clang  15.0.0git
CheckerContext.cpp
Go to the documentation of this file.
1 //== CheckerContext.cpp - Context info for path-sensitive checkers-----------=//
2 //
3 // Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
4 // See https://llvm.org/LICENSE.txt for license information.
5 // SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
6 //
7 //===----------------------------------------------------------------------===//
8 //
9 // This file defines CheckerContext that provides contextual info for
10 // path-sensitive checkers.
11 //
12 //===----------------------------------------------------------------------===//
13 
15 #include "clang/Basic/Builtins.h"
16 #include "clang/Lex/Lexer.h"
17 
18 using namespace clang;
19 using namespace ento;
20 
22  const FunctionDecl *D = CE->getDirectCallee();
23  if (D)
24  return D;
25 
26  const Expr *Callee = CE->getCallee();
27  SVal L = Pred->getSVal(Callee);
28  return L.getAsFunctionDecl();
29 }
30 
31 StringRef CheckerContext::getCalleeName(const FunctionDecl *FunDecl) const {
32  if (!FunDecl)
33  return StringRef();
34  IdentifierInfo *funI = FunDecl->getIdentifier();
35  if (!funI)
36  return StringRef();
37  return funI->getName();
38 }
39 
41  if (isa<ObjCMethodDecl, CXXMethodDecl>(D))
42  return "method";
43  if (isa<BlockDecl>(D))
44  return "anonymous block";
45  return "function";
46 }
47 
49  StringRef Name) {
50  // To avoid false positives (Ex: finding user defined functions with
51  // similar names), only perform fuzzy name matching when it's a builtin.
52  // Using a string compare is slow, we might want to switch on BuiltinID here.
53  unsigned BId = FD->getBuiltinID();
54  if (BId != 0) {
55  if (Name.empty())
56  return true;
57  StringRef BName = FD->getASTContext().BuiltinInfo.getName(BId);
58  size_t start = BName.find(Name);
59  if (start != StringRef::npos) {
60  // Accept exact match.
61  if (BName.size() == Name.size())
62  return true;
63 
64  // v-- match starts here
65  // ...xxxxx...
66  // _xxxxx_
67  // ^ ^ lookbehind and lookahead characters
68 
69  const auto MatchPredecessor = [=]() -> bool {
70  return start <= 0 || !llvm::isAlpha(BName[start - 1]);
71  };
72  const auto MatchSuccessor = [=]() -> bool {
73  std::size_t LookbehindPlace = start + Name.size();
74  return LookbehindPlace >= BName.size() ||
75  !llvm::isAlpha(BName[LookbehindPlace]);
76  };
77 
78  if (MatchPredecessor() && MatchSuccessor())
79  return true;
80  }
81  }
82 
83  const IdentifierInfo *II = FD->getIdentifier();
84  // If this is a special C++ name without IdentifierInfo, it can't be a
85  // C library function.
86  if (!II)
87  return false;
88 
89  // Look through 'extern "C"' and anything similar invented in the future.
90  // If this function is not in TU directly, it is not a C library function.
92  return false;
93 
94  // If this function is not externally visible, it is not a C library function.
95  // Note that we make an exception for inline functions, which may be
96  // declared in header files without external linkage.
97  if (!FD->isInlined() && !FD->isExternallyVisible())
98  return false;
99 
100  if (Name.empty())
101  return true;
102 
103  StringRef FName = II->getName();
104  if (FName.equals(Name))
105  return true;
106 
107  if (FName.startswith("__inline") && FName.contains(Name))
108  return true;
109 
110  if (FName.startswith("__") && FName.endswith("_chk") && FName.contains(Name))
111  return true;
112 
113  return false;
114 }
115 
117  if (Loc.isMacroID())
119  getLangOpts());
120  SmallString<16> buf;
122 }
123 
124 /// Evaluate comparison and return true if it's known that condition is true
125 static bool evalComparison(SVal LHSVal, BinaryOperatorKind ComparisonOp,
126  SVal RHSVal, ProgramStateRef State) {
127  if (LHSVal.isUnknownOrUndef())
128  return false;
129  ProgramStateManager &Mgr = State->getStateManager();
130  if (!LHSVal.getAs<NonLoc>()) {
131  LHSVal = Mgr.getStoreManager().getBinding(State->getStore(),
132  LHSVal.castAs<Loc>());
133  if (LHSVal.isUnknownOrUndef() || !LHSVal.getAs<NonLoc>())
134  return false;
135  }
136 
137  SValBuilder &Bldr = Mgr.getSValBuilder();
138  SVal Eval = Bldr.evalBinOp(State, ComparisonOp, LHSVal, RHSVal,
139  Bldr.getConditionType());
140  if (Eval.isUnknownOrUndef())
141  return false;
142  ProgramStateRef StTrue, StFalse;
143  std::tie(StTrue, StFalse) = State->assume(Eval.castAs<DefinedSVal>());
144  return StTrue && !StFalse;
145 }
146 
147 bool CheckerContext::isGreaterOrEqual(const Expr *E, unsigned long long Val) {
148  DefinedSVal V = getSValBuilder().makeIntVal(Val, getASTContext().LongLongTy);
149  return evalComparison(getSVal(E), BO_GE, V, getState());
150 }
151 
153  DefinedSVal V = getSValBuilder().makeIntVal(0, false);
154  return evalComparison(getSVal(E), BO_LT, V, getState());
155 }
Builtins.h
clang::Decl::getASTContext
ASTContext & getASTContext() const LLVM_READONLY
Definition: DeclBase.cpp:414
clang::ento::SVal::getAsFunctionDecl
const FunctionDecl * getAsFunctionDecl() const
getAsFunctionDecl - If this SVal is a MemRegionVal and wraps a CodeTextRegion wrapping a FunctionDecl...
Definition: SVals.cpp:65
clang::ento::CheckerContext::getDeclDescription
StringRef getDeclDescription(const Decl *D)
Returns the word that should be used to refer to the declaration in the report.
Definition: CheckerContext.cpp:40
clang::NamedDecl::isExternallyVisible
bool isExternallyVisible() const
Definition: Decl.h:405
clang::Lexer::getSpelling
static unsigned getSpelling(const Token &Tok, const char *&Buffer, const SourceManager &SourceMgr, const LangOptions &LangOpts, bool *Invalid=nullptr)
getSpelling - This method is used to get the spelling of a token into a preallocated buffer,...
Definition: Lexer.cpp:405
clang::SourceLocation
Encodes a location in the source.
Definition: SourceLocation.h:86
clang::ASTContext::BuiltinInfo
Builtin::Context & BuiltinInfo
Definition: ASTContext.h:657
clang::ento::ProgramStateRef
IntrusiveRefCntPtr< const ProgramState > ProgramStateRef
Definition: ProgramState_Fwd.h:37
clang::ento::CheckerContext::getCalleeDecl
const FunctionDecl * getCalleeDecl(const CallExpr *CE) const
Get the declaration of the called function (path-sensitive).
Definition: CheckerContext.cpp:21
clang::ento::CheckerContext::isGreaterOrEqual
bool isGreaterOrEqual(const Expr *E, unsigned long long Val)
Returns true if the value of E is greater than or equal to Val under unsigned comparison.
Definition: CheckerContext.cpp:147
clang::ento::CheckerContext::getState
const ProgramStateRef & getState() const
Definition: CheckerContext.h:71
clang::FunctionDecl::isInlined
bool isInlined() const
Determine whether this function should be inlined, because it is either marked "inline" or "constexpr...
Definition: Decl.h:2633
size_t
__SIZE_TYPE__ size_t
The unsigned integer type of the result of the sizeof operator.
Definition: opencl-c-base.h:117
clang::CallExpr::getCallee
Expr * getCallee()
Definition: Expr.h:2951
V
#define V(N, I)
Definition: ASTContext.h:3176
clang::ento::DefinedSVal
Definition: SVals.h:268
clang::CallExpr::getDirectCallee
FunctionDecl * getDirectCallee()
If the callee is a FunctionDecl, return it. Otherwise return null.
Definition: Expr.h:2971
evalComparison
static bool evalComparison(SVal LHSVal, BinaryOperatorKind ComparisonOp, SVal RHSVal, ProgramStateRef State)
Evaluate comparison and return true if it's known that condition is true.
Definition: CheckerContext.cpp:125
clang::ento::CheckerContext::getCalleeName
StringRef getCalleeName(const FunctionDecl *FunDecl) const
Get the name of the called function (path-sensitive).
Definition: CheckerContext.cpp:31
clang::DeclContext::isTranslationUnit
bool isTranslationUnit() const
Definition: DeclBase.h:1951
llvm::SmallString< 16 >
clang::ento::CheckerContext::getMacroNameOrSpelling
StringRef getMacroNameOrSpelling(SourceLocation &Loc)
Depending on wither the location corresponds to a macro, return either the macro name or the token sp...
Definition: CheckerContext.cpp:116
clang::Lexer::getImmediateMacroName
static StringRef getImmediateMacroName(SourceLocation Loc, const SourceManager &SM, const LangOptions &LangOpts)
Retrieve the name of the immediate macro expansion.
Definition: Lexer.cpp:998
clang::ento::CheckerContext::getSourceManager
const SourceManager & getSourceManager()
Definition: CheckerContext.h:108
clang::ento::CheckerContext::getLangOpts
const LangOptions & getLangOpts() const
Definition: CheckerContext.h:89
clang::ento::Loc
Definition: SVals.h:326
clang::ento::CheckerContext::getSValBuilder
SValBuilder & getSValBuilder()
Definition: CheckerContext.h:114
clang::DeclContext::getRedeclContext
DeclContext * getRedeclContext()
getRedeclContext - Retrieve the context in which an entity conflicts with other entities of the same ...
Definition: DeclBase.cpp:1793
clang::ento::CheckerContext::getASTContext
ASTContext & getASTContext()
Definition: CheckerContext.h:83
clang::NamedDecl::getIdentifier
IdentifierInfo * getIdentifier() const
Get the identifier that names this declaration, if there is one.
Definition: Decl.h:268
clang::Builtin::Context::getName
const char * getName(unsigned ID) const
Return the identifier name for the specified builtin, e.g.
Definition: Builtins.h:88
Lexer.h
clang::Decl
Decl - This represents one declaration (or definition), e.g.
Definition: DeclBase.h:83
clang::ento::SValBuilder::makeIntVal
nonloc::ConcreteInt makeIntVal(const IntegerLiteral *integer)
Definition: SValBuilder.h:300
State
LineState State
Definition: UnwrappedLineFormatter.cpp:1089
clang::BinaryOperatorKind
BinaryOperatorKind
Definition: OperationKinds.h:25
clang::IdentifierInfo
One of these records is kept for each identifier that is lexed.
Definition: IdentifierTable.h:84
clang::ento::CheckerContext::isCLibraryFunction
static bool isCLibraryFunction(const FunctionDecl *FD, StringRef Name=StringRef())
Returns true if the callee is an externally-visible function in the top-level namespace,...
Definition: CheckerContext.cpp:48
CheckerContext.h
clang::IdentifierInfo::getName
StringRef getName() const
Return the actual identifier string.
Definition: IdentifierTable.h:195
clang::ento::CheckerContext::isNegative
bool isNegative(const Expr *E)
Returns true if the value of E is negative.
Definition: CheckerContext.cpp:152
clang
Definition: CalledOnceCheck.h:17
clang::ento::ExplodedNode::getSVal
SVal getSVal(const Stmt *S) const
Get the value of an arbitrary expression at this node.
Definition: ExplodedGraph.h:175
clang::ento::SVal
SVal - This represents a symbolic expression, which can be either an L-value or an R-value.
Definition: SVals.h:74
clang::FunctionDecl::getBuiltinID
unsigned getBuiltinID(bool ConsiderWrapperFunctions=false) const
Returns a value indicating whether this function corresponds to a builtin function.
Definition: Decl.cpp:3382
clang::Expr
This represents one expression.
Definition: Expr.h:109
clang::ento::CheckerContext::getSVal
SVal getSVal(const Stmt *S) const
Get the value of arbitrary expressions at this point in the path.
Definition: CheckerContext.h:148
clang::FunctionDecl
Represents a function declaration or definition.
Definition: Decl.h:1872
clang::CallExpr
CallExpr - Represents a function call (C99 6.5.2.2, C++ [expr.call]).
Definition: Expr.h:2801
clang::Decl::getDeclContext
DeclContext * getDeclContext()
Definition: DeclBase.h:434