39 SVal LeftV = State->getSVal(LHS, SF);
40 SVal RightV = State->getSVal(RHS, SF);
44 if (Op == BO_Assign) {
53 evalStore(Tmp2, B, LHS, N, State->BindExpr(B, SF, ExprVal), LeftV,
70 ConjureIfNeeded(RightV, LeftV, RHS->
getType());
71 ConjureIfNeeded(LeftV, RightV, LHS->
getType());
78 State = createTemporaryRegionIfNeeded(State, SF, LHS);
84 State = State->BindExpr(B, SF,
Result);
91 Tmp2.
insert(Engine.makePostStmtNode(B, State, N));
99 llvm_unreachable(
"Invalid opcode for compound assignment.");
100 case BO_MulAssign: Op = BO_Mul;
break;
101 case BO_DivAssign: Op = BO_Div;
break;
102 case BO_RemAssign: Op = BO_Rem;
break;
103 case BO_AddAssign: Op = BO_Add;
break;
104 case BO_SubAssign: Op = BO_Sub;
break;
105 case BO_ShlAssign: Op = BO_Shl;
break;
106 case BO_ShrAssign: Op = BO_Shr;
break;
107 case BO_AndAssign: Op = BO_And;
break;
108 case BO_XorAssign: Op = BO_Xor;
break;
109 case BO_OrAssign: Op = BO_Or;
break;
115 evalLoad(Tmp, B, LHS, N, State, LeftV);
118 State = N->getState();
119 SVal V = State->getSVal(LHS, SF);
129 V = svalBuilder.evalCast(
V, CLHSTy, LTy);
141 StoredInLeftV = svalBuilder.conjureSymbolVal(
145 Result = svalBuilder.evalCast(StoredInLeftV, CTy, LTy);
149 StoredInLeftV = svalBuilder.evalCast(
Result, LTy, CTy);
155 State = State->BindExpr(B, SF, LeftV);
157 State = State->BindExpr(B, SF,
Result);
159 evalStore(Tmp2, B, LHS, N, State, LeftV, StoredInLeftV);
182 dyn_cast_or_null<BlockDataRegion>(
V.getAsRegion())) {
184 auto ReferencedVars = BDR->referenced_vars();
187 for (
auto Var : ReferencedVars) {
188 const VarRegion *capturedR = Var.getCapturedRegion();
197 const Expr *copyExpr =
nullptr;
199 assert(CI->getVariable() == capturedR->
getDecl());
200 copyExpr = CI->getCopyExpr();
204 if (capturedR != originalR) {
208 originalV = State->getSVal(copyExpr, SF);
217 ExplodedNode *N = Engine.makeNodeWithBinding(Pred, BE,
V, State,
229 if (
T->isLValueReferenceType()) {
232 }
else if (
T->isRValueReferenceType()) {
237 SVal OrigV = state->getSVal(Ex, SF);
238 SVal SimplifiedOrigV = svalBuilder.simplifySVal(state, OrigV);
239 SVal V = svalBuilder.evalCast(SimplifiedOrigV,
T, ExTy);
241 if (CastE->
getCastKind() == CK_BooleanToSignedIntegral &&
V.isValid())
242 V = svalBuilder.evalMinus(
V.castAs<
NonLoc>());
244 state = state->BindExpr(CastE, SF,
V);
248 Dst.
insert(Engine.makePostStmtNode(CastE, state, Pred));
263 evalLoad(Dst, CastE, CastE, Node, State, State->getSVal(Ex, SF));
267 if (CastE->
getCastKind() == CK_LValueToRValueBitCast) {
275 evalLocation(DstEvalLoc, CastE, Ex, Node, State, State->getSVal(Ex, SF),
289 if (
const MemRegion *MR = State->getSVal(Ex, SF).getAsRegion()) {
290 SVal OrigV = State->getSVal(MR);
291 CastedV = svalBuilder.evalCast(svalBuilder.simplifySVal(State, OrigV),
294 Dst.
insert(Engine.makeNodeWithBinding(Node, CastE, CastedV));
303 if (
const ExplicitCastExpr *ExCast=dyn_cast_or_null<ExplicitCastExpr>(CastE))
304 T = ExCast->getTypeAsWritten();
311 case CK_LValueToRValue:
312 case CK_LValueToRValueBitCast:
313 llvm_unreachable(
"LValueToRValue casts handled earlier.");
319 case CK_ARCProduceObject:
320 case CK_ARCConsumeObject:
321 case CK_ARCReclaimReturnedObject:
322 case CK_ARCExtendBlockObject:
323 case CK_CopyAndAutoreleaseBlockObject:
327 case CK_AtomicToNonAtomic:
328 case CK_NonAtomicToAtomic:
331 case CK_ConstructorConversion:
332 case CK_UserDefinedConversion:
333 case CK_FunctionToPointerDecay:
334 case CK_BuiltinFnToFnPtr:
335 case CK_HLSLArrayRValue: {
339 SVal V = state->getSVal(Ex, SF);
340 Dst.
insert(Engine.makeNodeWithBinding(Pred, CastE,
V));
343 case CK_MemberPointerToBoolean:
344 case CK_PointerToBoolean: {
345 SVal V = state->getSVal(Ex, SF);
348 V = svalBuilder.makeTruthVal(!PTMSV->isNullMemberPointer(), ExTy);
349 if (
V.isUndef() || PTMSV) {
350 Dst.
insert(Engine.makeNodeWithBinding(Pred, CastE,
V));
358 case CK_ArrayToPointerDecay:
360 case CK_AddressSpaceConversion:
361 case CK_BooleanToSignedIntegral:
362 case CK_IntegralToPointer:
363 case CK_PointerToIntegral: {
364 SVal V = state->getSVal(Ex, SF);
373 case CK_IntegralToBoolean:
374 case CK_IntegralToFloating:
375 case CK_FloatingToIntegral:
376 case CK_FloatingToBoolean:
377 case CK_FloatingCast:
378 case CK_FloatingRealToComplex:
379 case CK_FloatingComplexToReal:
380 case CK_FloatingComplexToBoolean:
381 case CK_FloatingComplexCast:
382 case CK_FloatingComplexToIntegralComplex:
383 case CK_IntegralRealToComplex:
384 case CK_IntegralComplexToReal:
385 case CK_IntegralComplexToBoolean:
386 case CK_IntegralComplexCast:
387 case CK_IntegralComplexToFloatingComplex:
388 case CK_CPointerToObjCPointerCast:
389 case CK_BlockPointerToObjCPointerCast:
390 case CK_AnyPointerToBlockPointerCast:
391 case CK_ObjCObjectLValueCast:
392 case CK_ZeroToOCLOpaqueType:
393 case CK_IntToOCLSampler:
394 case CK_LValueBitCast:
395 case CK_FloatingToFixedPoint:
396 case CK_FixedPointToFloating:
397 case CK_FixedPointCast:
398 case CK_FixedPointToBoolean:
399 case CK_FixedPointToIntegral:
400 case CK_IntegralToFixedPoint: {
404 case CK_IntegralCast: {
406 SVal V = state->getSVal(Ex, SF);
407 if (AMgr.options.analyzerSymbolicIntegerCasts())
408 V = svalBuilder.evalCast(
V,
T, ExTy);
410 V = svalBuilder.evalIntegralCast(state,
V,
T, ExTy);
411 Dst.
insert(Engine.makeNodeWithBinding(Pred, CastE,
V));
414 case CK_DerivedToBase:
415 case CK_UncheckedDerivedToBase: {
417 SVal val = state->getSVal(Ex, SF);
419 Dst.
insert(Engine.makeNodeWithBinding(Pred, CastE, val));
424 SVal val = state->getSVal(Ex, SF);
435 if (std::optional<SVal>
V =
436 StateMgr.getStoreManager().evalBaseToDerived(val,
T)) {
442 if (
T->isReferenceType()) {
445 Engine.makePostStmtNode(CastE, state, Pred,
true);
449 state = state->BindExpr(CastE, SF,
450 svalBuilder.makeNullWithType(resultType));
458 state = state->BindExpr(CastE, SF, NewSym);
461 state = state->BindExpr(CastE, SF, val);
463 Dst.
insert(Engine.makePostStmtNode(CastE, state, Pred));
466 case CK_BaseToDerived: {
467 SVal val = state->getSVal(Ex, SF);
479 val = svalBuilder.conjureSymbolVal(
483 Dst.
insert(Engine.makeNodeWithBinding(Pred, CastE, val));
486 case CK_NullToPointer: {
487 SVal V = svalBuilder.makeNullWithType(CastE->
getType());
488 Dst.
insert(Engine.makeNodeWithBinding(Pred, CastE,
V));
491 case CK_NullToMemberPointer: {
492 SVal V = svalBuilder.getMemberPointer(
nullptr);
493 Dst.
insert(Engine.makeNodeWithBinding(Pred, CastE,
V));
496 case CK_DerivedToBaseMemberPointer:
497 case CK_BaseToDerivedMemberPointer:
498 case CK_ReinterpretMemberPointer: {
499 SVal V = state->getSVal(Ex, SF);
502 svalBuilder.makePointerToMember(
getBasicVals().accumCXXBase(
504 Dst.
insert(Engine.makeNodeWithBinding(Pred, CastE, CastedPTMSV));
514 case CK_HLSLElementwiseCast:
515 case CK_HLSLAggregateSplatCast:
516 case CK_HLSLMatrixTruncation:
517 case CK_HLSLVectorTruncation: {
521 SVal result = svalBuilder.conjureSymbolVal(
524 Dst.
insert(Engine.makeNodeWithBinding(Pred, CastE, result));
538 SVal V = State->getSVal(
CL->getInitializer(), SF);
544 Loc CLLoc = State->getLValue(
CL, SF);
545 State = State->bindLoc(CLLoc,
V, SF);
551 Dst.
insert(Engine.makeNodeWithBinding(Pred,
CL,
V, State));
585 if (
const auto *IL = dyn_cast<InitListExpr>(EI);
586 IL && IL->getNumInits() == 1)
590 if (
const auto *DR = dyn_cast<DeclRefExpr>(EI->IgnoreParenImpCasts())) {
614 SVal InitVal = state->getSVal(InitEx, SF);
618 state = finishObjectConstruction(state, DS, SF);
621 dstEvaluated.
insert(Engine.makePostStmtNode(DS, state, UpdatedN));
627 if (InitEx->isGLValue()) {
631 InitVal = svalBuilder.conjureSymbolVal(
636 evalBind(dstEvaluated, DS, UpdatedN, state->getLValue(VD, SF), InitVal,
641 dstEvaluated.
insert(Engine.makePostStmtNode(DS, state, N));
676 Dst.
insert(Engine.makePostStmtNode(B, state, Pred));
688 Dst.
insert(Engine.makePostStmtNode(B, state, Pred));
696 Dst.
insert(Engine.makePostStmtNode(B, state, Pred));
709 if (
const BinaryOperator *Term = cast_or_null<BinaryOperator>(
T.getStmt())) {
711 assert(Term->isLogicalOp());
715 X = svalBuilder.makeIntVal(constant, B->
getType());
721 assert(!SrcBlock->
empty());
733 svalBuilder.makeZeroVal(RHS->getType()), B->
getType());
736 Dst.
insert(Engine.makeNodeWithBinding(Pred, B,
X));
753 auto Edge = N->getLocationAs<
BlockEdge>();
754 if (!Edge.has_value()) {
762 SrcBlock = Edge->getSrc();
763 SrcState = N->getState();
767 assert(SrcBlock &&
"missing function entry");
771 bool hasValue =
false;
774 for (
CFGElement CE : llvm::reverse(*SrcBlock)) {
775 if (std::optional<CFGStmt> CS = CE.getAs<
CFGStmt>()) {
782 L = OpaqueEx->getSourceExpr();
786 if (ValEx == L->
IgnoreParens() || ValEx == R->IgnoreParens()) {
788 V = SrcState->getSVal(ValEx, SF);
799 Dst.
insert(Engine.makeNodeWithBinding(Pred, Ex,
V));
806 APSInt IV =
Result.Val.getInt();
810 SVal X = svalBuilder.makeIntVal(IV);
811 Dst.
insert(Engine.makeNodeWithBinding(Pred, OOE,
X));
830 if (Ex->
getKind() == UETT_SizeOf || Ex->
getKind() == UETT_DataSizeOf ||
831 Ex->
getKind() == UETT_CountOf) {
832 if (!
T->isIncompleteType() && !
T->isConstantSizeType()) {
833 assert(
T->isVariableArrayType() &&
"Unknown non-constant-sized type.");
852 EvalSet.
insert(Engine.makeNodeWithBinding(N, Ex,
V));
867 auto MakeNodeForIdentityOp = [
U, &Engine = Engine](
ExplodedNode *N) {
868 const Expr *Ex =
U->getSubExpr()->IgnoreParens();
869 SVal SV = N->getState()->getSVal(Ex, N->getStackFrame());
870 return Engine.makeNodeWithBinding(N,
U, SV);
874 switch (
U->getOpcode()) {
882 const Expr *Ex =
U->getSubExpr()->IgnoreParens();
892 assert (
U->getType() == Ex->
getType());
893 EvalSet.
insert(MakeNodeForIdentityOp(N));
898 const Expr *Ex =
U->getSubExpr()->IgnoreParens();
907 EvalSet.
insert(Engine.makeNodeWithBinding(N,
U,
X));
913 const Expr *Ex =
U->getSubExpr()->IgnoreParens();
914 if (
const DeclRefExpr *DRE = dyn_cast<DeclRefExpr>(Ex)) {
919 EvalSet.
insert(Engine.makeNodeWithBinding(N,
U, SV));
924 EvalSet.
insert(MakeNodeForIdentityOp(N));
928 assert(!
U->isGLValue());
932 EvalSet.
insert(MakeNodeForIdentityOp(N));
939 assert (!
U->isGLValue());
940 const Expr *Ex =
U->getSubExpr()->IgnoreParens();
945 SVal V = state->getSVal(Ex, SF);
947 if (
V.isUnknownOrUndef()) {
948 EvalSet.
insert(Engine.makeNodeWithBinding(N,
U,
V));
952 switch (
U->getOpcode()) {
954 llvm_unreachable(
"Invalid Opcode.");
957 state = state->BindExpr(
958 U, SF, svalBuilder.evalComplement(
V.castAs<
NonLoc>()));
963 state->BindExpr(
U, SF, svalBuilder.evalMinus(
V.castAs<
NonLoc>()));
971 if (std::optional<Loc> LV =
V.getAs<
Loc>()) {
972 Loc X = svalBuilder.makeNullWithType(Ex->
getType());
982 state = state->BindExpr(
U, SF,
Result);
985 EvalSet.
insert(Engine.makePostStmtNode(
U, state, N));
998 assert (
U->isIncrementDecrementOp());
999 const Expr *Ex =
U->getSubExpr()->IgnoreParens();
1003 SVal loc = state->getSVal(Ex, SF);
1011 state = N->getState();
1012 assert(SF == N->getStackFrame());
1013 SVal V2_untested = state->getSVal(Ex, SF);
1017 state = state->BindExpr(
U, SF, V2_untested);
1034 if (
U->getType()->isAnyPointerType())
1035 RHS = svalBuilder.makeArrayIndex(1);
1036 else if (
U->getType()->isIntegralOrEnumerationType())
1037 RHS = svalBuilder.makeIntVal(1,
U->getType());
1045 if (
U->getType()->isBooleanType() &&
U->isIncrementOp())
1046 Result = svalBuilder.makeTruthVal(
true,
U->getType());
1062 svalBuilder.evalEQ(state, V2,svalBuilder.makeZeroVal(
U->getType()));
1064 if (!state->assume(Constraint,
true)) {
1067 Constraint = svalBuilder.evalEQ(state, SymVal,
1068 svalBuilder.makeZeroVal(
U->getType()));
1070 state = state->assume(Constraint,
false);
1079 state = state->BindExpr(
U, SF,
loc);
1081 state = state->BindExpr(
U, SF,
U->isPostfix() ? V2 :
Result);
Defines the C++ Decl subclasses, other than those for templates (found in DeclTemplate....
Defines the clang::Expr interface and subclasses for C++ expressions.
Holds long-lived AST nodes (such as types and decls) that can be referred to throughout the semantic ...
QualType getRValueReferenceType(QualType T) const
Return the uniqued reference to the type for an rvalue reference to the specified type.
static CanQualType getCanonicalType(QualType T)
Return the canonical (structural) type corresponding to the specified potentially non-canonical type ...
QualType getPointerType(QualType T) const
Return the uniqued reference to the type for a pointer to the specified type.
QualType getLValueReferenceType(QualType T, bool SpelledAsLValue=true) const
Return the uniqued reference to the type for an lvalue reference to the specified type.
A builtin binary operation expression such as "x + y" or "x <= y".
static bool isAdditiveOp(Opcode Opc)
static bool isAssignmentOp(Opcode Opc)
static bool isCompoundAssignmentOp(Opcode Opc)
BinaryOperatorKind Opcode
Represents a block literal declaration, which is like an unnamed FunctionDecl.
capture_const_iterator capture_begin() const
capture_const_iterator capture_end() const
const CFGBlock * getSrc() const
const CFGBlock * getDst() const
BlockExpr - Adaptor class for mixing a BlockDecl with expressions.
const BlockDecl * getBlockDecl() const
This class is used for builtin types like 'int'.
Represents a single basic block in a source-level CFG.
reverse_iterator rbegin()
CFGTerminator getTerminator() const
succ_iterator succ_begin()
unsigned succ_size() const
Represents a top-level expression in a basic block.
T castAs() const
Convert to the specified CFGElement type, asserting that this CFGElement is of the desired type.
const Stmt * getStmt() const
Represents CFGBlock terminator statement.
CastExpr - Base class for type casts, including both implicit casts (ImplicitCastExpr) and explicit c...
CastKind getCastKind() const
llvm::iterator_range< path_iterator > path()
Path through the class hierarchy taken by casts between base and derived classes (see implementation ...
CharUnits - This is an opaque type for sizes expressed in character units.
QuantityType getQuantity() const
getQuantity - Get the raw integer representation of this quantity.
static CharUnits fromQuantity(QuantityType Quantity)
fromQuantity - Construct a CharUnits quantity from a raw integer type.
CompoundLiteralExpr - [C99 6.5.2.5].
A reference to a declared variable, function, enum, etc.
DeclStmt - Adaptor class for mixing declarations with statements and expressions.
bool isSingleDecl() const
isSingleDecl - This method returns true if this DeclStmt refers to a single Decl.
decl_iterator decl_begin()
ExplicitCastExpr - An explicit cast written in the source code.
This represents one expression.
bool EvaluateAsInt(EvalResult &Result, const ASTContext &Ctx, SideEffectsKind AllowSideEffects=SE_NoSideEffects, bool InConstantContext=false) const
EvaluateAsInt - Return true if this is a constant which we can fold and convert to an integer,...
llvm::APSInt EvaluateKnownConstInt(const ASTContext &Ctx) const
EvaluateKnownConstInt - Call EvaluateAsRValue and return the folded integer.
Expr * IgnoreParens() LLVM_READONLY
Skip past any parentheses which might surround this expression until reaching a fixed point.
OffsetOfExpr - [C99 7.17] - This represents an expression of the form offsetof(record-type,...
OpaqueValueExpr - An expression referring to an opaque object of a fixed type and value class.
Represents a point after we ran remove dead bindings BEFORE processing the given statement.
T castAs() const
Convert to the specified ProgramPoint type, asserting that this ProgramPoint is of the desired type.
std::optional< T > getAs() const
Convert to the specified ProgramPoint type, returning std::nullopt if this ProgramPoint is not of the...
A (possibly-)qualified type.
It represents a stack frame of the call stack.
bool isSignedIntegerType() const
Return true if this is an integer type that is signed, according to C99 6.2.5p4 [char,...
bool isRValueReferenceType() const
const T * castAs() const
Member-template castAs<specific type>.
bool isReferenceType() const
bool isLValueReferenceType() const
bool isAnyComplexType() const
bool isVectorType() const
bool isFloatingType() const
UnaryExprOrTypeTraitExpr - expression with either a type or (unevaluated) expression operand.
QualType getTypeOfArgument() const
Gets the argument type, or the type of the argument expression, whichever is appropriate.
UnaryExprOrTypeTrait getKind() const
UnaryOperator - This represents the unary-expression's (except sizeof and alignof),...
Represent the declaration of a variable (in which case it is an lvalue) a function (in which case it ...
Represents a variable declaration or definition.
const Expr * getInit() const
BlockDataRegion - A region that represents a block instance.
void runCheckersForPostStmt(ExplodedNodeSet &Dst, const ExplodedNodeSet &Src, const Stmt *S, ExprEngine &Eng, bool wasInlined=false)
Run checkers for post-visiting Stmts.
void runCheckersForPreStmt(ExplodedNodeSet &Dst, const ExplodedNodeSet &Src, const Stmt *S, ExprEngine &Eng)
Run checkers for pre-visiting Stmts.
ExplodedNodeSet is a set of ExplodedNode * elements with the invariant that its elements cannot be nu...
void insert(ExplodedNode *N)
ImplTy::iterator iterator
const ProgramStateRef & getState() const
pred_iterator pred_begin()
ProgramPoint getLocation() const
getLocation - Returns the edge associated with the given node.
unsigned pred_size() const
const StackFrame * getStackFrame() const
void VisitBinaryOperator(const BinaryOperator *B, ExplodedNode *Pred, ExplodedNodeSet &Dst)
VisitBinaryOperator - Transfer function logic for binary operators.
void VisitGuardedExpr(const Expr *Ex, const Expr *L, const Expr *R, ExplodedNode *Pred, ExplodedNodeSet &Dst)
VisitGuardedExpr - Transfer function logic for ?, __builtin_choose.
ProgramStateRef handleLValueBitCast(ProgramStateRef state, const Expr *Ex, const StackFrame *SF, QualType T, QualType ExTy, const CastExpr *CastE, ExplodedNodeSet &Dst, ExplodedNode *Pred)
void VisitCast(const CastExpr *CastE, const Expr *Ex, ExplodedNode *Pred, ExplodedNodeSet &Dst)
VisitCast - Transfer function logic for all casts (implicit and explicit).
BasicValueFactory & getBasicVals()
void VisitLogicalExpr(const BinaryOperator *B, ExplodedNode *Pred, ExplodedNodeSet &Dst)
VisitLogicalExpr - Transfer function logic for '&&', '||'.
SVal evalBinOp(ProgramStateRef ST, BinaryOperator::Opcode Op, SVal LHS, SVal RHS, QualType T)
void VisitUnaryOperator(const UnaryOperator *B, ExplodedNode *Pred, ExplodedNodeSet &Dst)
VisitUnaryOperator - Transfer function logic for unary operators.
void VisitDeclStmt(const DeclStmt *DS, ExplodedNode *Pred, ExplodedNodeSet &Dst)
VisitDeclStmt - Transfer function logic for DeclStmts.
void VisitBlockExpr(const BlockExpr *BE, ExplodedNode *Pred, ExplodedNodeSet &Dst)
VisitBlockExpr - Transfer function logic for BlockExprs.
void VisitIncrementDecrementOperator(const UnaryOperator *U, ExplodedNode *Pred, ExplodedNodeSet &Dst)
Handle ++ and – (both pre- and post-increment).
ASTContext & getContext() const
getContext - Return the ASTContext associated with this analysis.
StoreManager & getStoreManager()
ConstCFGElementRef getCFGElementRef() const
void VisitUnaryExprOrTypeTraitExpr(const UnaryExprOrTypeTraitExpr *Ex, ExplodedNode *Pred, ExplodedNodeSet &Dst)
VisitUnaryExprOrTypeTraitExpr - Transfer function for sizeof.
ProgramStateRef escapeValues(ProgramStateRef State, ArrayRef< SVal > Vs, PointerEscapeKind K, const CallEvent *Call=nullptr) const
A simple wrapper when you only need to notify checkers of pointer-escape of some values.
CheckerManager & getCheckerManager() const
static std::optional< SVal > getObjectUnderConstruction(ProgramStateRef State, const ConstructionContextItem &Item, const StackFrame *SF)
By looking at a certain item that may be potentially part of an object's ConstructionContext,...
unsigned getNumVisitedCurrent() const
void VisitOffsetOfExpr(const OffsetOfExpr *Ex, ExplodedNode *Pred, ExplodedNodeSet &Dst)
VisitOffsetOfExpr - Transfer function for offsetof.
void evalLoad(ExplodedNodeSet &Dst, const Expr *NodeEx, const Expr *BoundExpr, ExplodedNode *Pred, ProgramStateRef St, SVal location, const ProgramPointTag *tag=nullptr, QualType LoadTy=QualType())
Simulate a read of the result of Ex.
void VisitCompoundLiteralExpr(const CompoundLiteralExpr *CL, ExplodedNode *Pred, ExplodedNodeSet &Dst)
VisitCompoundLiteralExpr - Transfer function logic for compound literals.
void evalStore(ExplodedNodeSet &Dst, const Expr *AssignE, const Expr *StoreE, ExplodedNode *Pred, ProgramStateRef St, SVal TargetLV, SVal Val, const ProgramPointTag *tag=nullptr)
evalStore - Handle the semantics of a store via an assignment.
static bool isLocType(QualType T)
MemRegion - The root abstract class for all memory regions.
SVal - This represents a symbolic expression, which can be either an L-value or an R-value.
bool isZeroConstant() const
bool isUnknownOrUndef() const
T castAs() const
Convert to the specified SVal type, asserting that this SVal is of the desired type.
SVal evalDerivedToBase(SVal Derived, const CastExpr *Cast)
Evaluates a chain of derived-to-base casts through the path specified in Cast.
std::optional< SVal > evalBaseToDerived(SVal Base, QualType DerivedPtrType)
Attempts to do a down cast.
TypedValueRegion - An abstract class representing regions having a typed value.
const VarDecl * getDecl() const override=0
Value representing integer constant.
Value representing pointer-to-member.
@ PSK_EscapeOther
The reason for pointer escape is unknown.
IntrusiveRefCntPtr< const ProgramState > ProgramStateRef
Top level wrappers for InstallAPI frontend operations.
CanQual< Type > CanQualType
Represents a canonical, potentially-qualified type.
bool isa(CodeGen::Address addr)
@ Result
The result type of a method or function.
const FunctionProtoType * T
U cast(CodeGen::Address addr)
@ Other
Other implicit parameter.
EvalResult is a struct with detailed info about an evaluated expression.