blob: 223069f925819fc28d891179c81acd42c78f23c0 [file] [log] [blame]
Ted Kremenekcdc3a892012-08-24 20:39:55 +00001// RUN: %clang_cc1 -analyze -analyzer-checker=core,alpha.core.CastToStruct -analyzer-store=region -analyzer-constraints=range -verify %s
Zhongxing Xuef8b28e2008-10-17 05:19:52 +00002
Zhongxing Xu72e16822008-10-24 08:51:58 +00003struct s {
4 int data;
5 int data_array[10];
6};
Zhongxing Xuef8b28e2008-10-17 05:19:52 +00007
Zhongxing Xu234a7d22008-10-27 09:19:25 +00008typedef struct {
9 int data;
10} STYPE;
11
Zhongxing Xu91844122009-05-20 09:18:48 +000012void g(char *p);
Zhongxing Xu04b90bc2008-11-02 13:17:44 +000013void g1(struct s* p);
14
Zhongxing Xu661fc392008-11-25 01:45:11 +000015// Array to pointer conversion. Array in the struct field.
Zhongxing Xuef8b28e2008-10-17 05:19:52 +000016void f(void) {
17 int a[10];
18 int (*p)[10];
19 p = &a;
20 (*p)[3] = 1;
21
22 struct s d;
23 struct s *q;
24 q = &d;
Zhongxing Xu72e16822008-10-24 08:51:58 +000025 q->data = 3;
26 d.data_array[9] = 17;
Zhongxing Xuef8b28e2008-10-17 05:19:52 +000027}
Zhongxing Xu2e971202008-10-25 14:11:23 +000028
Zhongxing Xu661fc392008-11-25 01:45:11 +000029// StringLiteral in lvalue context and pointer to array type.
30// p: ElementRegion, q: StringRegion
Zhongxing Xu2e971202008-10-25 14:11:23 +000031void f2() {
32 char *p = "/usr/local";
33 char (*q)[4];
34 q = &"abc";
35}
Zhongxing Xu234a7d22008-10-27 09:19:25 +000036
Zhongxing Xu661fc392008-11-25 01:45:11 +000037// Typedef'ed struct definition.
Zhongxing Xu234a7d22008-10-27 09:19:25 +000038void f3() {
39 STYPE s;
40}
Zhongxing Xudf2aa1e2008-10-31 10:23:14 +000041
Zhongxing Xu661fc392008-11-25 01:45:11 +000042// Initialize array with InitExprList.
Zhongxing Xudf2aa1e2008-10-31 10:23:14 +000043void f4() {
44 int a[] = { 1, 2, 3};
45 int b[3] = { 1, 2 };
Zhongxing Xub61f49c2009-01-23 10:23:13 +000046 struct s c[] = {{1,{1}}};
Zhongxing Xudf2aa1e2008-10-31 10:23:14 +000047}
Zhongxing Xu04b90bc2008-11-02 13:17:44 +000048
Zhongxing Xu661fc392008-11-25 01:45:11 +000049// Struct variable in lvalue context.
Zhongxing Xu5834ed62009-01-13 01:49:57 +000050// Assign UnknownVal to the whole struct.
Zhongxing Xu04b90bc2008-11-02 13:17:44 +000051void f5() {
52 struct s data;
53 g1(&data);
54}
Zhongxing Xub6701332008-11-13 07:59:15 +000055
Zhongxing Xu661fc392008-11-25 01:45:11 +000056// AllocaRegion test.
Zhongxing Xub6701332008-11-13 07:59:15 +000057void f6() {
58 char *p;
59 p = __builtin_alloca(10);
Zhongxing Xu91844122009-05-20 09:18:48 +000060 g(p);
61 char c = *p;
Zhongxing Xub6701332008-11-13 07:59:15 +000062 p[1] = 'a';
Zhongxing Xu2acc3992009-05-20 09:03:10 +000063 // Test if RegionStore::EvalBinOp converts the alloca region to element
64 // region.
Zhongxing Xu262fd032009-05-20 09:00:16 +000065 p += 2;
Zhongxing Xub6701332008-11-13 07:59:15 +000066}
Zhongxing Xufb75b252008-11-13 08:44:52 +000067
68struct s2;
69
70void g2(struct s2 *p);
71
Zhongxing Xu661fc392008-11-25 01:45:11 +000072// Incomplete struct pointer used as function argument.
Zhongxing Xufb75b252008-11-13 08:44:52 +000073void f7() {
74 struct s2 *p = __builtin_alloca(10);
75 g2(p);
76}
Zhongxing Xu26134a12008-11-13 09:20:05 +000077
Zhongxing Xu661fc392008-11-25 01:45:11 +000078// sizeof() is unsigned while -1 is signed in array index.
Zhongxing Xu26134a12008-11-13 09:20:05 +000079void f8() {
80 int a[10];
Zhongxing Xu33d7cbf2008-11-24 23:45:56 +000081 a[sizeof(a)/sizeof(int) - 1] = 1; // no-warning
Zhongxing Xu26134a12008-11-13 09:20:05 +000082}
Zhongxing Xu617ff312008-11-18 13:30:46 +000083
Zhongxing Xu661fc392008-11-25 01:45:11 +000084// Initialization of struct array elements.
Zhongxing Xu617ff312008-11-18 13:30:46 +000085void f9() {
86 struct s a[10];
87}
Zhongxing Xu27cae9e2008-11-30 05:51:19 +000088
89// Initializing array with string literal.
90void f10() {
91 char a1[4] = "abc";
Zhongxing Xu27cae9e2008-11-30 05:51:19 +000092 char a3[6] = "abc";
93}
Zhongxing Xu562c4d92009-01-23 11:22:12 +000094
95// Retrieve the default value of element/field region.
96void f11() {
97 struct s a;
Zhongxing Xu91844122009-05-20 09:18:48 +000098 g1(&a);
Zhongxing Xu562c4d92009-01-23 11:22:12 +000099 if (a.data == 0) // no-warning
100 a.data = 1;
101}
Zhongxing Xu3450a552009-02-19 08:42:43 +0000102
103// Convert unsigned offset to signed when creating ElementRegion from
104// SymbolicRegion.
105void f12(int *list) {
106 unsigned i = 0;
107 list[i] = 1;
108}
Zhongxing Xuc57bc592009-03-18 02:07:30 +0000109
110struct s1 {
111 struct s2 {
112 int d;
113 } e;
114};
115
116// The binding of a.e.d should not be removed. Test recursive subregion map
117// building: a->e, e->d. Only then 'a' could be added to live region roots.
118void f13(double timeout) {
119 struct s1 a;
John McCall680523a2009-11-07 03:30:10 +0000120 a.e.d = (int) timeout;
Zhongxing Xuc57bc592009-03-18 02:07:30 +0000121 if (a.e.d == 10)
122 a.e.d = 4;
123}
Zhongxing Xu3e001f32009-05-03 00:27:40 +0000124
125struct s3 {
126 int a[2];
127};
128
129static struct s3 opt;
130
131// Test if the embedded array is retrieved correctly.
132void f14() {
133 struct s3 my_opt = opt;
134}
Zhongxing Xu264e9372009-05-12 10:10:00 +0000135
136void bar(int*);
137
138// Test if the array is correctly invalidated.
139void f15() {
140 int a[10];
141 bar(a);
142 if (a[1]) // no-warning
Anders Carlsson9668b1f2009-07-30 22:37:41 +0000143 (void)1;
Zhongxing Xu264e9372009-05-12 10:10:00 +0000144}
Zhongxing Xu3f6978a2009-06-11 09:11:27 +0000145
146struct s3 p[1];
147
148// Code from postgresql.
149// Current cast logic of region store mistakenly leaves the final result region
150// an ElementRegion of type 'char'. Then load a nonloc::SymbolVal from it and
151// assigns to 'a'.
152void f16(struct s3 *p) {
Ted Kremenekc4bac8e2012-08-16 17:45:23 +0000153 struct s3 a = *((struct s3*) ((char*) &p[0])); // expected-warning{{Casting a non-structure type to a structure type and accessing a field can lead to memory access errors or data corruption}}
Zhongxing Xu3f6978a2009-06-11 09:11:27 +0000154}
Zhongxing Xu6bd8a522009-06-28 13:59:24 +0000155
156void inv(struct s1 *);
157
158// Invalidate the struct field.
159void f17() {
160 struct s1 t;
161 int x;
162 inv(&t);
163 if (t.e.d)
164 x = 1;
165}
Zhongxing Xua03f1572009-06-29 06:43:40 +0000166
167void read(char*);
168
169void f18() {
170 char *q;
171 char *p = (char *) __builtin_alloca(10);
172 read(p);
173 q = p;
174 q++;
175 if (*q) { // no-warning
176 }
177}