Anna Zaks | 1c215d0 | 2011-12-05 18:58:01 +0000 | [diff] [blame] | 1 | // RUN: %clang_cc1 -analyze -analyzer-checker=experimental.security.taint,debug.TaintTest -verify %s |
| 2 | |
| 3 | int scanf(const char *restrict format, ...); |
| 4 | int getchar(void); |
| 5 | |
| 6 | #define BUFSIZE 10 |
| 7 | int Buffer[BUFSIZE]; |
| 8 | |
| 9 | void bufferScanfAssignment(int x) { |
| 10 | int n; |
| 11 | int *addr = &Buffer[0]; |
| 12 | scanf("%d", &n); |
| 13 | addr += n;// expected-warning {{tainted}} |
Anna Zaks | d624f60 | 2011-12-05 21:32:58 +0000 | [diff] [blame] | 14 | *addr = n; // expected-warning 2 {{tainted}} |
Anna Zaks | c25efcc | 2011-12-06 23:12:27 +0000 | [diff] [blame] | 15 | |
| 16 | double tdiv = n / 30; // expected-warning 3 {{tainted}} |
| 17 | char *loc_cast = (char *) n; // expected-warning {{tainted}} |
| 18 | char tinc = tdiv++; // expected-warning {{tainted}} |
| 19 | int tincdec = (char)tinc--; // expected-warning 2 {{tainted}} |
| 20 | int tprtarithmetic1 = *(addr+1); |
| 21 | |
| 22 | |
Anna Zaks | 1c215d0 | 2011-12-05 18:58:01 +0000 | [diff] [blame] | 23 | } |