clang  10.0.0svn
Macros | Typedefs | Functions | Variables
BugReporter.cpp File Reference
#include "clang/StaticAnalyzer/Core/BugReporter/BugReporter.h"
#include "clang/AST/Decl.h"
#include "clang/AST/DeclBase.h"
#include "clang/AST/DeclObjC.h"
#include "clang/AST/Expr.h"
#include "clang/AST/ExprCXX.h"
#include "clang/AST/ParentMap.h"
#include "clang/AST/Stmt.h"
#include "clang/AST/StmtCXX.h"
#include "clang/AST/StmtObjC.h"
#include "clang/Analysis/AnalysisDeclContext.h"
#include "clang/Analysis/CFG.h"
#include "clang/Analysis/CFGStmtMap.h"
#include "clang/Analysis/PathDiagnostic.h"
#include "clang/Analysis/ProgramPoint.h"
#include "clang/Basic/LLVM.h"
#include "clang/Basic/SourceLocation.h"
#include "clang/Basic/SourceManager.h"
#include "clang/StaticAnalyzer/Core/AnalyzerOptions.h"
#include "clang/StaticAnalyzer/Core/BugReporter/BugReporterVisitors.h"
#include "clang/StaticAnalyzer/Core/BugReporter/BugType.h"
#include "clang/StaticAnalyzer/Core/Checker.h"
#include "clang/StaticAnalyzer/Core/CheckerManager.h"
#include "clang/StaticAnalyzer/Core/PathSensitive/ExplodedGraph.h"
#include "clang/StaticAnalyzer/Core/PathSensitive/ExprEngine.h"
#include "clang/StaticAnalyzer/Core/PathSensitive/MemRegion.h"
#include "clang/StaticAnalyzer/Core/PathSensitive/ProgramState.h"
#include "clang/StaticAnalyzer/Core/PathSensitive/SVals.h"
#include "clang/StaticAnalyzer/Core/PathSensitive/SymbolManager.h"
#include "llvm/ADT/ArrayRef.h"
#include "llvm/ADT/DenseMap.h"
#include "llvm/ADT/DenseSet.h"
#include "llvm/ADT/FoldingSet.h"
#include "llvm/ADT/None.h"
#include "llvm/ADT/Optional.h"
#include "llvm/ADT/STLExtras.h"
#include "llvm/ADT/SmallPtrSet.h"
#include "llvm/ADT/SmallString.h"
#include "llvm/ADT/SmallVector.h"
#include "llvm/ADT/Statistic.h"
#include "llvm/ADT/StringRef.h"
#include "llvm/ADT/iterator_range.h"
#include "llvm/Support/Casting.h"
#include "llvm/Support/Compiler.h"
#include "llvm/Support/ErrorHandling.h"
#include "llvm/Support/MemoryBuffer.h"
#include "llvm/Support/raw_ostream.h"
#include <algorithm>
#include <cassert>
#include <cstddef>
#include <iterator>
#include <memory>
#include <queue>
#include <string>
#include <tuple>
#include <utility>
#include <vector>

Go to the source code of this file.

Macros

#define DEBUG_TYPE   "BugReporter"
 

Typedefs

using OptimizedCallsSet = llvm::DenseSet< const PathDiagnosticCallPiece * >
 

Functions

 STATISTIC (MaxBugClassSize, "The maximum number of bug reports in the same equivalence class")
 
 STATISTIC (MaxValidBugClassSize, "The maximum number of bug reports in the same equivalence class " "where at least one report is valid (not suppressed)")
 
static PathDiagnosticEventPiece * eventsDescribeSameCondition (PathDiagnosticEventPiece *X, PathDiagnosticEventPiece *Y)
 
static void removeRedundantMsgs (PathPieces &path)
 An optimization pass over PathPieces that removes redundant diagnostics generated by both ConditionBRVisitor and TrackConstraintBRVisitor. More...
 
static bool removeUnneededCalls (const PathDiagnosticConstruct &C, PathPieces &pieces, const PathSensitiveBugReport *R, bool IsInteresting=false)
 Recursively scan through a path and prune out calls and macros pieces that aren't needed. More...
 
static void removePopUpNotes (PathPieces &Path)
 Same logic as above to remove extra pieces. More...
 
static bool hasImplicitBody (const Decl *D)
 Returns true if the given decl has been implicitly given a body, either by the analyzer or by the compiler proper. More...
 
static void adjustCallLocations (PathPieces &Pieces, PathDiagnosticLocation *LastCallLocation=nullptr)
 Recursively scan through a path and make sure that all call pieces have valid locations. More...
 
static void removeEdgesToDefaultInitializers (PathPieces &Pieces)
 Remove edges in and out of C++ default initializer expressions. More...
 
static void removePiecesWithInvalidLocations (PathPieces &Pieces)
 Remove all pieces with invalid locations as these cannot be serialized. More...
 
static const StmtgetEnclosingParent (const Stmt *S, const ParentMap &PM)
 
static PathDiagnosticLocation getEnclosingStmtLocation (const Stmt *S, const LocationContext *LC, bool allowNestedContexts=false)
 
static void CompactMacroExpandedPieces (PathPieces &path, const SourceManager &SM)
 CompactMacroExpandedPieces - This function postprocesses a PathDiagnostic object and collapses PathDiagosticPieces that are expanded by macros. More...
 
static bool isLoop (const Stmt *Term)
 
static bool isJumpToFalseBranch (const BlockEdge *BE)
 
static bool isContainedByStmt (const ParentMap &PM, const Stmt *S, const Stmt *SubS)
 
static const StmtgetStmtBeforeCond (const ParentMap &PM, const Stmt *Term, const ExplodedNode *N)
 
static bool isInLoopBody (const ParentMap &PM, const Stmt *S, const Stmt *Term)
 
static void addEdgeToPath (PathPieces &path, PathDiagnosticLocation &PrevLoc, PathDiagnosticLocation NewLoc)
 Adds a sanitized control-flow diagnostic edge to a path. More...
 
static const StmtgetTerminatorCondition (const CFGBlock *B)
 A customized wrapper for CFGBlock::getTerminatorCondition() which returns the element for ObjCForCollectionStmts. More...
 
static std::unique_ptr< FilesToLineNumsMap > findExecutedLines (const SourceManager &SM, const ExplodedNode *N)
 
static std::unique_ptr< PathDiagnostic > generateDiagnosticForBasicReport (const BasicBugReport *R)
 
static std::unique_ptr< PathDiagnostic > generateEmptyDiagnosticForReport (const PathSensitiveBugReport *R, const SourceManager &SM)
 
static const StmtgetStmtParent (const Stmt *S, const ParentMap &PM)
 
static bool isConditionForTerminator (const Stmt *S, const Stmt *Cond)
 
static bool isIncrementOrInitInForLoop (const Stmt *S, const Stmt *FL)
 
static void addContextEdges (PathPieces &pieces, const LocationContext *LC)
 Adds synthetic edges from top-level statements to their subexpressions. More...
 
static void simplifySimpleBranches (PathPieces &pieces)
 Move edges from a branch condition to a branch target when the condition is simple. More...
 
static Optional< size_tgetLengthOnSingleLine (const SourceManager &SM, SourceRange Range)
 Returns the number of bytes in the given (character-based) SourceRange. More...
 
static Optional< size_tgetLengthOnSingleLine (const SourceManager &SM, const Stmt *S)
 
static void removeContextCycles (PathPieces &Path, const SourceManager &SM)
 Eliminate two-edge cycles created by addContextEdges(). More...
 
static bool lexicalContains (const ParentMap &PM, const Stmt *X, const Stmt *Y)
 Return true if X is contained by Y. More...
 
static void removePunyEdges (PathPieces &path, const SourceManager &SM, const ParentMap &PM)
 
static void removeIdenticalEvents (PathPieces &path)
 
static bool optimizeEdges (const PathDiagnosticConstruct &C, PathPieces &path, OptimizedCallsSet &OCS)
 
static void dropFunctionEntryEdge (const PathDiagnosticConstruct &C, PathPieces &Path)
 Drop the very first edge in a path, which should be a function entry edge. More...
 
static void updateExecutedLinesWithDiagnosticPieces (PathDiagnostic &PD)
 Populate executes lines with lines containing at least one diagnostics. More...
 
template<class T >
static void insertToInterestingnessMap (llvm::DenseMap< T, bugreporter::TrackingKind > &InterestingnessMap, T Val, bugreporter::TrackingKind TKind)
 

Variables

constexpr llvm::StringLiteral StrEnteringLoop = "Entering loop body"
 
constexpr llvm::StringLiteral StrLoopBodyZero = "Loop body executed 0 times"
 
constexpr llvm::StringLiteral StrLoopRangeEmpty
 
constexpr llvm::StringLiteral StrLoopCollectionEmpty
 

Macro Definition Documentation

◆ DEBUG_TYPE

#define DEBUG_TYPE   "BugReporter"

Definition at line 76 of file BugReporter.cpp.

Typedef Documentation

◆ OptimizedCallsSet

using OptimizedCallsSet = llvm::DenseSet<const PathDiagnosticCallPiece *>

Definition at line 1403 of file BugReporter.cpp.

Function Documentation

◆ addContextEdges()

static void addContextEdges ( PathPieces &  pieces,
const LocationContext LC 
)
static

Adds synthetic edges from top-level statements to their subexpressions.

This avoids a "swoosh" effect, where an edge from a top-level statement A points to a sub-expression B.1 that's not at the start of B. In these cases, we'd like to see an edge from A to B, then another one from B to B.1.

Definition at line 1410 of file BugReporter.cpp.

References getEnclosingStmtLocation(), clang::LocationContext::getParentMap(), and getStmtParent().

Referenced by optimizeEdges().

◆ addEdgeToPath()

static void addEdgeToPath ( PathPieces &  path,
PathDiagnosticLocation &  PrevLoc,
PathDiagnosticLocation  NewLoc 
)
static

Adds a sanitized control-flow diagnostic edge to a path.

Definition at line 1075 of file BugReporter.cpp.

References clang::SourceLocation::isInvalid().

Referenced by updateExecutedLinesWithDiagnosticPieces().

◆ adjustCallLocations()

static void adjustCallLocations ( PathPieces &  Pieces,
PathDiagnosticLocation *  LastCallLocation = nullptr 
)
static

Recursively scan through a path and make sure that all call pieces have valid locations.

Definition at line 490 of file BugReporter.cpp.

References hasImplicitBody(), and clang::if().

Referenced by updateExecutedLinesWithDiagnosticPieces().

◆ CompactMacroExpandedPieces()

static void CompactMacroExpandedPieces ( PathPieces &  path,
const SourceManager SM 
)
static

◆ dropFunctionEntryEdge()

static void dropFunctionEntryEdge ( const PathDiagnosticConstruct &  C,
PathPieces &  Path 
)
static

Drop the very first edge in a path, which should be a function entry edge.

If the first edge is not a function entry edge (say, because the first statement had an invalid source location), this function does nothing.

Definition at line 1935 of file BugReporter.cpp.

References clang::ento::PathDiagnosticLocation::createBegin().

Referenced by updateExecutedLinesWithDiagnosticPieces().

◆ eventsDescribeSameCondition()

static PathDiagnosticEventPiece* eventsDescribeSameCondition ( PathDiagnosticEventPiece *  X,
PathDiagnosticEventPiece *  Y 
)
static

Definition at line 342 of file BugReporter.cpp.

References X.

Referenced by removeRedundantMsgs().

◆ findExecutedLines()

static std::unique_ptr<FilesToLineNumsMap> findExecutedLines ( const SourceManager SM,
const ExplodedNode *  N 
)
static

◆ generateDiagnosticForBasicReport()

static std::unique_ptr<PathDiagnostic> generateDiagnosticForBasicReport ( const BasicBugReport *  R)
static

Definition at line 1312 of file BugReporter.cpp.

Referenced by CompactMacroExpandedPieces().

◆ generateEmptyDiagnosticForReport()

static std::unique_ptr<PathDiagnostic> generateEmptyDiagnosticForReport ( const PathSensitiveBugReport *  R,
const SourceManager SM 
)
static

Definition at line 1322 of file BugReporter.cpp.

References findExecutedLines().

Referenced by updateExecutedLinesWithDiagnosticPieces().

◆ getEnclosingParent()

static const Stmt* getEnclosingParent ( const Stmt S,
const ParentMap PM 
)
static

◆ getEnclosingStmtLocation()

static PathDiagnosticLocation getEnclosingStmtLocation ( const Stmt S,
const LocationContext LC,
bool  allowNestedContexts = false 
)
static

◆ getLengthOnSingleLine() [1/2]

static Optional<size_t> getLengthOnSingleLine ( const SourceManager SM,
SourceRange  Range 
)
static

Returns the number of bytes in the given (character-based) SourceRange.

If the locations in the range are not on the same line, returns None.

Note that this does not do a precise user-visible character or column count.

Definition at line 1561 of file BugReporter.cpp.

References clang::SourceRange::getBegin(), clang::SourceManager::getBuffer(), clang::SourceRange::getEnd(), clang::SourceManager::getExpansionLoc(), clang::SourceManager::getExpansionRange(), clang::SourceManager::getFileID(), and clang::SourceManager::getFileOffset().

Referenced by getLengthOnSingleLine(), optimizeEdges(), removeContextCycles(), and removePunyEdges().

◆ getLengthOnSingleLine() [2/2]

static Optional<size_t> getLengthOnSingleLine ( const SourceManager SM,
const Stmt S 
)
static
See also
getLengthOnSingleLine(SourceManager, SourceRange)

Definition at line 1591 of file BugReporter.cpp.

References getLengthOnSingleLine(), and clang::Stmt::getSourceRange().

◆ getStmtBeforeCond()

static const Stmt* getStmtBeforeCond ( const ParentMap PM,
const Stmt Term,
const ExplodedNode *  N 
)
static

Definition at line 1027 of file BugReporter.cpp.

References isContainedByStmt().

◆ getStmtParent()

static const Stmt* getStmtParent ( const Stmt S,
const ParentMap PM 
)
static

Definition at line 1332 of file BugReporter.cpp.

References clang::ParentMap::getParentIgnoreParens().

Referenced by addContextEdges(), and optimizeEdges().

◆ getTerminatorCondition()

static const Stmt* getTerminatorCondition ( const CFGBlock B)
static

A customized wrapper for CFGBlock::getTerminatorCondition() which returns the element for ObjCForCollectionStmts.

Definition at line 1102 of file BugReporter.cpp.

References clang::CFGBlock::getTerminatorCondition().

Referenced by clang::CFGBlock::getTerminatorCondition(), and clang::CFGBlock::getTerminatorStmt().

◆ hasImplicitBody()

static bool hasImplicitBody ( const Decl D)
static

Returns true if the given decl has been implicitly given a body, either by the analyzer or by the compiler proper.

Definition at line 482 of file BugReporter.cpp.

References clang::Decl::hasBody(), and clang::Decl::isImplicit().

Referenced by adjustCallLocations().

◆ insertToInterestingnessMap()

template<class T >
static void insertToInterestingnessMap ( llvm::DenseMap< T, bugreporter::TrackingKind > &  InterestingnessMap,
Val,
bugreporter::TrackingKind  TKind 
)
static

Definition at line 2176 of file BugReporter.cpp.

References clang::ento::PathSensitiveBugReport::markInteresting(), and V.

◆ isConditionForTerminator()

static bool isConditionForTerminator ( const Stmt S,
const Stmt Cond 
)
static

Definition at line 1353 of file BugReporter.cpp.

References clang::Stmt::getStmtClass().

Referenced by optimizeEdges(), removePunyEdges(), and simplifySimpleBranches().

◆ isContainedByStmt()

static bool isContainedByStmt ( const ParentMap PM,
const Stmt S,
const Stmt SubS 
)
static

Definition at line 1017 of file BugReporter.cpp.

References clang::ParentMap::getParent().

Referenced by getStmtBeforeCond(), and isInLoopBody().

◆ isIncrementOrInitInForLoop()

static bool isIncrementOrInitInForLoop ( const Stmt S,
const Stmt FL 
)
static

Definition at line 1394 of file BugReporter.cpp.

Referenced by optimizeEdges().

◆ isInLoopBody()

static bool isInLoopBody ( const ParentMap PM,
const Stmt S,
const Stmt Term 
)
static

Definition at line 1041 of file BugReporter.cpp.

References clang::Stmt::getStmtClass(), and isContainedByStmt().

◆ isJumpToFalseBranch()

static bool isJumpToFalseBranch ( const BlockEdge BE)
static

◆ isLoop()

static bool isLoop ( const Stmt Term)
static

Definition at line 998 of file BugReporter.cpp.

References clang::Stmt::getStmtClass().

◆ lexicalContains()

static bool lexicalContains ( const ParentMap PM,
const Stmt X,
const Stmt Y 
)
static

Return true if X is contained by Y.

Definition at line 1667 of file BugReporter.cpp.

References clang::ParentMap::getParent().

Referenced by optimizeEdges().

◆ optimizeEdges()

static bool optimizeEdges ( const PathDiagnosticConstruct &  C,
PathPieces &  path,
OptimizedCallsSet OCS 
)
static

◆ removeContextCycles()

static void removeContextCycles ( PathPieces &  Path,
const SourceManager SM 
)
static

Eliminate two-edge cycles created by addContextEdges().

Once all the context edges are in place, there are plenty of cases where there's a single edge from a top-level statement to a subexpression, followed by a single path note, and then a reverse edge to get back out to the top level. If the statement is simple enough, the subexpression edges just add noise and make it harder to understand what's going on.

This function only removes edges in pairs, because removing only one edge might leave other edges dangling.

This will not remove edges in more complicated situations:

  • if there is more than one "hop" leading to or from a subexpression.
  • if there is an inlined call between the edges instead of a single event.
  • if the whole statement is large enough that having subexpression arrows might be helpful.

Definition at line 1612 of file BugReporter.cpp.

References getLengthOnSingleLine().

Referenced by optimizeEdges().

◆ removeEdgesToDefaultInitializers()

static void removeEdgesToDefaultInitializers ( PathPieces &  Pieces)
static

Remove edges in and out of C++ default initializer expressions.

These are for fields that have in-class initializers, as opposed to being initialized explicitly in a constructor or braced list.

Definition at line 523 of file BugReporter.cpp.

References clang::ento::CF, and End.

Referenced by updateExecutedLinesWithDiagnosticPieces().

◆ removeIdenticalEvents()

static void removeIdenticalEvents ( PathPieces &  path)
static

Definition at line 1730 of file BugReporter.cpp.

Referenced by optimizeEdges().

◆ removePiecesWithInvalidLocations()

static void removePiecesWithInvalidLocations ( PathPieces &  Pieces)
static

Remove all pieces with invalid locations as these cannot be serialized.

We might have pieces with invalid locations as a result of inlining Body Farm generated functions.

Definition at line 557 of file BugReporter.cpp.

References clang::ento::PathDiagnosticLocation::createDeclEnd().

Referenced by updateExecutedLinesWithDiagnosticPieces().

◆ removePopUpNotes()

static void removePopUpNotes ( PathPieces &  Path)
static

Same logic as above to remove extra pieces.

Definition at line 471 of file BugReporter.cpp.

Referenced by updateExecutedLinesWithDiagnosticPieces().

◆ removePunyEdges()

static void removePunyEdges ( PathPieces &  path,
const SourceManager SM,
const ParentMap PM 
)
static

◆ removeRedundantMsgs()

static void removeRedundantMsgs ( PathPieces &  path)
static

An optimization pass over PathPieces that removes redundant diagnostics generated by both ConditionBRVisitor and TrackConstraintBRVisitor.

Both BugReporterVisitors use different methods to generate diagnostics, with one capable of emitting diagnostics in some cases but not in others. This can lead to redundant diagnostic pieces at the same point in a path.

Definition at line 368 of file BugReporter.cpp.

References clang::ento::PathDiagnosticPiece::Call, clang::ento::PathDiagnosticPiece::ControlFlow, clang::ento::PathDiagnosticPiece::Event, eventsDescribeSameCondition(), clang::ento::PathDiagnosticPiece::Macro, clang::ento::PathDiagnosticPiece::Note, and clang::ento::PathDiagnosticPiece::PopUp.

Referenced by updateExecutedLinesWithDiagnosticPieces().

◆ removeUnneededCalls()

static bool removeUnneededCalls ( const PathDiagnosticConstruct &  C,
PathPieces &  pieces,
const PathSensitiveBugReport *  R,
bool  IsInteresting = false 
)
static

Recursively scan through a path and prune out calls and macros pieces that aren't needed.

Return true if afterwards the path contains "interesting stuff" which means it shouldn't be pruned from the parent path.

Definition at line 418 of file BugReporter.cpp.

References clang::ento::PathDiagnosticPiece::Call, clang::ento::PathDiagnosticPiece::ControlFlow, clang::ento::PathDiagnosticPiece::Event, clang::ento::PathDiagnosticPiece::Macro, clang::ento::PathDiagnosticPiece::Note, and clang::ento::PathDiagnosticPiece::PopUp.

Referenced by updateExecutedLinesWithDiagnosticPieces().

◆ simplifySimpleBranches()

static void simplifySimpleBranches ( PathPieces &  pieces)
static

Move edges from a branch condition to a branch target when the condition is simple.

This restructures some of the work of addContextEdges. That function creates edges this may destroy, but they work together to create a more aesthetically set of edges around branches. After the call to addContextEdges, we may have (1) an edge to the branch, (2) an edge from the branch to the branch condition, and (3) an edge from the branch condition to the branch target. We keep (1), but may wish to remove (2) and move the source of (3) to the branch if the branch condition is simple.

Definition at line 1491 of file BugReporter.cpp.

References isConditionForTerminator().

Referenced by optimizeEdges().

◆ STATISTIC() [1/2]

STATISTIC ( MaxBugClassSize  ,
"The maximum number of bug reports in the same equivalence class"   
)

◆ STATISTIC() [2/2]

STATISTIC ( MaxValidBugClassSize  ,
"The maximum number of bug reports in the same equivalence class " "where at least one report is valid (not suppressed)"   
)

◆ updateExecutedLinesWithDiagnosticPieces()

static void updateExecutedLinesWithDiagnosticPieces ( PathDiagnostic &  PD)
static

Variable Documentation

◆ StrEnteringLoop

constexpr llvm::StringLiteral StrEnteringLoop = "Entering loop body"

Definition at line 1109 of file BugReporter.cpp.

◆ StrLoopBodyZero

constexpr llvm::StringLiteral StrLoopBodyZero = "Loop body executed 0 times"

Definition at line 1110 of file BugReporter.cpp.

◆ StrLoopCollectionEmpty

constexpr llvm::StringLiteral StrLoopCollectionEmpty
Initial value:
=
"Loop body skipped when collection is empty"

Definition at line 1113 of file BugReporter.cpp.

◆ StrLoopRangeEmpty

constexpr llvm::StringLiteral StrLoopRangeEmpty
Initial value:
=
"Loop body skipped when range is empty"

Definition at line 1111 of file BugReporter.cpp.