blob: 2d5cb60edf7dab9142ed0dc6dc69e74a143321cd [file] [log] [blame]
Jordy Rose31ae2592012-05-16 16:01:07 +00001//==- ExprInspectionChecker.cpp - Used for regression tests ------*- C++ -*-==//
2//
3// The LLVM Compiler Infrastructure
4//
5// This file is distributed under the University of Illinois Open Source
6// License. See LICENSE.TXT for details.
7//
8//===----------------------------------------------------------------------===//
9
10#include "ClangSACheckers.h"
Jordy Rose31ae2592012-05-16 16:01:07 +000011#include "clang/StaticAnalyzer/Core/BugReporter/BugType.h"
Chandler Carruth3a022472012-12-04 09:13:33 +000012#include "clang/StaticAnalyzer/Core/Checker.h"
Jordy Rose31ae2592012-05-16 16:01:07 +000013#include "clang/StaticAnalyzer/Core/PathSensitive/CheckerContext.h"
Artem Dergachev895242f2016-01-15 15:22:05 +000014#include "clang/StaticAnalyzer/Checkers/SValExplainer.h"
Benjamin Kramerd7d2b1f2012-12-01 16:35:25 +000015#include "llvm/ADT/StringSwitch.h"
Jordy Rose31ae2592012-05-16 16:01:07 +000016
17using namespace clang;
18using namespace ento;
19
20namespace {
Artem Dergachev30ed5462016-11-30 17:57:18 +000021class ExprInspectionChecker : public Checker<eval::Call, check::DeadSymbols,
22 check::EndAnalysis> {
Ahmed Charlesb8984322014-03-07 20:03:18 +000023 mutable std::unique_ptr<BugType> BT;
Jordan Rose13937b12012-08-10 22:26:29 +000024
Artem Dergachev30ed5462016-11-30 17:57:18 +000025 // These stats are per-analysis, not per-branch, hence they shouldn't
26 // stay inside the program state.
27 struct ReachedStat {
28 ExplodedNode *ExampleNode;
29 unsigned NumTimesReached;
30 };
31 mutable llvm::DenseMap<const CallExpr *, ReachedStat> ReachedStats;
32
Jordan Rose13937b12012-08-10 22:26:29 +000033 void analyzerEval(const CallExpr *CE, CheckerContext &C) const;
34 void analyzerCheckInlined(const CallExpr *CE, CheckerContext &C) const;
Jordan Rose9db2d9a2013-10-03 16:57:03 +000035 void analyzerWarnIfReached(const CallExpr *CE, CheckerContext &C) const;
Artem Dergachev30ed5462016-11-30 17:57:18 +000036 void analyzerNumTimesReached(const CallExpr *CE, CheckerContext &C) const;
Jordan Rosee9c57222013-07-19 00:59:08 +000037 void analyzerCrash(const CallExpr *CE, CheckerContext &C) const;
Artem Dergachev733e71b2015-12-10 09:28:06 +000038 void analyzerWarnOnDeadSymbol(const CallExpr *CE, CheckerContext &C) const;
Artem Dergachev30ed5462016-11-30 17:57:18 +000039 void analyzerDump(const CallExpr *CE, CheckerContext &C) const;
Artem Dergachev895242f2016-01-15 15:22:05 +000040 void analyzerExplain(const CallExpr *CE, CheckerContext &C) const;
Artem Dergachev30ed5462016-11-30 17:57:18 +000041 void analyzerPrintState(const CallExpr *CE, CheckerContext &C) const;
Artem Dergachev895242f2016-01-15 15:22:05 +000042 void analyzerGetExtent(const CallExpr *CE, CheckerContext &C) const;
Jordan Rose13937b12012-08-10 22:26:29 +000043
44 typedef void (ExprInspectionChecker::*FnCheck)(const CallExpr *,
45 CheckerContext &C) const;
46
Artem Dergachev30ed5462016-11-30 17:57:18 +000047 ExplodedNode *reportBug(llvm::StringRef Msg, CheckerContext &C) const;
48 ExplodedNode *reportBug(llvm::StringRef Msg, BugReporter &BR,
49 ExplodedNode *N) const;
Artem Dergachev895242f2016-01-15 15:22:05 +000050
Jordy Rose31ae2592012-05-16 16:01:07 +000051public:
52 bool evalCall(const CallExpr *CE, CheckerContext &C) const;
Artem Dergachev733e71b2015-12-10 09:28:06 +000053 void checkDeadSymbols(SymbolReaper &SymReaper, CheckerContext &C) const;
Artem Dergachev30ed5462016-11-30 17:57:18 +000054 void checkEndAnalysis(ExplodedGraph &G, BugReporter &BR,
55 ExprEngine &Eng) const;
Jordy Rose31ae2592012-05-16 16:01:07 +000056};
Alexander Kornienkoab9db512015-06-22 23:07:51 +000057}
Jordy Rose31ae2592012-05-16 16:01:07 +000058
Artem Dergachev895242f2016-01-15 15:22:05 +000059REGISTER_SET_WITH_PROGRAMSTATE(MarkedSymbols, SymbolRef)
Artem Dergachev733e71b2015-12-10 09:28:06 +000060
Jordy Rose31ae2592012-05-16 16:01:07 +000061bool ExprInspectionChecker::evalCall(const CallExpr *CE,
Jordan Rose13937b12012-08-10 22:26:29 +000062 CheckerContext &C) const {
Jordy Rose31ae2592012-05-16 16:01:07 +000063 // These checks should have no effect on the surrounding environment
Jordan Rose13937b12012-08-10 22:26:29 +000064 // (globals should not be invalidated, etc), hence the use of evalCall.
65 FnCheck Handler = llvm::StringSwitch<FnCheck>(C.getCalleeName(CE))
66 .Case("clang_analyzer_eval", &ExprInspectionChecker::analyzerEval)
67 .Case("clang_analyzer_checkInlined",
68 &ExprInspectionChecker::analyzerCheckInlined)
Jordan Rosee9c57222013-07-19 00:59:08 +000069 .Case("clang_analyzer_crash", &ExprInspectionChecker::analyzerCrash)
Artem Dergachev733e71b2015-12-10 09:28:06 +000070 .Case("clang_analyzer_warnIfReached",
71 &ExprInspectionChecker::analyzerWarnIfReached)
72 .Case("clang_analyzer_warnOnDeadSymbol",
73 &ExprInspectionChecker::analyzerWarnOnDeadSymbol)
Artem Dergachev895242f2016-01-15 15:22:05 +000074 .Case("clang_analyzer_explain", &ExprInspectionChecker::analyzerExplain)
Artem Dergachev30ed5462016-11-30 17:57:18 +000075 .Case("clang_analyzer_dump", &ExprInspectionChecker::analyzerDump)
Artem Dergachev895242f2016-01-15 15:22:05 +000076 .Case("clang_analyzer_getExtent", &ExprInspectionChecker::analyzerGetExtent)
Artem Dergachev30ed5462016-11-30 17:57:18 +000077 .Case("clang_analyzer_printState",
78 &ExprInspectionChecker::analyzerPrintState)
79 .Case("clang_analyzer_numTimesReached",
80 &ExprInspectionChecker::analyzerNumTimesReached)
Craig Topper0dbb7832014-05-27 02:45:47 +000081 .Default(nullptr);
Jordan Rose13937b12012-08-10 22:26:29 +000082
83 if (!Handler)
84 return false;
85
86 (this->*Handler)(CE, C);
87 return true;
88}
89
90static const char *getArgumentValueString(const CallExpr *CE,
91 CheckerContext &C) {
92 if (CE->getNumArgs() == 0)
93 return "Missing assertion argument";
94
95 ExplodedNode *N = C.getPredecessor();
96 const LocationContext *LC = N->getLocationContext();
97 ProgramStateRef State = N->getState();
98
99 const Expr *Assertion = CE->getArg(0);
100 SVal AssertionVal = State->getSVal(Assertion, LC);
101
102 if (AssertionVal.isUndef())
103 return "UNDEFINED";
104
105 ProgramStateRef StTrue, StFalse;
Benjamin Kramer867ea1d2014-03-02 13:01:17 +0000106 std::tie(StTrue, StFalse) =
David Blaikie2fdacbc2013-02-20 05:52:05 +0000107 State->assume(AssertionVal.castAs<DefinedOrUnknownSVal>());
Jordan Rose13937b12012-08-10 22:26:29 +0000108
109 if (StTrue) {
110 if (StFalse)
111 return "UNKNOWN";
112 else
113 return "TRUE";
114 } else {
115 if (StFalse)
116 return "FALSE";
117 else
118 llvm_unreachable("Invalid constraint; neither true or false.");
119 }
120}
121
Artem Dergachev30ed5462016-11-30 17:57:18 +0000122ExplodedNode *ExprInspectionChecker::reportBug(llvm::StringRef Msg,
123 CheckerContext &C) const {
124 ExplodedNode *N = C.generateNonFatalErrorNode();
125 reportBug(Msg, C.getBugReporter(), N);
126 return N;
127}
128
129ExplodedNode *ExprInspectionChecker::reportBug(llvm::StringRef Msg,
130 BugReporter &BR,
131 ExplodedNode *N) const {
132 if (!N)
133 return nullptr;
134
Artem Dergachev895242f2016-01-15 15:22:05 +0000135 if (!BT)
136 BT.reset(new BugType(this, "Checking analyzer assumptions", "debug"));
137
Artem Dergachev30ed5462016-11-30 17:57:18 +0000138 BR.emitReport(llvm::make_unique<BugReport>(*BT, Msg, N));
139 return N;
Artem Dergachev895242f2016-01-15 15:22:05 +0000140}
141
Jordan Rose13937b12012-08-10 22:26:29 +0000142void ExprInspectionChecker::analyzerEval(const CallExpr *CE,
143 CheckerContext &C) const {
Devin Coughline39bd402015-09-16 22:03:05 +0000144 const LocationContext *LC = C.getPredecessor()->getLocationContext();
Jordy Rose31ae2592012-05-16 16:01:07 +0000145
Jordy Rose31ae2592012-05-16 16:01:07 +0000146 // A specific instantiation of an inlined function may have more constrained
147 // values than can generally be assumed. Skip the check.
Craig Topper0dbb7832014-05-27 02:45:47 +0000148 if (LC->getCurrentStackFrame()->getParent() != nullptr)
Jordan Rose13937b12012-08-10 22:26:29 +0000149 return;
Jordy Rose31ae2592012-05-16 16:01:07 +0000150
Artem Dergachev895242f2016-01-15 15:22:05 +0000151 reportBug(getArgumentValueString(CE, C), C);
Jordan Rose13937b12012-08-10 22:26:29 +0000152}
Jordy Rose31ae2592012-05-16 16:01:07 +0000153
Jordan Rose9db2d9a2013-10-03 16:57:03 +0000154void ExprInspectionChecker::analyzerWarnIfReached(const CallExpr *CE,
155 CheckerContext &C) const {
Artem Dergachev895242f2016-01-15 15:22:05 +0000156 reportBug("REACHABLE", C);
Jordan Rose9db2d9a2013-10-03 16:57:03 +0000157}
158
Artem Dergachev30ed5462016-11-30 17:57:18 +0000159void ExprInspectionChecker::analyzerNumTimesReached(const CallExpr *CE,
160 CheckerContext &C) const {
161 ++ReachedStats[CE].NumTimesReached;
162 if (!ReachedStats[CE].ExampleNode) {
163 // Later, in checkEndAnalysis, we'd throw a report against it.
164 ReachedStats[CE].ExampleNode = C.generateNonFatalErrorNode();
165 }
166}
167
Jordan Rose13937b12012-08-10 22:26:29 +0000168void ExprInspectionChecker::analyzerCheckInlined(const CallExpr *CE,
169 CheckerContext &C) const {
Devin Coughline39bd402015-09-16 22:03:05 +0000170 const LocationContext *LC = C.getPredecessor()->getLocationContext();
Jordan Rose13937b12012-08-10 22:26:29 +0000171
172 // An inlined function could conceivably also be analyzed as a top-level
173 // function. We ignore this case and only emit a message (TRUE or FALSE)
174 // when we are analyzing it as an inlined function. This means that
175 // clang_analyzer_checkInlined(true) should always print TRUE, but
176 // clang_analyzer_checkInlined(false) should never actually print anything.
Craig Topper0dbb7832014-05-27 02:45:47 +0000177 if (LC->getCurrentStackFrame()->getParent() == nullptr)
Jordan Rose13937b12012-08-10 22:26:29 +0000178 return;
179
Artem Dergachev895242f2016-01-15 15:22:05 +0000180 reportBug(getArgumentValueString(CE, C), C);
181}
Jordan Rose13937b12012-08-10 22:26:29 +0000182
Artem Dergachev895242f2016-01-15 15:22:05 +0000183void ExprInspectionChecker::analyzerExplain(const CallExpr *CE,
184 CheckerContext &C) const {
Artem Dergachev30ed5462016-11-30 17:57:18 +0000185 if (CE->getNumArgs() == 0) {
Artem Dergachev895242f2016-01-15 15:22:05 +0000186 reportBug("Missing argument for explaining", C);
Artem Dergachev30ed5462016-11-30 17:57:18 +0000187 return;
188 }
Artem Dergachev895242f2016-01-15 15:22:05 +0000189
190 SVal V = C.getSVal(CE->getArg(0));
191 SValExplainer Ex(C.getASTContext());
192 reportBug(Ex.Visit(V), C);
193}
194
Artem Dergachev30ed5462016-11-30 17:57:18 +0000195void ExprInspectionChecker::analyzerDump(const CallExpr *CE,
196 CheckerContext &C) const {
197 if (CE->getNumArgs() == 0) {
198 reportBug("Missing argument for dumping", C);
199 return;
200 }
201
202 SVal V = C.getSVal(CE->getArg(0));
203
204 llvm::SmallString<32> Str;
205 llvm::raw_svector_ostream OS(Str);
206 V.dumpToStream(OS);
207 reportBug(OS.str(), C);
208}
209
Artem Dergachev895242f2016-01-15 15:22:05 +0000210void ExprInspectionChecker::analyzerGetExtent(const CallExpr *CE,
211 CheckerContext &C) const {
Artem Dergachev30ed5462016-11-30 17:57:18 +0000212 if (CE->getNumArgs() == 0) {
Artem Dergachev895242f2016-01-15 15:22:05 +0000213 reportBug("Missing region for obtaining extent", C);
Artem Dergachev30ed5462016-11-30 17:57:18 +0000214 return;
215 }
Artem Dergachev895242f2016-01-15 15:22:05 +0000216
217 auto MR = dyn_cast_or_null<SubRegion>(C.getSVal(CE->getArg(0)).getAsRegion());
Artem Dergachev30ed5462016-11-30 17:57:18 +0000218 if (!MR) {
Artem Dergachev895242f2016-01-15 15:22:05 +0000219 reportBug("Obtaining extent of a non-region", C);
Artem Dergachev30ed5462016-11-30 17:57:18 +0000220 return;
221 }
Artem Dergachev895242f2016-01-15 15:22:05 +0000222
223 ProgramStateRef State = C.getState();
224 State = State->BindExpr(CE, C.getLocationContext(),
225 MR->getExtent(C.getSValBuilder()));
226 C.addTransition(State);
Jordy Rose31ae2592012-05-16 16:01:07 +0000227}
228
Artem Dergachev30ed5462016-11-30 17:57:18 +0000229void ExprInspectionChecker::analyzerPrintState(const CallExpr *CE,
230 CheckerContext &C) const {
231 C.getState()->dump();
232}
233
Artem Dergachev733e71b2015-12-10 09:28:06 +0000234void ExprInspectionChecker::analyzerWarnOnDeadSymbol(const CallExpr *CE,
235 CheckerContext &C) const {
236 if (CE->getNumArgs() == 0)
237 return;
238 SVal Val = C.getSVal(CE->getArg(0));
239 SymbolRef Sym = Val.getAsSymbol();
240 if (!Sym)
241 return;
242
243 ProgramStateRef State = C.getState();
244 State = State->add<MarkedSymbols>(Sym);
245 C.addTransition(State);
246}
247
248void ExprInspectionChecker::checkDeadSymbols(SymbolReaper &SymReaper,
249 CheckerContext &C) const {
250 ProgramStateRef State = C.getState();
251 const MarkedSymbolsTy &Syms = State->get<MarkedSymbols>();
Artem Dergachev30ed5462016-11-30 17:57:18 +0000252 ExplodedNode *N = C.getPredecessor();
Artem Dergachev733e71b2015-12-10 09:28:06 +0000253 for (auto I = Syms.begin(), E = Syms.end(); I != E; ++I) {
Artem Dergachev895242f2016-01-15 15:22:05 +0000254 SymbolRef Sym = *I;
Artem Dergachev733e71b2015-12-10 09:28:06 +0000255 if (!SymReaper.isDead(Sym))
256 continue;
257
Artem Dergachev30ed5462016-11-30 17:57:18 +0000258 // The non-fatal error node should be the same for all reports.
259 if (ExplodedNode *BugNode = reportBug("SYMBOL DEAD", C))
260 N = BugNode;
Artem Dergachev895242f2016-01-15 15:22:05 +0000261 State = State->remove<MarkedSymbols>(Sym);
Artem Dergachev733e71b2015-12-10 09:28:06 +0000262 }
Artem Dergachev30ed5462016-11-30 17:57:18 +0000263 C.addTransition(State, N);
264}
265
266void ExprInspectionChecker::checkEndAnalysis(ExplodedGraph &G, BugReporter &BR,
267 ExprEngine &Eng) const {
268 for (auto Item: ReachedStats) {
269 unsigned NumTimesReached = Item.second.NumTimesReached;
270 ExplodedNode *N = Item.second.ExampleNode;
271
272 reportBug(std::to_string(NumTimesReached), BR, N);
273 }
Artem Dergachev733e71b2015-12-10 09:28:06 +0000274}
275
Jordan Rosee9c57222013-07-19 00:59:08 +0000276void ExprInspectionChecker::analyzerCrash(const CallExpr *CE,
277 CheckerContext &C) const {
278 LLVM_BUILTIN_TRAP;
279}
280
Jordy Rose31ae2592012-05-16 16:01:07 +0000281void ento::registerExprInspectionChecker(CheckerManager &Mgr) {
282 Mgr.registerChecker<ExprInspectionChecker>();
283}
284