blob: 59def881803f4b415cb79d3a8cbc842444718297 [file] [log] [blame]
Ted Kremenekb663ffe2010-02-25 05:44:09 +00001// MacOSXAPIChecker.h - Checks proper use of various MacOS X APIs --*- C++ -*-//
2//
3// The LLVM Compiler Infrastructure
4//
5// This file is distributed under the University of Illinois Open Source
6// License. See LICENSE.TXT for details.
7//
8//===----------------------------------------------------------------------===//
9//
10// This defines MacOSXAPIChecker, which is an assortment of checks on calls
11// to various, widely used Mac OS X functions.
12//
13// FIXME: What's currently in BasicObjCFoundationChecks.cpp should be migrated
14// to here, using the new Checker interface.
15//
16//===----------------------------------------------------------------------===//
17
Argyrios Kyrtzidisa6d04d52011-02-15 07:42:33 +000018#include "ClangSACheckers.h"
Argyrios Kyrtzidis6a5674f2011-03-01 01:16:21 +000019#include "clang/StaticAnalyzer/Core/Checker.h"
Argyrios Kyrtzidis507ff532011-02-17 21:39:17 +000020#include "clang/StaticAnalyzer/Core/CheckerManager.h"
Argyrios Kyrtzidisdff865d2011-02-23 01:05:36 +000021#include "clang/StaticAnalyzer/Core/PathSensitive/CheckerContext.h"
Ted Kremenekf8cbac42011-02-10 01:03:03 +000022#include "clang/StaticAnalyzer/Core/BugReporter/BugType.h"
Ted Kremenek001fd5b2011-08-15 22:09:50 +000023#include "clang/StaticAnalyzer/Core/PathSensitive/ProgramStateTrait.h"
Argyrios Kyrtzidisdff865d2011-02-23 01:05:36 +000024#include "clang/Basic/TargetInfo.h"
Ted Kremenekb663ffe2010-02-25 05:44:09 +000025#include "llvm/ADT/SmallString.h"
26#include "llvm/ADT/StringSwitch.h"
27#include "llvm/Support/raw_ostream.h"
28
29using namespace clang;
Ted Kremenek98857c92010-12-23 07:20:52 +000030using namespace ento;
Ted Kremenekb663ffe2010-02-25 05:44:09 +000031
32namespace {
Argyrios Kyrtzidis6a5674f2011-03-01 01:16:21 +000033class MacOSXAPIChecker : public Checker< check::PreStmt<CallExpr> > {
Jordy Roseede26952011-07-15 06:02:19 +000034 mutable llvm::OwningPtr<BugType> BT_dispatchOnce;
Ted Kremenekb663ffe2010-02-25 05:44:09 +000035
36public:
Argyrios Kyrtzidisdff865d2011-02-23 01:05:36 +000037 void checkPreStmt(const CallExpr *CE, CheckerContext &C) const;
Jordy Roseede26952011-07-15 06:02:19 +000038
39 void CheckDispatchOnce(CheckerContext &C, const CallExpr *CE,
40 const IdentifierInfo *FI) const;
41
42 typedef void (MacOSXAPIChecker::*SubChecker)(CheckerContext &,
43 const CallExpr *,
44 const IdentifierInfo *) const;
Ted Kremenekb663ffe2010-02-25 05:44:09 +000045};
46} //end anonymous namespace
47
Ted Kremenekb663ffe2010-02-25 05:44:09 +000048//===----------------------------------------------------------------------===//
49// dispatch_once and dispatch_once_f
50//===----------------------------------------------------------------------===//
51
Jordy Roseede26952011-07-15 06:02:19 +000052void MacOSXAPIChecker::CheckDispatchOnce(CheckerContext &C, const CallExpr *CE,
53 const IdentifierInfo *FI) const {
Ted Kremenekb663ffe2010-02-25 05:44:09 +000054 if (CE->getNumArgs() < 1)
55 return;
56
57 // Check if the first argument is stack allocated. If so, issue a warning
58 // because that's likely to be bad news.
Ted Kremenek001fd5b2011-08-15 22:09:50 +000059 const ProgramState *state = C.getState();
Ted Kremenekb663ffe2010-02-25 05:44:09 +000060 const MemRegion *R = state->getSVal(CE->getArg(0)).getAsRegion();
61 if (!R || !isa<StackSpaceRegion>(R->getMemorySpace()))
62 return;
63
Ted Kremenek750b7ac2010-12-20 21:19:09 +000064 ExplodedNode *N = C.generateSink(state);
Ted Kremenekb663ffe2010-02-25 05:44:09 +000065 if (!N)
66 return;
67
Jordy Roseede26952011-07-15 06:02:19 +000068 if (!BT_dispatchOnce)
69 BT_dispatchOnce.reset(new BugType("Improper use of 'dispatch_once'",
70 "Mac OS X API"));
71
Ted Kremenekb663ffe2010-02-25 05:44:09 +000072 llvm::SmallString<256> S;
73 llvm::raw_svector_ostream os(S);
74 os << "Call to '" << FI->getName() << "' uses";
75 if (const VarRegion *VR = dyn_cast<VarRegion>(R))
76 os << " the local variable '" << VR->getDecl()->getName() << '\'';
77 else
78 os << " stack allocated memory";
79 os << " for the predicate value. Using such transient memory for "
80 "the predicate is potentially dangerous.";
81 if (isa<VarRegion>(R) && isa<StackLocalsSpaceRegion>(R->getMemorySpace()))
82 os << " Perhaps you intended to declare the variable as 'static'?";
83
Jordy Roseede26952011-07-15 06:02:19 +000084 RangedBugReport *report = new RangedBugReport(*BT_dispatchOnce, os.str(), N);
Ted Kremenekb663ffe2010-02-25 05:44:09 +000085 report->addRange(CE->getArg(0)->getSourceRange());
86 C.EmitReport(report);
87}
88
89//===----------------------------------------------------------------------===//
90// Central dispatch function.
91//===----------------------------------------------------------------------===//
92
Argyrios Kyrtzidisdff865d2011-02-23 01:05:36 +000093void MacOSXAPIChecker::checkPreStmt(const CallExpr *CE,
94 CheckerContext &C) const {
Jordy Roseede26952011-07-15 06:02:19 +000095 // FIXME: This sort of logic is common to several checkers, including
96 // UnixAPIChecker, PthreadLockChecker, and CStringChecker. Should refactor.
Ted Kremenek001fd5b2011-08-15 22:09:50 +000097 const ProgramState *state = C.getState();
Ted Kremenekb663ffe2010-02-25 05:44:09 +000098 const Expr *Callee = CE->getCallee();
Jordy Roseede26952011-07-15 06:02:19 +000099 const FunctionDecl *Fn = state->getSVal(Callee).getAsFunctionDecl();
Ted Kremenekb663ffe2010-02-25 05:44:09 +0000100
101 if (!Fn)
102 return;
103
Jordy Roseede26952011-07-15 06:02:19 +0000104 const IdentifierInfo *FI = Fn->getIdentifier();
Ted Kremenekb663ffe2010-02-25 05:44:09 +0000105 if (!FI)
106 return;
107
Jordy Roseede26952011-07-15 06:02:19 +0000108 SubChecker SC =
109 llvm::StringSwitch<SubChecker>(FI->getName())
110 .Cases("dispatch_once", "dispatch_once_f",
111 &MacOSXAPIChecker::CheckDispatchOnce)
112 .Default(NULL);
Ted Kremenekb663ffe2010-02-25 05:44:09 +0000113
Jordy Roseede26952011-07-15 06:02:19 +0000114 if (SC)
115 (this->*SC)(C, CE, FI);
Ted Kremenekb663ffe2010-02-25 05:44:09 +0000116}
Argyrios Kyrtzidisdff865d2011-02-23 01:05:36 +0000117
118//===----------------------------------------------------------------------===//
119// Registration.
120//===----------------------------------------------------------------------===//
121
122void ento::registerMacOSXAPIChecker(CheckerManager &mgr) {
123 mgr.registerChecker<MacOSXAPIChecker>();
124}