clang 24.0.0git
RawPtrRefCallArgsChecker.cpp
Go to the documentation of this file.
1//=======- RawPtrRefCallArgsChecker.cpp --------------------------*- C++ -*-==//
2//
3// Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
4// See https://llvm.org/LICENSE.txt for license information.
5// SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
6//
7//===----------------------------------------------------------------------===//
8
9#include "ASTUtils.h"
10#include "DiagOutputUtils.h"
11#include "PtrTypesSemantics.h"
13#include "clang/AST/Decl.h"
14#include "clang/AST/DeclCXX.h"
18#include "clang/Lex/Lexer.h"
23#include "llvm/Support/SaveAndRestore.h"
24#include <optional>
25
26using namespace clang;
27using namespace ento;
28
29namespace {
30
31class RawPtrRefCallArgsChecker
32 : public Checker<check::ASTDecl<TranslationUnitDecl>> {
33 BugType Bug;
34
35 TrivialFunctionAnalysis TFA;
36 EnsureFunctionAnalysis EFA;
37
38protected:
39 mutable BugReporter *BR;
40 const std::unique_ptr<PtrRefSafetyModel> Model;
41
42public:
43 RawPtrRefCallArgsChecker(const char *description,
44 std::unique_ptr<PtrRefSafetyModel> Model)
45 : Bug(this, description, "WebKit coding guidelines"),
46 Model(std::move(Model)) {}
47
48 void checkASTDecl(const TranslationUnitDecl *TUD, AnalysisManager &MGR,
49 BugReporter &BRArg) const {
50 BR = &BRArg;
51
52 // The calls to checkAST* from AnalysisConsumer don't
53 // visit template instantiations or lambda classes. We
54 // want to visit those, so we make our own RecursiveASTVisitor.
55 struct LocalVisitor : DynamicRecursiveASTVisitor {
56 const RawPtrRefCallArgsChecker *Checker;
57 Decl *DeclWithIssue{nullptr};
58
59 explicit LocalVisitor(const RawPtrRefCallArgsChecker *Checker)
60 : Checker(Checker) {
61 assert(Checker);
62 ShouldVisitTemplateInstantiations = true;
63 ShouldVisitImplicitCode = false;
64 }
65
66 bool TraverseClassTemplateDecl(ClassTemplateDecl *Decl) override {
68 return true;
69 return DynamicRecursiveASTVisitor::TraverseClassTemplateDecl(Decl);
70 }
71
72 bool TraverseDecl(Decl *D) override {
73 // A template pattern is checked through its instantiations, which are
74 // traversed from the TemplateDecl itself. In the pattern the callee of
75 // a call may still be an unresolved overload set and the type of an
76 // expression may still be dependent, neither of which can be reasoned
77 // about, so don't enter it at all.
78 if (D && !isa<TemplateDecl>(D) && D->isTemplated())
79 return true;
80 llvm::SaveAndRestore SavedDecl(DeclWithIssue);
81 if (D && (isa<FunctionDecl>(D) || isa<ObjCMethodDecl>(D)))
82 DeclWithIssue = D;
84 }
85
86 bool TraverseLambdaExpr(LambdaExpr *L) override {
88 if (!FTD)
89 return DynamicRecursiveASTVisitor::TraverseLambdaExpr(L);
90 // The body of a generic lambda is the pattern of its call operator,
91 // but it is reached from the LambdaExpr as a statement, so TraverseDecl
92 // never gets to skip it. Traverse the capture initializers, which are
93 // evaluated in the enclosing scope, and then the call operator itself,
94 // of which the pattern is skipped like any other and the instantiations
95 // are traversed. The initializers are traversed as expressions because
96 // the variable of an init capture is declared in the pattern.
97 for (unsigned I = 0, N = L->capture_size(); I != N; ++I) {
98 if (!(L->capture_begin() + I)->isExplicit())
99 continue;
100 if (auto *Init = L->capture_init_begin()[I];
101 Init && !TraverseStmt(Init))
102 return false;
103 }
104 return TraverseDecl(FTD);
105 }
106
107 bool VisitCallExpr(CallExpr *CE) override {
108 Checker->visitCallExpr(CE, DeclWithIssue);
109 return true;
110 }
111
112 bool VisitCXXConstructExpr(CXXConstructExpr *CE) override {
113 Checker->visitConstructExpr(CE, DeclWithIssue);
114 return true;
115 }
116
117 bool VisitTypedefDecl(TypedefDecl *TD) override {
118 if (auto *RTC = Checker->Model->retainTypeChecker())
119 RTC->visitTypedef(TD);
120 return true;
121 }
122
123 bool VisitObjCMessageExpr(ObjCMessageExpr *ObjCMsgExpr) override {
124 Checker->visitObjCMessageExpr(ObjCMsgExpr, DeclWithIssue);
125 return true;
126 }
127 };
128
129 LocalVisitor visitor(this);
130 if (auto *RTC = Model->retainTypeChecker())
131 RTC->visitTranslationUnitDecl(TUD);
132 visitor.TraverseDecl(const_cast<TranslationUnitDecl *>(TUD));
133 }
134
135 template <typename CallOrConstruct>
136 void visitCallOrConstructExpr(const CallOrConstruct *CE,
137 const FunctionDecl *F, const Decl *D) const {
138 if (F) {
139 unsigned ArgIdx = 0;
140 if (auto *MemberCallExpr = dyn_cast<CXXMemberCallExpr>(CE)) {
141 checkThisArg(F, MemberCallExpr, D);
142 } else if (isa<CXXOperatorCallExpr>(CE) && isa<CXXMethodDecl>(F)) {
143 // An overloaded member operator (e.g. lambda or std::function call
144 // operator) receives the receiver object as argument 0; start the
145 // parameter loop at 1 so we don't match it against the operator's
146 // first declared parameter.
147 auto *Receiver = CE->getArg(0);
148 checkThisArg(F, Receiver, Receiver->getType(), D);
149 ArgIdx = 1;
150 }
151
152 for (auto P = F->param_begin();
153 P < F->param_end() && ArgIdx < CE->getNumArgs(); ++P, ++ArgIdx) {
154 // TODO: attributes.
155 // if ((*P)->hasAttr<SafeRefCntblRawPtrAttr>())
156 // continue;
157 checkArg(F, CE->getArg(ArgIdx), (*P)->getType(), *P, D);
158 }
159 for (; ArgIdx < CE->getNumArgs(); ++ArgIdx) {
160 auto *Arg = CE->getArg(ArgIdx);
161 checkArg(F, Arg, Arg->getType(), nullptr, D);
162 }
163 }
164 }
165
166 void visitCallExpr(const CallExpr *CE, const Decl *D) const {
167 auto *Callee = CE->getDirectCallee();
168 if (shouldSkipCall(CE, Callee))
169 return;
170
171 if (Callee)
172 visitCallOrConstructExpr(CE, Callee, D);
173 else if (auto *Decl = CE->getCalleeDecl()) {
174 if (auto *FnType = Decl->getFunctionType()) {
175 if (auto *ProtoType = dyn_cast<FunctionProtoType>(FnType)) {
176 if (auto *MemberCallExpr = dyn_cast<CXXMemberCallExpr>(CE))
177 checkThisArg(nullptr, MemberCallExpr, D);
178 unsigned ArgIdx = 0;
179 for (auto PT = ProtoType->param_type_begin();
180 PT < ProtoType->param_type_end() && ArgIdx < CE->getNumArgs();
181 ++PT, ++ArgIdx)
182 checkArg(nullptr, CE->getArg(ArgIdx), *PT, nullptr, D);
183 for (; ArgIdx < CE->getNumArgs(); ++ArgIdx) {
184 auto *Arg = CE->getArg(ArgIdx);
185 checkArg(nullptr, Arg, Arg->getType(), nullptr, D);
186 }
187 }
188 }
189 }
190 }
191
192 void visitConstructExpr(const CXXConstructExpr *CE, const Decl *D) const {
193 auto *Constructor = CE->getConstructor();
194 if (shouldSkipCall(CE, Constructor))
195 return;
196 if (Constructor)
197 visitCallOrConstructExpr(CE, Constructor, D);
198 }
199
200 void visitObjCMessageExpr(const ObjCMessageExpr *E, const Decl *D) const {
201 if (BR->getSourceManager().isInSystemHeader(E->getExprLoc()))
202 return;
203
204 if (auto *Receiver = E->getInstanceReceiver()) {
205 std::optional<bool> IsUnsafe = Model->isUnsafePtr(E->getReceiverType());
206 const Expr *Origin = nullptr;
207 if (IsUnsafe && *IsUnsafe && !isPtrOriginSafe(Receiver, &Origin)) {
208 if (isAllocInit(E))
209 return;
210 reportBugOnReceiver(E->getMethodDecl(), Receiver, D, Origin);
211 }
212 }
213
214 auto *MethodDecl = E->getMethodDecl();
215 if (!MethodDecl)
216 return;
217
218 auto ArgCount = E->getNumArgs();
219 for (unsigned i = 0; i < ArgCount; ++i) {
220 auto *Arg = E->getArg(i);
221 bool hasParam = i < MethodDecl->param_size();
222 auto *Param = hasParam ? MethodDecl->getParamDecl(i) : nullptr;
223 auto ArgType = Arg->getType();
224 std::optional<bool> IsUnsafe = Model->isUnsafePtr(ArgType);
225 if (!IsUnsafe || !(*IsUnsafe))
226 continue;
227 const Expr *Origin = nullptr;
228 if (isPtrOriginSafe(Arg, &Origin))
229 continue;
230 reportBug(MethodDecl, Arg, Param, D, Origin);
231 }
232 }
233
234 static bool isRefCountingOperation(const CXXMethodDecl *MD) {
235 if (!MD)
236 return false;
237 auto name = safeGetName(MD);
238 return name == "ref" || name == "deref" ||
239 name == "incrementCheckedPtrCount" ||
240 name == "decrementCheckedPtrCount";
241 }
242
243 void checkThisArg(const NamedDecl *Callee,
244 const CXXMemberCallExpr *MemberCallExpr,
245 const Decl *DeclWithIssue) const {
246 if (isRefCountingOperation(MemberCallExpr->getMethodDecl()))
247 return;
248 checkThisArg(Callee, MemberCallExpr->getImplicitObjectArgument(),
249 MemberCallExpr->getObjectType(), DeclWithIssue);
250 }
251
252 void checkThisArg(const NamedDecl *Callee, const Expr *Receiver,
253 QualType ReceiverType, const Decl *DeclWithIssue) const {
254 // There is no ParmVarDecl for the implicit object parameter, so
255 // synthesize its type ('T&' per [over.match.funcs]) for the model to
256 // classify.
257 QualType ParamType = BR->getContext().getLValueReferenceType(
258 ReceiverType.getCanonicalType());
259 std::optional<bool> IsUnsafe = Model->isUnsafePtr(ParamType);
260 if (!IsUnsafe || !*IsUnsafe)
261 return;
262
263 const Expr *Origin = nullptr;
264 if (isPtrOriginSafe(Receiver, &Origin))
265 return;
266
267 reportBugOnThis(Callee, Receiver, DeclWithIssue, Origin);
268 }
269
270 void checkArg(const NamedDecl *Callee, const Expr *Arg, QualType ParamType,
271 const ParmVarDecl *Param, const Decl *DeclWithIssue) const {
272 std::optional<bool> IsUncounted = Model->isUnsafePtr(ParamType);
273 if (!IsUncounted || !(*IsUncounted))
274 return;
275
276 if (auto *DefaultArg = dyn_cast<CXXDefaultArgExpr>(Arg))
277 Arg = DefaultArg->getExpr();
278
279 const Expr *Origin = nullptr;
280 if (isPtrOriginSafe(Arg, &Origin))
281 return;
282
283 reportBug(Callee, Arg, Param, DeclWithIssue, Origin);
284 }
285
286 bool isPtrOriginSafe(const Expr *Arg, const Expr **Origin = nullptr) const {
287 return tryToFindPtrOrigin(
288 Arg, /*StopAtFirstRefCountedObj=*/true,
289 Model->checksForInteriorDestruction(),
290 [&](const clang::CXXRecordDecl *Record) {
291 return Model->isSafePtr(Record);
292 },
293 [&](const clang::QualType T) { return Model->isSafePtrType(T); },
294 [&](const clang::Decl *D) {
295 return Model->isSafeDecl(D, BR->getSourceManager());
296 },
297 // A temporary on the path to an argument's origin is safe: the full
298 // expression does not end until the call returns.
299 [&](const clang::Expr *ArgOrigin, bool IsSafe,
300 bool /*OriginDependsOnFullExpressionTemporary*/,
301 bool PtrIsLifetimeBoundToOrigin) {
302 if (IsSafe)
303 return true;
304 if (isNullPtr(ArgOrigin))
305 return true;
306 if (isa<IntegerLiteral>(ArgOrigin)) {
307 // FIXME: Check the value.
308 // foo(123)
309 return true;
310 }
311 if (isa<CXXBoolLiteralExpr>(ArgOrigin))
312 return true;
313 if (isa<ObjCStringLiteral>(ArgOrigin))
314 return true;
315 if (!Model->checksForInteriorDestruction() &&
316 originOutlivesCall(ArgOrigin))
317 return true;
318 if (EFA.isACallToEnsureFn(ArgOrigin)) {
319 auto *MCE = dyn_cast<CXXMemberCallExpr>(ArgOrigin);
320 assert(MCE);
321 if (isPtrOriginSafe(MCE->getImplicitObjectArgument()))
322 return true;
323 }
324 if (Model->isSafeExpr(ArgOrigin, PtrIsLifetimeBoundToOrigin))
325 return true;
326 if (Origin && !*Origin)
327 *Origin = ArgOrigin;
328 return false;
329 });
330 }
331
332 template <typename CallOrConstruct>
333 bool shouldSkipCall(const CallOrConstruct *CE,
334 const FunctionDecl *Callee) const {
335 if (BR->getSourceManager().isInSystemHeader(CE->getExprLoc()))
336 return true;
337
338 if (Callee && TFA.isTrivial(Callee))
339 return true;
340
341 if (isTrivialBuiltinFunction(Callee))
342 return true;
343
344 if (CE->getNumArgs() == 0)
345 return false;
346
347 // If an assignment is problematic we should warn about the sole existence
348 // of object on LHS.
349 if (auto *MemberOp = dyn_cast<CXXOperatorCallExpr>(CE)) {
350 // Note: assignemnt to built-in type isn't derived from CallExpr.
351 if (MemberOp->getOperator() ==
352 OO_Equal) { // Ignore assignment to Ref/RefPtr.
353 auto *callee = MemberOp->getDirectCallee();
354 if (auto *calleeDecl = dyn_cast<CXXMethodDecl>(callee)) {
355 if (const CXXRecordDecl *classDecl = calleeDecl->getParent()) {
356 if (Model->isSafePtr(classDecl))
357 return true;
358 }
359 }
360 }
361 if (MemberOp->isAssignmentOp())
362 return false;
363 }
364
365 if (!Callee)
366 return false;
367
368 if (isMethodOnWTFContainerType(Callee))
369 return true;
370
371 auto overloadedOperatorType = Callee->getOverloadedOperator();
372 if (overloadedOperatorType == OO_EqualEqual ||
373 overloadedOperatorType == OO_ExclaimEqual ||
374 overloadedOperatorType == OO_LessEqual ||
375 overloadedOperatorType == OO_GreaterEqual ||
376 overloadedOperatorType == OO_Spaceship ||
377 overloadedOperatorType == OO_AmpAmp ||
378 overloadedOperatorType == OO_PipePipe)
379 return true;
380
381 if (isCtorOfSafePtr(Callee) || isPtrConversion(Callee))
382 return true;
383
384 auto name = safeGetName(Callee);
385 if (name == "adoptRef" || name == "getPtr" || name == "WeakPtr" ||
386 name == "is" || name == "equal" || name == "hash" || name == "isType" ||
387 // FIXME: Most/all of these should be implemented via attributes.
388 name == "CFEqual" || name == "equalIgnoringASCIICase" ||
389 name == "equalIgnoringASCIICaseCommon" ||
390 name == "equalIgnoringNullity" || name == "toString")
391 return true;
392
393 return false;
394 }
395
396 bool isMethodOnWTFContainerType(const FunctionDecl *Decl) const {
398 return false;
399 auto *ClassDecl = Decl->getParent();
400 if (!ClassDecl || !isa<CXXRecordDecl>(ClassDecl))
401 return false;
402
403 auto *NsDecl = ClassDecl->getParent();
404 if (!NsDecl || !isa<NamespaceDecl>(NsDecl))
405 return false;
406
407 auto MethodName = safeGetName(Decl);
408 auto ClsNameStr = safeGetName(ClassDecl);
409 StringRef ClsName = ClsNameStr; // FIXME: Make safeGetName return StringRef.
410 auto NamespaceName = safeGetName(NsDecl);
411 // FIXME: These should be implemented via attributes.
412 return NamespaceName == "WTF" &&
413 (MethodName == "find" || MethodName == "findIf" ||
414 MethodName == "reverseFind" || MethodName == "reverseFindIf" ||
415 MethodName == "findIgnoringASCIICase" || MethodName == "get" ||
416 MethodName == "inlineGet" || MethodName == "contains" ||
417 MethodName == "containsIf" ||
418 MethodName == "containsIgnoringASCIICase" ||
419 MethodName == "startsWith" || MethodName == "endsWith" ||
420 MethodName == "startsWithIgnoringASCIICase" ||
421 MethodName == "endsWithIgnoringASCIICase" ||
422 MethodName == "substring") &&
423 (ClsName.ends_with("Vector") || ClsName.ends_with("Set") ||
424 ClsName.ends_with("Map") || ClsName == "StringImpl" ||
425 ClsName.ends_with("String"));
426 }
427
428 void reportBug(const NamedDecl *Callee, const Expr *CallArg,
429 const ParmVarDecl *Param, const Decl *DeclWithIssue,
430 const Expr *Origin) const {
431 assert(CallArg);
432
434 llvm::raw_svector_ostream Os(Buf);
435
436 const std::string paramName = safeGetName(Param);
437 Os << "Function argument";
438 printArgument(Os, CallArg);
439 if (!paramName.empty() || Callee)
440 Os << " (";
441 if (!paramName.empty()) {
442 Os << "parameter ";
443 printQuotedQualifiedName(Os, Param);
444 }
445 if (Callee) {
446 if (!paramName.empty())
447 Os << " ";
448 Os << "to ";
449 printQuotedQualifiedName(Os, Callee);
450 }
451 if (!paramName.empty() || Callee)
452 Os << ")";
453 Os << " is a ";
454 Model->describeHazard(Os, Origin, CallArg->getType());
455
456 bool usesDefaultArgValue = isa<CXXDefaultArgExpr>(CallArg) && Param;
457 const SourceLocation SrcLocToReport =
458 usesDefaultArgValue ? Param->getDefaultArg()->getExprLoc()
459 : CallArg->getSourceRange().getBegin();
460
461 PathDiagnosticLocation BSLoc(SrcLocToReport, BR->getSourceManager());
462 auto Report = std::make_unique<BasicBugReport>(Bug, Os.str(), BSLoc);
463 Report->addRange(CallArg->getSourceRange());
464 Report->setDeclWithIssue(DeclWithIssue);
465 BR->emitReport(std::move(Report));
466 }
467
468 void reportBugOnThis(const NamedDecl *Callee, const Expr *CallArg,
469 const Decl *DeclWithIssue, const Expr *Origin) const {
470 assert(CallArg);
471
472 const SourceLocation SrcLocToReport = CallArg->getSourceRange().getBegin();
473
475 llvm::raw_svector_ostream Os(Buf);
476 Os << "Function argument";
477 printArgument(Os, CallArg);
478 Os << " (parameter 'this'";
479 if (Callee) {
480 Os << " to ";
481 printQuotedQualifiedName(Os, Callee);
482 }
483 Os << ") is a ";
484 printHazardOrPointerTo(Os, CallArg, Origin);
485
486 PathDiagnosticLocation BSLoc(SrcLocToReport, BR->getSourceManager());
487 auto Report = std::make_unique<BasicBugReport>(Bug, Os.str(), BSLoc);
488 Report->addRange(CallArg->getSourceRange());
489 Report->setDeclWithIssue(DeclWithIssue);
490 BR->emitReport(std::move(Report));
491 }
492
493 void reportBugOnReceiver(const NamedDecl *Callee, const Expr *CallArg,
494 const Decl *DeclWithIssue,
495 const Expr *Origin) const {
496 assert(CallArg);
497
498 const SourceLocation SrcLocToReport = CallArg->getSourceRange().getBegin();
499
501 llvm::raw_svector_ostream Os(Buf);
502 Os << "Receiver";
503 printArgument(Os, CallArg);
504 if (Callee) {
505 Os << " (to ";
506 printQuotedQualifiedName(Os, Callee);
507 Os << ")";
508 }
509 Os << " is a ";
510 printHazardOrPointerTo(Os, CallArg, Origin);
511
512 PathDiagnosticLocation BSLoc(SrcLocToReport, BR->getSourceManager());
513 auto Report = std::make_unique<BasicBugReport>(Bug, Os.str(), BSLoc);
514 Report->addRange(CallArg->getSourceRange());
515 Report->setDeclWithIssue(DeclWithIssue);
516 BR->emitReport(std::move(Report));
517 }
518
519 void printHazardOrPointerTo(llvm::raw_svector_ostream &Os,
520 const Expr *CallArg, const Expr *Origin) const {
521 if (Model->checksForInteriorDestruction()) {
522 Model->describeHazard(Os, Origin, CallArg->getType());
523 return;
524 }
525 // 'this' is a pointer even when the call is spelled with '.', so don't
526 // infer pointer vs reference from the argument type.
527 Os << "raw pointer to " << Model->typeName() << " ";
528 printTypeName(Os, CallArg->getType());
529 }
530
531 void printArgument(llvm::raw_svector_ostream &Os, const Expr *Arg) const {
533 llvm::raw_svector_ostream ArgOs(Buf);
534 Arg->printPretty(ArgOs, /*Helper=*/nullptr,
536 StringRef ArgCode = ArgOs.str();
537 if (ArgCode.contains('\n'))
538 return;
539 ArgCode = ArgCode.take_front(50);
540 if (ArgCode.size() == 50)
541 Os << " '" << ArgCode << "...'";
542 else
543 Os << " '" << ArgCode << "'";
544 }
545};
546
547class UncountedCallArgsChecker final : public RawPtrRefCallArgsChecker {
548public:
549 UncountedCallArgsChecker()
550 : RawPtrRefCallArgsChecker("Uncounted call argument for a raw "
551 "pointer/reference parameter",
553};
554
555class UncheckedCallArgsChecker final : public RawPtrRefCallArgsChecker {
556public:
557 UncheckedCallArgsChecker()
558 : RawPtrRefCallArgsChecker("Unchecked call argument for a raw "
559 "pointer/reference parameter",
561};
562
563class UnretainedCallArgsChecker final : public RawPtrRefCallArgsChecker {
564public:
565 UnretainedCallArgsChecker()
566 : RawPtrRefCallArgsChecker("Unretained call argument for a raw "
567 "pointer/reference parameter",
569};
570
571class UnborrowedCallArgsChecker final : public RawPtrRefCallArgsChecker {
572public:
573 UnborrowedCallArgsChecker()
574 : RawPtrRefCallArgsChecker("Loan on a CanBorrow object not guarded by "
575 "a Borrow",
577};
578
579} // namespace
580
581void ento::registerUncountedCallArgsChecker(CheckerManager &Mgr) {
582 Mgr.registerChecker<UncountedCallArgsChecker>();
583}
584
585bool ento::shouldRegisterUncountedCallArgsChecker(const CheckerManager &) {
586 return true;
587}
588
589void ento::registerUncheckedCallArgsChecker(CheckerManager &Mgr) {
590 Mgr.registerChecker<UncheckedCallArgsChecker>();
591}
592
593bool ento::shouldRegisterUncheckedCallArgsChecker(const CheckerManager &) {
594 return true;
595}
596
597void ento::registerUnretainedCallArgsChecker(CheckerManager &Mgr) {
598 Mgr.registerChecker<UnretainedCallArgsChecker>();
599}
600
601bool ento::shouldRegisterUnretainedCallArgsChecker(const CheckerManager &) {
602 return true;
603}
604
605void ento::registerUnborrowedCallArgsChecker(CheckerManager &Mgr) {
606 Mgr.registerChecker<UnborrowedCallArgsChecker>();
607}
608
609bool ento::shouldRegisterUnborrowedCallArgsChecker(const CheckerManager &) {
610 return true;
611}
Defines the C++ Decl subclasses, other than those for templates (found in DeclTemplate....
llvm::MachO::Record Record
Definition MachO.h:31
Defines the clang::SourceLocation class and associated facilities.
static void printArgument(const TemplateArgument &A, const PrintingPolicy &PP, llvm::raw_ostream &OS, bool IncludeType)
const clang::PrintingPolicy & getPrintingPolicy() const
Definition ASTContext.h:903
CXXConstructorDecl * getConstructor() const
Get the constructor that this expression will (ultimately) call.
Definition ExprCXX.h:1616
CXXMethodDecl * getMethodDecl() const
Retrieve the declaration of the called method.
Definition ExprCXX.cpp:773
Expr * getImplicitObjectArgument() const
Retrieve the implicit object argument for the member call.
Definition ExprCXX.cpp:754
QualType getObjectType() const
Retrieve the type of the object argument.
Definition ExprCXX.cpp:766
Represents a C++ struct/union/class.
Definition DeclCXX.h:258
FunctionTemplateDecl * getDependentLambdaCallOperator() const
Retrieve the dependent lambda call operator of the closure type if this is a templated closure type.
Definition DeclCXX.cpp:1739
Expr * getArg(unsigned Arg)
getArg - Return the specified argument.
Definition Expr.h:3191
FunctionDecl * getDirectCallee()
If the callee is a FunctionDecl, return it. Otherwise return null.
Definition Expr.h:3170
unsigned getNumArgs() const
getNumArgs - Return the number of actual arguments to this call.
Definition Expr.h:3178
Decl * getCalleeDecl()
Definition Expr.h:3164
DeclContext * getParent()
getParent - Returns the containing DeclContext.
Definition DeclBase.h:2126
Decl - This represents one declaration (or definition), e.g.
Definition DeclBase.h:86
bool isTemplated() const
Determine whether this declaration is a templated entity (whether it is.
Definition DeclBase.cpp:308
virtual bool TraverseDecl(MaybeConst< Decl > *D)
This represents one expression.
Definition Expr.h:113
SourceLocation getExprLoc() const LLVM_READONLY
getExprLoc - Return the preferred location for the arrow when diagnosing a problem with a generic exp...
Definition Expr.cpp:283
QualType getType() const
Definition Expr.h:145
Represents a function declaration or definition.
Definition Decl.h:2059
param_iterator param_begin()
Definition Decl.h:2917
capture_iterator capture_begin() const
Retrieve an iterator pointing to the first lambda capture.
Definition ExprCXX.cpp:1395
unsigned capture_size() const
Determine the number of captures in this lambda.
Definition ExprCXX.h:2054
capture_init_iterator capture_init_begin()
Retrieve the first initialization argument for this lambda expression (which initializes the first ca...
Definition ExprCXX.h:2099
CXXRecordDecl * getLambdaClass() const
Retrieve the class that corresponds to the lambda.
Definition ExprCXX.cpp:1432
This represents a decl that may have a name.
Definition Decl.h:275
Expr * getArg(unsigned Arg)
getArg - Return the specified argument.
Definition ExprObjC.h:1435
Expr * getInstanceReceiver()
Returns the object expression (receiver) for an instance message, or null for a message that is not a...
Definition ExprObjC.h:1300
const ObjCMethodDecl * getMethodDecl() const
Definition ExprObjC.h:1396
QualType getReceiverType() const
Retrieve the receiver type to which this message is being directed.
Definition ExprObjC.cpp:308
unsigned getNumArgs() const
Return the number of actual arguments in this message, not counting the receiver.
Definition ExprObjC.h:1422
Represents a parameter to a function.
Definition Decl.h:1820
QualType getCanonicalType() const
Definition TypeBase.h:8498
Encodes a location in the source.
bool isInSystemHeader(SourceLocation Loc) const
Returns if a SourceLocation is in a system header.
SourceLocation getBegin() const
void printPretty(raw_ostream &OS, PrinterHelper *Helper, const PrintingPolicy &Policy, unsigned Indentation=0, StringRef NewlineSymbol="\n", const ASTContext *Context=nullptr) const
SourceRange getSourceRange() const LLVM_READONLY
SourceLocation tokens are not useful in isolation - they are low level value objects created/interpre...
Definition Stmt.cpp:343
bool isTrivial(const Decl *D, const Stmt **OffendingStmt=nullptr) const
const SourceManager & getSourceManager()
ASTContext & getContext()
virtual void emitReport(std::unique_ptr< BugReport > R)
Add the given report to the set of reports tracked by BugReporter.
CHECKER * registerChecker(AT &&...Args)
Register a single-part checker (derived from Checker): construct its singleton instance,...
Simple checker classes that implement one frontend (i.e.
Definition Checker.h:565
std::variant< struct RequiresDecl, struct HeaderDecl, struct UmbrellaDirDecl, struct ModuleDecl, struct ExcludeDecl, struct ExportDecl, struct ExportAsDecl, struct ExternModuleDecl, struct UseDecl, struct LinkDecl, struct ConfigMacrosDecl, struct ConflictDecl > Decl
All declarations that can appear in a module declaration.
RangeSelector name(std::string ID)
Given a node with a "name", (like NamedDecl, DeclRefExpr, CxxCtorInitializer, and TypeLoc) selects th...
Top level wrappers for InstallAPI frontend operations.
bool isCtorOfSafePtr(const clang::FunctionDecl *F)
bool isTrivialBuiltinFunction(const FunctionDecl *F)
bool isa(CodeGen::Address addr)
Definition Address.h:330
std::unique_ptr< PtrRefSafetyModel > makeBorrowSafetyModel()
if(T->getSizeExpr()) TRY_TO(TraverseStmt(const_cast< Expr * >(T -> getSizeExpr())))
bool isPtrConversion(const FunctionDecl *F)
std::unique_ptr< PtrRefSafetyModel > makeCheckedPtrSafetyModel()
void printQuotedQualifiedName(llvm::raw_ostream &Os, const NamedDeclDerivedT &D)
const FunctionProtoType * T
bool isSmartPtrClass(const std::string &Name)
bool originOutlivesCall(const Expr *E)
For E referring to a ref-countable/-counted pointer/reference we return whether the pointee outlives ...
Definition ASTUtils.cpp:481
void printTypeName(llvm::raw_ostream &Os, const QualType QT)
std::string safeGetName(const T *ASTNode)
Definition ASTUtils.h:109
DynamicRecursiveASTVisitorBase< false > DynamicRecursiveASTVisitor
std::unique_ptr< PtrRefSafetyModel > makeRefPtrSafetyModel()
bool tryToFindPtrOrigin(const Expr *E, bool StopAtFirstRefCountedObj, bool FollowLifetimeBound, std::function< bool(const clang::CXXRecordDecl *)> isSafePtr, std::function< bool(const clang::QualType)> isSafePtrType, std::function< bool(const clang::Decl *)> isSafeGlobalDecl, std::function< bool(const clang::Expr *, bool, bool, bool)> callback)
This function de-facto defines a set of transformations that we consider safe (in heuristical sense).
Definition ASTUtils.cpp:464
bool isAllocInit(const Expr *E, const Expr **InnerExpr)
Definition ASTUtils.cpp:575
std::unique_ptr< PtrRefSafetyModel > makeRetainPtrSafetyModel()