[analyzer] operator new: Fix path diagnostics around the operator call.
Implements finding appropriate source locations for intermediate diagnostic
pieces in path-sensitive bug reports that need to descend into an inlined
operator new() call that was called via new-expression. The diagnostics have
worked correctly when operator new() was called "directly".
Differential Revision: https://reviews.llvm.org/D41409
rdar://problem/12180598
llvm-svn: 322791
diff --git a/clang/test/Analysis/new-ctor-malloc.cpp b/clang/test/Analysis/new-ctor-malloc.cpp
index d07242c..74b1e21 100644
--- a/clang/test/Analysis/new-ctor-malloc.cpp
+++ b/clang/test/Analysis/new-ctor-malloc.cpp
@@ -1,4 +1,4 @@
-// RUN: %clang_analyze_cc1 -analyzer-checker=core,debug.ExprInspection,unix.Malloc -analyzer-config c++-allocator-inlining=true -std=c++11 -verify %s
+// RUN: %clang_analyze_cc1 -analyzer-checker=core,debug.ExprInspection,unix.Malloc -analyzer-config c++-allocator-inlining=true -analyzer-output=text -std=c++11 -verify %s
void clang_analyzer_eval(bool);
@@ -7,12 +7,15 @@
void *malloc(size_t size);
void *operator new(size_t size) throw() {
- void *x = malloc(size);
- if (!x)
+ void *x = malloc(size); // expected-note {{Memory is allocated}}
+ if (!x) // expected-note {{Assuming 'x' is non-null}}
+ // expected-note@-1 {{Taking false branch}}
return nullptr;
return x;
}
void checkNewAndConstructorInlining() {
- int *s = new int;
+ int *s = new int; // expected-note {{Calling 'operator new'}}
+ // expected-note@-1{{Returning from 'operator new'}}
} // expected-warning {{Potential leak of memory pointed to by 's'}}
+ // expected-note@-1 {{Potential leak of memory pointed to by 's'}}