blob: 133204a6d350cb12db42fd8c16c8be941dd2bb09 [file] [log] [blame]
Ted Kremenekdb09a4d2008-07-03 04:29:21 +00001//==- CheckObjCDealloc.cpp - Check ObjC -dealloc implementation --*- C++ -*-==//
2//
3// The LLVM Compiler Infrastructure
4//
5// This file is distributed under the University of Illinois Open Source
6// License. See LICENSE.TXT for details.
7//
8//===----------------------------------------------------------------------===//
9//
Ted Kremenek078c0bc2008-07-11 20:53:14 +000010// This file defines a CheckObjCDealloc, a checker that
11// analyzes an Objective-C class's implementation to determine if it
12// correctly implements -dealloc.
Ted Kremenekdb09a4d2008-07-03 04:29:21 +000013//
14//===----------------------------------------------------------------------===//
15
Argyrios Kyrtzidis7dd445e2011-02-17 21:39:33 +000016#include "ClangSACheckers.h"
Argyrios Kyrtzidisec8605f2011-03-01 01:16:21 +000017#include "clang/StaticAnalyzer/Core/Checker.h"
Argyrios Kyrtzidis7dd445e2011-02-17 21:39:33 +000018#include "clang/StaticAnalyzer/Core/PathSensitive/AnalysisManager.h"
Ted Kremenek9b663712011-02-10 01:03:03 +000019#include "clang/StaticAnalyzer/Core/BugReporter/PathDiagnostic.h"
20#include "clang/StaticAnalyzer/Core/BugReporter/BugReporter.h"
Ted Kremenekdb09a4d2008-07-03 04:29:21 +000021#include "clang/AST/ExprObjC.h"
22#include "clang/AST/Expr.h"
23#include "clang/AST/DeclObjC.h"
Ted Kremenek3cd483c2008-07-03 14:35:01 +000024#include "clang/Basic/LangOptions.h"
Ted Kremenek6f2bb362008-10-29 04:30:28 +000025#include "llvm/Support/raw_ostream.h"
Ted Kremenekdb09a4d2008-07-03 04:29:21 +000026
27using namespace clang;
Ted Kremenek9ef65372010-12-23 07:20:52 +000028using namespace ento;
Ted Kremenekdb09a4d2008-07-03 04:29:21 +000029
Ted Kremenek9c378f72011-08-12 23:37:29 +000030static bool scan_dealloc(Stmt *S, Selector Dealloc) {
Mike Stump1eb44332009-09-09 15:08:12 +000031
Ted Kremenek9c378f72011-08-12 23:37:29 +000032 if (ObjCMessageExpr *ME = dyn_cast<ObjCMessageExpr>(S))
Douglas Gregor04badcf2010-04-21 00:45:42 +000033 if (ME->getSelector() == Dealloc) {
34 switch (ME->getReceiverKind()) {
35 case ObjCMessageExpr::Instance: return false;
36 case ObjCMessageExpr::SuperInstance: return true;
37 case ObjCMessageExpr::Class: break;
38 case ObjCMessageExpr::SuperClass: break;
39 }
40 }
Ted Kremenekdb09a4d2008-07-03 04:29:21 +000041
42 // Recurse to children.
43
44 for (Stmt::child_iterator I = S->child_begin(), E= S->child_end(); I!=E; ++I)
45 if (*I && scan_dealloc(*I, Dealloc))
46 return true;
Mike Stump1eb44332009-09-09 15:08:12 +000047
Ted Kremenekdb09a4d2008-07-03 04:29:21 +000048 return false;
49}
50
Ted Kremenek9c378f72011-08-12 23:37:29 +000051static bool scan_ivar_release(Stmt *S, ObjCIvarDecl *ID,
52 const ObjCPropertyDecl *PD,
Mike Stump1eb44332009-09-09 15:08:12 +000053 Selector Release,
Ted Kremenekd3b25c52008-10-30 15:13:43 +000054 IdentifierInfo* SelfII,
Ted Kremenek9c378f72011-08-12 23:37:29 +000055 ASTContext &Ctx) {
Mike Stump1eb44332009-09-09 15:08:12 +000056
Ted Kremenekd3b25c52008-10-30 15:13:43 +000057 // [mMyIvar release]
Ted Kremenek9c378f72011-08-12 23:37:29 +000058 if (ObjCMessageExpr *ME = dyn_cast<ObjCMessageExpr>(S))
Ted Kremenek6f2bb362008-10-29 04:30:28 +000059 if (ME->getSelector() == Release)
Douglas Gregor04badcf2010-04-21 00:45:42 +000060 if (ME->getInstanceReceiver())
Ted Kremenek9c378f72011-08-12 23:37:29 +000061 if (Expr *Receiver = ME->getInstanceReceiver()->IgnoreParenCasts())
62 if (ObjCIvarRefExpr *E = dyn_cast<ObjCIvarRefExpr>(Receiver))
Ted Kremenekd3b25c52008-10-30 15:13:43 +000063 if (E->getDecl() == ID)
64 return true;
Ted Kremenek6f2bb362008-10-29 04:30:28 +000065
Ted Kremenekd3b25c52008-10-30 15:13:43 +000066 // [self setMyIvar:nil];
Ted Kremenek9c378f72011-08-12 23:37:29 +000067 if (ObjCMessageExpr *ME = dyn_cast<ObjCMessageExpr>(S))
Douglas Gregor04badcf2010-04-21 00:45:42 +000068 if (ME->getInstanceReceiver())
Ted Kremenek9c378f72011-08-12 23:37:29 +000069 if (Expr *Receiver = ME->getInstanceReceiver()->IgnoreParenCasts())
70 if (DeclRefExpr *E = dyn_cast<DeclRefExpr>(Receiver))
Ted Kremenekd3b25c52008-10-30 15:13:43 +000071 if (E->getDecl()->getIdentifier() == SelfII)
72 if (ME->getMethodDecl() == PD->getSetterMethodDecl() &&
73 ME->getNumArgs() == 1 &&
Douglas Gregorce940492009-09-25 04:25:58 +000074 ME->getArg(0)->isNullPointerConstant(Ctx,
75 Expr::NPC_ValueDependentIsNull))
Ted Kremenekd3b25c52008-10-30 15:13:43 +000076 return true;
Mike Stump1eb44332009-09-09 15:08:12 +000077
Ted Kremenekd3b25c52008-10-30 15:13:43 +000078 // self.myIvar = nil;
79 if (BinaryOperator* BO = dyn_cast<BinaryOperator>(S))
80 if (BO->isAssignmentOp())
Ted Kremenek9c378f72011-08-12 23:37:29 +000081 if (ObjCPropertyRefExpr *PRE =
John McCall12f78a62010-12-02 01:19:52 +000082 dyn_cast<ObjCPropertyRefExpr>(BO->getLHS()->IgnoreParenCasts()))
83 if (PRE->isExplicitProperty() && PRE->getExplicitProperty() == PD)
Douglas Gregorce940492009-09-25 04:25:58 +000084 if (BO->getRHS()->isNullPointerConstant(Ctx,
85 Expr::NPC_ValueDependentIsNull)) {
Ted Kremenek2c615662008-12-08 21:44:15 +000086 // This is only a 'release' if the property kind is not
87 // 'assign'.
88 return PD->getSetterKind() != ObjCPropertyDecl::Assign;;
89 }
Mike Stump1eb44332009-09-09 15:08:12 +000090
Ted Kremenek6f2bb362008-10-29 04:30:28 +000091 // Recurse to children.
92 for (Stmt::child_iterator I = S->child_begin(), E= S->child_end(); I!=E; ++I)
Ted Kremenekd3b25c52008-10-30 15:13:43 +000093 if (*I && scan_ivar_release(*I, ID, PD, Release, SelfII, Ctx))
Ted Kremenek6f2bb362008-10-29 04:30:28 +000094 return true;
95
96 return false;
97}
98
Ted Kremenek9c378f72011-08-12 23:37:29 +000099static void checkObjCDealloc(const ObjCImplementationDecl *D,
Argyrios Kyrtzidis7dd445e2011-02-17 21:39:33 +0000100 const LangOptions& LOpts, BugReporter& BR) {
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000101
Douglas Gregore289d812011-09-13 17:21:33 +0000102 assert (LOpts.getGC() != LangOptions::GCOnly);
Mike Stump1eb44332009-09-09 15:08:12 +0000103
Ted Kremenek9c378f72011-08-12 23:37:29 +0000104 ASTContext &Ctx = BR.getContext();
105 const ObjCInterfaceDecl *ID = D->getClassInterface();
Mike Stump1eb44332009-09-09 15:08:12 +0000106
Ted Kremenek00fed8d2008-07-07 06:36:08 +0000107 // Does the class contain any ivars that are pointers (or id<...>)?
108 // If not, skip the check entirely.
109 // NOTE: This is motivated by PR 2517:
110 // http://llvm.org/bugs/show_bug.cgi?id=2517
Mike Stump1eb44332009-09-09 15:08:12 +0000111
Ted Kremenek00fed8d2008-07-07 06:36:08 +0000112 bool containsPointerIvar = false;
Mike Stump1eb44332009-09-09 15:08:12 +0000113
Ted Kremenek00fed8d2008-07-07 06:36:08 +0000114 for (ObjCInterfaceDecl::ivar_iterator I=ID->ivar_begin(), E=ID->ivar_end();
115 I!=E; ++I) {
Mike Stump1eb44332009-09-09 15:08:12 +0000116
Ted Kremenek9c378f72011-08-12 23:37:29 +0000117 ObjCIvarDecl *ID = *I;
Ted Kremenekf4ebf422008-07-15 23:04:27 +0000118 QualType T = ID->getType();
Mike Stump1eb44332009-09-09 15:08:12 +0000119
Steve Narofff4954562009-07-16 15:41:00 +0000120 if (!T->isObjCObjectPointerType() ||
Ted Kremenek857e9182010-05-19 17:38:06 +0000121 ID->getAttr<IBOutletAttr>() || // Skip IBOutlets.
122 ID->getAttr<IBOutletCollectionAttr>()) // Skip IBOutletCollections.
Ted Kremenek684b9d22008-07-25 17:04:49 +0000123 continue;
Mike Stump1eb44332009-09-09 15:08:12 +0000124
Ted Kremenek684b9d22008-07-25 17:04:49 +0000125 containsPointerIvar = true;
126 break;
Ted Kremenek00fed8d2008-07-07 06:36:08 +0000127 }
Mike Stump1eb44332009-09-09 15:08:12 +0000128
Ted Kremenek00fed8d2008-07-07 06:36:08 +0000129 if (!containsPointerIvar)
130 return;
Mike Stump1eb44332009-09-09 15:08:12 +0000131
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000132 // Determine if the class subclasses NSObject.
133 IdentifierInfo* NSObjectII = &Ctx.Idents.get("NSObject");
Ted Kremenek8cb6fb32009-02-11 07:10:07 +0000134 IdentifierInfo* SenTestCaseII = &Ctx.Idents.get("SenTestCase");
135
Mike Stump1eb44332009-09-09 15:08:12 +0000136
Ted Kremenek8cb6fb32009-02-11 07:10:07 +0000137 for ( ; ID ; ID = ID->getSuperClass()) {
138 IdentifierInfo *II = ID->getIdentifier();
139
140 if (II == NSObjectII)
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000141 break;
Ted Kremenek8cb6fb32009-02-11 07:10:07 +0000142
143 // FIXME: For now, ignore classes that subclass SenTestCase, as these don't
144 // need to implement -dealloc. They implement tear down in another way,
145 // which we should try and catch later.
146 // http://llvm.org/bugs/show_bug.cgi?id=3187
147 if (II == SenTestCaseII)
148 return;
149 }
Mike Stump1eb44332009-09-09 15:08:12 +0000150
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000151 if (!ID)
152 return;
Mike Stump1eb44332009-09-09 15:08:12 +0000153
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000154 // Get the "dealloc" selector.
155 IdentifierInfo* II = &Ctx.Idents.get("dealloc");
Mike Stump1eb44332009-09-09 15:08:12 +0000156 Selector S = Ctx.Selectors.getSelector(0, &II);
Ted Kremenek9c378f72011-08-12 23:37:29 +0000157 ObjCMethodDecl *MD = 0;
Mike Stump1eb44332009-09-09 15:08:12 +0000158
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000159 // Scan the instance methods for "dealloc".
Argyrios Kyrtzidis17945a02009-06-30 02:36:12 +0000160 for (ObjCImplementationDecl::instmeth_iterator I = D->instmeth_begin(),
161 E = D->instmeth_end(); I!=E; ++I) {
Mike Stump1eb44332009-09-09 15:08:12 +0000162
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000163 if ((*I)->getSelector() == S) {
164 MD = *I;
165 break;
Mike Stump1eb44332009-09-09 15:08:12 +0000166 }
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000167 }
Mike Stump1eb44332009-09-09 15:08:12 +0000168
Anna Zaks590dd8e2011-09-20 21:38:35 +0000169 PathDiagnosticLocation DLoc =
170 PathDiagnosticLocation::createBegin(D, BR.getSourceManager());
171
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000172 if (!MD) { // No dealloc found.
Mike Stump1eb44332009-09-09 15:08:12 +0000173
Douglas Gregore289d812011-09-13 17:21:33 +0000174 const char* name = LOpts.getGC() == LangOptions::NonGC
Mike Stump1eb44332009-09-09 15:08:12 +0000175 ? "missing -dealloc"
Ted Kremenek57202072008-07-14 17:40:50 +0000176 : "missing -dealloc (Hybrid MM, non-GC)";
Mike Stump1eb44332009-09-09 15:08:12 +0000177
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000178 std::string buf;
179 llvm::raw_string_ostream os(buf);
Benjamin Kramerf9780592012-02-07 11:57:45 +0000180 os << "Objective-C class '" << *D << "' lacks a 'dealloc' instance method";
Mike Stump1eb44332009-09-09 15:08:12 +0000181
Ted Kremenek6fd45052012-04-05 20:43:28 +0000182 BR.EmitBasicReport(D, name, categories::CoreFoundationObjectiveC,
183 os.str(), DLoc);
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000184 return;
185 }
Mike Stump1eb44332009-09-09 15:08:12 +0000186
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000187 // dealloc found. Scan for missing [super dealloc].
Argyrios Kyrtzidis6fb0aee2009-06-30 02:35:26 +0000188 if (MD->getBody() && !scan_dealloc(MD->getBody(), S)) {
Mike Stump1eb44332009-09-09 15:08:12 +0000189
Douglas Gregore289d812011-09-13 17:21:33 +0000190 const char* name = LOpts.getGC() == LangOptions::NonGC
Ted Kremenek57202072008-07-14 17:40:50 +0000191 ? "missing [super dealloc]"
192 : "missing [super dealloc] (Hybrid MM, non-GC)";
Mike Stump1eb44332009-09-09 15:08:12 +0000193
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000194 std::string buf;
195 llvm::raw_string_ostream os(buf);
Benjamin Kramerf9780592012-02-07 11:57:45 +0000196 os << "The 'dealloc' instance method in Objective-C class '" << *D
Ted Kremenek3cd483c2008-07-03 14:35:01 +0000197 << "' does not send a 'dealloc' message to its super class"
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000198 " (missing [super dealloc])";
Mike Stump1eb44332009-09-09 15:08:12 +0000199
Ted Kremenek6fd45052012-04-05 20:43:28 +0000200 BR.EmitBasicReport(MD, name, categories::CoreFoundationObjectiveC,
201 os.str(), DLoc);
Ted Kremenek57202072008-07-14 17:40:50 +0000202 return;
Mike Stump1eb44332009-09-09 15:08:12 +0000203 }
204
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000205 // Get the "release" selector.
206 IdentifierInfo* RII = &Ctx.Idents.get("release");
Mike Stump1eb44332009-09-09 15:08:12 +0000207 Selector RS = Ctx.Selectors.getSelector(0, &RII);
208
Ted Kremenekd3b25c52008-10-30 15:13:43 +0000209 // Get the "self" identifier
210 IdentifierInfo* SelfII = &Ctx.Idents.get("self");
Mike Stump1eb44332009-09-09 15:08:12 +0000211
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000212 // Scan for missing and extra releases of ivars used by implementations
213 // of synthesized properties
Argyrios Kyrtzidis17945a02009-06-30 02:36:12 +0000214 for (ObjCImplementationDecl::propimpl_iterator I = D->propimpl_begin(),
215 E = D->propimpl_end(); I!=E; ++I) {
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000216
217 // We can only check the synthesized properties
Mike Stump1eb44332009-09-09 15:08:12 +0000218 if ((*I)->getPropertyImplementation() != ObjCPropertyImplDecl::Synthesize)
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000219 continue;
Mike Stump1eb44332009-09-09 15:08:12 +0000220
Ted Kremenek9c378f72011-08-12 23:37:29 +0000221 ObjCIvarDecl *ID = (*I)->getPropertyIvarDecl();
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000222 if (!ID)
223 continue;
Mike Stump1eb44332009-09-09 15:08:12 +0000224
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000225 QualType T = ID->getType();
Steve Narofff4954562009-07-16 15:41:00 +0000226 if (!T->isObjCObjectPointerType()) // Skip non-pointer ivars
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000227 continue;
228
Ted Kremenek9c378f72011-08-12 23:37:29 +0000229 const ObjCPropertyDecl *PD = (*I)->getPropertyDecl();
Mike Stump1eb44332009-09-09 15:08:12 +0000230 if (!PD)
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000231 continue;
Mike Stump1eb44332009-09-09 15:08:12 +0000232
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000233 // ivars cannot be set via read-only properties, so we'll skip them
Mike Stump1eb44332009-09-09 15:08:12 +0000234 if (PD->isReadOnly())
Benjamin Kramerb8989f22011-10-14 18:45:37 +0000235 continue;
Mike Stump1eb44332009-09-09 15:08:12 +0000236
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000237 // ivar must be released if and only if the kind of setter was not 'assign'
238 bool requiresRelease = PD->getSetterKind() != ObjCPropertyDecl::Assign;
Mike Stump1eb44332009-09-09 15:08:12 +0000239 if (scan_ivar_release(MD->getBody(), ID, PD, RS, SelfII, Ctx)
Ted Kremenekd3b25c52008-10-30 15:13:43 +0000240 != requiresRelease) {
Ted Kremenek6fd45052012-04-05 20:43:28 +0000241 const char *name = 0;
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000242 std::string buf;
243 llvm::raw_string_ostream os(buf);
244
Mike Stump1eb44332009-09-09 15:08:12 +0000245 if (requiresRelease) {
Douglas Gregore289d812011-09-13 17:21:33 +0000246 name = LOpts.getGC() == LangOptions::NonGC
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000247 ? "missing ivar release (leak)"
248 : "missing ivar release (Hybrid MM, non-GC)";
Mike Stump1eb44332009-09-09 15:08:12 +0000249
Benjamin Kramerb8989f22011-10-14 18:45:37 +0000250 os << "The '" << *ID
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000251 << "' instance variable was retained by a synthesized property but "
Mike Stump1eb44332009-09-09 15:08:12 +0000252 "wasn't released in 'dealloc'";
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000253 } else {
Douglas Gregore289d812011-09-13 17:21:33 +0000254 name = LOpts.getGC() == LangOptions::NonGC
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000255 ? "extra ivar release (use-after-release)"
256 : "extra ivar release (Hybrid MM, non-GC)";
Mike Stump1eb44332009-09-09 15:08:12 +0000257
Benjamin Kramerb8989f22011-10-14 18:45:37 +0000258 os << "The '" << *ID
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000259 << "' instance variable was not retained by a synthesized property "
260 "but was released in 'dealloc'";
261 }
Mike Stump1eb44332009-09-09 15:08:12 +0000262
Anna Zaks590dd8e2011-09-20 21:38:35 +0000263 PathDiagnosticLocation SDLoc =
264 PathDiagnosticLocation::createBegin((*I), BR.getSourceManager());
265
Ted Kremenek6fd45052012-04-05 20:43:28 +0000266 BR.EmitBasicReport(MD, name, categories::CoreFoundationObjectiveC,
267 os.str(), SDLoc);
Ted Kremenek6f2bb362008-10-29 04:30:28 +0000268 }
269 }
Ted Kremenekdb09a4d2008-07-03 04:29:21 +0000270}
271
Argyrios Kyrtzidis7dd445e2011-02-17 21:39:33 +0000272//===----------------------------------------------------------------------===//
273// ObjCDeallocChecker
274//===----------------------------------------------------------------------===//
275
276namespace {
Argyrios Kyrtzidisec8605f2011-03-01 01:16:21 +0000277class ObjCDeallocChecker : public Checker<
Argyrios Kyrtzidis7dd445e2011-02-17 21:39:33 +0000278 check::ASTDecl<ObjCImplementationDecl> > {
279public:
280 void checkASTDecl(const ObjCImplementationDecl *D, AnalysisManager& mgr,
281 BugReporter &BR) const {
David Blaikie4e4d0842012-03-11 07:00:24 +0000282 if (mgr.getLangOpts().getGC() == LangOptions::GCOnly)
Argyrios Kyrtzidis7dd445e2011-02-17 21:39:33 +0000283 return;
David Blaikie4e4d0842012-03-11 07:00:24 +0000284 checkObjCDealloc(cast<ObjCImplementationDecl>(D), mgr.getLangOpts(), BR);
Argyrios Kyrtzidis7dd445e2011-02-17 21:39:33 +0000285 }
286};
287}
288
289void ento::registerObjCDeallocChecker(CheckerManager &mgr) {
290 mgr.registerChecker<ObjCDeallocChecker>();
291}