blob: 932a6f5945f28af0b0b14438974d9f5a93cfdab6 [file] [log] [blame]
Ted Kremenekdb09a4d2008-07-03 04:29:21 +00001//==- CheckObjCDealloc.cpp - Check ObjC -dealloc implementation --*- C++ -*-==//
2//
3// The LLVM Compiler Infrastructure
4//
5// This file is distributed under the University of Illinois Open Source
6// License. See LICENSE.TXT for details.
7//
8//===----------------------------------------------------------------------===//
9//
Ted Kremenek078c0bc2008-07-11 20:53:14 +000010// This file defines a CheckObjCDealloc, a checker that
11// analyzes an Objective-C class's implementation to determine if it
12// correctly implements -dealloc.
Ted Kremenekdb09a4d2008-07-03 04:29:21 +000013//
14//===----------------------------------------------------------------------===//
15
Ted Kremenek21142582010-12-23 19:38:26 +000016#include "clang/StaticAnalyzer/Checkers/LocalCheckers.h"
17#include "clang/StaticAnalyzer/BugReporter/PathDiagnostic.h"
18#include "clang/StaticAnalyzer/BugReporter/BugReporter.h"
Ted Kremenekdb09a4d2008-07-03 04:29:21 +000019#include "clang/AST/ExprObjC.h"
20#include "clang/AST/Expr.h"
21#include "clang/AST/DeclObjC.h"
Ted Kremenek3cd483c2008-07-03 14:35:01 +000022#include "clang/Basic/LangOptions.h"
Ted Kremenek6f2bb362008-10-29 04:30:28 +000023#include "llvm/Support/raw_ostream.h"
Ted Kremenekdb09a4d2008-07-03 04:29:21 +000024
25using namespace clang;
Ted Kremenek9ef65372010-12-23 07:20:52 +000026using namespace ento;
Ted Kremenekdb09a4d2008-07-03 04:29:21 +000027
Mike Stump1eb44332009-09-09 15:08:12 +000028static bool scan_dealloc(Stmt* S, Selector Dealloc) {
29
Ted Kremenekdb09a4d2008-07-03 04:29:21 +000030 if (ObjCMessageExpr* ME = dyn_cast<ObjCMessageExpr>(S))
Douglas Gregor04badcf2010-04-21 00:45:42 +000031 if (ME->getSelector() == Dealloc) {
32 switch (ME->getReceiverKind()) {
33 case ObjCMessageExpr::Instance: return false;
34 case ObjCMessageExpr::SuperInstance: return true;
35 case ObjCMessageExpr::Class: break;
36 case ObjCMessageExpr::SuperClass: break;
37 }
38 }
Ted Kremenekdb09a4d2008-07-03 04:29:21 +000039
40 // Recurse to children.
41
42 for (Stmt::child_iterator I = S->child_begin(), E= S->child_end(); I!=E; ++I)
43 if (*I && scan_dealloc(*I, Dealloc))
44 return true;
Mike Stump1eb44332009-09-09 15:08:12 +000045
Ted Kremenekdb09a4d2008-07-03 04:29:21 +000046 return false;
47}
48
Mike Stump1eb44332009-09-09 15:08:12 +000049static bool scan_ivar_release(Stmt* S, ObjCIvarDecl* ID,
50 const ObjCPropertyDecl* PD,
51 Selector Release,
Ted Kremenekd3b25c52008-10-30 15:13:43 +000052 IdentifierInfo* SelfII,
Mike Stump1eb44332009-09-09 15:08:12 +000053 ASTContext& Ctx) {
54
Ted Kremenekd3b25c52008-10-30 15:13:43 +000055 // [mMyIvar release]
Ted Kremenek6f2bb362008-10-29 04:30:28 +000056 if (ObjCMessageExpr* ME = dyn_cast<ObjCMessageExpr>(S))
57 if (ME->getSelector() == Release)
Douglas Gregor04badcf2010-04-21 00:45:42 +000058 if (ME->getInstanceReceiver())
59 if (Expr* Receiver = ME->getInstanceReceiver()->IgnoreParenCasts())
Ted Kremenekd3b25c52008-10-30 15:13:43 +000060 if (ObjCIvarRefExpr* E = dyn_cast<ObjCIvarRefExpr>(Receiver))
61 if (E->getDecl() == ID)
62 return true;
Ted Kremenek6f2bb362008-10-29 04:30:28 +000063
Ted Kremenekd3b25c52008-10-30 15:13:43 +000064 // [self setMyIvar:nil];
65 if (ObjCMessageExpr* ME = dyn_cast<ObjCMessageExpr>(S))
Douglas Gregor04badcf2010-04-21 00:45:42 +000066 if (ME->getInstanceReceiver())
67 if (Expr* Receiver = ME->getInstanceReceiver()->IgnoreParenCasts())
Ted Kremenekd3b25c52008-10-30 15:13:43 +000068 if (DeclRefExpr* E = dyn_cast<DeclRefExpr>(Receiver))
69 if (E->getDecl()->getIdentifier() == SelfII)
70 if (ME->getMethodDecl() == PD->getSetterMethodDecl() &&
71 ME->getNumArgs() == 1 &&
Douglas Gregorce940492009-09-25 04:25:58 +000072 ME->getArg(0)->isNullPointerConstant(Ctx,
73 Expr::NPC_ValueDependentIsNull))
Ted Kremenekd3b25c52008-10-30 15:13:43 +000074 return true;
Mike Stump1eb44332009-09-09 15:08:12 +000075
Ted Kremenekd3b25c52008-10-30 15:13:43 +000076 // self.myIvar = nil;
77 if (BinaryOperator* BO = dyn_cast<BinaryOperator>(S))
78 if (BO->isAssignmentOp())
Mike Stump1eb44332009-09-09 15:08:12 +000079 if (ObjCPropertyRefExpr* PRE =
John McCall12f78a62010-12-02 01:19:52 +000080 dyn_cast<ObjCPropertyRefExpr>(BO->getLHS()->IgnoreParenCasts()))
81 if (PRE->isExplicitProperty() && PRE->getExplicitProperty() == PD)
Douglas Gregorce940492009-09-25 04:25:58 +000082 if (BO->getRHS()->isNullPointerConstant(Ctx,
83 Expr::NPC_ValueDependentIsNull)) {
Ted Kremenek2c615662008-12-08 21:44:15 +000084 // This is only a 'release' if the property kind is not
85 // 'assign'.
86 return PD->getSetterKind() != ObjCPropertyDecl::Assign;;
87 }
Mike Stump1eb44332009-09-09 15:08:12 +000088
Ted Kremenek6f2bb362008-10-29 04:30:28 +000089 // Recurse to children.
90 for (Stmt::child_iterator I = S->child_begin(), E= S->child_end(); I!=E; ++I)
Ted Kremenekd3b25c52008-10-30 15:13:43 +000091 if (*I && scan_ivar_release(*I, ID, PD, Release, SelfII, Ctx))
Ted Kremenek6f2bb362008-10-29 04:30:28 +000092 return true;
93
94 return false;
95}
96
Ted Kremenek9ef65372010-12-23 07:20:52 +000097void ento::CheckObjCDealloc(const ObjCImplementationDecl* D,
Argyrios Kyrtzidis5a4f98f2010-12-22 18:53:20 +000098 const LangOptions& LOpts, BugReporter& BR) {
Ted Kremenekdb09a4d2008-07-03 04:29:21 +000099
Ted Kremenek3cd483c2008-07-03 14:35:01 +0000100 assert (LOpts.getGCMode() != LangOptions::GCOnly);
Mike Stump1eb44332009-09-09 15:08:12 +0000101
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000102 ASTContext& Ctx = BR.getContext();
Ted Kremenek23760022009-08-21 23:58:43 +0000103 const ObjCInterfaceDecl* ID = D->getClassInterface();
Mike Stump1eb44332009-09-09 15:08:12 +0000104
Ted Kremenek00fed8d2008-07-07 06:36:08 +0000105 // Does the class contain any ivars that are pointers (or id<...>)?
106 // If not, skip the check entirely.
107 // NOTE: This is motivated by PR 2517:
108 // http://llvm.org/bugs/show_bug.cgi?id=2517
Mike Stump1eb44332009-09-09 15:08:12 +0000109
Ted Kremenek00fed8d2008-07-07 06:36:08 +0000110 bool containsPointerIvar = false;
Mike Stump1eb44332009-09-09 15:08:12 +0000111
Ted Kremenek00fed8d2008-07-07 06:36:08 +0000112 for (ObjCInterfaceDecl::ivar_iterator I=ID->ivar_begin(), E=ID->ivar_end();
113 I!=E; ++I) {
Mike Stump1eb44332009-09-09 15:08:12 +0000114
Ted Kremenekf4ebf422008-07-15 23:04:27 +0000115 ObjCIvarDecl* ID = *I;
116 QualType T = ID->getType();
Mike Stump1eb44332009-09-09 15:08:12 +0000117
Steve Narofff4954562009-07-16 15:41:00 +0000118 if (!T->isObjCObjectPointerType() ||
Ted Kremenek857e9182010-05-19 17:38:06 +0000119 ID->getAttr<IBOutletAttr>() || // Skip IBOutlets.
120 ID->getAttr<IBOutletCollectionAttr>()) // Skip IBOutletCollections.
Ted Kremenek684b9d22008-07-25 17:04:49 +0000121 continue;
Mike Stump1eb44332009-09-09 15:08:12 +0000122
Ted Kremenek684b9d22008-07-25 17:04:49 +0000123 containsPointerIvar = true;
124 break;
Ted Kremenek00fed8d2008-07-07 06:36:08 +0000125 }
Mike Stump1eb44332009-09-09 15:08:12 +0000126
Ted Kremenek00fed8d2008-07-07 06:36:08 +0000127 if (!containsPointerIvar)
128 return;
Mike Stump1eb44332009-09-09 15:08:12 +0000129
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000130 // Determine if the class subclasses NSObject.
131 IdentifierInfo* NSObjectII = &Ctx.Idents.get("NSObject");
Ted Kremenek8cb6fb32009-02-11 07:10:07 +0000132 IdentifierInfo* SenTestCaseII = &Ctx.Idents.get("SenTestCase");
133
Mike Stump1eb44332009-09-09 15:08:12 +0000134
Ted Kremenek8cb6fb32009-02-11 07:10:07 +0000135 for ( ; ID ; ID = ID->getSuperClass()) {
136 IdentifierInfo *II = ID->getIdentifier();
137
138 if (II == NSObjectII)
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000139 break;
Ted Kremenek8cb6fb32009-02-11 07:10:07 +0000140
141 // FIXME: For now, ignore classes that subclass SenTestCase, as these don't
142 // need to implement -dealloc. They implement tear down in another way,
143 // which we should try and catch later.
144 // http://llvm.org/bugs/show_bug.cgi?id=3187
145 if (II == SenTestCaseII)
146 return;
147 }
Mike Stump1eb44332009-09-09 15:08:12 +0000148
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000149 if (!ID)
150 return;
Mike Stump1eb44332009-09-09 15:08:12 +0000151
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000152 // Get the "dealloc" selector.
153 IdentifierInfo* II = &Ctx.Idents.get("dealloc");
Mike Stump1eb44332009-09-09 15:08:12 +0000154 Selector S = Ctx.Selectors.getSelector(0, &II);
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000155 ObjCMethodDecl* MD = 0;
Mike Stump1eb44332009-09-09 15:08:12 +0000156
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000157 // Scan the instance methods for "dealloc".
Argyrios Kyrtzidis17945a02009-06-30 02:36:12 +0000158 for (ObjCImplementationDecl::instmeth_iterator I = D->instmeth_begin(),
159 E = D->instmeth_end(); I!=E; ++I) {
Mike Stump1eb44332009-09-09 15:08:12 +0000160
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000161 if ((*I)->getSelector() == S) {
162 MD = *I;
163 break;
Mike Stump1eb44332009-09-09 15:08:12 +0000164 }
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000165 }
Mike Stump1eb44332009-09-09 15:08:12 +0000166
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000167 if (!MD) { // No dealloc found.
Mike Stump1eb44332009-09-09 15:08:12 +0000168
169 const char* name = LOpts.getGCMode() == LangOptions::NonGC
170 ? "missing -dealloc"
Ted Kremenek57202072008-07-14 17:40:50 +0000171 : "missing -dealloc (Hybrid MM, non-GC)";
Mike Stump1eb44332009-09-09 15:08:12 +0000172
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000173 std::string buf;
174 llvm::raw_string_ostream os(buf);
Benjamin Kramer900fc632010-04-17 09:33:03 +0000175 os << "Objective-C class '" << D << "' lacks a 'dealloc' instance method";
Mike Stump1eb44332009-09-09 15:08:12 +0000176
Benjamin Kramerf0171732009-11-29 18:27:55 +0000177 BR.EmitBasicReport(name, os.str(), D->getLocStart());
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000178 return;
179 }
Mike Stump1eb44332009-09-09 15:08:12 +0000180
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000181 // dealloc found. Scan for missing [super dealloc].
Argyrios Kyrtzidis6fb0aee2009-06-30 02:35:26 +0000182 if (MD->getBody() && !scan_dealloc(MD->getBody(), S)) {
Mike Stump1eb44332009-09-09 15:08:12 +0000183
Ted Kremenek57202072008-07-14 17:40:50 +0000184 const char* name = LOpts.getGCMode() == LangOptions::NonGC
185 ? "missing [super dealloc]"
186 : "missing [super dealloc] (Hybrid MM, non-GC)";
Mike Stump1eb44332009-09-09 15:08:12 +0000187
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000188 std::string buf;
189 llvm::raw_string_ostream os(buf);
Benjamin Kramer900fc632010-04-17 09:33:03 +0000190 os << "The 'dealloc' instance method in Objective-C class '" << D
Ted Kremenek3cd483c2008-07-03 14:35:01 +0000191 << "' does not send a 'dealloc' message to its super class"
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000192 " (missing [super dealloc])";
Mike Stump1eb44332009-09-09 15:08:12 +0000193
Benjamin Kramerf0171732009-11-29 18:27:55 +0000194 BR.EmitBasicReport(name, os.str(), D->getLocStart());
Ted Kremenek57202072008-07-14 17:40:50 +0000195 return;
Mike Stump1eb44332009-09-09 15:08:12 +0000196 }
197
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000198 // Get the "release" selector.
199 IdentifierInfo* RII = &Ctx.Idents.get("release");
Mike Stump1eb44332009-09-09 15:08:12 +0000200 Selector RS = Ctx.Selectors.getSelector(0, &RII);
201
Ted Kremenekd3b25c52008-10-30 15:13:43 +0000202 // Get the "self" identifier
203 IdentifierInfo* SelfII = &Ctx.Idents.get("self");
Mike Stump1eb44332009-09-09 15:08:12 +0000204
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000205 // Scan for missing and extra releases of ivars used by implementations
206 // of synthesized properties
Argyrios Kyrtzidis17945a02009-06-30 02:36:12 +0000207 for (ObjCImplementationDecl::propimpl_iterator I = D->propimpl_begin(),
208 E = D->propimpl_end(); I!=E; ++I) {
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000209
210 // We can only check the synthesized properties
Mike Stump1eb44332009-09-09 15:08:12 +0000211 if ((*I)->getPropertyImplementation() != ObjCPropertyImplDecl::Synthesize)
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000212 continue;
Mike Stump1eb44332009-09-09 15:08:12 +0000213
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000214 ObjCIvarDecl* ID = (*I)->getPropertyIvarDecl();
215 if (!ID)
216 continue;
Mike Stump1eb44332009-09-09 15:08:12 +0000217
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000218 QualType T = ID->getType();
Steve Narofff4954562009-07-16 15:41:00 +0000219 if (!T->isObjCObjectPointerType()) // Skip non-pointer ivars
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000220 continue;
221
222 const ObjCPropertyDecl* PD = (*I)->getPropertyDecl();
Mike Stump1eb44332009-09-09 15:08:12 +0000223 if (!PD)
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000224 continue;
Mike Stump1eb44332009-09-09 15:08:12 +0000225
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000226 // ivars cannot be set via read-only properties, so we'll skip them
Mike Stump1eb44332009-09-09 15:08:12 +0000227 if (PD->isReadOnly())
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000228 continue;
Mike Stump1eb44332009-09-09 15:08:12 +0000229
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000230 // ivar must be released if and only if the kind of setter was not 'assign'
231 bool requiresRelease = PD->getSetterKind() != ObjCPropertyDecl::Assign;
Mike Stump1eb44332009-09-09 15:08:12 +0000232 if (scan_ivar_release(MD->getBody(), ID, PD, RS, SelfII, Ctx)
Ted Kremenekd3b25c52008-10-30 15:13:43 +0000233 != requiresRelease) {
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000234 const char *name;
235 const char* category = "Memory (Core Foundation/Objective-C)";
Mike Stump1eb44332009-09-09 15:08:12 +0000236
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000237 std::string buf;
238 llvm::raw_string_ostream os(buf);
239
Mike Stump1eb44332009-09-09 15:08:12 +0000240 if (requiresRelease) {
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000241 name = LOpts.getGCMode() == LangOptions::NonGC
242 ? "missing ivar release (leak)"
243 : "missing ivar release (Hybrid MM, non-GC)";
Mike Stump1eb44332009-09-09 15:08:12 +0000244
Benjamin Kramer900fc632010-04-17 09:33:03 +0000245 os << "The '" << ID
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000246 << "' instance variable was retained by a synthesized property but "
Mike Stump1eb44332009-09-09 15:08:12 +0000247 "wasn't released in 'dealloc'";
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000248 } else {
249 name = LOpts.getGCMode() == LangOptions::NonGC
250 ? "extra ivar release (use-after-release)"
251 : "extra ivar release (Hybrid MM, non-GC)";
Mike Stump1eb44332009-09-09 15:08:12 +0000252
Benjamin Kramer900fc632010-04-17 09:33:03 +0000253 os << "The '" << ID
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000254 << "' instance variable was not retained by a synthesized property "
255 "but was released in 'dealloc'";
256 }
Mike Stump1eb44332009-09-09 15:08:12 +0000257
Benjamin Kramerf0171732009-11-29 18:27:55 +0000258 BR.EmitBasicReport(name, category, os.str(), (*I)->getLocation());
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000259 }
260 }
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000261}
262