Ted Kremenek | ef91004 | 2009-11-04 04:24:16 +0000 | [diff] [blame] | 1 | //===--- UndefinedAssignmentChecker.h ---------------------------*- C++ -*--==// |
| 2 | // |
| 3 | // The LLVM Compiler Infrastructure |
| 4 | // |
| 5 | // This file is distributed under the University of Illinois Open Source |
| 6 | // License. See LICENSE.TXT for details. |
| 7 | // |
| 8 | //===----------------------------------------------------------------------===// |
| 9 | // |
Argyrios Kyrtzidis | 098874a | 2011-02-28 01:27:37 +0000 | [diff] [blame] | 10 | // This defines UndefinedAssignmentChecker, a builtin check in ExprEngine that |
Ted Kremenek | ef91004 | 2009-11-04 04:24:16 +0000 | [diff] [blame] | 11 | // checks for assigning undefined values. |
| 12 | // |
| 13 | //===----------------------------------------------------------------------===// |
| 14 | |
Argyrios Kyrtzidis | 098874a | 2011-02-28 01:27:37 +0000 | [diff] [blame] | 15 | #include "ClangSACheckers.h" |
Chandler Carruth | 3a02247 | 2012-12-04 09:13:33 +0000 | [diff] [blame] | 16 | #include "clang/StaticAnalyzer/Core/BugReporter/BugType.h" |
Argyrios Kyrtzidis | 6a5674f | 2011-03-01 01:16:21 +0000 | [diff] [blame] | 17 | #include "clang/StaticAnalyzer/Core/Checker.h" |
Argyrios Kyrtzidis | 098874a | 2011-02-28 01:27:37 +0000 | [diff] [blame] | 18 | #include "clang/StaticAnalyzer/Core/CheckerManager.h" |
| 19 | #include "clang/StaticAnalyzer/Core/PathSensitive/CheckerContext.h" |
Ted Kremenek | ef91004 | 2009-11-04 04:24:16 +0000 | [diff] [blame] | 20 | |
| 21 | using namespace clang; |
Ted Kremenek | 98857c9 | 2010-12-23 07:20:52 +0000 | [diff] [blame] | 22 | using namespace ento; |
Ted Kremenek | ef91004 | 2009-11-04 04:24:16 +0000 | [diff] [blame] | 23 | |
Zhongxing Xu | f0b7fc8 | 2009-11-22 12:29:52 +0000 | [diff] [blame] | 24 | namespace { |
Kovarththanan Rajaratnam | 65c6566 | 2009-11-28 06:07:30 +0000 | [diff] [blame] | 25 | class UndefinedAssignmentChecker |
Argyrios Kyrtzidis | 6a5674f | 2011-03-01 01:16:21 +0000 | [diff] [blame] | 26 | : public Checker<check::Bind> { |
Ahmed Charles | b898432 | 2014-03-07 20:03:18 +0000 | [diff] [blame] | 27 | mutable std::unique_ptr<BugType> BT; |
Argyrios Kyrtzidis | 098874a | 2011-02-28 01:27:37 +0000 | [diff] [blame] | 28 | |
Zhongxing Xu | f0b7fc8 | 2009-11-22 12:29:52 +0000 | [diff] [blame] | 29 | public: |
Anna Zaks | 3e0f415 | 2011-10-06 00:43:15 +0000 | [diff] [blame] | 30 | void checkBind(SVal location, SVal val, const Stmt *S, |
| 31 | CheckerContext &C) const; |
Zhongxing Xu | f0b7fc8 | 2009-11-22 12:29:52 +0000 | [diff] [blame] | 32 | }; |
| 33 | } |
| 34 | |
Argyrios Kyrtzidis | 098874a | 2011-02-28 01:27:37 +0000 | [diff] [blame] | 35 | void UndefinedAssignmentChecker::checkBind(SVal location, SVal val, |
Anna Zaks | 3e0f415 | 2011-10-06 00:43:15 +0000 | [diff] [blame] | 36 | const Stmt *StoreE, |
Argyrios Kyrtzidis | 098874a | 2011-02-28 01:27:37 +0000 | [diff] [blame] | 37 | CheckerContext &C) const { |
Ted Kremenek | ef91004 | 2009-11-04 04:24:16 +0000 | [diff] [blame] | 38 | if (!val.isUndef()) |
| 39 | return; |
| 40 | |
Anna Zaks | 0325646 | 2013-06-18 23:16:15 +0000 | [diff] [blame] | 41 | // Do not report assignments of uninitialized values inside swap functions. |
| 42 | // This should allow to swap partially uninitialized structs |
| 43 | // (radar://14129997) |
| 44 | if (const FunctionDecl *EnclosingFunctionDecl = |
| 45 | dyn_cast<FunctionDecl>(C.getStackFrame()->getDecl())) |
| 46 | if (C.getCalleeName(EnclosingFunctionDecl) == "swap") |
| 47 | return; |
| 48 | |
Devin Coughlin | e39bd40 | 2015-09-16 22:03:05 +0000 | [diff] [blame] | 49 | ExplodedNode *N = C.generateErrorNode(); |
Ted Kremenek | ef91004 | 2009-11-04 04:24:16 +0000 | [diff] [blame] | 50 | |
| 51 | if (!N) |
| 52 | return; |
| 53 | |
Artem Dergachev | f119bf9 | 2018-02-27 22:05:55 +0000 | [diff] [blame] | 54 | static const char *const DefaultMsg = |
| 55 | "Assigned value is garbage or undefined"; |
Ted Kremenek | ef91004 | 2009-11-04 04:24:16 +0000 | [diff] [blame] | 56 | if (!BT) |
Artem Dergachev | f119bf9 | 2018-02-27 22:05:55 +0000 | [diff] [blame] | 57 | BT.reset(new BuiltinBug(this, DefaultMsg)); |
Ted Kremenek | ef91004 | 2009-11-04 04:24:16 +0000 | [diff] [blame] | 58 | |
| 59 | // Generate a report for this bug. |
Artem Dergachev | f119bf9 | 2018-02-27 22:05:55 +0000 | [diff] [blame] | 60 | llvm::SmallString<128> Str; |
| 61 | llvm::raw_svector_ostream OS(Str); |
| 62 | |
Craig Topper | 0dbb783 | 2014-05-27 02:45:47 +0000 | [diff] [blame] | 63 | const Expr *ex = nullptr; |
Ted Kremenek | ef91004 | 2009-11-04 04:24:16 +0000 | [diff] [blame] | 64 | |
Ted Kremenek | 07343c0 | 2010-09-02 00:56:20 +0000 | [diff] [blame] | 65 | while (StoreE) { |
Roman Lebedev | 88b56ca | 2017-11-30 09:18:35 +0000 | [diff] [blame] | 66 | if (const UnaryOperator *U = dyn_cast<UnaryOperator>(StoreE)) { |
Artem Dergachev | f119bf9 | 2018-02-27 22:05:55 +0000 | [diff] [blame] | 67 | OS << "The expression is an uninitialized value. " |
Roman Lebedev | 88b56ca | 2017-11-30 09:18:35 +0000 | [diff] [blame] | 68 | "The computed value will also be garbage"; |
| 69 | |
| 70 | ex = U->getSubExpr(); |
| 71 | break; |
| 72 | } |
| 73 | |
Ted Kremenek | 07343c0 | 2010-09-02 00:56:20 +0000 | [diff] [blame] | 74 | if (const BinaryOperator *B = dyn_cast<BinaryOperator>(StoreE)) { |
Ted Kremenek | 28ec56d | 2010-03-22 22:16:26 +0000 | [diff] [blame] | 75 | if (B->isCompoundAssignmentOp()) { |
George Karpenkov | d703ec9 | 2018-01-17 20:27:29 +0000 | [diff] [blame] | 76 | if (C.getSVal(B->getLHS()).isUndef()) { |
Artem Dergachev | f119bf9 | 2018-02-27 22:05:55 +0000 | [diff] [blame] | 77 | OS << "The left expression of the compound assignment is an " |
Ted Kremenek | 28ec56d | 2010-03-22 22:16:26 +0000 | [diff] [blame] | 78 | "uninitialized value. The computed value will also be garbage"; |
| 79 | ex = B->getLHS(); |
| 80 | break; |
| 81 | } |
| 82 | } |
Ted Kremenek | ef91004 | 2009-11-04 04:24:16 +0000 | [diff] [blame] | 83 | |
Ted Kremenek | 209e31b | 2009-11-05 00:42:23 +0000 | [diff] [blame] | 84 | ex = B->getRHS(); |
Ted Kremenek | 28ec56d | 2010-03-22 22:16:26 +0000 | [diff] [blame] | 85 | break; |
| 86 | } |
| 87 | |
Ted Kremenek | 07343c0 | 2010-09-02 00:56:20 +0000 | [diff] [blame] | 88 | if (const DeclStmt *DS = dyn_cast<DeclStmt>(StoreE)) { |
Ted Kremenek | 5ef32db | 2011-08-12 23:37:29 +0000 | [diff] [blame] | 89 | const VarDecl *VD = dyn_cast<VarDecl>(DS->getSingleDecl()); |
Ted Kremenek | 209e31b | 2009-11-05 00:42:23 +0000 | [diff] [blame] | 90 | ex = VD->getInit(); |
| 91 | } |
Ted Kremenek | 28ec56d | 2010-03-22 22:16:26 +0000 | [diff] [blame] | 92 | |
Artem Dergachev | f119bf9 | 2018-02-27 22:05:55 +0000 | [diff] [blame] | 93 | if (const auto *CD = |
| 94 | dyn_cast<CXXConstructorDecl>(C.getStackFrame()->getDecl())) { |
| 95 | if (CD->isImplicit()) { |
| 96 | for (auto I : CD->inits()) { |
| 97 | if (I->getInit()->IgnoreImpCasts() == StoreE) { |
| 98 | OS << "Value assigned to field '" << I->getMember()->getName() |
| 99 | << "' in implicit constructor is garbage or undefined"; |
| 100 | break; |
| 101 | } |
| 102 | } |
| 103 | } |
| 104 | } |
| 105 | |
Ted Kremenek | 28ec56d | 2010-03-22 22:16:26 +0000 | [diff] [blame] | 106 | break; |
Ted Kremenek | ef91004 | 2009-11-04 04:24:16 +0000 | [diff] [blame] | 107 | } |
| 108 | |
Artem Dergachev | f119bf9 | 2018-02-27 22:05:55 +0000 | [diff] [blame] | 109 | if (OS.str().empty()) |
| 110 | OS << DefaultMsg; |
| 111 | |
| 112 | auto R = llvm::make_unique<BugReport>(*BT, OS.str(), N); |
Ted Kremenek | 28ec56d | 2010-03-22 22:16:26 +0000 | [diff] [blame] | 113 | if (ex) { |
| 114 | R->addRange(ex->getSourceRange()); |
Jordan Rose | a0f7d35 | 2012-08-28 00:50:51 +0000 | [diff] [blame] | 115 | bugreporter::trackNullOrUndefValue(N, ex, *R); |
Ted Kremenek | 28ec56d | 2010-03-22 22:16:26 +0000 | [diff] [blame] | 116 | } |
Aaron Ballman | 8d3a7a5 | 2015-06-23 13:15:32 +0000 | [diff] [blame] | 117 | C.emitReport(std::move(R)); |
Ted Kremenek | 28ec56d | 2010-03-22 22:16:26 +0000 | [diff] [blame] | 118 | } |
Ted Kremenek | ef91004 | 2009-11-04 04:24:16 +0000 | [diff] [blame] | 119 | |
Argyrios Kyrtzidis | 098874a | 2011-02-28 01:27:37 +0000 | [diff] [blame] | 120 | void ento::registerUndefinedAssignmentChecker(CheckerManager &mgr) { |
| 121 | mgr.registerChecker<UndefinedAssignmentChecker>(); |
| 122 | } |