clang  6.0.0svn
FixedAddressChecker.cpp
Go to the documentation of this file.
1 //=== FixedAddressChecker.cpp - Fixed address usage checker ----*- C++ -*--===//
2 //
3 // The LLVM Compiler Infrastructure
4 //
5 // This file is distributed under the University of Illinois Open Source
6 // License. See LICENSE.TXT for details.
7 //
8 //===----------------------------------------------------------------------===//
9 //
10 // This files defines FixedAddressChecker, a builtin checker that checks for
11 // assignment of a fixed address to a pointer.
12 // This check corresponds to CWE-587.
13 //
14 //===----------------------------------------------------------------------===//
15 
16 #include "ClangSACheckers.h"
21 
22 using namespace clang;
23 using namespace ento;
24 
25 namespace {
26 class FixedAddressChecker
27  : public Checker< check::PreStmt<BinaryOperator> > {
28  mutable std::unique_ptr<BuiltinBug> BT;
29 
30 public:
31  void checkPreStmt(const BinaryOperator *B, CheckerContext &C) const;
32 };
33 }
34 
35 void FixedAddressChecker::checkPreStmt(const BinaryOperator *B,
36  CheckerContext &C) const {
37  // Using a fixed address is not portable because that address will probably
38  // not be valid in all environments or platforms.
39 
40  if (B->getOpcode() != BO_Assign)
41  return;
42 
43  QualType T = B->getType();
44  if (!T->isPointerType())
45  return;
46 
48  SVal RV = state->getSVal(B->getRHS(), C.getLocationContext());
49 
50  if (!RV.isConstant() || RV.isZeroConstant())
51  return;
52 
54  if (!BT)
55  BT.reset(
56  new BuiltinBug(this, "Use fixed address",
57  "Using a fixed address is not portable because that "
58  "address will probably not be valid in all "
59  "environments or platforms."));
60  auto R = llvm::make_unique<BugReport>(*BT, BT->getDescription(), N);
61  R->addRange(B->getRHS()->getSourceRange());
62  C.emitReport(std::move(R));
63  }
64 }
65 
66 void ento::registerFixedAddressChecker(CheckerManager &mgr) {
67  mgr.registerChecker<FixedAddressChecker>();
68 }
A (possibly-)qualified type.
Definition: Type.h:653
Opcode getOpcode() const
Definition: Expr.h:3026
i32 captured_struct **param SharedsTy A type which contains references the shared variables *param Shareds Context with the list of shared variables from the p *TaskFunction *param Data Additional data for task generation like final * state
A builtin binary operation expression such as "x + y" or "x <= y".
Definition: Expr.h:2985
bool isConstant() const
Definition: SVals.cpp:207
const FunctionProtoType * T
QualType getType() const
Definition: Expr.h:128
ExplodedNode * generateNonFatalErrorNode(ProgramStateRef State=nullptr, const ProgramPointTag *Tag=nullptr)
Generate a transition to a node that will be used to report an error.
void emitReport(std::unique_ptr< BugReport > R)
Emit the diagnostics report.
CHECKER * registerChecker()
Used to register checkers.
SVal - This represents a symbolic expression, which can be either an L-value or an R-value...
Definition: SVals.h:63
Dataflow Directional Tag Classes.
bool isZeroConstant() const
Definition: SVals.cpp:219
const ProgramStateRef & getState() const
SourceRange getSourceRange() const LLVM_READONLY
SourceLocation tokens are not useful in isolation - they are low level value objects created/interpre...
Definition: Stmt.cpp:265
Expr * getRHS() const
Definition: Expr.h:3031
bool isPointerType() const
Definition: Type.h:5944
const LocationContext * getLocationContext() const