clang 24.0.0git
LifetimeSafety.h
Go to the documentation of this file.
1//===- LifetimeSafety.h - C++ Lifetime Safety Analysis -*----------- C++-*-===//
2//
3// Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
4// See https://llvm.org/LICENSE.txt for license information.
5// SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
6//
7//===----------------------------------------------------------------------===//
8//
9// This file defines the main entry point and orchestrator for the C++ Lifetime
10// Safety Analysis. It coordinates the entire analysis pipeline: fact
11// generation, loan propagation, live origins analysis, and enforcement of
12// lifetime safety policy.
13//
14// The analysis is based on the concepts of "origins" and "loans" to track
15// pointer lifetimes and detect issues like use-after-free and dangling
16// pointers. See the RFC for more details:
17// https://discourse.llvm.org/t/rfc-intra-procedural-lifetime-analysis-in-clang/86291
18//
19//===----------------------------------------------------------------------===//
20#ifndef LLVM_CLANG_ANALYSIS_ANALYSES_LIFETIMESAFETY_H
21#define LLVM_CLANG_ANALYSIS_ANALYSES_LIFETIMESAFETY_H
22
23#include "clang/AST/Decl.h"
31#include "llvm/ADT/PointerUnion.h"
32#include <cstddef>
33#include <memory>
34
35namespace clang::lifetimes {
36
38 /// Maximum number of CFG blocks to analyze. Functions with larger CFGs will
39 /// be skipped.
41
42 /// Whether to suggest lifetime annotations.
44
49};
50
51/// Enum to track functions visible across or within TU.
52enum class WarningScope {
53 CrossTU, // For warnings on declarations visible across Translation Units.
54 IntraTU // For warnings on functions local to a Translation Unit.
55};
56
57/// Abstract interface for operations requiring Sema access.
58///
59/// This class exists to break a circular dependency: the LifetimeSafety
60/// analysis target cannot directly depend on clangSema (which would create the
61/// cycle: clangSema -> clangAnalysis -> clangAnalysisLifetimeSafety ->
62/// clangSema).
63///
64/// Instead, this interface is implemented in AnalysisBasedWarnings.cpp (part of
65/// clangSema), allowing the analysis to report diagnostics and modify the AST
66/// through Sema without introducing a circular dependency.
68public:
70 virtual ~LifetimeSafetySemaHelper() = default;
71
72 virtual void reportUseAfterScope(const Expr *IssueExpr, const Expr *UseExpr,
73 const Expr *MovedExpr,
74 SourceLocation FreeLoc,
76
77 // TODO: Report where the object was destroyed when that happens before the
78 // return (inner scopes, temporaries).
79 virtual void reportUseAfterReturn(const Expr *IssueExpr,
80 const Expr *ReturnExpr,
81 const Expr *MovedExpr,
83
84 virtual void reportDanglingField(const Expr *IssueExpr,
85 const FieldDecl *Field,
86 const Expr *MovedExpr,
87 bool IsCapturedByLambda,
88 SourceLocation ExpiryLoc) {}
89
90 virtual void reportDanglingGlobal(const Expr *IssueExpr,
91 const VarDecl *DanglingGlobal,
92 const Expr *MovedExpr,
93 SourceLocation ExpiryLoc,
94 bool IsMain = false) {}
95
96 // Reports when a reference/iterator is used after the container operation
97 // that invalidated it.
98 virtual void
99 reportUseAfterInvalidation(const Expr *IssueExpr, const Expr *UseExpr,
100 const Expr *InvalidationExpr,
101 llvm::ArrayRef<const Expr *> ExprChain) {}
102 virtual void
103 reportUseAfterInvalidation(const ParmVarDecl *PVD, const Expr *UseExpr,
104 const Expr *InvalidationExpr,
105 llvm::ArrayRef<const Expr *> ExprChain) {}
106 virtual void reportInvalidatedField(const Expr *IssueExpr,
107 const FieldDecl *Field,
108 const Expr *InvalidationExpr) {}
109 virtual void reportInvalidatedField(const ParmVarDecl *PVD,
110 const FieldDecl *Field,
111 const Expr *InvalidationExpr) {}
112 virtual void reportInvalidatedGlobal(const Expr *IssueExpr,
113 const VarDecl *Global,
114 const Expr *InvalidationExpr) {}
115 virtual void reportInvalidatedGlobal(const ParmVarDecl *PVD,
116 const VarDecl *Global,
117 const Expr *InvalidationExpr) {}
118
120 llvm::PointerUnion<const Expr *, const FieldDecl *, const VarDecl *>;
121
122 // Suggests lifetime bound annotations for function parameters.
124 const ParmVarDecl *ParmToAnnotate,
126
127 // Reports misuse of [[clang::noescape]] when parameter escapes through return
128 virtual void reportNoescapeViolation(const ParmVarDecl *ParmWithNoescape,
129 const Expr *EscapeExpr) {}
130 // Reports misuse of [[clang::noescape]] when parameter escapes through field
131 virtual void reportNoescapeViolation(const ParmVarDecl *ParmWithNoescape,
132 const FieldDecl *EscapeField) {}
133 // Reports misuse of [[clang::noescape]] when parameter escapes through
134 // assignment to a global variable
135 virtual void reportNoescapeViolation(const ParmVarDecl *ParmWithNoescape,
136 const VarDecl *EscapeGlobal) {}
137
138 // Reports misuse of [[clang::lifetimebound]] when parameter doesn't escape
139 // through return.
140 virtual void
141 reportLifetimeboundViolation(const ParmVarDecl *ParmWithLifetimebound) {}
142
143 // Reports misuse of [[clang::lifetimebound]] when implicit this parameter
144 // doesn't escape through return.
145 virtual void
146 reportLifetimeboundViolation(const CXXMethodDecl *MDWithLifetimebound) {}
147
148 // Reports a member function definition that has [[clang::lifetimebound]] on
149 // the implicit this parameter when the canonical declaration does not.
151 const CXXMethodDecl *FDef,
152 const CXXMethodDecl *FDecl) {}
153
154 // Reports a function definition parameter that has [[clang::lifetimebound]]
155 // when the corresponding parameter in the canonical declaration.
157 const ParmVarDecl *PVDDef,
158 const ParmVarDecl *PVDDecl) {}
159
161
162 // Suggests lifetime bound annotations for implicit this.
164 const CXXMethodDecl *MD,
165 const Expr *EscapeExpr) {}
166
167 // Adds inferred lifetime bound attribute for implicit this to its
168 // TypeSourceInfo.
170};
171
172/// The main entry point for the analysis.
174 LifetimeSafetySemaHelper *SemaHelper,
175 const LifetimeSafetyOpts &Opts,
176 LifetimeSafetyStats &Stats, bool CollectStats);
177
178namespace internal {
179
180void collectLifetimeStats(AnalysisDeclContext &AC, OriginManager &OM,
181 LifetimeSafetyStats &Stats);
182
183/// An object to hold the factories for immutable collections, ensuring
184/// that all created states share the same underlying memory management.
186 OriginLoanMap::Factory OriginMapFactory;
187 LoanSet::Factory LoanSetFactory;
188 MovedLoansMap::Factory MovedLoansMapFactory;
189 LivenessMap::Factory LivenessMapFactory;
190};
191
192/// Running the lifetime safety analysis and querying its results. It
193/// encapsulates the various dataflow analyses.
195public:
197 LifetimeSafetySemaHelper *SemaHelper,
198 const LifetimeSafetyOpts &LSOpts);
199
200 void run();
201
202 /// \note These are provided only for testing purposes.
204 return *LoanPropagation;
205 }
206 LiveOriginsAnalysis &getLiveOrigins() const { return *LiveOrigins; }
207 FactManager &getFactManager() { return *FactMgr; }
208
209private:
211 LifetimeSafetySemaHelper *SemaHelper;
212 const LifetimeSafetyOpts LSOpts;
213 LifetimeFactory Factory;
214 std::unique_ptr<FactManager> FactMgr;
215 std::unique_ptr<LiveOriginsAnalysis> LiveOrigins;
216 std::unique_ptr<LoanPropagationAnalysis> LoanPropagation;
217 std::unique_ptr<MovedLoansAnalysis> MovedLoans;
218};
219} // namespace internal
220} // namespace clang::lifetimes
221
222#endif // LLVM_CLANG_ANALYSIS_ANALYSES_LIFETIMESAFETY_H
This file defines AnalysisDeclContext, a class that manages the analysis context data for context sen...
AnalysisDeclContext contains the context data for the function, method or block under analysis.
Represents a static or instance method of a struct/union/class.
Definition DeclCXX.h:2150
This represents one expression.
Definition Expr.h:113
Represents a member of a struct/union/class.
Definition Decl.h:3295
Represents a parameter to a function.
Definition Decl.h:1820
Scope - A scope is a transient data structure that is used while parsing the program.
Definition Scope.h:41
Encodes a location in the source.
Represents a variable declaration or definition.
Definition Decl.h:933
Abstract interface for operations requiring Sema access.
virtual void reportInapplicableLifetimebound(const ParmVarDecl *PVD)
virtual void reportDanglingGlobal(const Expr *IssueExpr, const VarDecl *DanglingGlobal, const Expr *MovedExpr, SourceLocation ExpiryLoc, bool IsMain=false)
virtual void reportUseAfterInvalidation(const Expr *IssueExpr, const Expr *UseExpr, const Expr *InvalidationExpr, llvm::ArrayRef< const Expr * > ExprChain)
llvm::PointerUnion< const Expr *, const FieldDecl *, const VarDecl * > EscapingTarget
virtual void reportUseAfterInvalidation(const ParmVarDecl *PVD, const Expr *UseExpr, const Expr *InvalidationExpr, llvm::ArrayRef< const Expr * > ExprChain)
virtual void suggestLifetimeboundToParmVar(WarningScope Scope, const ParmVarDecl *ParmToAnnotate, EscapingTarget Target)
virtual void reportInvalidatedField(const ParmVarDecl *PVD, const FieldDecl *Field, const Expr *InvalidationExpr)
virtual void reportMisplacedLifetimebound(WarningScope Scope, const ParmVarDecl *PVDDef, const ParmVarDecl *PVDDecl)
virtual void reportDanglingField(const Expr *IssueExpr, const FieldDecl *Field, const Expr *MovedExpr, bool IsCapturedByLambda, SourceLocation ExpiryLoc)
virtual void reportNoescapeViolation(const ParmVarDecl *ParmWithNoescape, const VarDecl *EscapeGlobal)
virtual void reportNoescapeViolation(const ParmVarDecl *ParmWithNoescape, const FieldDecl *EscapeField)
virtual void reportLifetimeboundViolation(const ParmVarDecl *ParmWithLifetimebound)
virtual void reportUseAfterScope(const Expr *IssueExpr, const Expr *UseExpr, const Expr *MovedExpr, SourceLocation FreeLoc, llvm::ArrayRef< const Expr * > ExprChain)
virtual void addLifetimeBoundToImplicitThis(const CXXMethodDecl *MD)
virtual void reportNoescapeViolation(const ParmVarDecl *ParmWithNoescape, const Expr *EscapeExpr)
virtual void reportMisplacedLifetimebound(WarningScope Scope, const CXXMethodDecl *FDef, const CXXMethodDecl *FDecl)
virtual void suggestLifetimeboundToImplicitThis(WarningScope Scope, const CXXMethodDecl *MD, const Expr *EscapeExpr)
virtual void reportLifetimeboundViolation(const CXXMethodDecl *MDWithLifetimebound)
virtual void reportInvalidatedGlobal(const ParmVarDecl *PVD, const VarDecl *Global, const Expr *InvalidationExpr)
virtual void reportInvalidatedGlobal(const Expr *IssueExpr, const VarDecl *Global, const Expr *InvalidationExpr)
virtual void reportInvalidatedField(const Expr *IssueExpr, const FieldDecl *Field, const Expr *InvalidationExpr)
virtual void reportUseAfterReturn(const Expr *IssueExpr, const Expr *ReturnExpr, const Expr *MovedExpr, llvm::ArrayRef< const Expr * > ExprChain)
LifetimeSafetyAnalysis(AnalysisDeclContext &AC, LifetimeSafetySemaHelper *SemaHelper, const LifetimeSafetyOpts &LSOpts)
LoanPropagationAnalysis & getLoanPropagation() const
void collectLifetimeStats(AnalysisDeclContext &AC, OriginManager &OM, LifetimeSafetyStats &Stats)
void runLifetimeSafetyAnalysis(AnalysisDeclContext &AC, LifetimeSafetySemaHelper *SemaHelper, const LifetimeSafetyOpts &Opts, LifetimeSafetyStats &Stats, bool CollectStats)
The main entry point for the analysis.
WarningScope
Enum to track functions visible across or within TU.
bool SuggestAnnotations
Whether to suggest lifetime annotations.
size_t MaxCFGBlocks
Maximum number of CFG blocks to analyze.
An object to hold the factories for immutable collections, ensuring that all created states share the...