You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
LLVM frontend: the importer recovers pointer element types from the debug
information (previously every pointer was translated to opaque*, losing
signedness and layouts), types allocas from llvm.dbg.declare only (a llvm.dbg.value on an array made the array a scalar), and handles anonymous typedef struct types, class templates, C++ empty bases and [[no_unique_address]] members, pointers to members, empty parameters
dropped by clang, llvm.global_ctors, and glibc symbol aliases. The ikos-import regression tests are regenerated from upstream's expectations; var-args.ll, vla.ll and virtual-inheritance.ll are no longer skipped.
ikos-pp lowers sized and aligned operator new/operator delete (default
in clang 19+, including their 32-bit manglings) so that dfa, boa and uaf see them; the std::thread modeling pass no longer crashes on invoke instructions, including for pthread_once.
LLVM frontend: an alloca is no longer typed from the debug information of
another variable (a reference bound to a temporary made the allocation too
small, or opaque); classes passed by reference are matched against every
structure type of the module with the same name, whatever its .<n> suffix.
Composite scalar domain: the taint component was widened and narrowed twice
and the taint of assigned integers was forgotten.
Buffer overflow checker: no more assertion failure on zero-sized element
types.
Value analysis: the models of read, gets and fgets wrote a literal zero
byte into the buffer, hiding bugs from every checker.
Analysis engine: a pointer to a local variable returned by a function is now
matched with the result of the call, so use-after-return through return &x
is detected.
Taint analysis: tainted memory is tracked per memory location (definitely and
possibly tainted), taint propagates through operations, unknown functions, strdup, strndup, memcpy, memmove and the string functions, sinks
receiving possibly tainted data are warnings, sources in the configuration
are honored (including scanf, recv, getline), and -a=taint requires
a taint configuration. Unknown functions no longer clear the taint of the
buffers they receive, overwriting a buffer with untainted data (strcpy, sprintf, memset) makes it possibly tainted only, string literals and
other constants are never tainted, and integers loaded from memory carry the
taint of their cell.
Concurrency checker: rewritten as a lockset analysis with a thread count; no
crash on unknown pointers or without pointer analysis; std::mutex and lock
guards recognized by name (including guards over mutex types with nested
names); single-threaded code is not reported.
Use-after-free checker: unknown, null and uninitialized pointers are left to
the other checkers, use-after-return is only reported for local variables.
Use-after-move checker: rewritten on top of the value analysis (dereference
of a null pointer loaded from a moved-from object) instead of a global set of
moved locations; no hardcoded class names; reassigned objects are not
reported.
ikos-report and ikos-view no longer crash on the new check kinds; ikos-report -t no longer crashes on a database without timing results; the
SARIF rules are the check kinds, so that every result refers to a declared
rule; ikos-view check kind filters work and malformed filters are ignored; ikos-serve uses the right columns and reports a missing database at
startup; ikos-scan --taint keeps the default analyses; the taint
configuration is only passed to the analyzer when the taint analysis is
enabled, and ikos warns when --taint-config or --taint-profile is given
without it.
script/regen_checks.py: leading output lines are kept, CHECK-LABEL
lines are regenerated correctly when the label changes, tests without CHECK
lines are supported, failures to run the tools are reported, and the tools
can be given with --ikos-import and --file-check.
Packaging: the python virtual environment is created in the staging
directory when make install runs with DESTDIR, so the Debian package
contains it; the package installs under /opt/nikos, links the tools into /usr/bin and depends on clang-20 and llvm-20; the continuous
integration builds, checks and publishes it for tagged releases; script/install.sh installs the latest release on Ubuntu 24.04; the Docker
image builds again (LLVM apt repository in both stages, python3-venv);
versions taken from the project version; RPM file list matches the install
tree; LLVM apt repository key handled without apt-key.
Changed
uaf is no longer part of the default analyses of the ikos driver (boa
already reports use after free and use after return).
fastapi and uvicorn are optional (pip install ikos[serve]); nikos-bridge summarizes a SARIF report and no longer modifies sources.
Removed the IKOS 3.0 installation guides, the old distribution Dockerfiles, script/bootstrap, the duplicated test/taint directory and the tracked
build artifacts.