wala/ML

Callable identification should be further up the analysis

开放

#207 创建于 2024年7月19日

 (0 条评论) (0 个反应) (0 位负责人)Java (17 个派生)auto 404
enhancementhelp wanted

仓库指标

星标
 (27 个星标)
PR 合并指标
 (PR 指标待抓取)

描述

Related to https://github.com/wala/WALA/discussions/1417#discussioncomment-10085680

In the current callable identification code, we are seeing imprecision in identifing the callable when there's multiple possible receivers according to the PA. This could happen for a number of reasons (one test case is added in https://github.com/ponder-lab/ML/pull/121), but what we are seeing is that if the call stack is sufficiently deep, we lose the ability to distinguish objects in the PA. Another reason could be due to dynamic dispatch, though we haven't tested it yet.

The reason we are using PA in the first place is because the receiver comes to use as just an object with no other information. If we explicitly call __call__(), the receiver is instead a trampoline. Thus, it would seem to me that calls to objects need to be distinguished before we get to com.ibm.wala.ipa.callgraph.MethodTargetSelector.getCalleeTarget(). In other words, while this method works for a bunch of cases, I don't think it's the correct place to do it properly. Instead, we should figure out how to make the receiver the same as it was called explicitly.`

贡献者指南