blob: f152d4451d8d26958fe20dcb53eaf46db72e24bc [file] [log] [blame]
Ted Kremenekf45d18c2008-09-18 06:33:41 +00001//=- CheckNSError.cpp - Coding conventions for uses of NSError ---*- C++ -*-==//
2//
3// The LLVM Compiler Infrastructure
4//
5// This file is distributed under the University of Illinois Open Source
6// License. See LICENSE.TXT for details.
7//
8//===----------------------------------------------------------------------===//
9//
10// This file defines a CheckNSError, a flow-insenstive check
11// that determines if an Objective-C class interface correctly returns
12// a non-void return type.
13//
14// File under feature request PR 2600.
15//
16//===----------------------------------------------------------------------===//
17
18#include "clang/Analysis/LocalCheckers.h"
19#include "clang/Analysis/PathSensitive/BugReporter.h"
Ted Kremenekcfdf9b42008-09-18 21:25:13 +000020#include "clang/Analysis/PathSensitive/GRExprEngine.h"
21#include "BasicObjCFoundationChecks.h"
22#include "llvm/Support/Compiler.h"
Ted Kremenekf45d18c2008-09-18 06:33:41 +000023#include "clang/AST/DeclObjC.h"
Ted Kremenekcfdf9b42008-09-18 21:25:13 +000024#include "clang/AST/Decl.h"
25#include "llvm/ADT/SmallVector.h"
Ted Kremenekf45d18c2008-09-18 06:33:41 +000026
27using namespace clang;
28
Ted Kremenekcfdf9b42008-09-18 21:25:13 +000029namespace {
Ted Kremenekcf118d42009-02-04 23:49:09 +000030class VISIBILITY_HIDDEN NSErrorCheck : public BugType {
Zhongxing Xu5ab128b2009-08-21 02:18:44 +000031 const Decl &CodeDecl;
Ted Kremenekcf118d42009-02-04 23:49:09 +000032 const bool isNSErrorWarning;
33 IdentifierInfo * const II;
34 GRExprEngine &Eng;
Ted Kremenekf45d18c2008-09-18 06:33:41 +000035
Zhongxing Xu5ab128b2009-08-21 02:18:44 +000036 void CheckSignature(const ObjCMethodDecl& MD, QualType& ResultTy,
Ted Kremenekcf118d42009-02-04 23:49:09 +000037 llvm::SmallVectorImpl<VarDecl*>& ErrorParams);
Ted Kremenekcc9ac412008-10-01 23:24:09 +000038
Zhongxing Xu5ab128b2009-08-21 02:18:44 +000039 void CheckSignature(const FunctionDecl& MD, QualType& ResultTy,
Ted Kremenekcf118d42009-02-04 23:49:09 +000040 llvm::SmallVectorImpl<VarDecl*>& ErrorParams);
Ted Kremenekcfdf9b42008-09-18 21:25:13 +000041
Ted Kremenekcf118d42009-02-04 23:49:09 +000042 bool CheckNSErrorArgument(QualType ArgTy);
43 bool CheckCFErrorArgument(QualType ArgTy);
Ted Kremenekcfdf9b42008-09-18 21:25:13 +000044
Ted Kremenekc8781382009-06-17 22:28:13 +000045 void CheckParamDeref(VarDecl* V, const GRState *state, BugReporter& BR);
Ted Kremenekcc9ac412008-10-01 23:24:09 +000046
Zhongxing Xu5ab128b2009-08-21 02:18:44 +000047 void EmitRetTyWarning(BugReporter& BR, const Decl& CodeDecl);
Ted Kremenek7360fda2008-09-18 23:09:54 +000048
Ted Kremenekcfdf9b42008-09-18 21:25:13 +000049public:
Zhongxing Xu5ab128b2009-08-21 02:18:44 +000050 NSErrorCheck(const Decl &D, bool isNSError, GRExprEngine& eng)
51 : BugType(isNSError ? "NSError** null dereference"
52 : "CFErrorRef* null dereference",
53 "Coding Conventions (Apple)"),
54 CodeDecl(D),
Ted Kremenekcf118d42009-02-04 23:49:09 +000055 isNSErrorWarning(isNSError),
56 II(&eng.getContext().Idents.get(isNSErrorWarning ? "NSError":"CFErrorRef")),
57 Eng(eng) {}
Ted Kremenek7360fda2008-09-18 23:09:54 +000058
Ted Kremenekcf118d42009-02-04 23:49:09 +000059 void FlushReports(BugReporter& BR);
Ted Kremenekcfdf9b42008-09-18 21:25:13 +000060};
61
62} // end anonymous namespace
63
Zhongxing Xu5ab128b2009-08-21 02:18:44 +000064void clang::RegisterNSErrorChecks(BugReporter& BR, GRExprEngine &Eng,
65 const Decl &D) {
66 BR.Register(new NSErrorCheck(D, true, Eng));
67 BR.Register(new NSErrorCheck(D, false, Eng));
Ted Kremenekcfdf9b42008-09-18 21:25:13 +000068}
69
Ted Kremenekcf118d42009-02-04 23:49:09 +000070void NSErrorCheck::FlushReports(BugReporter& BR) {
Ted Kremenekcfdf9b42008-09-18 21:25:13 +000071 // Get the analysis engine and the exploded analysis graph.
Zhongxing Xu031ccc02009-08-06 12:48:26 +000072 ExplodedGraph& G = Eng.getGraph();
Ted Kremenekcfdf9b42008-09-18 21:25:13 +000073
Ted Kremenekcfdf9b42008-09-18 21:25:13 +000074 // Get the ASTContext, which is useful for querying type information.
Ted Kremenekf45d18c2008-09-18 06:33:41 +000075 ASTContext &Ctx = BR.getContext();
Ted Kremenekcfdf9b42008-09-18 21:25:13 +000076
77 QualType ResultTy;
Ted Kremenekcf118d42009-02-04 23:49:09 +000078 llvm::SmallVector<VarDecl*, 5> ErrorParams;
Ted Kremenekcc9ac412008-10-01 23:24:09 +000079
Zhongxing Xu5ab128b2009-08-21 02:18:44 +000080 if (const ObjCMethodDecl* MD = dyn_cast<ObjCMethodDecl>(&CodeDecl))
Ted Kremenekcf118d42009-02-04 23:49:09 +000081 CheckSignature(*MD, ResultTy, ErrorParams);
Zhongxing Xu5ab128b2009-08-21 02:18:44 +000082 else if (const FunctionDecl* FD = dyn_cast<FunctionDecl>(&CodeDecl))
Ted Kremenekcf118d42009-02-04 23:49:09 +000083 CheckSignature(*FD, ResultTy, ErrorParams);
Ted Kremenekcc9ac412008-10-01 23:24:09 +000084 else
Ted Kremenekcfdf9b42008-09-18 21:25:13 +000085 return;
86
Ted Kremenekcf118d42009-02-04 23:49:09 +000087 if (ErrorParams.empty())
Ted Kremenekcc9ac412008-10-01 23:24:09 +000088 return;
89
Ted Kremenekcf118d42009-02-04 23:49:09 +000090 if (ResultTy == Ctx.VoidTy) EmitRetTyWarning(BR, CodeDecl);
Ted Kremenek7360fda2008-09-18 23:09:54 +000091
Zhongxing Xu031ccc02009-08-06 12:48:26 +000092 for (ExplodedGraph::roots_iterator RI=G.roots_begin(), RE=G.roots_end();
93 RI!=RE; ++RI) {
Ted Kremenekcf118d42009-02-04 23:49:09 +000094 // Scan the parameters for an implicit null dereference.
95 for (llvm::SmallVectorImpl<VarDecl*>::iterator I=ErrorParams.begin(),
96 E=ErrorParams.end(); I!=E; ++I)
Ted Kremenekc8781382009-06-17 22:28:13 +000097 CheckParamDeref(*I, (*RI)->getState(), BR);
Ted Kremenekcc9ac412008-10-01 23:24:09 +000098
Ted Kremenekcc9ac412008-10-01 23:24:09 +000099 }
Ted Kremenekf45d18c2008-09-18 06:33:41 +0000100}
Ted Kremenekcfdf9b42008-09-18 21:25:13 +0000101
Zhongxing Xu5ab128b2009-08-21 02:18:44 +0000102void NSErrorCheck::EmitRetTyWarning(BugReporter& BR, const Decl& CodeDecl) {
Ted Kremenekcf118d42009-02-04 23:49:09 +0000103 std::string sbuf;
104 llvm::raw_string_ostream os(sbuf);
Ted Kremenekcc9ac412008-10-01 23:24:09 +0000105
106 if (isa<ObjCMethodDecl>(CodeDecl))
107 os << "Method";
108 else
109 os << "Function";
110
111 os << " accepting ";
112 os << (isNSErrorWarning ? "NSError**" : "CFErrorRef*");
113 os << " should have a non-void return value to indicate whether or not an "
Ted Kremenek355a6922009-08-06 05:01:36 +0000114 "error occurred";
Ted Kremenekcc9ac412008-10-01 23:24:09 +0000115
116 BR.EmitBasicReport(isNSErrorWarning
117 ? "Bad return type when passing NSError**"
118 : "Bad return type when passing CFError*",
Ted Kremenekcf118d42009-02-04 23:49:09 +0000119 getCategory().c_str(), os.str().c_str(),
120 CodeDecl.getLocation());
Ted Kremenekcc9ac412008-10-01 23:24:09 +0000121}
122
123void
Zhongxing Xu5ab128b2009-08-21 02:18:44 +0000124NSErrorCheck::CheckSignature(const ObjCMethodDecl& M, QualType& ResultTy,
Ted Kremenekcf118d42009-02-04 23:49:09 +0000125 llvm::SmallVectorImpl<VarDecl*>& ErrorParams) {
Ted Kremenekcfdf9b42008-09-18 21:25:13 +0000126
127 ResultTy = M.getResultType();
128
129 for (ObjCMethodDecl::param_iterator I=M.param_begin(),
Ted Kremenekcc9ac412008-10-01 23:24:09 +0000130 E=M.param_end(); I!=E; ++I) {
131
132 QualType T = (*I)->getType();
133
Ted Kremenekcf118d42009-02-04 23:49:09 +0000134 if (isNSErrorWarning) {
135 if (CheckNSErrorArgument(T)) ErrorParams.push_back(*I);
136 }
137 else if (CheckCFErrorArgument(T))
138 ErrorParams.push_back(*I);
Ted Kremenekcc9ac412008-10-01 23:24:09 +0000139 }
Ted Kremenekcfdf9b42008-09-18 21:25:13 +0000140}
141
Ted Kremenekcc9ac412008-10-01 23:24:09 +0000142void
Zhongxing Xu5ab128b2009-08-21 02:18:44 +0000143NSErrorCheck::CheckSignature(const FunctionDecl& F, QualType& ResultTy,
Ted Kremenekcf118d42009-02-04 23:49:09 +0000144 llvm::SmallVectorImpl<VarDecl*>& ErrorParams) {
Ted Kremenekcc9ac412008-10-01 23:24:09 +0000145
146 ResultTy = F.getResultType();
147
Zhongxing Xu5ab128b2009-08-21 02:18:44 +0000148 for (FunctionDecl::param_const_iterator I = F.param_begin(),
149 E = F.param_end(); I != E; ++I) {
Ted Kremenekcc9ac412008-10-01 23:24:09 +0000150
151 QualType T = (*I)->getType();
Ted Kremenekcf118d42009-02-04 23:49:09 +0000152
153 if (isNSErrorWarning) {
154 if (CheckNSErrorArgument(T)) ErrorParams.push_back(*I);
155 }
156 else if (CheckCFErrorArgument(T))
157 ErrorParams.push_back(*I);
Ted Kremenekcc9ac412008-10-01 23:24:09 +0000158 }
159}
160
161
Ted Kremenekcf118d42009-02-04 23:49:09 +0000162bool NSErrorCheck::CheckNSErrorArgument(QualType ArgTy) {
Ted Kremenekcc9ac412008-10-01 23:24:09 +0000163
Ted Kremenek6217b802009-07-29 21:53:49 +0000164 const PointerType* PPT = ArgTy->getAs<PointerType>();
Steve Naroff14108da2009-07-10 23:34:53 +0000165 if (!PPT)
166 return false;
Ted Kremenekcfdf9b42008-09-18 21:25:13 +0000167
Steve Naroff14108da2009-07-10 23:34:53 +0000168 const ObjCObjectPointerType* PT =
169 PPT->getPointeeType()->getAsObjCObjectPointerType();
170
171 if (!PT)
172 return false;
Ted Kremenekcfdf9b42008-09-18 21:25:13 +0000173
Steve Naroff14108da2009-07-10 23:34:53 +0000174 const ObjCInterfaceDecl *ID = PT->getInterfaceDecl();
Ted Kremenekcfdf9b42008-09-18 21:25:13 +0000175
Steve Naroff14108da2009-07-10 23:34:53 +0000176 // FIXME: Can ID ever be NULL?
177 if (ID)
178 return II == ID->getIdentifier();
179
180 return false;
Ted Kremenekcfdf9b42008-09-18 21:25:13 +0000181}
Ted Kremenek7360fda2008-09-18 23:09:54 +0000182
Ted Kremenekcf118d42009-02-04 23:49:09 +0000183bool NSErrorCheck::CheckCFErrorArgument(QualType ArgTy) {
Ted Kremenekcc9ac412008-10-01 23:24:09 +0000184
Ted Kremenek6217b802009-07-29 21:53:49 +0000185 const PointerType* PPT = ArgTy->getAs<PointerType>();
Ted Kremenekcc9ac412008-10-01 23:24:09 +0000186 if (!PPT) return false;
187
188 const TypedefType* TT = PPT->getPointeeType()->getAsTypedefType();
189 if (!TT) return false;
190
Ted Kremenekcf118d42009-02-04 23:49:09 +0000191 return TT->getDecl()->getIdentifier() == II;
Ted Kremenekcc9ac412008-10-01 23:24:09 +0000192}
193
Ted Kremenekc8781382009-06-17 22:28:13 +0000194void NSErrorCheck::CheckParamDeref(VarDecl* Param, const GRState *rootState,
Ted Kremenekcf118d42009-02-04 23:49:09 +0000195 BugReporter& BR) {
Ted Kremenek7360fda2008-09-18 23:09:54 +0000196
Ted Kremenekc8781382009-06-17 22:28:13 +0000197 SVal ParamL = rootState->getLValue(Param);
Ted Kremenek993f1c72008-10-17 20:28:54 +0000198 const MemRegion* ParamR = cast<loc::MemRegionVal>(ParamL).getRegionAs<VarRegion>();
199 assert (ParamR && "Parameters always have VarRegions.");
Ted Kremenekc8781382009-06-17 22:28:13 +0000200 SVal ParamSVal = rootState->getSVal(ParamR);
Ted Kremenek993f1c72008-10-17 20:28:54 +0000201
Zhongxing Xu1c96b242008-10-17 05:57:07 +0000202 // FIXME: For now assume that ParamSVal is symbolic. We need to generalize
Ted Kremenek7360fda2008-09-18 23:09:54 +0000203 // this later.
Ted Kremenek93e71452009-03-30 19:53:37 +0000204 SymbolRef ParamSym = ParamSVal.getAsLocSymbol();
205 if (!ParamSym)
206 return;
Ted Kremenek7360fda2008-09-18 23:09:54 +0000207
208 // Iterate over the implicit-null dereferences.
209 for (GRExprEngine::null_deref_iterator I=Eng.implicit_null_derefs_begin(),
210 E=Eng.implicit_null_derefs_end(); I!=E; ++I) {
211
Ted Kremenekc8781382009-06-17 22:28:13 +0000212 const GRState *state = (*I)->getState();
213 const SVal* X = state->get<GRState::NullDerefTag>();
Ted Kremenek93e71452009-03-30 19:53:37 +0000214
215 if (!X || X->getAsSymbol() != ParamSym)
216 continue;
Ted Kremenek7360fda2008-09-18 23:09:54 +0000217
218 // Emit an error.
Ted Kremenekcf118d42009-02-04 23:49:09 +0000219 std::string sbuf;
220 llvm::raw_string_ostream os(sbuf);
Ted Kremenekcc9ac412008-10-01 23:24:09 +0000221 os << "Potential null dereference. According to coding standards ";
222
223 if (isNSErrorWarning)
224 os << "in 'Creating and Returning NSError Objects' the parameter '";
225 else
226 os << "documented in CoreFoundation/CFError.h the parameter '";
227
Chris Lattnerd9d22dd2008-11-24 05:29:24 +0000228 os << Param->getNameAsString() << "' may be null.";
Ted Kremenekcf118d42009-02-04 23:49:09 +0000229
230 BugReport *report = new BugReport(*this, os.str().c_str(), *I);
231 // FIXME: Notable symbols are now part of the report. We should
232 // add support for notable symbols in BugReport.
233 // BR.addNotableSymbol(SV->getSymbol());
234 BR.EmitReport(report);
Ted Kremenek7360fda2008-09-18 23:09:54 +0000235 }
236}