clang 24.0.0git
CallEvent.cpp
Go to the documentation of this file.
1//===- CallEvent.cpp - Wrapper for all function and method calls ----------===//
2//
3// Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
4// See https://llvm.org/LICENSE.txt for license information.
5// SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
6//
7//===----------------------------------------------------------------------===//
8//
9/// \file This file defines CallEvent and its subclasses, which represent path-
10/// sensitive instances of different kinds of function and method calls
11/// (C, C++, and Objective-C).
12//
13//===----------------------------------------------------------------------===//
14
17#include "clang/AST/Attr.h"
18#include "clang/AST/Decl.h"
19#include "clang/AST/DeclBase.h"
20#include "clang/AST/DeclCXX.h"
21#include "clang/AST/DeclObjC.h"
22#include "clang/AST/Expr.h"
23#include "clang/AST/ExprCXX.h"
24#include "clang/AST/ExprObjC.h"
25#include "clang/AST/ParentMap.h"
26#include "clang/AST/Stmt.h"
27#include "clang/AST/Type.h"
29#include "clang/Analysis/CFG.h"
34#include "clang/Basic/LLVM.h"
49#include "llvm/ADT/ArrayRef.h"
50#include "llvm/ADT/DenseMap.h"
51#include "llvm/ADT/ImmutableList.h"
52#include "llvm/ADT/PointerIntPair.h"
53#include "llvm/ADT/SmallSet.h"
54#include "llvm/ADT/SmallVector.h"
55#include "llvm/ADT/StringExtras.h"
56#include "llvm/ADT/StringRef.h"
57#include "llvm/Support/Compiler.h"
58#include "llvm/Support/Debug.h"
59#include "llvm/Support/ErrorHandling.h"
60#include "llvm/Support/raw_ostream.h"
61#include <cassert>
62#include <optional>
63#include <utility>
64
65#define DEBUG_TYPE "static-analyzer-call-event"
66
67using namespace clang;
68using namespace ento;
69
71 ASTContext &Ctx = getState()->getStateManager().getContext();
72 const Expr *E = getOriginExpr();
73 if (!E)
74 return Ctx.VoidTy;
75 return Ctx.getReferenceQualifiedType(E);
76}
77
78static bool isCallback(QualType T) {
79 // If a parameter is a block or a callback, assume it can modify pointer.
80 if (T->isBlockPointerType() ||
81 T->isFunctionPointerType() ||
82 T->isObjCSelType())
83 return true;
84
85 // Check if a callback is passed inside a struct (for both, struct passed by
86 // reference and by value). Dig just one level into the struct for now.
87
88 if (T->isAnyPointerType() || T->isReferenceType())
89 T = T->getPointeeType();
90
91 if (const RecordType *RT = T->getAsStructureType()) {
92 const RecordDecl *RD = RT->getDecl()->getDefinitionOrSelf();
93 for (const auto *I : RD->fields()) {
94 QualType FieldT = I->getType();
95 if (FieldT->isBlockPointerType() || FieldT->isFunctionPointerType())
96 return true;
97 }
98 }
99 return false;
100}
101
103 if (const auto *PT = T->getAs<PointerType>()) {
104 QualType PointeeTy = PT->getPointeeType();
105 if (PointeeTy.isConstQualified())
106 return false;
107 return PointeeTy->isVoidType();
108 } else
109 return false;
110}
111
113 unsigned NumOfArgs = getNumArgs();
114
115 // If calling using a function pointer, assume the function does not
116 // satisfy the callback.
117 // TODO: We could check the types of the arguments here.
118 if (!getDecl())
119 return false;
120
121 unsigned Idx = 0;
123 E = param_type_end();
124 I != E && Idx < NumOfArgs; ++I, ++Idx) {
125 // If the parameter is 0, it's harmless.
126 if (getArgSVal(Idx).isZeroConstant())
127 continue;
128
129 if (Condition(*I))
130 return true;
131 }
132 return false;
133}
134
138
142
143bool CallEvent::isGlobalCFunction(StringRef FunctionName) const {
144 const auto *FD = dyn_cast_or_null<FunctionDecl>(getDecl());
145 if (!FD)
146 return false;
147
148 return CheckerContext::isCLibraryFunction(FD, FunctionName);
149}
150
152 const Decl *D = getDecl();
153 if (!D)
154 return nullptr;
155
157 SF->getAnalysisDeclContext()->getManager()->getContext(D);
158
159 return ADC;
160}
161
162const StackFrame *CallEvent::getCalleeStackFrame(unsigned BlockCount) const {
164 if (!ADC)
165 return nullptr;
166
167 const Expr *E = getOriginExpr();
168 if (!E)
169 return nullptr;
170
171 // Recover CFG block via reverse lookup.
172 // TODO: If we were to keep CFG element information as part of the CallEvent
173 // instead of doing this reverse lookup, we would be able to build the stack
174 // frame for non-expression-based calls, and also we wouldn't need the reverse
175 // lookup.
176 const CFGStmtMap *Map = SF->getAnalysisDeclContext()->getCFGStmtMap();
177 const CFGBlock *B = Map->getBlock(E);
178 assert(B);
179
180 // Also recover CFG index by scanning the CFG block.
181 unsigned Idx = 0, Sz = B->size();
182 for (; Idx < Sz; ++Idx)
183 if (auto StmtElem = (*B)[Idx].getAs<CFGStmt>())
184 if (StmtElem->getStmt() == E)
185 break;
186 assert(Idx < Sz);
187
188 return ADC->getStackFrame(SF, nullptr, E, B, BlockCount, Idx);
189}
190
191const ParamVarRegion
192*CallEvent::getParameterLocation(unsigned Index, unsigned BlockCount) const {
193 const StackFrame *SF = getCalleeStackFrame(BlockCount);
194 // We cannot construct a VarRegion without a stack frame.
195 if (!SF)
196 return nullptr;
197
198 const ParamVarRegion *PVR =
199 State->getStateManager().getRegionManager().getParamVarRegion(
200 getOriginExpr(), Index, SF);
201 return PVR;
202}
203
204/// Returns true if a type is a pointer-to-const or reference-to-const
205/// with no further indirection.
206static bool isPointerToConst(QualType Ty) {
207 QualType PointeeTy = Ty->getPointeeType();
208 if (PointeeTy == QualType())
209 return false;
210 if (!PointeeTy.isConstQualified())
211 return false;
212 if (PointeeTy->isAnyPointerType())
213 return false;
214 return true;
215}
216
217// Try to retrieve the function declaration and find the function parameter
218// types which are pointers/references to a non-pointer const.
219// We will not invalidate the corresponding argument regions.
220static void findPtrToConstParams(llvm::SmallSet<unsigned, 4> &PreserveArgs,
221 const CallEvent &Call) {
222 unsigned Idx = 0;
223 for (CallEvent::param_type_iterator I = Call.param_type_begin(),
224 E = Call.param_type_end();
225 I != E; ++I, ++Idx) {
226 if (isPointerToConst(*I))
227 PreserveArgs.insert(Idx);
228 }
229}
230
232 if (const auto *CtorCall = dyn_cast<CXXConstructorCall>(&Call)) {
233 if (const MemRegion *R = CtorCall->getCXXThisVal().getAsRegion())
234 return R->getBaseRegion();
235 }
236 return nullptr;
237}
238
240 ProgramStateRef State) const {
241 // Don't invalidate anything if the callee is marked pure/const.
242 if (const Decl *Callee = getDecl())
243 if (Callee->hasAttr<PureAttr>() || Callee->hasAttr<ConstAttr>())
244 return State;
245
246 SmallVector<SVal, 8> ValuesToInvalidate;
248
249 getExtraInvalidatedValues(ValuesToInvalidate, &ETraits);
250
251 // Indexes of arguments whose values will be preserved by the call.
252 llvm::SmallSet<unsigned, 4> PreserveArgs;
253 if (!argumentsMayEscape())
254 findPtrToConstParams(PreserveArgs, *this);
255
256 // We should not preserve the contents of the region pointed by "this" when
257 // constructing the object, even if an argument refers to it.
258 const auto *ThisRegionBaseOrNull = getThisRegionBaseOrNull(*this);
259
260 for (unsigned Idx = 0, Count = getNumArgs(); Idx != Count; ++Idx) {
261 // Mark this region for invalidation. We batch invalidate regions
262 // below for efficiency.
263 if (PreserveArgs.count(Idx)) {
264 if (const MemRegion *ArgBaseR = getArgSVal(Idx).getAsRegion()) {
265 ArgBaseR = ArgBaseR->getBaseRegion();
266
267 // Preserve the contents of the pointee of the argument - except if it
268 // refers to the object under construction (ctor call).
269 if (ArgBaseR != ThisRegionBaseOrNull) {
270 ETraits.setTrait(
272 // TODO: Factor this out + handle the lower level const pointers.
273 }
274 }
275 }
276
277 ValuesToInvalidate.push_back(getArgSVal(Idx));
278
279 // If a function accepts an object by argument (which would of course be a
280 // temporary that isn't lifetime-extended), invalidate the object itself,
281 // not only other objects reachable from it. This is necessary because the
282 // destructor has access to the temporary object after the call.
283 // TODO: Support placement arguments once we start
284 // constructing them directly.
285 // TODO: This is unnecessary when there's no destructor, but that's
286 // currently hard to figure out.
287 if (getKind() != CE_CXXAllocator)
289 if (auto AdjIdx = getAdjustedParameterIndex(Idx))
290 if (const TypedValueRegion *TVR =
291 getParameterLocation(*AdjIdx, BlockCount))
292 ValuesToInvalidate.push_back(loc::MemRegionVal(TVR));
293 }
294
295 // Invalidate designated regions using the batch invalidation API.
296 // NOTE: Even if RegionsToInvalidate is empty, we may still invalidate
297 // global variables.
298 return State->invalidateRegions(ValuesToInvalidate, getCFGElementRef(),
299 BlockCount, getStackFrame(),
300 /*CausedByPointerEscape*/ true,
301 /*Symbols=*/nullptr, this, &ETraits);
302}
303
305 const ProgramPointTag *Tag) const {
306
307 if (const Expr *E = getOriginExpr()) {
308 if (IsPreVisit)
309 return PreStmt(E, getStackFrame(), Tag);
310 return PostStmt(E, getStackFrame(), Tag);
311 }
312
313 const Decl *D = getDecl();
314 assert(D && "Cannot get a program point without a statement or decl");
315 assert(ElemRef.getParent() &&
316 "Cannot get a program point without a CFGElementRef");
317
319 if (IsPreVisit)
320 return PreImplicitCall(D, Loc, getStackFrame(), ElemRef, Tag);
321 return PostImplicitCall(D, Loc, getStackFrame(), ElemRef, Tag);
322}
323
324SVal CallEvent::getArgSVal(unsigned Index) const {
325 const Expr *ArgE = getArgExpr(Index);
326 if (!ArgE)
327 return UnknownVal();
328 return getSVal(ArgE);
329}
330
332 const Expr *ArgE = getArgExpr(Index);
333 if (!ArgE)
334 return {};
335 return ArgE->getSourceRange();
336}
337
339 const Expr *E = getOriginExpr();
340 if (!E)
341 return UndefinedVal();
342 return getSVal(E);
343}
344
345LLVM_DUMP_METHOD void CallEvent::dump() const { dump(llvm::errs()); }
346
347void CallEvent::dump(raw_ostream &Out) const {
348 ASTContext &Ctx = getState()->getStateManager().getContext();
349 if (const Expr *E = getOriginExpr()) {
350 E->printPretty(Out, nullptr, Ctx.getPrintingPolicy());
351 return;
352 }
353
354 if (const Decl *D = getDecl()) {
355 Out << "Call to ";
356 D->print(Out, Ctx.getPrintingPolicy());
357 return;
358 }
359
360 Out << "Unknown call (type " << getKindAsString() << ")";
361}
362
366
368 assert(D);
369 if (const auto *FD = dyn_cast<FunctionDecl>(D))
370 return FD->getReturnType();
371 if (const auto *MD = dyn_cast<ObjCMethodDecl>(D))
372 return MD->getReturnType();
373 if (const auto *BD = dyn_cast<BlockDecl>(D)) {
374 // Blocks are difficult because the return type may not be stored in the
375 // BlockDecl itself. The AST should probably be enhanced, but for now we
376 // just do what we can.
377 // If the block is declared without an explicit argument list, the
378 // signature-as-written just includes the return type, not the entire
379 // function type.
380 // FIXME: All blocks should have signatures-as-written, even if the return
381 // type is inferred. (That's signified with a dependent result type.)
382 if (const TypeSourceInfo *TSI = BD->getSignatureAsWritten()) {
383 QualType Ty = TSI->getType();
384 if (const FunctionType *FT = Ty->getAs<FunctionType>())
385 Ty = FT->getReturnType();
386 if (!Ty->isDependentType())
387 return Ty;
388 }
389
390 return {};
391 }
392
393 llvm_unreachable("unknown callable kind");
394}
395
397 assert(D);
398
399 if (const auto *FD = dyn_cast<FunctionDecl>(D))
400 return FD->isVariadic();
401 if (const auto *MD = dyn_cast<ObjCMethodDecl>(D))
402 return MD->isVariadic();
403 if (const auto *BD = dyn_cast<BlockDecl>(D))
404 return BD->isVariadic();
405
406 llvm_unreachable("unknown callable kind");
407}
408
410 const RecordType *UT = T->getAsUnionType();
411 return UT &&
412 UT->getDecl()->getMostRecentDecl()->hasAttr<TransparentUnionAttr>();
413}
414
415// In some cases, symbolic cases should be transformed before we associate
416// them with parameters. This function incapsulates such cases.
417static SVal processArgument(SVal Value, const Expr *ArgumentExpr,
418 const ParmVarDecl *Parameter, SValBuilder &SVB) {
419 QualType ParamType = Parameter->getType();
420 QualType ArgumentType = ArgumentExpr->getType();
421
422 // Transparent unions allow users to easily convert values of union field
423 // types into union-typed objects.
424 //
425 // Also, more importantly, they allow users to define functions with different
426 // different parameter types, substituting types matching transparent union
427 // field types with the union type itself.
428 //
429 // Here, we check specifically for latter cases and prevent binding
430 // field-typed values to union-typed regions.
431 if (isTransparentUnion(ParamType) &&
432 // Let's check that we indeed trying to bind different types.
433 !isTransparentUnion(ArgumentType)) {
435
436 llvm::ImmutableList<SVal> CompoundSVals = BVF.getEmptySValList();
437 CompoundSVals = BVF.prependSVal(Value, CompoundSVals);
438
439 // Wrap it with compound value.
440 return SVB.makeCompoundVal(ParamType, CompoundSVals);
441 }
442
443 return Value;
444}
445
446/// Cast the argument value to the type of the parameter at the function
447/// declaration.
448/// Returns the argument value if it didn't need a cast.
449/// Or returns the cast argument if it needed a cast.
450/// Or returns 'Unknown' if it would need a cast but the callsite and the
451/// runtime definition don't match in terms of argument and parameter count.
452static SVal castArgToParamTypeIfNeeded(const CallEvent &Call, unsigned ArgIdx,
453 SVal ArgVal, SValBuilder &SVB) {
454 const auto *CallExprDecl = dyn_cast_or_null<FunctionDecl>(Call.getDecl());
455 if (!CallExprDecl)
456 return ArgVal;
457
458 const FunctionDecl *Definition = CallExprDecl;
459 Definition->hasBody(Definition);
460
461 // The function decl of the Call (in the AST) will not have any parameter
462 // declarations, if it was 'only' declared without a prototype. However, the
463 // engine will find the appropriate runtime definition - basically a
464 // redeclaration, which has a function body (and a function prototype).
465 if (CallExprDecl->hasPrototype() || !Definition->hasPrototype())
466 return ArgVal;
467
468 // Only do this cast if the number arguments at the callsite matches with
469 // the parameters at the runtime definition.
470 if (Call.getNumArgs() != Definition->getNumParams())
471 return UnknownVal();
472
473 const Expr *ArgExpr = Call.getArgExpr(ArgIdx);
474 const ParmVarDecl *Param = Definition->getParamDecl(ArgIdx);
475 return SVB.evalCast(ArgVal, Param->getType(), ArgExpr->getType());
476}
477
478static void addParameterValuesToBindings(const StackFrame *CalleeSF,
480 SValBuilder &SVB,
481 const CallEvent &Call,
482 ArrayRef<ParmVarDecl *> parameters) {
483 MemRegionManager &MRMgr = SVB.getRegionManager();
484
485 // If the function has fewer parameters than the call has arguments, we simply
486 // do not bind any values to them.
487 unsigned NumArgs = Call.getNumArgs();
488 unsigned Idx = 0;
489 ArrayRef<ParmVarDecl*>::iterator I = parameters.begin(), E = parameters.end();
490 for (; I != E && Idx < NumArgs; ++I, ++Idx) {
491 assert(*I && "Formal parameter has no decl?");
492
493 // TODO: Support allocator calls.
494 if (Call.getKind() != CE_CXXAllocator)
495 if (Call.isArgumentConstructedDirectly(Call.getASTArgumentIndex(Idx)))
496 continue;
497
498 // TODO: Allocators should receive the correct size and possibly alignment,
499 // determined in compile-time but not represented as arg-expressions,
500 // which makes getArgSVal() fail and return UnknownVal.
501 SVal ArgVal = Call.getArgSVal(Idx);
502 const Expr *ArgExpr = Call.getArgExpr(Idx);
503
504 if (ArgVal.isUnknown())
505 continue;
506
507 // Cast the argument value to match the type of the parameter in some
508 // edge-cases.
509 ArgVal = castArgToParamTypeIfNeeded(Call, Idx, ArgVal, SVB);
510
511 Loc ParamLoc = SVB.makeLoc(
512 MRMgr.getParamVarRegion(Call.getOriginExpr(), Idx, CalleeSF));
513 Bindings.push_back(
514 std::make_pair(ParamLoc, processArgument(ArgVal, ArgExpr, *I, SVB)));
515 }
516
517 // FIXME: Variadic arguments are not handled at all right now.
518}
519
522 if (!StackFrame)
523 return nullptr;
524
526 if (const auto Ctor = Element.getAs<CFGConstructor>()) {
527 return Ctor->getConstructionContext();
528 }
529
530 if (const auto RecCall = Element.getAs<CFGCXXRecordTypedCall>()) {
531 return RecCall->getConstructionContext();
532 }
533
534 return nullptr;
535}
536
538 const auto *CallSF = this->getStackFrame();
539 if (!CallSF || CallSF->inTopFrame())
540 return nullptr;
541
542 CallEventManager &CEMgr = State->getStateManager().getCallEventManager();
543 return CEMgr.getCaller(CallSF, State);
544}
545
547 if (const CallEventRef<> Caller = getCaller())
548 return Caller->isInSystemHeader();
549
550 return false;
551}
552
554 const auto *CC = getConstructionContext();
555 if (!CC)
556 return std::nullopt;
557
558 EvalCallOptions CallOpts;
559 ExprEngine &Engine = getState()->getStateManager().getOwningEngine();
560 unsigned NumVisitedCall =
561 Engine.getNumVisited(getStackFrame(), getCFGElementRef().getParent());
562 SVal RetVal = Engine.computeObjectUnderConstruction(
563 getOriginExpr(), getState(), NumVisitedCall, getStackFrame(), CC,
564 CallOpts);
565 return RetVal;
566}
567
569 const FunctionDecl *D = getDecl();
570 if (!D)
571 return {};
572 return D->parameters();
573}
574
576 const FunctionDecl *FD = getDecl();
577 if (!FD)
578 return {};
579
580 // Note that the AnalysisDeclContext will have the FunctionDecl with
581 // the definition (if one exists).
584 bool IsAutosynthesized;
585 Stmt* Body = AD->getBody(IsAutosynthesized);
586 LLVM_DEBUG({
587 if (IsAutosynthesized)
588 llvm::dbgs() << "Using autosynthesized body for " << FD->getName()
589 << "\n";
590 });
591
592 ExprEngine &Engine = getState()->getStateManager().getOwningEngine();
594 *Engine.getCrossTranslationUnitContext();
595
596 AnalyzerOptions &Opts = Engine.getAnalysisManager().options;
597
598 if (Body) {
599 const Decl* Decl = AD->getDecl();
600 if (Opts.IsNaiveCTUEnabled && CTUCtx.isImportedAsNew(Decl)) {
601 // A newly created definition, but we had error(s) during the import.
602 if (CTUCtx.hasError(Decl))
603 return {};
604 return RuntimeDefinition(Decl, /*Foreign=*/true);
605 }
606 return RuntimeDefinition(Decl, /*Foreign=*/false);
607 }
608
609 // Try to get CTU definition only if CTUDir is provided.
610 if (!Opts.IsNaiveCTUEnabled)
611 return {};
612
614 CTUCtx.getCrossTUDefinition(FD, Opts.CTUDir, Opts.CTUIndexName,
615 Opts.DisplayCTUProgress);
616
617 if (!CTUDeclOrError) {
618 handleAllErrors(CTUDeclOrError.takeError(),
619 [&](const cross_tu::IndexError &IE) {
620 auto Loc = getOriginExpr() ? getOriginExpr()->getExprLoc()
621 : FD->getLocation();
622 CTUCtx.emitCrossTUDiagnostics(IE, Loc);
623 });
624 return {};
625 }
626
627 return RuntimeDefinition(*CTUDeclOrError, /*Foreign=*/true);
628}
629
631 BindingsTy &Bindings) const {
632 const auto *D = cast<FunctionDecl>(CalleeSF->getDecl());
633 SValBuilder &SVB = getState()->getStateManager().getSValBuilder();
634 addParameterValuesToBindings(CalleeSF, Bindings, SVB, *this, D->parameters());
635}
636
639 return true;
640
641 const FunctionDecl *D = getDecl();
642 if (!D)
643 return true;
644
645 const IdentifierInfo *II = D->getIdentifier();
646 if (!II)
647 return false;
648
649 // This set of "escaping" APIs is
650
651 // - 'int pthread_setspecific(ptheread_key k, const void *)' stores a
652 // value into thread local storage. The value can later be retrieved with
653 // 'void *ptheread_getspecific(pthread_key)'. So even thought the
654 // parameter is 'const void *', the region escapes through the call.
655 if (II->isStr("pthread_setspecific"))
656 return true;
657
658 // - xpc_connection_set_context stores a value which can be retrieved later
659 // with xpc_connection_get_context.
660 if (II->isStr("xpc_connection_set_context"))
661 return true;
662
663 // - funopen - sets a buffer for future IO calls.
664 if (II->isStr("funopen"))
665 return true;
666
667 // - __cxa_demangle - can reallocate memory and can return the pointer to
668 // the input buffer.
669 if (II->isStr("__cxa_demangle"))
670 return true;
671
672 StringRef FName = II->getName();
673
674 // - CoreFoundation functions that end with "NoCopy" can free a passed-in
675 // buffer even if it is const.
676 if (FName.ends_with("NoCopy"))
677 return true;
678
679 // - NSXXInsertXX, for example NSMapInsertIfAbsent, since they can
680 // be deallocated by NSMapRemove.
681 if (FName.starts_with("NS") && FName.contains("Insert"))
682 return true;
683
684 // - Many CF containers allow objects to escape through custom
685 // allocators/deallocators upon container construction. (PR12101)
686 if (FName.starts_with("CF") || FName.starts_with("CG")) {
687 return FName.contains_insensitive("InsertValue") ||
688 FName.contains_insensitive("AddValue") ||
689 FName.contains_insensitive("SetValue") ||
690 FName.contains_insensitive("WithData") ||
691 FName.contains_insensitive("AppendValue") ||
692 FName.contains_insensitive("SetAttribute");
693 }
694
695 return false;
696}
697
700 if (D)
701 return D;
702
704}
705
707 // Clang converts lambdas to function pointers using an implicit conversion
708 // operator, which returns the lambda's '__invoke' method. However, Sema
709 // leaves the body of '__invoke' empty (it is generated later in CodeGen), so
710 // we need to skip '__invoke' and access the lambda's operator() directly.
711 if (const auto *CMD = dyn_cast_if_present<CXXMethodDecl>(getDecl());
712 CMD && CMD->isLambdaStaticInvoker())
713 return RuntimeDefinition{CMD->getParent()->getLambdaCallOperator()};
714
716}
717
719 const auto *CE = cast_or_null<CallExpr>(getOriginExpr());
720 if (!CE)
722
723 const FunctionDecl *D = CE->getDirectCallee();
724 if (D)
725 return D;
726
727 return getSVal(CE->getCallee()).getAsFunctionDecl();
728}
729
731 ValueList &Values, RegionAndSymbolInvalidationTraits *ETraits) const {
732 SVal ThisVal = getCXXThisVal();
733 Values.push_back(ThisVal);
734
735 // Don't invalidate if the method is const and there are no mutable fields.
736 if (const auto *D = cast_or_null<CXXMethodDecl>(getDecl())) {
737 if (!D->isConst())
738 return;
739
740 // Get the record decl for the class of 'This'. D->getParent() may return
741 // a base class decl, rather than the class of the instance which needs to
742 // be checked for mutable fields.
743 const CXXRecordDecl *ParentRecord = getDeclForDynamicType().first;
744 if (!ParentRecord || !ParentRecord->hasDefinition())
745 return;
746
747 if (ParentRecord->hasMutableFields())
748 return;
749
750 // Preserve CXXThis.
751 const MemRegion *ThisRegion = ThisVal.getAsRegion();
752 if (!ThisRegion)
753 return;
754
755 ETraits->setTrait(ThisRegion->getBaseRegion(),
757 }
758}
759
761 const Expr *Base = getCXXThisExpr();
762 // FIXME: This doesn't handle an overloaded ->* operator.
763 SVal ThisVal = Base ? getSVal(Base) : UnknownVal();
764
765 if (isa<NonLoc>(ThisVal)) {
766 SValBuilder &SVB = getState()->getStateManager().getSValBuilder();
767 QualType OriginalTy = ThisVal.getType(SVB.getContext());
768 return SVB.evalCast(ThisVal, Base->getType(), OriginalTy);
769 }
770
771 assert(ThisVal.isUnknownOrUndef() || isa<Loc>(ThisVal));
772 return ThisVal;
773}
774
775std::pair<const CXXRecordDecl *, bool>
777 const MemRegion *R = getCXXThisVal().getAsRegion();
778 if (!R)
779 return {};
780
782 if (!DynType.isValid())
783 return {};
784
785 assert(!DynType.getType()->getPointeeType().isNull());
786 return {DynType.getType()->getPointeeCXXRecordDecl(),
787 DynType.canBeASubClass()};
788}
789
791 // Do we have a decl at all?
792 const Decl *D = getDecl();
793 if (!D)
794 return {};
795
796 // If the method is non-virtual, we know we can inline it.
797 const auto *MD = cast<CXXMethodDecl>(D);
798 if (!MD->isVirtual())
800
801 // If the method is final or declared in a final class, we can inline it.
802 if (MD->hasAttr<FinalAttr>() || MD->getParent()->hasAttr<FinalAttr>())
804
805 auto [RD, CanBeSubClass] = getDeclForDynamicType();
806 if (!RD || !RD->hasDefinition())
807 return {};
808
809 // We can confidently inline a method called on an object with final type.
810 if (RD->hasAttr<FinalAttr>())
811 CanBeSubClass = false;
812
813 // Find the decl for this method in that class.
814 const CXXMethodDecl *Result = MD->getCorrespondingMethodInClass(RD, true);
815 if (!Result) {
816 // We might not even get the original statically-resolved method due to
817 // some particularly nasty casting (e.g. casts to sister classes).
818 // However, we should at least be able to search up and down our own class
819 // hierarchy, and some real bugs have been caught by checking this.
820 assert(!RD->isDerivedFrom(MD->getParent()) && "Couldn't find known method");
821
822 // FIXME: This is checking that our DynamicTypeInfo is at least as good as
823 // the static type. However, because we currently don't update
824 // DynamicTypeInfo when an object is cast, we can't actually be sure the
825 // DynamicTypeInfo is up to date. This assert should be re-enabled once
826 // this is fixed.
827 //
828 // assert(!MD->getParent()->isDerivedFrom(RD) && "Bad DynamicTypeInfo");
829
830 return {};
831 }
832
833 // A final method cannot be overriden in a subclass.
834 if (Result->hasAttr<FinalAttr>())
835 CanBeSubClass = false;
836
837 // Does the decl that we found have an implementation?
839 if (!Result->hasBody(Definition)) {
840 if (!CanBeSubClass)
842 return {};
843 }
844
845 // We found a definition. If we're not sure that this devirtualization is
846 // actually what will happen at runtime, make sure to provide the region so
847 // that ExprEngine can decide what to do with it.
848 if (CanBeSubClass)
850 getCXXThisVal().getAsRegion()->StripCasts());
851 return RuntimeDefinition(Definition, /*DispatchRegion=*/nullptr);
852}
853
855 BindingsTy &Bindings) const {
857
858 // Handle the binding of 'this' in the new stack frame.
859 SVal ThisVal = getCXXThisVal();
860 if (!ThisVal.isUnknown()) {
861 ProgramStateManager &StateMgr = getState()->getStateManager();
862 SValBuilder &SVB = StateMgr.getSValBuilder();
863
864 const auto *MD = cast<CXXMethodDecl>(CalleeSF->getDecl());
865 Loc ThisLoc = SVB.getCXXThis(MD, CalleeSF);
866
867 // If we devirtualized to a different member function, we need to make sure
868 // we have the proper layering of CXXBaseObjectRegions.
869 if (MD->getCanonicalDecl() != getDecl()->getCanonicalDecl()) {
870 ASTContext &Ctx = SVB.getContext();
871 const CXXRecordDecl *Class = MD->getParent();
873
874 // FIXME: CallEvent maybe shouldn't be directly accessing StoreManager.
875 std::optional<SVal> V =
876 StateMgr.getStoreManager().evalBaseToDerived(ThisVal, Ty);
877 if (!V) {
878 // We might have suffered some sort of placement new earlier, so
879 // we're constructing in a completely unexpected storage.
880 // Fall back to a generic pointer cast for this-value.
881 const CXXMethodDecl *StaticMD = cast<CXXMethodDecl>(getDecl());
882 const CXXRecordDecl *StaticClass = StaticMD->getParent();
883 CanQualType StaticTy =
884 Ctx.getPointerType(Ctx.getCanonicalTagType(StaticClass));
885 ThisVal = SVB.evalCast(ThisVal, Ty, StaticTy);
886 } else
887 ThisVal = *V;
888 }
889
890 if (!ThisVal.isUnknown())
891 Bindings.push_back(std::make_pair(ThisLoc, ThisVal));
892 }
893}
894
898
900 // C++11 [expr.call]p1: ...If the selected function is non-virtual, or if the
901 // id-expression in the class member access expression is a qualified-id,
902 // that function is called. Otherwise, its final overrider in the dynamic type
903 // of the object expression is called.
904 if (const auto *ME = dyn_cast<MemberExpr>(getOriginExpr()->getCallee()))
905 if (ME->hasQualifier())
907
909}
910
912 return getOriginExpr()->getArg(0);
913}
914
916 const Expr *Callee = getOriginExpr()->getCallee();
917 const MemRegion *DataReg = getSVal(Callee).getAsRegion();
918
919 return dyn_cast_or_null<BlockDataRegion>(DataReg);
920}
921
923 const BlockDecl *D = getDecl();
924 if (!D)
925 return {};
926 return D->parameters();
927}
928
930 RegionAndSymbolInvalidationTraits *ETraits) const {
931 // FIXME: This also needs to invalidate captured globals.
932 if (const MemRegion *R = getBlockRegion())
933 Values.push_back(loc::MemRegionVal(R));
934}
935
937 BindingsTy &Bindings) const {
938 SValBuilder &SVB = getState()->getStateManager().getSValBuilder();
941 auto *LambdaOperatorDecl = cast<CXXMethodDecl>(CalleeSF->getDecl());
942 Params = LambdaOperatorDecl->parameters();
943
944 // For blocks converted from a C++ lambda, the callee declaration is the
945 // operator() method on the lambda so we bind "this" to
946 // the lambda captured by the block.
947 const VarRegion *CapturedLambdaRegion = getRegionStoringCapturedLambda();
948 SVal ThisVal = loc::MemRegionVal(CapturedLambdaRegion);
949 Loc ThisLoc = SVB.getCXXThis(LambdaOperatorDecl, CalleeSF);
950 Bindings.push_back(std::make_pair(ThisLoc, ThisVal));
951 } else {
952 Params = cast<BlockDecl>(CalleeSF->getDecl())->parameters();
953 }
954
955 addParameterValuesToBindings(CalleeSF, Bindings, SVB, *this, Params);
956}
957
959 if (Data)
960 return loc::MemRegionVal(static_cast<const MemRegion *>(Data));
961 return UnknownVal();
962}
963
965 RegionAndSymbolInvalidationTraits *ETraits) const {
966 SVal V = getCXXThisVal();
967 if (SymbolRef Sym = V.getAsSymbol(true))
968 ETraits->setTrait(Sym,
970
971 // Standard classes don't reinterpret-cast and modify super regions.
972 const bool IsStdClassCtor = isWithinStdNamespace(getDecl());
973 if (const MemRegion *Obj = V.getAsRegion(); Obj && IsStdClassCtor) {
974 ETraits->setTrait(
976 }
977
978 Values.push_back(V);
979}
980
982 const StackFrame *CalleeSF, BindingsTy &Bindings) const {
984
985 SVal ThisVal = getCXXThisVal();
986 if (!ThisVal.isUnknown()) {
987 SValBuilder &SVB = getState()->getStateManager().getSValBuilder();
988 const auto *MD = cast<CXXMethodDecl>(CalleeSF->getDecl());
989 Loc ThisLoc = SVB.getCXXThis(MD, CalleeSF);
990 Bindings.push_back(std::make_pair(ThisLoc, ThisVal));
991 }
992}
993
995 const StackFrame *SF = getStackFrame();
996 while (isa<CXXInheritedCtorInitExpr>(SF->getCallSite()))
997 SF = SF->getParent();
998 return SF;
999}
1000
1002 if (Data)
1003 return loc::MemRegionVal(DtorDataTy::getFromOpaqueValue(Data).getPointer());
1004 return UnknownVal();
1005}
1006
1008 // Base destructors are always called non-virtually.
1009 // Skip CXXInstanceCall's devirtualization logic in this case.
1010 if (isBaseDestructor())
1012
1014}
1015
1017 const ObjCMethodDecl *D = getDecl();
1018 if (!D)
1019 return {};
1020 return D->parameters();
1021}
1022
1024 ValueList &Values, RegionAndSymbolInvalidationTraits *ETraits) const {
1025
1026 // If the method call is a setter for property known to be backed by
1027 // an instance variable, don't invalidate the entire receiver, just
1028 // the storage for that instance variable.
1029 if (const ObjCPropertyDecl *PropDecl = getAccessedProperty()) {
1030 if (const ObjCIvarDecl *PropIvar = PropDecl->getPropertyIvarDecl()) {
1031 SVal IvarLVal = getState()->getLValue(PropIvar, getReceiverSVal());
1032 if (const MemRegion *IvarRegion = IvarLVal.getAsRegion()) {
1033 ETraits->setTrait(
1034 IvarRegion,
1036 ETraits->setTrait(
1037 IvarRegion,
1039 Values.push_back(IvarLVal);
1040 }
1041 return;
1042 }
1043 }
1044
1045 Values.push_back(getReceiverSVal());
1046}
1047
1049 // FIXME: Is this the best way to handle class receivers?
1050 if (!isInstanceMessage())
1051 return UnknownVal();
1052
1053 if (const Expr *RecE = getOriginExpr()->getInstanceReceiver())
1054 return getSVal(RecE);
1055
1056 // An instance message with no expression means we are sending to super.
1057 // In this case the object reference is the same as 'self'.
1058 assert(getOriginExpr()->getReceiverKind() == ObjCMessageExpr::SuperInstance);
1059 SVal SelfVal = getState()->getSelfSVal(getStackFrame());
1060 assert(SelfVal.isValid() && "Calling super but not in ObjC method");
1061 return SelfVal;
1062}
1063
1065 if (getOriginExpr()->getReceiverKind() == ObjCMessageExpr::SuperInstance ||
1066 getOriginExpr()->getReceiverKind() == ObjCMessageExpr::SuperClass)
1067 return true;
1068
1069 if (!isInstanceMessage())
1070 return false;
1071
1072 SVal RecVal = getSVal(getOriginExpr()->getInstanceReceiver());
1073 SVal SelfVal = getState()->getSelfSVal(getStackFrame());
1074
1075 return (RecVal == SelfVal);
1076}
1077
1079 switch (getMessageKind()) {
1080 case OCM_Message:
1081 return getOriginExpr()->getSourceRange();
1082 case OCM_PropertyAccess:
1083 case OCM_Subscript:
1084 return getContainingPseudoObjectExpr()->getSourceRange();
1085 }
1086 llvm_unreachable("unknown message kind");
1087}
1088
1089using ObjCMessageDataTy = llvm::PointerIntPair<const PseudoObjectExpr *, 2>;
1090
1091const PseudoObjectExpr *ObjCMethodCall::getContainingPseudoObjectExpr() const {
1092 assert(Data && "Lazy lookup not yet performed.");
1093 assert(getMessageKind() != OCM_Message && "Explicit message send.");
1094 return ObjCMessageDataTy::getFromOpaqueValue(Data).getPointer();
1095}
1096
1097static const Expr *
1099 const Expr *Syntactic = POE->getSyntacticForm()->IgnoreParens();
1100
1101 // This handles the funny case of assigning to the result of a getter.
1102 // This can happen if the getter returns a non-const reference.
1103 if (const auto *BO = dyn_cast<BinaryOperator>(Syntactic))
1104 Syntactic = BO->getLHS()->IgnoreParens();
1105
1106 return Syntactic;
1107}
1108
1110 if (!Data) {
1111 // Find the parent, ignoring implicit casts.
1112 const ParentMap &PM = getStackFrame()->getParentMap();
1114
1115 // Check if parent is a PseudoObjectExpr.
1116 if (const auto *POE = dyn_cast_or_null<PseudoObjectExpr>(S)) {
1117 const Expr *Syntactic = getSyntacticFromForPseudoObjectExpr(POE);
1118
1120 switch (Syntactic->getStmtClass()) {
1121 case Stmt::ObjCPropertyRefExprClass:
1123 break;
1124 case Stmt::ObjCSubscriptRefExprClass:
1125 K = OCM_Subscript;
1126 break;
1127 default:
1128 // FIXME: Can this ever happen?
1129 K = OCM_Message;
1130 break;
1131 }
1132
1133 if (K != OCM_Message) {
1134 const_cast<ObjCMethodCall *>(this)->Data
1135 = ObjCMessageDataTy(POE, K).getOpaqueValue();
1136 assert(getMessageKind() == K);
1137 return K;
1138 }
1139 }
1140
1141 const_cast<ObjCMethodCall *>(this)->Data
1142 = ObjCMessageDataTy(nullptr, 1).getOpaqueValue();
1143 assert(getMessageKind() == OCM_Message);
1144 return OCM_Message;
1145 }
1146
1147 ObjCMessageDataTy Info = ObjCMessageDataTy::getFromOpaqueValue(Data);
1148 if (!Info.getPointer())
1149 return OCM_Message;
1150 return static_cast<ObjCMessageKind>(Info.getInt());
1151}
1152
1154 // Look for properties accessed with property syntax (foo.bar = ...)
1156 const PseudoObjectExpr *POE = getContainingPseudoObjectExpr();
1157 assert(POE && "Property access without PseudoObjectExpr?");
1158
1159 const Expr *Syntactic = getSyntacticFromForPseudoObjectExpr(POE);
1160 auto *RefExpr = cast<ObjCPropertyRefExpr>(Syntactic);
1161
1162 if (RefExpr->isExplicitProperty())
1163 return RefExpr->getExplicitProperty();
1164 }
1165
1166 // Look for properties accessed with method syntax ([foo setBar:...]).
1167 const ObjCMethodDecl *MD = getDecl();
1168 if (!MD || !MD->isPropertyAccessor())
1169 return nullptr;
1170
1171 // Note: This is potentially quite slow.
1172 return MD->findPropertyDecl();
1173}
1174
1176 Selector Sel) const {
1177 assert(IDecl);
1178 AnalysisManager &AMgr =
1179 getState()->getStateManager().getOwningEngine().getAnalysisManager();
1180 // If the class interface is declared inside the main file, assume it is not
1181 // subcassed.
1182 // TODO: It could actually be subclassed if the subclass is private as well.
1183 // This is probably very rare.
1184 SourceLocation InterfLoc = IDecl->getEndOfDefinitionLoc();
1185 if (InterfLoc.isValid() && AMgr.isInCodeFile(InterfLoc))
1186 return false;
1187
1188 // Assume that property accessors are not overridden.
1190 return false;
1191
1192 // We assume that if the method is public (declared outside of main file) or
1193 // has a parent which publicly declares the method, the method could be
1194 // overridden in a subclass.
1195
1196 // Find the first declaration in the class hierarchy that declares
1197 // the selector.
1198 ObjCMethodDecl *D = nullptr;
1199 while (true) {
1200 D = IDecl->lookupMethod(Sel, true);
1201
1202 // Cannot find a public definition.
1203 if (!D)
1204 return false;
1205
1206 // If outside the main file,
1207 if (D->getLocation().isValid() && !AMgr.isInCodeFile(D->getLocation()))
1208 return true;
1209
1210 if (D->isOverriding()) {
1211 // Search in the superclass on the next iteration.
1212 IDecl = D->getClassInterface();
1213 if (!IDecl)
1214 return false;
1215
1216 IDecl = IDecl->getSuperClass();
1217 if (!IDecl)
1218 return false;
1219
1220 continue;
1221 }
1222
1223 return false;
1224 };
1225
1226 llvm_unreachable("The while loop should always terminate.");
1227}
1228
1230 if (!MD)
1231 return MD;
1232
1233 // Find the redeclaration that defines the method.
1234 if (!MD->hasBody()) {
1235 for (auto *I : MD->redecls())
1236 if (I->hasBody())
1237 MD = cast<ObjCMethodDecl>(I);
1238 }
1239 return MD;
1240}
1241
1247
1248namespace llvm {
1249template <> struct DenseMapInfo<PrivateMethodKey> {
1250 using InterfaceInfo = DenseMapInfo<const ObjCInterfaceDecl *>;
1251 using SelectorInfo = DenseMapInfo<Selector>;
1252
1253 static unsigned getHashValue(const PrivateMethodKey &Key) {
1254 return llvm::hash_combine(
1255 llvm::hash_code(InterfaceInfo::getHashValue(Key.Interface)),
1256 llvm::hash_code(SelectorInfo::getHashValue(Key.LookupSelector)),
1257 Key.IsClassMethod);
1258 }
1259
1260 static bool isEqual(const PrivateMethodKey &LHS,
1261 const PrivateMethodKey &RHS) {
1262 return InterfaceInfo::isEqual(LHS.Interface, RHS.Interface) &&
1263 SelectorInfo::isEqual(LHS.LookupSelector, RHS.LookupSelector) &&
1264 LHS.IsClassMethod == RHS.IsClassMethod;
1265 }
1266};
1267} // end namespace llvm
1268
1269// NOTE: This cache is a "global" variable, and it is cleared by
1270// CallEventManager's constructor so we do not keep old entries when
1271// loading/unloading ASTs. If we are worried about concurrency, we may need to
1272// revisit this someday. In terms of memory, this table stays around until clang
1273// quits, which also may be bad if we need to release memory.
1275 llvm::DenseMap<PrivateMethodKey, std::optional<const ObjCMethodDecl *>>;
1277
1278static const ObjCMethodDecl *
1280 Selector LookupSelector, bool InstanceMethod) {
1281 // Repeatedly calling lookupPrivateMethod() is expensive, especially
1282 // when in many cases it returns null. We cache the results so
1283 // that repeated queries on the same ObjCIntefaceDecl and Selector
1284 // don't incur the same cost. On some test cases, we can see the
1285 // same query being issued thousands of times.
1286 std::optional<const ObjCMethodDecl *> &Val =
1287 PrivateMethodCache[{Interface, LookupSelector, InstanceMethod}];
1288
1289 // Query lookupPrivateMethod() if the cache does not hit.
1290 if (!Val) {
1291 Val = Interface->lookupPrivateMethod(LookupSelector, InstanceMethod);
1292
1293 if (!*Val) {
1294 // Query 'lookupMethod' as a backup.
1295 Val = Interface->lookupMethod(LookupSelector, InstanceMethod);
1296 }
1297 }
1298
1299 return *Val;
1300}
1301
1303 const ObjCMessageExpr *E = getOriginExpr();
1304 assert(E);
1305 Selector Sel = E->getSelector();
1306
1307 if (E->isInstanceMessage()) {
1308 // Find the receiver type.
1309 const ObjCObjectType *ReceiverT = nullptr;
1310 bool CanBeSubClassed = false;
1311 bool LookingForInstanceMethod = true;
1312 QualType SupersType = E->getSuperType();
1313 const MemRegion *Receiver = nullptr;
1314
1315 if (!SupersType.isNull()) {
1316 // The receiver is guaranteed to be 'super' in this case.
1317 // Super always means the type of immediate predecessor to the method
1318 // where the call occurs.
1319 ReceiverT = cast<ObjCObjectPointerType>(SupersType)->getObjectType();
1320 } else {
1321 Receiver = getReceiverSVal().getAsRegion();
1322 if (!Receiver)
1323 return {};
1324
1325 DynamicTypeInfo DTI = getDynamicTypeInfo(getState(), Receiver);
1326 if (!DTI.isValid()) {
1327 assert(isa<AllocaRegion>(Receiver) &&
1328 "Unhandled untyped region class!");
1329 return {};
1330 }
1331
1332 QualType DynType = DTI.getType();
1333 CanBeSubClassed = DTI.canBeASubClass();
1334
1335 const auto *ReceiverDynT =
1336 dyn_cast<ObjCObjectPointerType>(DynType.getCanonicalType());
1337
1338 if (ReceiverDynT) {
1339 ReceiverT = ReceiverDynT->getObjectType();
1340
1341 // It can be actually class methods called with Class object as a
1342 // receiver. This type of messages is treated by the compiler as
1343 // instance (not class).
1344 if (ReceiverT->isObjCClass()) {
1345
1346 SVal SelfVal = getState()->getSelfSVal(getStackFrame());
1347 // For [self classMethod], return compiler visible declaration.
1348 if (Receiver == SelfVal.getAsRegion()) {
1350 }
1351
1352 // Otherwise, let's check if we know something about the type
1353 // inside of this class object.
1354 if (SymbolRef ReceiverSym = getReceiverSVal().getAsSymbol()) {
1355 DynamicTypeInfo DTI =
1357 if (DTI.isValid()) {
1358 // Let's use this type for lookup.
1359 ReceiverT =
1361
1362 CanBeSubClassed = DTI.canBeASubClass();
1363 // And it should be a class method instead.
1364 LookingForInstanceMethod = false;
1365 }
1366 }
1367 }
1368
1369 if (CanBeSubClassed)
1370 if (ObjCInterfaceDecl *IDecl = ReceiverT->getInterface())
1371 // Even if `DynamicTypeInfo` told us that it can be
1372 // not necessarily this type, but its descendants, we still want
1373 // to check again if this selector can be actually overridden.
1374 CanBeSubClassed = canBeOverridenInSubclass(IDecl, Sel);
1375 }
1376 }
1377
1378 // Lookup the instance method implementation.
1379 if (ReceiverT)
1380 if (ObjCInterfaceDecl *IDecl = ReceiverT->getInterface()) {
1381 const ObjCMethodDecl *MD =
1382 lookupRuntimeDefinition(IDecl, Sel, LookingForInstanceMethod);
1383
1384 if (MD && !MD->hasBody())
1385 MD = MD->getCanonicalDecl();
1386
1387 if (CanBeSubClassed)
1388 return RuntimeDefinition(MD, Receiver);
1389 else
1390 return RuntimeDefinition(MD, nullptr);
1391 }
1392 } else {
1393 // This is a class method.
1394 // If we have type info for the receiver class, we are calling via
1395 // class name.
1396 if (ObjCInterfaceDecl *IDecl = E->getReceiverInterface()) {
1397 // Find/Return the method implementation.
1398 return RuntimeDefinition(IDecl->lookupPrivateClassMethod(Sel));
1399 }
1400 }
1401
1402 return {};
1403}
1404
1406 if (isInSystemHeader() && !isInstanceMessage()) {
1407 Selector Sel = getSelector();
1408 if (Sel.getNumArgs() == 1 &&
1409 Sel.getIdentifierInfoForSlot(0)->isStr("valueWithPointer"))
1410 return true;
1411 }
1412
1414}
1415
1417 BindingsTy &Bindings) const {
1418 const auto *D = cast<ObjCMethodDecl>(CalleeSF->getDecl());
1419 SValBuilder &SVB = getState()->getStateManager().getSValBuilder();
1420 addParameterValuesToBindings(CalleeSF, Bindings, SVB, *this, D->parameters());
1421
1422 SVal SelfVal = getReceiverSVal();
1423 if (!SelfVal.isUnknown()) {
1424 const VarDecl *SelfD = CalleeSF->getAnalysisDeclContext()->getSelfDecl();
1425 MemRegionManager &MRMgr = SVB.getRegionManager();
1426 Loc SelfLoc = SVB.makeLoc(MRMgr.getVarRegion(SelfD, CalleeSF));
1427 Bindings.push_back(std::make_pair(SelfLoc, SelfVal));
1428 }
1429}
1430
1431CallEventManager::CallEventManager(llvm::BumpPtrAllocator &alloc)
1432 : Alloc(alloc) {
1433 // Clear the method cache to avoid hits when multiple AST are loaded/unloaded
1434 // within a single process. This can happen with unit tests, for instance.
1435 PrivateMethodCache.clear();
1436}
1437
1440 const StackFrame *SF,
1442 if (const auto *MCE = dyn_cast<CXXMemberCallExpr>(CE))
1443 return create<CXXMemberCall>(MCE, State, SF, ElemRef);
1444
1445 if (const auto *OpCE = dyn_cast<CXXOperatorCallExpr>(CE)) {
1446 const FunctionDecl *DirectCallee = OpCE->getDirectCallee();
1447 if (const auto *MD = dyn_cast<CXXMethodDecl>(DirectCallee)) {
1448 if (MD->isImplicitObjectMemberFunction())
1449 return create<CXXMemberOperatorCall>(OpCE, State, SF, ElemRef);
1450 if (MD->isStatic())
1451 return create<CXXStaticOperatorCall>(OpCE, State, SF, ElemRef);
1452 }
1453
1454 } else if (CE->getCallee()->getType()->isBlockPointerType()) {
1455 return create<BlockCall>(CE, State, SF, ElemRef);
1456 }
1457
1458 // Otherwise, it's a normal function call, static member function call, or
1459 // something we can't reason about.
1460 return create<SimpleFunctionCall>(CE, State, SF, ElemRef);
1461}
1462
1464 ProgramStateRef State) {
1465 const StackFrame *ParentSF = CalleeSF->getParent();
1466 const StackFrame *CallerSF = ParentSF;
1467 CFGBlock::ConstCFGElementRef ElemRef = {CalleeSF->getCallSiteBlock(),
1468 CalleeSF->getIndex()};
1469 assert(CallerSF && "This should not be used for top-level stack frames");
1470
1471 const Expr *CallSite = CalleeSF->getCallSite();
1472
1473 if (CallSite) {
1474 if (CallEventRef<> Out = getCall(CallSite, State, CallerSF, ElemRef))
1475 return Out;
1476
1477 SValBuilder &SVB = State->getStateManager().getSValBuilder();
1478 const auto *Ctor = cast<CXXMethodDecl>(CalleeSF->getDecl());
1479 Loc ThisPtr = SVB.getCXXThis(Ctor, CalleeSF);
1480 SVal ThisVal = State->getSVal(ThisPtr);
1481
1482 if (const auto *CE = dyn_cast<CXXConstructExpr>(CallSite))
1483 return getCXXConstructorCall(CE, ThisVal.getAsRegion(), State, CallerSF,
1484 ElemRef);
1485 if (const auto *CIE = dyn_cast<CXXInheritedCtorInitExpr>(CallSite))
1486 return getCXXInheritedConstructorCall(CIE, ThisVal.getAsRegion(), State,
1487 CallerSF, ElemRef);
1488 // All other cases are handled by getCall.
1489 llvm_unreachable("This is not an inlineable statement");
1490 }
1491
1492 // Fall back to the CFG. The only thing we haven't handled yet is
1493 // destructors, though this could change in the future.
1494 const CFGBlock *B = CalleeSF->getCallSiteBlock();
1495 CFGElement E = (*B)[CalleeSF->getIndex()];
1496 assert((E.getAs<CFGImplicitDtor>() || E.getAs<CFGTemporaryDtor>()) &&
1497 "All other CFG elements should have exprs");
1498
1499 SValBuilder &SVB = State->getStateManager().getSValBuilder();
1500 const auto *Dtor = cast<CXXDestructorDecl>(CalleeSF->getDecl());
1501 Loc ThisPtr = SVB.getCXXThis(Dtor, CalleeSF);
1502 SVal ThisVal = State->getSVal(ThisPtr);
1503
1504 const Stmt *Trigger;
1505 if (std::optional<CFGAutomaticObjDtor> AutoDtor =
1507 Trigger = AutoDtor->getTriggerStmt();
1508 else if (std::optional<CFGDeleteDtor> DeleteDtor = E.getAs<CFGDeleteDtor>())
1509 Trigger = DeleteDtor->getDeleteExpr();
1510 else
1511 Trigger = Dtor->getBody();
1512
1513 return getCXXDestructorCall(Dtor, Trigger, ThisVal.getAsRegion(),
1514 E.getAs<CFGBaseDtor>().has_value(), State,
1515 CallerSF, ElemRef);
1516}
1517
1519 const StackFrame *SF,
1521 if (const auto *CE = dyn_cast<CallExpr>(S)) {
1522 return getSimpleCall(CE, State, SF, ElemRef);
1523 } else if (const auto *NE = dyn_cast<CXXNewExpr>(S)) {
1524 return getCXXAllocatorCall(NE, State, SF, ElemRef);
1525 } else if (const auto *DE = dyn_cast<CXXDeleteExpr>(S)) {
1526 return getCXXDeallocatorCall(DE, State, SF, ElemRef);
1527 } else if (const auto *ME = dyn_cast<ObjCMessageExpr>(S)) {
1528 return getObjCMethodCall(ME, State, SF, ElemRef);
1529 } else {
1530 return nullptr;
1531 }
1532}
Defines the clang::ASTContext interface.
#define V(N, I)
This file defines AnalysisDeclContext, a class that manages the analysis context data for context sen...
static bool isZeroConstant(const llvm::Value *Value)
static bool isVoidPointerToNonConst(QualType T)
static const ObjCMethodDecl * findDefiningRedecl(const ObjCMethodDecl *MD)
static const ObjCMethodDecl * lookupRuntimeDefinition(const ObjCInterfaceDecl *Interface, Selector LookupSelector, bool InstanceMethod)
static const MemRegion * getThisRegionBaseOrNull(const CallEvent &Call)
static const Expr * getSyntacticFromForPseudoObjectExpr(const PseudoObjectExpr *POE)
static bool isTransparentUnion(QualType T)
llvm::PointerIntPair< const PseudoObjectExpr *, 2 > ObjCMessageDataTy
static bool isCallback(QualType T)
Definition CallEvent.cpp:78
static SVal castArgToParamTypeIfNeeded(const CallEvent &Call, unsigned ArgIdx, SVal ArgVal, SValBuilder &SVB)
Cast the argument value to the type of the parameter at the function declaration.
llvm::DenseMap< PrivateMethodKey, std::optional< const ObjCMethodDecl * > > PrivateMethodCacheTy
static SVal processArgument(SVal Value, const Expr *ArgumentExpr, const ParmVarDecl *Parameter, SValBuilder &SVB)
static PrivateMethodCacheTy PrivateMethodCache
static void findPtrToConstParams(llvm::SmallSet< unsigned, 4 > &PreserveArgs, const CallEvent &Call)
static void addParameterValuesToBindings(const StackFrame *CalleeSF, CallEvent::BindingsTy &Bindings, SValBuilder &SVB, const CallEvent &Call, ArrayRef< ParmVarDecl * > parameters)
Defines the C++ Decl subclasses, other than those for templates (found in DeclTemplate....
Defines the clang::Expr interface and subclasses for C++ expressions.
Defines the clang::IdentifierInfo, clang::IdentifierTable, and clang::Selector interfaces.
static const Decl * getCanonicalDecl(const Decl *D)
Forward-declares and imports various common LLVM datatypes that clang wants to use unqualified.
llvm::SmallVector< std::pair< const MemRegion *, SVal >, 4 > Bindings
Defines the clang::SourceLocation class and associated facilities.
Defines various enumerations that describe declaration and type specifiers.
C Language Family Type Representation.
static bool isPointerToConst(const QualType &QT)
Holds long-lived AST nodes (such as types and decls) that can be referred to throughout the semantic ...
Definition ASTContext.h:239
QualType getPointerType(QualType T) const
Return the uniqued reference to the type for a pointer to the specified type.
QualType getReferenceQualifiedType(const Expr *e) const
getReferenceQualifiedType - Given an expr, will return the type for that expression,...
const clang::PrintingPolicy & getPrintingPolicy() const
Definition ASTContext.h:899
CanQualType VoidTy
CanQualType getCanonicalTagType(const TagDecl *TD) const
AnalysisDeclContext * getContext(const Decl *D)
AnalysisDeclContext contains the context data for the function, method or block under analysis.
const ImplicitParamDecl * getSelfDecl() const
AnalysisDeclContextManager * getManager() const
const StackFrame * getStackFrame(const StackFrame *ParentSF, const void *Data, const Expr *E, const CFGBlock *Blk, unsigned BlockCount, unsigned Index)
Obtain a context of the call stack using its parent context.
Stores options for the analyzer from the command line.
Represents a block literal declaration, which is like an unnamed FunctionDecl.
Definition Decl.h:4810
ArrayRef< ParmVarDecl * > parameters() const
Definition Decl.h:4896
Represents C++ object destructor implicitly generated for automatic object or temporary bound to cons...
Definition CFG.h:465
Represents C++ object destructor implicitly generated for base object in destructor.
Definition CFG.h:516
Represents a single basic block in a source-level CFG.
Definition CFG.h:652
unsigned size() const
Definition CFG.h:999
ElementRefImpl< true > ConstCFGElementRef
Definition CFG.h:968
Represents a function call that returns a C++ object by value.
Definition CFG.h:190
Represents C++ constructor call.
Definition CFG.h:161
Represents C++ object destructor generated from a call to delete.
Definition CFG.h:490
Represents a top-level expression in a basic block.
Definition CFG.h:55
std::optional< T > getAs() const
Convert to the specified CFGElement type, returning std::nullopt if this CFGElement is not of the des...
Definition CFG.h:113
Represents C++ object destructor implicitly generated by compiler on various occasions.
Definition CFG.h:414
const CFGBlock * getBlock(const Stmt *S) const
Returns the CFGBlock the specified Stmt* appears in.
Represents C++ object destructor implicitly generated at the end of full expression for temporary obj...
Definition CFG.h:558
Expr * getImplicitObjectArgument() const
Retrieve the implicit object argument for the member call.
Definition ExprCXX.cpp:755
Represents a static or instance method of a struct/union/class.
Definition DeclCXX.h:2150
const CXXRecordDecl * getParent() const
Return the parent of this method declaration, which is the class in which this method is defined.
Definition DeclCXX.h:2293
Represents a C++ struct/union/class.
Definition DeclCXX.h:258
bool hasMutableFields() const
Determine whether this class, or any of its class subobjects, contains a mutable field.
Definition DeclCXX.h:1243
bool hasDefinition() const
Definition DeclCXX.h:562
CallExpr - Represents a function call (C99 6.5.2.2, C++ [expr.call]).
Definition Expr.h:2987
Expr * getArg(unsigned Arg)
getArg - Return the specified argument.
Definition Expr.h:3191
FunctionDecl * getDirectCallee()
If the callee is a FunctionDecl, return it. Otherwise return null.
Definition Expr.h:3170
Expr * getCallee()
Definition Expr.h:3134
ConstructionContext's subclasses describe different ways of constructing an object in C++.
Decl - This represents one declaration (or definition), e.g.
Definition DeclBase.h:86
SourceLocation getLocation() const
Definition DeclBase.h:447
redecl_range redecls() const
Returns an iterator range for all the redeclarations of the same decl.
Definition DeclBase.h:1066
This represents one expression.
Definition Expr.h:113
Expr * IgnoreParens() LLVM_READONLY
Skip past any parentheses which might surround this expression until reaching a fixed point.
Definition Expr.cpp:3119
QualType getType() const
Definition Expr.h:145
Represents a function declaration or definition.
Definition Decl.h:2059
ArrayRef< ParmVarDecl * > parameters() const
Definition Decl.h:2905
FunctionType - C99 6.7.5.3 - Function Declarators.
Definition TypeBase.h:4594
One of these records is kept for each identifier that is lexed.
bool isStr(const char(&Str)[StrLen]) const
Return true if this is the identifier for the specified string.
StringRef getName() const
Return the actual identifier string.
IdentifierInfo * getIdentifier() const
Get the identifier that names this declaration, if there is one.
Definition Decl.h:296
StringRef getName() const
Get the name of identifier for this declaration as a StringRef.
Definition Decl.h:302
Represents an ObjC class declaration.
Definition DeclObjC.h:1160
ObjCMethodDecl * lookupMethod(Selector Sel, bool isInstance, bool shallowCategoryLookup=false, bool followSuper=true, const ObjCCategoryDecl *C=nullptr) const
lookupMethod - This method returns an instance/class method by looking in the class,...
Definition DeclObjC.cpp:696
SourceLocation getEndOfDefinitionLoc() const
Definition DeclObjC.h:1884
ObjCInterfaceDecl * getSuperClass() const
Definition DeclObjC.cpp:349
ObjCIvarDecl - Represents an ObjC instance variable.
Definition DeclObjC.h:1958
An expression that sends a message to the given Objective-C object or class.
Definition ExprObjC.h:972
Selector getSelector() const
Definition ExprObjC.cpp:301
@ SuperInstance
The receiver is the instance of the superclass object.
Definition ExprObjC.h:986
@ SuperClass
The receiver is a superclass.
Definition ExprObjC.h:983
bool isInstanceMessage() const
Determine whether this is an instance message to either a computed object or to super.
Definition ExprObjC.h:1288
ObjCInterfaceDecl * getReceiverInterface() const
Retrieve the Objective-C interface to which this message is being directed, if known.
Definition ExprObjC.cpp:322
QualType getSuperType() const
Retrieve the type referred to by 'super'.
Definition ExprObjC.h:1376
const ObjCMethodDecl * getMethodDecl() const
Definition ExprObjC.h:1396
ObjCMethodDecl - Represents an instance or class method declaration.
Definition DeclObjC.h:140
bool hasBody() const override
Determine whether this method has a body.
Definition DeclObjC.h:526
bool isOverriding() const
Whether this method overrides any other in the class hierarchy.
Definition DeclObjC.h:465
ArrayRef< ParmVarDecl * > parameters() const
Definition DeclObjC.h:376
bool isPropertyAccessor() const
Definition DeclObjC.h:439
const ObjCPropertyDecl * findPropertyDecl(bool CheckOverrides=true) const
Returns the property associated with this method's selector.
ObjCMethodDecl * getCanonicalDecl() override
Retrieves the "canonical" declaration of the given declaration.
ObjCInterfaceDecl * getClassInterface()
Represents one property declaration in an Objective-C interface.
Definition DeclObjC.h:734
Stmt * getParentIgnoreParenCasts(Stmt *) const
Represents a parameter to a function.
Definition Decl.h:1820
PointerType - C99 6.7.5.1 - Pointer Declarators.
Definition TypeBase.h:3396
Represents a program point just after an implicit call event.
Represents a program point just before an implicit call event.
ProgramPoints can be "tagged" as representing points specific to a given analysis entity.
PseudoObjectExpr - An expression which accesses a pseudo-object l-value.
Definition Expr.h:6854
Expr * getSyntacticForm()
Return the syntactic form of this expression, i.e.
Definition Expr.h:6891
A (possibly-)qualified type.
Definition TypeBase.h:938
bool isNull() const
Return true if this QualType doesn't point to a type yet.
Definition TypeBase.h:1005
QualType getCanonicalType() const
Definition TypeBase.h:8480
bool isConstQualified() const
Determine whether this type is const-qualified.
Definition TypeBase.h:8501
Represents a struct/union/class.
Definition Decl.h:4460
field_range fields() const
Definition Decl.h:4663
RecordDecl * getDefinitionOrSelf() const
Definition Decl.h:4648
Smart pointer class that efficiently represents Objective-C method names.
const IdentifierInfo * getIdentifierInfoForSlot(unsigned argIndex) const
Retrieve the identifier at a given position in the selector.
unsigned getNumArgs() const
Encodes a location in the source.
bool isValid() const
Return true if this is a valid SourceLocation object.
A trivial tuple used to represent a source range.
SourceLocation getBegin() const
It represents a stack frame of the call stack.
const ParentMap & getParentMap() const
unsigned getIndex() const
LLVM_ATTRIBUTE_RETURNS_NONNULL AnalysisDeclContext * getAnalysisDeclContext() const
const Expr * getCallSite() const
CFGElement getCallSiteCFGElement() const
const Decl * getDecl() const
const StackFrame * getParent() const
It might return null.
const CFGBlock * getCallSiteBlock() const
Stmt - This represents one statement.
Definition Stmt.h:85
StmtClass getStmtClass() const
Definition Stmt.h:1505
SourceRange getSourceRange() const LLVM_READONLY
SourceLocation tokens are not useful in isolation - they are low level value objects created/interpre...
Definition Stmt.cpp:343
A container of type source information.
Definition TypeBase.h:8399
bool isBlockPointerType() const
Definition TypeBase.h:8685
bool isVoidType() const
Definition TypeBase.h:9037
bool isFunctionPointerType() const
Definition TypeBase.h:8732
const CXXRecordDecl * getPointeeCXXRecordDecl() const
If this is a pointer or reference to a RecordType, return the CXXRecordDecl that the type refers to.
Definition Type.cpp:2076
QualType getPointeeType() const
If this is a pointer, ObjC object pointer, or block pointer, this returns the respective pointee.
Definition Type.cpp:881
bool isDependentType() const
Whether this type is a dependent type, meaning that its definition somehow depends on a template para...
Definition TypeBase.h:2859
bool isAnyPointerType() const
Definition TypeBase.h:8673
const T * getAs() const
Member-template getAs<specific type>'.
Definition TypeBase.h:9264
Represents a variable declaration or definition.
Definition Decl.h:933
This class is used for tools that requires cross translation unit capability.
llvm::Expected< const FunctionDecl * > getCrossTUDefinition(const FunctionDecl *FD, StringRef CrossTUDir, StringRef IndexName, bool DisplayCTUProgress=false)
This function loads a function or variable definition from an external AST file and merges it into th...
bool hasError(const Decl *ToDecl) const
Returns true if the given Decl is mapped (or created) during an import but there was an unrecoverable...
bool isImportedAsNew(const Decl *ToDecl) const
Returns true if the given Decl is newly created during the import.
static bool isInCodeFile(SourceLocation SL, const SourceManager &SM)
void getExtraInvalidatedValues(ValueList &Values, RegionAndSymbolInvalidationTraits *ETraits) const override
Used to specify non-argument regions that will be invalidated as a result of this call.
SVal getCXXThisVal() const
Returns the value of the implicit 'this' object.
void getInitialStackFrameContents(const StackFrame *CalleeSF, BindingsTy &Bindings) const override
Populates the given SmallVector with the bindings in the callee's stack frame at the start of this ca...
void getInitialStackFrameContents(const StackFrame *CalleeSF, BindingsTy &Bindings) const override
Populates the given SmallVector with the bindings in the callee's stack frame at the start of this ca...
const FunctionDecl * getDecl() const override
Returns the declaration of the function or method that will be called.
Definition CallEvent.h:522
ArrayRef< ParmVarDecl * > parameters() const override
Return call's formal parameters.
bool argumentsMayEscape() const override
Returns true if any of the arguments are known to escape to long- term storage, even if this method w...
RuntimeDefinition getRuntimeDefinition() const override
Returns the definition of the function or method that will be called.
llvm::ImmutableList< SVal > getEmptySValList()
llvm::ImmutableList< SVal > prependSVal(SVal X, llvm::ImmutableList< SVal > L)
const BlockDecl * getDecl() const override
Returns the declaration of the function or method that will be called.
Definition CallEvent.h:614
void getInitialStackFrameContents(const StackFrame *CalleeSF, BindingsTy &Bindings) const override
Populates the given SmallVector with the bindings in the callee's stack frame at the start of this ca...
const BlockDataRegion * getBlockRegion() const
Returns the region associated with this instance of the block.
bool isConversionFromLambda() const
Definition CallEvent.h:621
ArrayRef< ParmVarDecl * > parameters() const override
Return call's formal parameters.
void getExtraInvalidatedValues(ValueList &Values, RegionAndSymbolInvalidationTraits *ETraits) const override
Used to specify non-argument regions that will be invalidated as a result of this call.
const VarRegion * getRegionStoringCapturedLambda() const
For a block converted from a C++ lambda, returns the block VarRegion for the variable holding the cap...
Definition CallEvent.h:631
const CallExpr * getOriginExpr() const override
Returns the expression whose value will be the result of this call.
Definition CallEvent.h:599
BlockDataRegion - A region that represents a block instance.
Definition MemRegion.h:712
SVal getCXXThisVal() const override
Returns the value of the implicit 'this' object.
RuntimeDefinition getRuntimeDefinition() const override
Returns the definition of the function or method that will be called.
bool isBaseDestructor() const
Returns true if this is a call to a base class destructor.
Definition CallEvent.h:945
const StackFrame * getInheritingStackFrame() const
Obtain the stack frame of the inheriting constructor.
std::pair< const CXXRecordDecl *, bool > getDeclForDynamicType() const
Returns the decl refered to by the "dynamic type" of the current object and if the class can be a sub...
void getExtraInvalidatedValues(ValueList &Values, RegionAndSymbolInvalidationTraits *ETraits) const override
Used to specify non-argument regions that will be invalidated as a result of this call.
virtual SVal getCXXThisVal() const
Returns the value of the implicit 'this' object.
RuntimeDefinition getRuntimeDefinition() const override
Returns the definition of the function or method that will be called.
virtual const Expr * getCXXThisExpr() const
Returns the expression representing the implicit 'this' object.
Definition CallEvent.h:707
const FunctionDecl * getDecl() const override
Returns the declaration of the function or method that will be called.
void getInitialStackFrameContents(const StackFrame *CalleeSF, BindingsTy &Bindings) const override
Populates the given SmallVector with the bindings in the callee's stack frame at the start of this ca...
const CXXMemberCallExpr * getOriginExpr() const override
Returns the expression whose value will be the result of this call.
Definition CallEvent.h:811
const Expr * getCXXThisExpr() const override
Returns the expression representing the implicit 'this' object.
RuntimeDefinition getRuntimeDefinition() const override
Returns the definition of the function or method that will be called.
const Expr * getCXXThisExpr() const override
Returns the expression representing the implicit 'this' object.
const CXXOperatorCallExpr * getOriginExpr() const override
Returns the expression whose value will be the result of this call.
Definition CallEvent.h:856
CallEventRef getCaller(const StackFrame *CalleeSF, ProgramStateRef State)
Gets an outside caller given a callee context.
CallEventRef< CXXConstructorCall > getCXXConstructorCall(const CXXConstructExpr *E, const MemRegion *Target, ProgramStateRef State, const StackFrame *SF, CFGBlock::ConstCFGElementRef ElemRef)
Definition CallEvent.h:1440
CallEventRef< CXXAllocatorCall > getCXXAllocatorCall(const CXXNewExpr *E, ProgramStateRef State, const StackFrame *SF, CFGBlock::ConstCFGElementRef ElemRef)
Definition CallEvent.h:1464
CallEventRef< CXXInheritedConstructorCall > getCXXInheritedConstructorCall(const CXXInheritedCtorInitExpr *E, const MemRegion *Target, ProgramStateRef State, const StackFrame *SF, CFGBlock::ConstCFGElementRef ElemRef)
Definition CallEvent.h:1447
CallEventManager(llvm::BumpPtrAllocator &alloc)
CallEventRef< CXXDeallocatorCall > getCXXDeallocatorCall(const CXXDeleteExpr *E, ProgramStateRef State, const StackFrame *SF, CFGBlock::ConstCFGElementRef ElemRef)
Definition CallEvent.h:1471
CallEventRef< CXXDestructorCall > getCXXDestructorCall(const CXXDestructorDecl *DD, const Stmt *Trigger, const MemRegion *Target, bool IsBase, ProgramStateRef State, const StackFrame *SF, CFGBlock::ConstCFGElementRef ElemRef)
Definition CallEvent.h:1455
CallEventRef< ObjCMethodCall > getObjCMethodCall(const ObjCMessageExpr *E, ProgramStateRef State, const StackFrame *SF, CFGBlock::ConstCFGElementRef ElemRef)
Definition CallEvent.h:1433
CallEventRef getCall(const Stmt *S, ProgramStateRef State, const StackFrame *SF, CFGBlock::ConstCFGElementRef ElemRef)
Gets a call event for a function call, Objective-C method call, a 'new', or a 'delete' call.
CallEventRef getSimpleCall(const CallExpr *E, ProgramStateRef State, const StackFrame *SF, CFGBlock::ConstCFGElementRef ElemRef)
Represents an abstract call to a function or method along a particular path.
Definition CallEvent.h:152
virtual SourceRange getArgSourceRange(unsigned Index) const
Returns the source range for errors associated with this argument.
virtual void getExtraInvalidatedValues(ValueList &Values, RegionAndSymbolInvalidationTraits *ETraits) const
Used to specify non-argument regions that will be invalidated as a result of this call.
Definition CallEvent.h:210
virtual StringRef getKindAsString() const =0
SVal getSVal(const Expr *E) const
Get the value of arbitrary expressions at this point in the path.
Definition CallEvent.h:201
virtual const Expr * getOriginExpr() const
Returns the expression whose value will be the result of this call.
Definition CallEvent.h:262
ProgramStateRef getState() const
A state for looking up relevant Environment entries (arguments, return value), dynamic type informati...
Definition CallEvent.h:221
static bool isCallStmt(const Stmt *S)
Returns true if this is a statement is a function or method call of some kind.
const ConstructionContext * getConstructionContext() const
Returns the construction context of the call, if it is a C++ constructor call or a call of a function...
param_type_iterator param_type_end() const
Definition CallEvent.h:498
const ParamVarRegion * getParameterLocation(unsigned Index, unsigned BlockCount) const
Returns memory location for a parameter variable within the callee stack frame.
bool isCalledFromSystemHeader() const
AnalysisDeclContext * getCalleeAnalysisDeclContext() const
Returns AnalysisDeclContext for the callee stack frame.
virtual std::optional< unsigned > getAdjustedParameterIndex(unsigned ASTArgumentIndex) const
Some calls have parameter numbering mismatched from argument numbering.
Definition CallEvent.h:444
QualType getResultType() const
Returns the result type, adjusted for references.
Definition CallEvent.cpp:70
ProgramStateRef invalidateRegions(unsigned BlockCount, ProgramStateRef State) const
Invalidates the regions (arguments, globals, special regions like 'this') that may have been written ...
friend class CallEventManager
Definition CallEvent.h:181
llvm::mapped_iterator< ArrayRef< ParmVarDecl * >::iterator, GetTypeFn > param_type_iterator
Definition CallEvent.h:486
const StackFrame * getCalleeStackFrame(unsigned BlockCount) const
Returns the callee stack frame.
bool isInSystemHeader() const
Returns true if the callee is known to be from a system header.
Definition CallEvent.h:274
bool isGlobalCFunction(StringRef SpecificName=StringRef()) const
Returns true if the callee is an externally-visible function in the top-level namespace,...
virtual bool argumentsMayEscape() const
Returns true if any of the arguments are known to escape to long- term storage, even if this method w...
Definition CallEvent.h:336
param_type_iterator param_type_begin() const
Returns an iterator over the types of the call's formal parameters.
Definition CallEvent.h:494
const StackFrame * getStackFrame() const
The stack frame in which the call is being evaluated.
Definition CallEvent.h:250
ProgramPoint getProgramPoint(bool IsPreVisit=false, const ProgramPointTag *Tag=nullptr) const
Returns an appropriate ProgramPoint for this call.
static QualType getDeclaredResultType(const Decl *D)
Returns the result type of a function or method declaration.
static bool isVariadic(const Decl *D)
Returns true if the given decl is known to be variadic.
virtual SVal getArgSVal(unsigned Index) const
Returns the value of a given argument at the time of the call.
bool hasNonNullArgumentsWithType(bool(*Condition)(QualType)) const
Returns true if the type of any of the non-null arguments satisfies the condition.
std::optional< SVal > getReturnValueUnderConstruction() const
If the call returns a C++ record type then the region of its return value can be retrieved from its c...
virtual const Expr * getArgExpr(unsigned Index) const
Returns the expression associated with a given argument.
Definition CallEvent.h:305
virtual unsigned getNumArgs() const =0
Returns the number of arguments (explicit and implicit).
bool hasVoidPointerToNonConstArg() const
Returns true if any of the arguments is void*.
const CallEventRef getCaller() const
bool isArgumentConstructedDirectly(unsigned Index) const
Returns true if on the current path, the argument was constructed by calling a C++ constructor over i...
Definition CallEvent.h:432
SmallVectorImpl< FrameBindingTy > BindingsTy
Definition CallEvent.h:380
SVal getReturnValue() const
Returns the return value of the call.
virtual const Decl * getDecl() const
Returns the declaration of the function or method that will be called.
Definition CallEvent.h:233
const CFGBlock::ConstCFGElementRef & getCFGElementRef() const
Definition CallEvent.h:252
bool hasNonZeroCallbackArg() const
Returns true if any of the arguments appear to represent callbacks.
virtual Kind getKind() const =0
Returns the kind of call this is.
SmallVectorImpl< SVal > ValueList
Definition CallEvent.h:205
virtual SourceRange getSourceRange() const
Returns a source range for the entire call, suitable for outputting in diagnostics.
Definition CallEvent.h:296
static bool isCLibraryFunction(const FunctionDecl *FD, StringRef Name=StringRef())
Returns true if the given function is an externally-visible function in the top-level namespace,...
Stores the currently inferred strictest bound on the runtime type of a region in a given state along ...
bool canBeASubClass() const
Returns false if the type information is precise (the type 'DynTy' is the only type in the lattice),...
QualType getType() const
Returns the currently inferred upper bound on the runtime type.
bool isValid() const
Returns true if the dynamic type info is available.
SVal computeObjectUnderConstruction(const Expr *E, ProgramStateRef State, unsigned NumVisitedCaller, const StackFrame *SF, const ConstructionContext *CC, EvalCallOptions &CallOpts, unsigned Idx=0)
Find location of the object that is being constructed by a given constructor.
unsigned getNumVisited(const StackFrame *SF, const CFGBlock *Block) const
Definition ExprEngine.h:258
const ParamVarRegion * getParamVarRegion(const Expr *OriginExpr, unsigned Index, const StackFrame *SF)
getParamVarRegion - Retrieve or create the memory region associated with a specified CallExpr,...
const VarRegion * getVarRegion(const VarDecl *VD, const StackFrame *SF)
getVarRegion - Retrieve or create the memory region associated with a specified VarDecl and StackFram...
MemRegion - The root abstract class for all memory regions.
Definition MemRegion.h:97
LLVM_ATTRIBUTE_RETURNS_NONNULL const MemRegion * getBaseRegion() const
const ObjCMethodDecl * getDecl() const override
Returns the declaration of the function or method that will be called.
Definition CallEvent.h:1280
void getExtraInvalidatedValues(ValueList &Values, RegionAndSymbolInvalidationTraits *ETraits) const override
Used to specify non-argument regions that will be invalidated as a result of this call.
ObjCMessageKind getMessageKind() const
Returns how the message was written in the source (property access, subscript, or explicit message se...
const ObjCMessageExpr * getOriginExpr() const override
Returns the expression whose value will be the result of this call.
Definition CallEvent.h:1276
ArrayRef< ParmVarDecl * > parameters() const override
Return call's formal parameters.
void getInitialStackFrameContents(const StackFrame *CalleeSF, BindingsTy &Bindings) const override
Populates the given SmallVector with the bindings in the callee's stack frame at the start of this ca...
SourceRange getSourceRange() const override
Returns a source range for the entire call, suitable for outputting in diagnostics.
virtual bool canBeOverridenInSubclass(ObjCInterfaceDecl *IDecl, Selector Sel) const
Check if the selector may have multiple definitions (may have overrides).
bool argumentsMayEscape() const override
Returns true if any of the arguments are known to escape to long- term storage, even if this method w...
SVal getReceiverSVal() const
Returns the value of the receiver at the time of this call.
RuntimeDefinition getRuntimeDefinition() const override
Returns the definition of the function or method that will be called.
ObjCMethodCall(const ObjCMessageExpr *Msg, ProgramStateRef St, const StackFrame *SF, CFGBlock::ConstCFGElementRef ElemRef)
Definition CallEvent.h:1257
bool isReceiverSelfOrSuper() const
Checks if the receiver refers to 'self' or 'super'.
Selector getSelector() const
Definition CallEvent.h:1298
const ObjCPropertyDecl * getAccessedProperty() const
ParamVarRegion - Represents a region for parameters.
Definition MemRegion.h:1072
Information about invalidation for a particular region/symbol.
Definition MemRegion.h:1663
@ TK_PreserveContents
Tells that a region's contents is not changed.
Definition MemRegion.h:1678
@ TK_SuppressEscape
Suppress pointer-escaping of a region.
Definition MemRegion.h:1681
void setTrait(SymbolRef Sym, InvalidationKinds IK)
Defines the runtime definition of the called function.
Definition CallEvent.h:109
BasicValueFactory & getBasicValueFactory()
NonLoc makeCompoundVal(QualType type, llvm::ImmutableList< SVal > vals)
MemRegionManager & getRegionManager()
ProgramStateManager & getStateManager()
ASTContext & getContext()
loc::MemRegionVal makeLoc(SymbolRef sym)
SVal evalCast(SVal V, QualType CastTy, QualType OriginalTy)
Cast a given SVal to another SVal using given QualType's.
loc::MemRegionVal getCXXThis(const CXXMethodDecl *D, const StackFrame *SF)
Return a memory region for the 'this' object reference.
SVal - This represents a symbolic expression, which can be either an L-value or an R-value.
Definition SVals.h:57
bool isUnknownOrUndef() const
Definition SVals.h:115
const FunctionDecl * getAsFunctionDecl() const
getAsFunctionDecl - If this SVal is a MemRegionVal and wraps a CodeTextRegion wrapping a FunctionDecl...
Definition SVals.cpp:45
QualType getType(const ASTContext &) const
Try to get a reasonable type for the given value.
Definition SVals.cpp:180
const MemRegion * getAsRegion() const
Definition SVals.cpp:119
bool isValid() const
Definition SVals.h:117
bool isUnknown() const
Definition SVals.h:111
RuntimeDefinition getRuntimeDefinition() const override
Returns the definition of the function or method that will be called.
const CallExpr * getOriginExpr() const override
Returns the expression whose value will be the result of this call.
Definition CallEvent.h:558
const FunctionDecl * getDecl() const override
Returns the declaration of the function or method that will be called.
std::optional< SVal > evalBaseToDerived(SVal Base, QualType DerivedPtrType)
Attempts to do a down cast.
Definition Store.cpp:318
TypedValueRegion - An abstract class representing regions having a typed value.
Definition MemRegion.h:569
static const FunctionDecl * getCallee(const CXXConstructExpr &D)
bool isWithinStdNamespace(const Decl *D)
Returns true if declaration D is in std namespace or any nested namespace or class scope.
IntrusiveRefCntPtr< const ProgramState > ProgramStateRef
const SymExpr * SymbolRef
Definition SymExpr.h:133
DynamicTypeInfo getDynamicTypeInfo(ProgramStateRef State, const MemRegion *MR)
Get dynamic type information for the region MR.
@ CE_CXXAllocator
Definition CallEvent.h:71
ObjCMessageKind
Represents the ways an Objective-C message send can occur.
Definition CallEvent.h:1246
DynamicTypeInfo getClassObjectDynamicTypeInfo(ProgramStateRef State, SymbolRef Sym)
Get dynamic type information stored in a class object represented by Sym.
Top level wrappers for InstallAPI frontend operations.
CanQual< Type > CanQualType
Represents a canonical, potentially-qualified type.
bool isa(CodeGen::Address addr)
Definition Address.h:330
@ Parameter
The parameter type of a method or function.
Definition TypeBase.h:909
@ Result
The result type of a method or function.
Definition TypeBase.h:906
const FunctionProtoType * T
U cast(CodeGen::Address addr)
Definition Address.h:327
@ Interface
The "__interface" keyword introduces the elaborated-type-specifier.
Definition TypeBase.h:6001
@ Class
The "class" keyword introduces the elaborated-type-specifier.
Definition TypeBase.h:6007
Diagnostic wrappers for TextAPI types for error reporting.
Definition Dominators.h:30
Selector LookupSelector
const ObjCInterfaceDecl * Interface
Hints for figuring out if a call should be inlined during evalCall().
Definition ExprEngine.h:92
DenseMapInfo< Selector > SelectorInfo
static unsigned getHashValue(const PrivateMethodKey &Key)
DenseMapInfo< const ObjCInterfaceDecl * > InterfaceInfo
static bool isEqual(const PrivateMethodKey &LHS, const PrivateMethodKey &RHS)