_index,
662 const void *real_area1, const void *real_area2,
663 mc_snapshot_t snapshot1,
664 mc_snapshot_t snapshot2,
665 xbt_dynar_t previous, int size,
668 simgrid::mc::Process* process = &mc_model_checker->process();
671 const void *addr_pointed1, *addr_pointed2;
672 int pointer_align, res_compare;
673 ssize_t ignore1, ignore2;
675 mc_mem_region_t heap_region1 = MC_get_heap_region(snapshot1);
676 mc_mem_region_t heap_region2 = MC_get_heap_region(snapshot2);
680 if (check_ignore > 0) {
682 heap_comparison_ignore_size(state->to_ignore1,
683 (char *) real_area1 + i)) != -1) {
685 heap_comparison_ignore_size(state->to_ignore2,
686 (char *) real_area2 + i)) == ignore1) {
699 if (MC_snapshot_region_memcmp(((char *) real_area1) + i, heap_region1, ((char *) real_area2) + i, heap_region2, 1) != 0) {
701 pointer_align = (i / sizeof(void *)) * sizeof(void *);
702 addr_pointed1 = snapshot1->read(
703 remote((void**)((char *) real_area1 + pointer_align)), process_index);
704 addr_pointed2 = snapshot2->read(
705 remote((void**)((char *) real_area2 + pointer_align)), process_index);
707 if (process->in_maestro_stack(remote(addr_pointed1))
708 && process->in_maestro_stack(remote(addr_pointed2))) {
709 i = pointer_align + sizeof(void *);
711 } else if (addr_pointed1 > state->std_heap_copy.heapbase
712 && addr_pointed1 < mc_snapshot_get_heap_end(snapshot1)
713 && addr_pointed2 > state->std_heap_copy.heapbase
714 && addr_pointed2 < mc_snapshot_get_heap_end(snapshot2)) {
715 // Both addreses are in the heap:
717 compare_heap_area(process_index, addr_pointed1, addr_pointed2, snapshot1,
718 snapshot2, previous, NULL, 0);
719 if (res_compare == 1) {
722 i = pointer_align + sizeof(void *);
741 * @param real_area1 Process address for state 1
742 * @param real_area2 Process address for state 2
743 * @param snapshot1 Snapshot of state 1
744 * @param snapshot2 Snapshot of state 2
747 * @param area_size either a byte_size or an elements_count (?)
748 * @param check_ignore
749 * @param pointer_level
750 * @return 0 (same), 1 (different), -1 (unknown)
752 static int compare_heap_area_with_type(struct s_mc_diff *state, int process_index,
753 const void *real_area1, const void *real_area2,
754 mc_snapshot_t snapshot1,
755 mc_snapshot_t snapshot2,
756 xbt_dynar_t previous, simgrid::mc::Type* type,
757 int area_size, int check_ignore,
761 // HACK: This should not happen but in pratice, there is some
762 // DW_TAG_typedef without DW_AT_type. We should fix this somehow.
766 if (is_stack(real_area1) && is_stack(real_area2))
768 ssize_t ignore1, ignore2;
770 if ((check_ignore > 0)
771 && ((ignore1 = heap_comparison_ignore_size(state->to_ignore1, real_area1))
773 && ((ignore2 = heap_comparison_ignore_size(state->to_ignore2, real_area2))
778 simgrid::mc::Type *subtype, *subsubtype;
780 const void *addr_pointed1, *addr_pointed2;
782 mc_mem_region_t heap_region1 = MC_get_heap_region(snapshot1);
783 mc_mem_region_t heap_region2 = MC_get_heap_region(snapshot2);
785 switch (type->type) {
786 case DW_TAG_unspecified_type:
789 case DW_TAG_base_type:
790 if (!type->name.empty() && type->name == "char") { /* String, hence random (arbitrary ?) size */
791 if (real_area1 == real_area2)
794 return (MC_snapshot_region_memcmp(real_area1, heap_region1, real_area2, heap_region2, area_size) != 0);
796 if (area_size != -1 && type->byte_size != area_size)
799 return (MC_snapshot_region_memcmp(real_area1, heap_region1, real_area2, heap_region2, type->byte_size) != 0);
803 case DW_TAG_enumeration_type:
804 if (area_size != -1 && type->byte_size != area_size)
807 return (MC_snapshot_region_memcmp(real_area1, heap_region1, real_area2, heap_region2, type->byte_size) != 0);
810 case DW_TAG_const_type:
811 case DW_TAG_volatile_type:
813 type = type->subtype;
816 case DW_TAG_array_type:
817 subtype = type->subtype;
818 switch (subtype->type) {
819 case DW_TAG_unspecified_type:
822 case DW_TAG_base_type:
823 case DW_TAG_enumeration_type:
824 case DW_TAG_pointer_type:
825 case DW_TAG_reference_type:
826 case DW_TAG_rvalue_reference_type:
827 case DW_TAG_structure_type:
828 case DW_TAG_class_type:
829 case DW_TAG_union_type:
830 if (subtype->full_type)
831 subtype = subtype->full_type;
832 elm_size = subtype->byte_size;
834 // TODO, just remove the type indirection?
835 case DW_TAG_const_type:
837 case DW_TAG_volatile_type:
838 subsubtype = subtype->subtype;
839 if (subsubtype->full_type)
840 subsubtype = subsubtype->full_type;
841 elm_size = subsubtype->byte_size;
847 for (int i = 0; i < type->element_count; i++) {
848 // TODO, add support for variable stride (DW_AT_byte_stride)
850 compare_heap_area_with_type(state, process_index,
851 (char *) real_area1 + (i * elm_size),
852 (char *) real_area2 + (i * elm_size),
853 snapshot1, snapshot2, previous,
854 type->subtype, subtype->byte_size,
855 check_ignore, pointer_level);
860 case DW_TAG_reference_type:
861 case DW_TAG_rvalue_reference_type:
862 case DW_TAG_pointer_type:
863 if (type->subtype && type->subtype->type == DW_TAG_subroutine_type) {
864 addr_pointed1 = snapshot1->read(remote((void**)real_area1), process_index);
865 addr_pointed2 = snapshot2->read(remote((void**)real_area2), process_index);
866 return (addr_pointed1 != addr_pointed2);;
869 if (pointer_level > 1) { /* Array of pointers */
870 for (size_t i = 0; i < (area_size / sizeof(void *)); i++) {
871 addr_pointed1 = snapshot1->read(
872 remote((void**)((char*) real_area1 + i * sizeof(void *))),
874 addr_pointed2 = snapshot2->read(
875 remote((void**)((char*) real_area2 + i * sizeof(void *))),
877 if (addr_pointed1 > state->std_heap_copy.heapbase
878 && addr_pointed1 < mc_snapshot_get_heap_end(snapshot1)
879 && addr_pointed2 > state->std_heap_copy.heapbase
880 && addr_pointed2 < mc_snapshot_get_heap_end(snapshot2))
882 compare_heap_area(process_index, addr_pointed1, addr_pointed2, snapshot1,
883 snapshot2, previous, type->subtype,
886 res = (addr_pointed1 != addr_pointed2);
891 addr_pointed1 = snapshot1->read(remote((void**)real_area1), process_index);
892 addr_pointed2 = snapshot2->read(remote((void**)real_area2), process_index);
893 if (addr_pointed1 > state->std_heap_copy.heapbase
894 && addr_pointed1 < mc_snapshot_get_heap_end(snapshot1)
895 && addr_pointed2 > state->std_heap_copy.heapbase
896 && addr_pointed2 < mc_snapshot_get_heap_end(snapshot2))
897 return compare_heap_area(process_index, addr_pointed1, addr_pointed2, snapshot1,
898 snapshot2, previous, type->subtype,
901 return (addr_pointed1 != addr_pointed2);
905 case DW_TAG_structure_type:
906 case DW_TAG_class_type:
908 type = type->full_type;
909 if (area_size != -1 && type->byte_size != area_size) {
910 if (area_size > type->byte_size && area_size % type->byte_size == 0) {
911 for (size_t i = 0; i < (size_t)(area_size / type->byte_size); i++) {
913 compare_heap_area_with_type(state, process_index,
914 (char *) real_area1 + i * type->byte_size,
915 (char *) real_area2 + i * type->byte_size,
916 snapshot1, snapshot2, previous, type, -1,
925 for(simgrid::mc::Member& member : type->members) {
926 // TODO, optimize this? (for the offset case)
927 void *real_member1 = simgrid::dwarf::resolve_member(
928 real_area1, type, &member, (simgrid::mc::AddressSpace*) snapshot1, process_index);
929 void *real_member2 = simgrid::dwarf::resolve_member(
930 real_area2, type, &member, (simgrid::mc::AddressSpace*) snapshot2, process_index);
932 compare_heap_area_with_type(state, process_index, real_member1, real_member2,
933 snapshot1, snapshot2,
934 previous, member.type, -1,
942 case DW_TAG_union_type:
943 return compare_heap_area_without_type(state, process_index, real_area1, real_area2,
944 snapshot1, snapshot2, previous,
945 type->byte_size, check_ignore);
955 /** Infer the type of a part of the block from the type of the block
957 * TODO, handle DW_TAG_array_type as well as arrays of the object ((*p)[5], p[5])
959 * TODO, handle subfields ((*p).bar.foo, (*p)[5].bar…)
961 * @param type_id DWARF type ID of the root address
963 * @return DWARF type ID for given offset
965 static simgrid::mc::Type* get_offset_type(void *real_base_address, simgrid::mc::Type* type,
966 int offset, int area_size,
967 mc_snapshot_t snapshot, int process_index)
970 // Beginning of the block, the infered variable type if the type of the block:
974 switch (type->type) {
975 case DW_TAG_structure_type:
976 case DW_TAG_class_type:
978 type = type->full_type;
980 if (area_size != -1 && type->byte_size != area_size) {
981 if (area_size > type->byte_size && area_size % type->byte_size == 0)
986 for(simgrid::mc::Member& member : type->members) {
988 if (member.has_offset_location()) {
989 // We have the offset, use it directly (shortcut):
990 if (member.offset() == offset)
993 void *real_member = simgrid::dwarf::resolve_member(
994 real_base_address, type, &member, snapshot, process_index);
995 if ((char*) real_member - (char *) real_base_address == offset)
1004 /* FIXME : other cases ? */
1012 * @param area1 Process address for state 1
1013 * @param area2 Process address for state 2
1014 * @param snapshot1 Snapshot of state 1
1015 * @param snapshot2 Snapshot of state 2
1016 * @param previous Pairs of blocks already compared on the current path (or NULL)
1017 * @param type_id Type of variable
1018 * @param pointer_level
1019 * @return 0 (same), 1 (different), -1
1021 int compare_heap_area(int process_index, const void *area1, const void *area2, mc_snapshot_t snapshot1,
1022 mc_snapshot_t snapshot2, xbt_dynar_t previous,
1023 simgrid::mc::Type* type, int pointer_level)
1025 simgrid::mc::Process* process = &mc_model_checker->process();
1027 struct s_mc_diff *state = mc_diff_info;
1030 ssize_t block1, frag1, block2, frag2;
1032 int check_ignore = 0;
1034 void *real_addr_block1, *real_addr_block2, *real_addr_frag1, *real_addr_frag2;
1036 int offset1 = 0, offset2 = 0;
1037 int new_size1 = -1, new_size2 = -1;
1038 simgrid::mc::Type *new_type1 = NULL, *new_type2 = NULL;
1040 int match_pairs = 0;
1042 // This is the address of std_heap->heapinfo in the application process:
1043 void* heapinfo_address = &((xbt_mheap_t) process->heap_address)->heapinfo;
1045 const malloc_info* heapinfos1 = snapshot1->read(
1046 remote((const malloc_info**)heapinfo_address), process_index);
1047 const malloc_info* heapinfos2 = snapshot2->read(
1048 remote((const malloc_info**)heapinfo_address), process_index);
1050 malloc_info heapinfo_temp1, heapinfo_temp2;
1052 if (previous == NULL) {
1054 xbt_dynar_new(sizeof(heap_area_pair_t), heap_area_pair_free_voidp);
1057 // Get block number:
1060 (char *) state->std_heap_copy.heapbase) / BLOCKSIZE + 1;
1063 (char *) state->std_heap_copy.heapbase) / BLOCKSIZE + 1;
1065 // If either block is a stack block:
1066 if (is_block_stack((int) block1) && is_block_stack((int) block2)) {
1067 add_heap_area_pair(previous, block1, -1, block2, -1);
1069 match_equals(state, previous);
1070 xbt_dynar_free(&previous);
1074 // If either block is not in the expected area of memory:
1075 if (((char *) area1 < (char *) state->std_heap_copy.heapbase)
1076 || (block1 > (ssize_t) state->heapsize1) || (block1 < 1)
1077 || ((char *) area2 < (char *) state->std_heap_copy.heapbase)
1078 || (block2 > (ssize_t) state->heapsize2) || (block2 < 1)) {
1080 xbt_dynar_free(&previous);
1085 // Process address of the block:
1086 real_addr_block1 = (ADDR2UINT(block1) - 1) * BLOCKSIZE +
1087 (char *) state->std_heap_copy.heapbase;
1088 real_addr_block2 = (ADDR2UINT(block2) - 1) * BLOCKSIZE +
1089 (char *) state->std_heap_copy.heapbase;
1093 if (type->full_type)
1094 type = type->full_type;
1096 // This assume that for "boring" types (volatile ...) byte_size is absent:
1097 while (type->byte_size == 0 && type->subtype != NULL)
1098 type = type->subtype;
1101 if ((type->type == DW_TAG_pointer_type)
1102 || ((type->type == DW_TAG_base_type) && !type->name.empty()
1103 && type->name == "char"))
1106 type_size = type->byte_size;
1110 mc_mem_region_t heap_region1 = MC_get_heap_region(snapshot1);
1111 mc_mem_region_t heap_region2 = MC_get_heap_region(snapshot2);
1113 const malloc_info* heapinfo1 = (const malloc_info*) MC_region_read(
1114 heap_region1, &heapinfo_temp1, &heapinfos1[block1], sizeof(malloc_info));
1115 const malloc_info* heapinfo2 = (const malloc_info*) MC_region_read(
1116 heap_region2, &heapinfo_temp2, &heapinfos2[block2], sizeof(malloc_info));
1118 if ((heapinfo1->type == MMALLOC_TYPE_FREE || heapinfo1->type==MMALLOC_TYPE_HEAPINFO)
1119 && (heapinfo2->type == MMALLOC_TYPE_FREE || heapinfo2->type ==MMALLOC_TYPE_HEAPINFO)) {
1123 match_equals(state, previous);
1124 xbt_dynar_free(&previous);
1128 } else if (heapinfo1->type == MMALLOC_TYPE_UNFRAGMENTED
1129 && heapinfo2->type == MMALLOC_TYPE_UNFRAGMENTED) {
1130 /* Complete block */
1132 // TODO, lookup variable type from block type as done for fragmented blocks
1134 offset1 = (char *) area1 - (char *) real_addr_block1;
1135 offset2 = (char *) area2 - (char *) real_addr_block2;
1137 if (state->equals_to1_(block1, 0).valid
1138 && state->equals_to2_(block2, 0).valid) {
1139 if (equal_blocks(state, block1, block2)) {
1141 match_equals(state, previous);
1142 xbt_dynar_free(&previous);
1148 if (type_size != -1) {
1149 if (type_size != (ssize_t) heapinfo1->busy_block.busy_size
1150 && type_size != (ssize_t) heapinfo2->busy_block.busy_size
1151 && (type->name.empty() || type->name == "struct s_smx_context")) {
1153 match_equals(state, previous);
1154 xbt_dynar_free(&previous);
1160 if (heapinfo1->busy_block.size !=
1161 heapinfo2->busy_block.size) {
1163 xbt_dynar_free(&previous);
1168 if (heapinfo1->busy_block.busy_size !=
1169 heapinfo2->busy_block.busy_size) {
1171 xbt_dynar_free(&previous);
1176 if (!add_heap_area_pair(previous, block1, -1, block2, -1)) {
1178 match_equals(state, previous);
1179 xbt_dynar_free(&previous);
1184 size = heapinfo1->busy_block.busy_size;
1186 // Remember (basic) type inference.
1187 // The current data structure only allows us to do this for the whole block.
1188 if (type != NULL && area1 == real_addr_block1) {
1189 state->types1_(block1, 0) = type;
1191 if (type != NULL && area2 == real_addr_block2) {
1192 state->types2_(block2, 0) = type;
1197 match_equals(state, previous);
1198 xbt_dynar_free(&previous);
1206 if ((heapinfo1->busy_block.ignore > 0)
1207 && (heapinfo2->busy_block.ignore ==
1208 heapinfo1->busy_block.ignore))
1209 check_ignore = heapinfo1->busy_block.ignore;
1211 } else if ((heapinfo1->type > 0) && (heapinfo2->type > 0)) { /* Fragmented block */
1215 ((uintptr_t) (ADDR2UINT(area1) % (BLOCKSIZE))) >> heapinfo1->type;
1217 ((uintptr_t) (ADDR2UINT(area2) % (BLOCKSIZE))) >> heapinfo2->type;
1219 // Process address of the fragment:
1221 (void *) ((char *) real_addr_block1 +
1222 (frag1 << heapinfo1->type));
1224 (void *) ((char *) real_addr_block2 +
1225 (frag2 << heapinfo2->type));
1227 // Check the size of the fragments against the size of the type:
1228 if (type_size != -1) {
1229 if (heapinfo1->busy_frag.frag_size[frag1] == -1
1230 || heapinfo2->busy_frag.frag_size[frag2] == -1) {
1232 match_equals(state, previous);
1233 xbt_dynar_free(&previous);
1238 if (type_size != heapinfo1->busy_frag.frag_size[frag1]
1239 || type_size != heapinfo2->busy_frag.frag_size[frag2]) {
1241 match_equals(state, previous);
1242 xbt_dynar_free(&previous);
1248 // Check if the blocks are already matched together:
1249 if (state->equals_to1_(block1, frag1).valid
1250 && state->equals_to2_(block2, frag2).valid) {
1251 if (offset1==offset2 && equal_fragments(state, block1, frag1, block2, frag2)) {
1253 match_equals(state, previous);
1254 xbt_dynar_free(&previous);
1259 // Compare the size of both fragments:
1260 if (heapinfo1->busy_frag.frag_size[frag1] !=
1261 heapinfo2->busy_frag.frag_size[frag2]) {
1262 if (type_size == -1) {
1264 match_equals(state, previous);
1265 xbt_dynar_free(&previous);
1270 xbt_dynar_free(&previous);
1276 // Size of the fragment:
1277 size = heapinfo1->busy_frag.frag_size[frag1];
1279 // Remember (basic) type inference.
1280 // The current data structure only allows us to do this for the whole fragment.
1281 if (type != NULL && area1 == real_addr_frag1) {
1282 state->types1_(block1, frag1) = type;
1284 if (type != NULL && area2 == real_addr_frag2) {
1285 state->types2_(block2, frag2) = type;
1287 // The type of the variable is already known:
1292 // Type inference from the block type.
1293 else if (state->types1_(block1, frag1) != NULL
1294 || state->types2_(block2, frag2) != NULL) {
1296 offset1 = (char *) area1 - (char *) real_addr_frag1;
1297 offset2 = (char *) area2 - (char *) real_addr_frag2;
1299 if (state->types1_(block1, frag1) != NULL
1300 && state->types2_(block2, frag2) != NULL) {
1302 get_offset_type(real_addr_frag1, state->types1_(block1, frag1),
1303 offset1, size, snapshot1, process_index);
1305 get_offset_type(real_addr_frag2, state->types2_(block2, frag2),
1306 offset1, size, snapshot2, process_index);
1307 } else if (state->types1_(block1, frag1) != NULL) {
1309 get_offset_type(real_addr_frag1, state->types1_(block1, frag1),
1310 offset1, size, snapshot1, process_index);
1312 get_offset_type(real_addr_frag2, state->types1_(block1, frag1),
1313 offset2, size, snapshot2, process_index);
1314 } else if (state->types2_(block2, frag2) != NULL) {
1316 get_offset_type(real_addr_frag1, state->types2_(block2, frag2),
1317 offset1, size, snapshot1, process_index);
1319 get_offset_type(real_addr_frag2, state->types2_(block2, frag2),
1320 offset2, size, snapshot2, process_index);
1323 match_equals(state, previous);
1324 xbt_dynar_free(&previous);
1329 if (new_type1 != NULL && new_type2 != NULL && new_type1 != new_type2) {
1332 while (type->byte_size == 0 && type->subtype != NULL)
1333 type = type->subtype;
1334 new_size1 = type->byte_size;
1337 while (type->byte_size == 0 && type->subtype != NULL)
1338 type = type->subtype;
1339 new_size2 = type->byte_size;
1343 match_equals(state, previous);
1344 xbt_dynar_free(&previous);
1350 if (new_size1 > 0 && new_size1 == new_size2) {
1355 if (offset1 == 0 && offset2 == 0) {
1356 if (!add_heap_area_pair(previous, block1, frag1, block2, frag2)) {
1358 match_equals(state, previous);
1359 xbt_dynar_free(&previous);
1367 match_equals(state, previous);
1368 xbt_dynar_free(&previous);
1373 if ((heapinfo1->busy_frag.ignore[frag1] > 0)
1374 && (heapinfo2->busy_frag.ignore[frag2] ==
1375 heapinfo1->busy_frag.ignore[frag1]))
1376 check_ignore = heapinfo1->busy_frag.ignore[frag1];
1381 xbt_dynar_free(&previous);
1388 /* Start comparison */
1391 compare_heap_area_with_type(state, process_index, area1, area2, snapshot1, snapshot2,
1392 previous, type, size, check_ignore,
1396 compare_heap_area_without_type(state, process_index, area1, area2, snapshot1, snapshot2,
1397 previous, size, check_ignore);
1399 if (res_compare == 1) {
1401 xbt_dynar_free(&previous);
1406 match_equals(state, previous);
1407 xbt_dynar_free(&previous);
1413 /*********************************************** Miscellaneous ***************************************************/
1414 /****************************************************************************************************************/
1416 // Not used and broken code:
1420 static int get_pointed_area_size(void *area, int heap)
1423 struct s_mc_diff *state = mc_diff_info;
1426 malloc_info *heapinfo;
1429 heapinfo = state->heapinfo1;
1431 heapinfo = state->heapinfo2;
1435 (char *) state->std_heap_copy.heapbase) / BLOCKSIZE + 1;
1437 if (((char *) area < (char *) state->std_heap_copy.heapbase)
1438 || (block > state->heapsize1) || (block < 1))
1441 if (heapinfo[block].type == MMALLOC_TYPE_FREE || heapinfo[block].type == MMALLOC_TYPE_HEAPINFO) { /* Free block */
1443 } else if (heapinfo[block].type == MMALLOC_TYPE_UNFRAGMENTED) { /* Complete block */
1444 return (int) heapinfo[block].busy_block.busy_size;
1447 ((uintptr_t) (ADDR2UINT(area) % (BLOCKSIZE))) >> heapinfo[block].type;
1448 return (int) heapinfo[block].busy_frag.frag_size[frag];
1453 #define max( a, b ) ( ((a) > (b)) ? (a) : (b) )
1457 int mmalloc_linear_compare_heap(xbt_mheap_t heap1, xbt_mheap_t heap2)
1460 struct s_mc_diff *state = mc_diff_info;
1462 if (heap1 == NULL && heap1 == NULL) {
1463 XBT_DEBUG("Malloc descriptors null");
1467 if (heap1->heaplimit != heap2->heaplimit) {
1468 XBT_DEBUG("Different limit of valid info table indices");
1472 /* Heap information */
1473 state->heaplimit = ((struct mdesc *) heap1)->heaplimit;
1475 state->std_heap_copy = *mc_model_checker->process().get_heap();
1477 state->heapbase1 = (char *) heap1 + BLOCKSIZE;
1478 state->heapbase2 = (char *) heap2 + BLOCKSIZE;
1481 (malloc_info *) ((char *) heap1 +
1483 ((char *) heap1->heapinfo - (char *) state->s_heap)));
1485 (malloc_info *) ((char *) heap2 +
1487 ((char *) heap2->heapinfo - (char *) state->s_heap)));
1489 state->heapsize1 = heap1->heapsize;
1490 state->heapsize2 = heap2->heapsize;
1492 /* Start comparison */
1494 void *addr_block1, *addr_block2, *addr_frag1, *addr_frag2;
1498 /* Check busy blocks */
1502 while (i <= state->heaplimit) {
1505 ((void *) (((ADDR2UINT(i)) - 1) * BLOCKSIZE +
1506 (char *) state->heapbase1));
1508 ((void *) (((ADDR2UINT(i)) - 1) * BLOCKSIZE +
1509 (char *) state->heapbase2));
1511 if (state->heapinfo1[i].type != state->heapinfo2[i].type) {
1513 distance += BLOCKSIZE;
1514 XBT_DEBUG("Different type of blocks (%zu) : %d - %d -> distance = %d", i,
1515 state->heapinfo1[i].type, state->heapinfo2[i].type, distance);
1520 if (state->heapinfo1[i].type == MMALLOC_TYPE_FREE
1521 || state->heapinfo1[i].type == MMALLOC_TYPE_HAPINFO) { /* Free block */
1526 if (state->heapinfo1[i].type == MMALLOC_TYPE_UNFRAGMENTED) { /* Large block */
1528 if (state->heapinfo1[i].busy_block.size !=
1529 state->heapinfo2[i].busy_block.size) {
1531 BLOCKSIZE * max(state->heapinfo1[i].busy_block.size,
1532 state->heapinfo2[i].busy_block.size);
1533 i += max(state->heapinfo1[i].busy_block.size,
1534 state->heapinfo2[i].busy_block.size);
1536 ("Different larger of cluster at block %zu : %zu - %zu -> distance = %d",
1537 i, state->heapinfo1[i].busy_block.size,
1538 state->heapinfo2[i].busy_block.size, distance);
1542 /*if(heapinfo1[i].busy_block.busy_size != heapinfo2[i].busy_block.busy_size){
1543 distance += max(heapinfo1[i].busy_block.busy_size, heapinfo2[i].busy_block.busy_size);
1544 i += max(heapinfo1[i].busy_block.size, heapinfo2[i].busy_block.size);
1545 XBT_DEBUG("Different size used oin large cluster at block %zu : %zu - %zu -> distance = %d", i, heapinfo1[i].busy_block.busy_size, heapinfo2[i].busy_block.busy_size, distance);
1551 //while(k < (heapinfo1[i].busy_block.busy_size)){
1552 while (k < state->heapinfo1[i].busy_block.size * BLOCKSIZE) {
1553 if (memcmp((char *) addr_block1 + k, (char *) addr_block2 + k, 1) !=
1562 } else { /* Fragmented block */
1564 for (j = 0; j < (size_t) (BLOCKSIZE >> state->heapinfo1[i].type); j++) {
1567 (void *) ((char *) addr_block1 + (j << state->heapinfo1[i].type));
1569 (void *) ((char *) addr_block2 + (j << state->heapinfo2[i].type));
1571 if (state->heapinfo1[i].busy_frag.frag_size[j] == 0
1572 && state->heapinfo2[i].busy_frag.frag_size[j] == 0) {
1577 /*if(heapinfo1[i].busy_frag.frag_size[j] != heapinfo2[i].busy_frag.frag_size[j]){
1578 distance += max(heapinfo1[i].busy_frag.frag_size[j], heapinfo2[i].busy_frag.frag_size[j]);
1579 XBT_DEBUG("Different size used in fragment %zu in block %zu : %d - %d -> distance = %d", j, i, heapinfo1[i].busy_frag.frag_size[j], heapinfo2[i].busy_frag.frag_size[j], distance);
1585 //while(k < max(heapinfo1[i].busy_frag.frag_size[j], heapinfo2[i].busy_frag.frag_size[j])){
1586 while (k < (BLOCKSIZE / (BLOCKSIZE >> state->heapinfo1[i].type))) {
1587 if (memcmp((char *) addr_frag1 + k, (char *) addr_frag2 + k, 1) !=