Ted Kremenek | 99c6ad3 | 2008-03-27 07:25:52 +0000 | [diff] [blame] | 1 | //== BasicObjCFoundationChecks.cpp - Simple Apple-Foundation checks -*- C++ -*-- |
| 2 | // |
| 3 | // The LLVM Compiler Infrastructure |
| 4 | // |
| 5 | // This file is distributed under the University of Illinois Open Source |
| 6 | // License. See LICENSE.TXT for details. |
| 7 | // |
| 8 | //===----------------------------------------------------------------------===// |
| 9 | // |
| 10 | // This file defines BasicObjCFoundationChecks, a class that encapsulates |
| 11 | // a set of simple checks to run on Objective-C code using Apple's Foundation |
| 12 | // classes. |
| 13 | // |
| 14 | //===----------------------------------------------------------------------===// |
| 15 | |
Ted Kremenek | 5275561 | 2008-03-27 17:17:22 +0000 | [diff] [blame] | 16 | #include "BasicObjCFoundationChecks.h" |
| 17 | |
Ted Kremenek | 99c6ad3 | 2008-03-27 07:25:52 +0000 | [diff] [blame] | 18 | #include "clang/Analysis/PathSensitive/ExplodedGraph.h" |
Ted Kremenek | f1ae705 | 2008-04-03 17:57:38 +0000 | [diff] [blame] | 19 | #include "clang/Analysis/PathSensitive/GRExprEngine.h" |
Ted Kremenek | 99c6ad3 | 2008-03-27 07:25:52 +0000 | [diff] [blame] | 20 | #include "clang/Analysis/PathSensitive/GRSimpleAPICheck.h" |
| 21 | #include "clang/Analysis/PathSensitive/ValueState.h" |
Ted Kremenek | f1ae705 | 2008-04-03 17:57:38 +0000 | [diff] [blame] | 22 | #include "clang/Analysis/PathSensitive/BugReporter.h" |
Ted Kremenek | 99c6ad3 | 2008-03-27 07:25:52 +0000 | [diff] [blame] | 23 | #include "clang/Analysis/PathDiagnostic.h" |
| 24 | #include "clang/AST/Expr.h" |
| 25 | #include "clang/AST/ASTContext.h" |
| 26 | #include "llvm/Support/Compiler.h" |
| 27 | |
| 28 | #include <vector> |
Ted Kremenek | 4ba6283 | 2008-03-27 22:05:32 +0000 | [diff] [blame] | 29 | #include <sstream> |
Ted Kremenek | 99c6ad3 | 2008-03-27 07:25:52 +0000 | [diff] [blame] | 30 | |
| 31 | using namespace clang; |
Ted Kremenek | 5275561 | 2008-03-27 17:17:22 +0000 | [diff] [blame] | 32 | |
Ted Kremenek | 4ba6283 | 2008-03-27 22:05:32 +0000 | [diff] [blame] | 33 | static ObjCInterfaceType* GetReceiverType(ObjCMessageExpr* ME) { |
| 34 | Expr* Receiver = ME->getReceiver(); |
| 35 | |
| 36 | if (!Receiver) |
| 37 | return NULL; |
| 38 | |
Ted Kremenek | 7956f75 | 2008-04-03 21:44:24 +0000 | [diff] [blame^] | 39 | // FIXME: Cleanup |
| 40 | QualType X = Receiver->getType(); |
| 41 | Type* TP = X.getTypePtr(); |
| 42 | assert (TP->isPointerType()); |
Ted Kremenek | 4ba6283 | 2008-03-27 22:05:32 +0000 | [diff] [blame] | 43 | |
Ted Kremenek | 7956f75 | 2008-04-03 21:44:24 +0000 | [diff] [blame^] | 44 | const PointerType* T = TP->getAsPointerType(); |
Ted Kremenek | 4ba6283 | 2008-03-27 22:05:32 +0000 | [diff] [blame] | 45 | |
| 46 | return dyn_cast<ObjCInterfaceType>(T->getPointeeType().getTypePtr()); |
| 47 | } |
| 48 | |
| 49 | static const char* GetReceiverNameType(ObjCMessageExpr* ME) { |
| 50 | ObjCInterfaceType* ReceiverType = GetReceiverType(ME); |
| 51 | return ReceiverType ? ReceiverType->getDecl()->getIdentifier()->getName() |
| 52 | : NULL; |
| 53 | } |
Ted Kremenek | 5275561 | 2008-03-27 17:17:22 +0000 | [diff] [blame] | 54 | |
Ted Kremenek | f1ae705 | 2008-04-03 17:57:38 +0000 | [diff] [blame] | 55 | namespace { |
| 56 | |
| 57 | class VISIBILITY_HIDDEN NilArg : public BugDescription { |
| 58 | std::string Msg; |
| 59 | const char* s; |
| 60 | SourceRange R; |
| 61 | public: |
| 62 | NilArg(ObjCMessageExpr* ME, unsigned Arg); |
| 63 | virtual ~NilArg() {} |
| 64 | |
| 65 | virtual const char* getName() const { |
| 66 | return "nil argument"; |
| 67 | } |
| 68 | |
| 69 | virtual const char* getDescription() const { |
| 70 | return s; |
| 71 | } |
| 72 | |
| 73 | virtual void getRanges(const SourceRange*& beg, |
| 74 | const SourceRange*& end) const { |
| 75 | beg = &R; |
| 76 | end = beg+1; |
| 77 | } |
| 78 | |
| 79 | }; |
| 80 | |
| 81 | NilArg::NilArg(ObjCMessageExpr* ME, unsigned Arg) : s(NULL) { |
| 82 | |
| 83 | Expr* E = ME->getArg(Arg); |
| 84 | R = E->getSourceRange(); |
| 85 | |
| 86 | std::ostringstream os; |
| 87 | |
| 88 | os << "Argument to '" << GetReceiverNameType(ME) << "' method '" |
| 89 | << ME->getSelector().getName() << "' cannot be nil."; |
| 90 | |
| 91 | Msg = os.str(); |
| 92 | s = Msg.c_str(); |
| 93 | } |
| 94 | |
| 95 | |
| 96 | class VISIBILITY_HIDDEN BasicObjCFoundationChecks : public GRSimpleAPICheck { |
| 97 | |
| 98 | ASTContext &Ctx; |
| 99 | ValueStateManager* VMgr; |
| 100 | |
| 101 | typedef std::vector<std::pair<NodeTy*,BugDescription*> > ErrorsTy; |
| 102 | ErrorsTy Errors; |
| 103 | |
| 104 | RVal GetRVal(ValueState* St, Expr* E) { return VMgr->GetRVal(St, E); } |
| 105 | |
| 106 | bool isNSString(ObjCInterfaceType* T, const char* suffix); |
| 107 | bool AuditNSString(NodeTy* N, ObjCMessageExpr* ME); |
| 108 | |
| 109 | void Warn(NodeTy* N, Expr* E, const std::string& s); |
| 110 | void WarnNilArg(NodeTy* N, Expr* E); |
| 111 | |
| 112 | bool CheckNilArg(NodeTy* N, unsigned Arg); |
| 113 | |
| 114 | public: |
| 115 | BasicObjCFoundationChecks(ASTContext& ctx, ValueStateManager* vmgr) |
| 116 | : Ctx(ctx), VMgr(vmgr) {} |
| 117 | |
| 118 | virtual ~BasicObjCFoundationChecks() { |
| 119 | for (ErrorsTy::iterator I = Errors.begin(), E = Errors.end(); I!=E; ++I) |
| 120 | delete I->second; |
| 121 | } |
| 122 | |
| 123 | virtual bool Audit(ExplodedNode<ValueState>* N); |
| 124 | |
| 125 | virtual void ReportResults(Diagnostic& Diag, PathDiagnosticClient* PD, |
| 126 | ASTContext& Ctx, BugReporter& BR, |
| 127 | ExplodedGraph<GRExprEngine>& G); |
| 128 | |
| 129 | private: |
| 130 | |
| 131 | void AddError(NodeTy* N, BugDescription* D) { |
| 132 | Errors.push_back(std::make_pair(N, D)); |
| 133 | } |
| 134 | |
| 135 | void WarnNilArg(NodeTy* N, ObjCMessageExpr* ME, unsigned Arg) { |
| 136 | AddError(N, new NilArg(ME, Arg)); |
| 137 | } |
| 138 | }; |
| 139 | |
| 140 | } // end anonymous namespace |
| 141 | |
| 142 | |
| 143 | GRSimpleAPICheck* |
| 144 | clang::CreateBasicObjCFoundationChecks(ASTContext& Ctx, |
| 145 | ValueStateManager* VMgr) { |
| 146 | |
| 147 | return new BasicObjCFoundationChecks(Ctx, VMgr); |
| 148 | } |
| 149 | |
| 150 | |
| 151 | |
Ted Kremenek | 99c6ad3 | 2008-03-27 07:25:52 +0000 | [diff] [blame] | 152 | bool BasicObjCFoundationChecks::Audit(ExplodedNode<ValueState>* N) { |
| 153 | |
| 154 | ObjCMessageExpr* ME = |
| 155 | cast<ObjCMessageExpr>(cast<PostStmt>(N->getLocation()).getStmt()); |
Ted Kremenek | 99c6ad3 | 2008-03-27 07:25:52 +0000 | [diff] [blame] | 156 | |
Ted Kremenek | 4ba6283 | 2008-03-27 22:05:32 +0000 | [diff] [blame] | 157 | ObjCInterfaceType* ReceiverType = GetReceiverType(ME); |
Ted Kremenek | 99c6ad3 | 2008-03-27 07:25:52 +0000 | [diff] [blame] | 158 | |
| 159 | if (!ReceiverType) |
Ted Kremenek | 4ba6283 | 2008-03-27 22:05:32 +0000 | [diff] [blame] | 160 | return NULL; |
Ted Kremenek | 99c6ad3 | 2008-03-27 07:25:52 +0000 | [diff] [blame] | 161 | |
Ted Kremenek | 4ba6283 | 2008-03-27 22:05:32 +0000 | [diff] [blame] | 162 | const char* name = ReceiverType->getDecl()->getIdentifier()->getName(); |
| 163 | |
| 164 | if (!name) |
| 165 | return false; |
Ted Kremenek | 99c6ad3 | 2008-03-27 07:25:52 +0000 | [diff] [blame] | 166 | |
| 167 | if (name[0] != 'N' || name[1] != 'S') |
| 168 | return false; |
| 169 | |
| 170 | name += 2; |
| 171 | |
| 172 | // FIXME: Make all of this faster. |
| 173 | |
| 174 | if (isNSString(ReceiverType, name)) |
| 175 | return AuditNSString(N, ME); |
| 176 | |
| 177 | return false; |
| 178 | } |
| 179 | |
Ted Kremenek | e5d5c20 | 2008-03-27 21:15:17 +0000 | [diff] [blame] | 180 | static inline bool isNil(RVal X) { |
| 181 | return isa<lval::ConcreteInt>(X); |
| 182 | } |
| 183 | |
Ted Kremenek | 99c6ad3 | 2008-03-27 07:25:52 +0000 | [diff] [blame] | 184 | //===----------------------------------------------------------------------===// |
| 185 | // Error reporting. |
| 186 | //===----------------------------------------------------------------------===// |
| 187 | |
| 188 | |
Ted Kremenek | f1ae705 | 2008-04-03 17:57:38 +0000 | [diff] [blame] | 189 | void BasicObjCFoundationChecks::ReportResults(Diagnostic& Diag, |
| 190 | PathDiagnosticClient* PD, |
| 191 | ASTContext& Ctx, BugReporter& BR, |
| 192 | ExplodedGraph<GRExprEngine>& G) { |
Ted Kremenek | e5d5c20 | 2008-03-27 21:15:17 +0000 | [diff] [blame] | 193 | |
Ted Kremenek | f1ae705 | 2008-04-03 17:57:38 +0000 | [diff] [blame] | 194 | for (ErrorsTy::iterator I=Errors.begin(), E=Errors.end(); I!=E; ++I) |
| 195 | BR.EmitPathWarning(Diag, PD, Ctx, *I->second, G, I->first); |
Ted Kremenek | 4ba6283 | 2008-03-27 22:05:32 +0000 | [diff] [blame] | 196 | } |
| 197 | |
| 198 | bool BasicObjCFoundationChecks::CheckNilArg(NodeTy* N, unsigned Arg) { |
| 199 | ObjCMessageExpr* ME = |
| 200 | cast<ObjCMessageExpr>(cast<PostStmt>(N->getLocation()).getStmt()); |
| 201 | |
| 202 | Expr * E = ME->getArg(Arg); |
| 203 | |
| 204 | if (isNil(GetRVal(N->getState(), E))) { |
Ted Kremenek | f1ae705 | 2008-04-03 17:57:38 +0000 | [diff] [blame] | 205 | WarnNilArg(N, ME, Arg); |
Ted Kremenek | 4ba6283 | 2008-03-27 22:05:32 +0000 | [diff] [blame] | 206 | return true; |
| 207 | } |
| 208 | |
| 209 | return false; |
| 210 | } |
| 211 | |
Ted Kremenek | 99c6ad3 | 2008-03-27 07:25:52 +0000 | [diff] [blame] | 212 | //===----------------------------------------------------------------------===// |
| 213 | // NSString checking. |
| 214 | //===----------------------------------------------------------------------===// |
| 215 | |
| 216 | bool BasicObjCFoundationChecks::isNSString(ObjCInterfaceType* T, |
| 217 | const char* suffix) { |
| 218 | |
| 219 | return !strcmp("String", suffix) || !strcmp("MutableString", suffix); |
| 220 | } |
| 221 | |
| 222 | bool BasicObjCFoundationChecks::AuditNSString(NodeTy* N, |
| 223 | ObjCMessageExpr* ME) { |
| 224 | |
| 225 | Selector S = ME->getSelector(); |
| 226 | |
| 227 | if (S.isUnarySelector()) |
| 228 | return false; |
| 229 | |
| 230 | // FIXME: This is going to be really slow doing these checks with |
| 231 | // lexical comparisons. |
| 232 | |
| 233 | std::string name = S.getName(); |
Ted Kremenek | 9b3fdea | 2008-03-27 21:23:57 +0000 | [diff] [blame] | 234 | assert (!name.empty()); |
| 235 | const char* cstr = &name[0]; |
| 236 | unsigned len = name.size(); |
Ted Kremenek | 4ba6283 | 2008-03-27 22:05:32 +0000 | [diff] [blame] | 237 | |
Ted Kremenek | 9b3fdea | 2008-03-27 21:23:57 +0000 | [diff] [blame] | 238 | switch (len) { |
| 239 | default: |
| 240 | break; |
Ted Kremenek | 8730e13 | 2008-03-28 16:09:38 +0000 | [diff] [blame] | 241 | case 8: |
Ted Kremenek | 4ba6283 | 2008-03-27 22:05:32 +0000 | [diff] [blame] | 242 | if (!strcmp(cstr, "compare:")) |
| 243 | return CheckNilArg(N, 0); |
| 244 | |
| 245 | break; |
Ted Kremenek | 8730e13 | 2008-03-28 16:09:38 +0000 | [diff] [blame] | 246 | |
| 247 | case 15: |
| 248 | // FIXME: Checking for initWithFormat: will not work in most cases |
| 249 | // yet because [NSString alloc] returns id, not NSString*. We will |
| 250 | // need support for tracking expected-type information in the analyzer |
| 251 | // to find these errors. |
| 252 | if (!strcmp(cstr, "initWithFormat:")) |
| 253 | return CheckNilArg(N, 0); |
| 254 | |
| 255 | break; |
Ted Kremenek | 99c6ad3 | 2008-03-27 07:25:52 +0000 | [diff] [blame] | 256 | |
Ted Kremenek | 4ba6283 | 2008-03-27 22:05:32 +0000 | [diff] [blame] | 257 | case 16: |
| 258 | if (!strcmp(cstr, "compare:options:")) |
| 259 | return CheckNilArg(N, 0); |
Ted Kremenek | 9b3fdea | 2008-03-27 21:23:57 +0000 | [diff] [blame] | 260 | |
| 261 | break; |
Ted Kremenek | 4ba6283 | 2008-03-27 22:05:32 +0000 | [diff] [blame] | 262 | |
| 263 | case 22: |
| 264 | if (!strcmp(cstr, "compare:options:range:")) |
| 265 | return CheckNilArg(N, 0); |
| 266 | |
| 267 | break; |
| 268 | |
| 269 | case 23: |
| 270 | |
| 271 | if (!strcmp(cstr, "caseInsensitiveCompare:")) |
| 272 | return CheckNilArg(N, 0); |
| 273 | |
| 274 | break; |
Ted Kremenek | 8730e13 | 2008-03-28 16:09:38 +0000 | [diff] [blame] | 275 | |
Ted Kremenek | 4ba6283 | 2008-03-27 22:05:32 +0000 | [diff] [blame] | 276 | case 29: |
| 277 | if (!strcmp(cstr, "compare:options:range:locale:")) |
| 278 | return CheckNilArg(N, 0); |
| 279 | |
| 280 | break; |
| 281 | |
| 282 | case 37: |
| 283 | if (!strcmp(cstr, "componentsSeparatedByCharactersInSet:")) |
| 284 | return CheckNilArg(N, 0); |
| 285 | |
| 286 | break; |
Ted Kremenek | 99c6ad3 | 2008-03-27 07:25:52 +0000 | [diff] [blame] | 287 | } |
| 288 | |
| 289 | return false; |
| 290 | } |