Dominic Chen | 184c624 | 2017-03-03 18:02:02 +0000 | [diff] [blame] | 1 | // RUN: %clang_analyze_cc1 -analyzer-checker=unix.cstring.BadSizeArg -analyzer-store=region -Wno-strncat-size -Wno-strlcpy-strlcat-size -Wno-sizeof-array-argument -Wno-sizeof-pointer-memaccess -verify %s |
Anna Zaks | 87b6ff0 | 2012-01-31 19:33:39 +0000 | [diff] [blame] | 2 | |
| 3 | typedef __SIZE_TYPE__ size_t; |
| 4 | char *strncat(char *, const char *, size_t); |
| 5 | size_t strlen (const char *s); |
David Carlier | 8e75de2 | 2018-07-19 21:50:03 +0000 | [diff] [blame^] | 6 | size_t strlcpy(char *, const char *, size_t); |
Anna Zaks | 87b6ff0 | 2012-01-31 19:33:39 +0000 | [diff] [blame] | 7 | |
| 8 | void testStrncat(const char *src) { |
| 9 | char dest[10]; |
| 10 | strncat(dest, "AAAAAAAAAAAAAAAAAAAAAAAAAAAAA", sizeof(dest) - 1); // expected-warning {{Potential buffer overflow. Replace with 'sizeof(dest) - strlen(dest) - 1' or use a safer 'strlcat' API}} |
| 11 | strncat(dest, "AAAAAAAAAAAAAAAAAAAAAAAAAAA", sizeof(dest)); // expected-warning {{Potential buffer overflow. Replace with}} |
| 12 | strncat(dest, "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA", sizeof(dest) - strlen(dest)); // expected-warning {{Potential buffer overflow. Replace with}} |
| 13 | strncat(dest, src, sizeof(src)); // expected-warning {{Potential buffer overflow. Replace with}} |
Gabor Horvath | 3b00853 | 2017-02-02 08:20:54 +0000 | [diff] [blame] | 14 | // Should not crash when sizeof has a type argument. |
| 15 | strncat(dest, "AAAAAAAAAAAAAAAAAAAAAAAAAAA", sizeof(char)); |
Anna Zaks | 87b6ff0 | 2012-01-31 19:33:39 +0000 | [diff] [blame] | 16 | } |
David Carlier | 8e75de2 | 2018-07-19 21:50:03 +0000 | [diff] [blame^] | 17 | |
| 18 | void testStrlcpy(const char *src) { |
| 19 | char dest[10]; |
| 20 | size_t destlen = sizeof(dest); |
| 21 | size_t srclen = sizeof(src); |
| 22 | size_t badlen = 20; |
| 23 | size_t ulen; |
| 24 | strlcpy(dest, src, sizeof(dest)); |
| 25 | strlcpy(dest, src, destlen); |
| 26 | strlcpy(dest, src, 10); |
| 27 | strlcpy(dest, src, 20); // expected-warning {{The third argument is larger than the size of the input buffer. Replace with the value 'sizeof(dest)` or lower}} |
| 28 | strlcpy(dest, src, badlen); // expected-warning {{The third argument is larger than the size of the input buffer. Replace with the value 'sizeof(dest)` or lower}} |
| 29 | strlcpy(dest, src, ulen); |
| 30 | } |