blob: 665195565d30b1fced8ffdcd75f7a3d11fbd547a [file] [log] [blame]
Ted Kremenek033a07e2011-08-03 23:14:55 +00001// RUN: %clang_cc1 -Wno-array-bounds -analyze -analyzer-checker=core,experimental.unix,experimental.security.ArrayBound -analyzer-store=region -verify %s
Zhongxing Xu3ed04d32010-01-18 08:54:31 +00002
3typedef __typeof(sizeof(int)) size_t;
4void *malloc(size_t);
Zhongxing Xua5ce9662010-06-01 03:01:33 +00005void *calloc(size_t, size_t);
Zhongxing Xu20f01782008-11-24 02:19:49 +00006
7char f1() {
8 char* s = "abcd";
Ted Kremenekf9e96842009-01-22 20:36:33 +00009 char c = s[4]; // no-warning
Zhongxing Xu58e689f2009-11-11 12:33:27 +000010 return s[5] + c; // expected-warning{{Access out-of-bound array element (buffer overflow)}}
Zhongxing Xu20f01782008-11-24 02:19:49 +000011}
Zhongxing Xu3ed04d32010-01-18 08:54:31 +000012
13void f2() {
14 int *p = malloc(12);
15 p[3] = 4; // expected-warning{{Access out-of-bound array element (buffer overflow)}}
16}
Zhongxing Xu9618b852010-04-01 08:20:27 +000017
18struct three_words {
19 int c[3];
20};
21
22struct seven_words {
23 int c[7];
24};
25
26void f3() {
27 struct three_words a, *p;
28 p = &a;
29 p[0] = a; // no-warning
30 p[1] = a; // expected-warning{{Access out-of-bound array element (buffer overflow)}}
31}
32
33void f4() {
34 struct seven_words c;
35 struct three_words a, *p = (struct three_words *)&c;
36 p[0] = a; // no-warning
37 p[1] = a; // no-warning
38 p[2] = a; // expected-warning{{Access out-of-bound array element (buffer overflow)}}
39}
Zhongxing Xua5ce9662010-06-01 03:01:33 +000040
41void f5() {
42 char *p = calloc(2,2);
43 p[3] = '.'; // no-warning
44 p[4] = '!'; // expected-warning{{out-of-bound}}
45}
Jordy Rose4d912b22010-06-25 23:23:04 +000046
47void f6() {
48 char a[2];
49 int *b = (int*)a;
50 b[1] = 3; // expected-warning{{out-of-bound}}
51}
Jordy Rose32f26562010-07-04 00:00:41 +000052
53void f7() {
54 struct three_words a;
55 a.c[3] = 1; // expected-warning{{out-of-bound}}
56}
Jordy Rose52e04c52010-07-05 00:50:15 +000057
58void vla(int a) {
59 if (a == 5) {
60 int x[a];
61 x[4] = 4; // no-warning
62 x[5] = 5; // expected-warning{{out-of-bound}}
63 }
64}
Jordy Roseb7e3aab2010-07-05 04:42:43 +000065
66void sizeof_vla(int a) {
67 if (a == 5) {
68 char x[a];
69 int y[sizeof(x)];
70 y[4] = 4; // no-warning
71 y[5] = 5; // expected-warning{{out-of-bound}}
72 }
73}
Jordy Rose8556cc42010-08-14 20:46:10 +000074
75void alloca_region(int a) {
76 if (a == 5) {
77 char *x = __builtin_alloca(a);
78 x[4] = 4; // no-warning
79 x[5] = 5; // expected-warning{{out-of-bound}}
80 }
81}
Jordy Rosee7011172010-08-16 01:15:17 +000082
83int symbolic_index(int a) {
84 int x[2] = {1, 2};
85 if (a == 2) {
86 return x[a]; // expected-warning{{out-of-bound}}
87 }
88 return 0;
89}
90
91int symbolic_index2(int a) {
92 int x[2] = {1, 2};
93 if (a < 0) {
94 return x[a]; // expected-warning{{out-of-bound}}
95 }
96 return 0;
97}