21#include "llvm/ADT/SmallString.h"
22#include "llvm/Support/raw_ostream.h"
28class UndefResultChecker
29 :
public Checker< check::PostStmt<BinaryOperator> > {
31 mutable std::unique_ptr<BugType> BT;
41 if (!isa<ArraySubscriptExpr>(Ex))
57 std::tie(StInBound, StOutBound) = state->assumeInBoundDual(Idx, ElementCount);
58 return StOutBound && !StInBound;
62 return C.isGreaterOrEqual(
72 assert(LHS && RHS &&
"Values unknown, inconsistent state");
73 return (
unsigned)RHS->getZExtValue() > LHS->countl_zero();
78 if (
C.getSVal(B).isUndef()) {
84 dyn_cast<FunctionDecl>(
C.getStackFrame()->getDecl()))
85 if (
C.getCalleeName(EnclosingFunctionDecl) ==
"swap")
95 new BuiltinBug(
this,
"Result of operation is garbage or undefined"));
98 llvm::raw_svector_ostream
OS(sbuf);
99 const Expr *Ex =
nullptr;
102 if (
C.getSVal(B->
getLHS()).isUndef()) {
106 else if (
C.getSVal(B->
getRHS()).isUndef()) {
112 OS <<
"The " << (isLeft ?
"left" :
"right") <<
" operand of '"
114 <<
"' is a garbage value";
116 OS <<
" due to array index out of bounds";
119 if ((B->
getOpcode() == BinaryOperatorKind::BO_Shl ||
120 B->
getOpcode() == BinaryOperatorKind::BO_Shr) &&
122 OS <<
"The result of the "
123 << ((B->
getOpcode() == BinaryOperatorKind::BO_Shl) ?
"left"
125 <<
" shift is undefined because the right operand is negative";
127 }
else if ((B->
getOpcode() == BinaryOperatorKind::BO_Shl ||
128 B->
getOpcode() == BinaryOperatorKind::BO_Shr) &&
131 OS <<
"The result of the "
132 << ((B->
getOpcode() == BinaryOperatorKind::BO_Shl) ?
"left"
134 <<
" shift is undefined due to shifting by ";
138 const llvm::APSInt *I =
141 OS <<
"a value that is";
142 else if (I->isUnsigned())
143 OS <<
'\'' << I->getZExtValue() <<
"\', which is";
145 OS <<
'\'' << I->getSExtValue() <<
"\', which is";
147 OS <<
" greater or equal to the width of type '"
149 }
else if (B->
getOpcode() == BinaryOperatorKind::BO_Shl &&
151 OS <<
"The result of the left shift is undefined because the left "
152 "operand is negative";
154 }
else if (B->
getOpcode() == BinaryOperatorKind::BO_Shl &&
158 const llvm::APSInt *LHS =
160 const llvm::APSInt *RHS =
162 OS <<
"The result of the left shift is undefined due to shifting \'"
163 << LHS->getSExtValue() <<
"\' by \'" << RHS->getZExtValue()
164 <<
"\', which is unrepresentable in the unsigned version of "
168 OS <<
"The result of the '"
170 <<
"' expression is undefined";
173 auto report = std::make_unique<PathSensitiveBugReport>(*BT,
OS.str(), N);
181 C.emitReport(std::move(report));
189bool ento::shouldRegisterUndefResultChecker(
const CheckerManager &mgr) {
static bool isLeftShiftResultUnrepresentable(const BinaryOperator *B, CheckerContext &C)
static bool isArrayIndexOutOfBounds(CheckerContext &C, const Expr *Ex)
static bool isShiftOverflow(const BinaryOperator *B, CheckerContext &C)
A builtin binary operation expression such as "x + y" or "x <= y".
StringRef getOpcodeStr() const
This represents one expression.
Expr * IgnoreParenCasts() LLVM_READONLY
Skip past any parentheses and casts which might surround this expression until reaching a fixed point...
Represents a function declaration or definition.
SourceRange getSourceRange() const LLVM_READONLY
SourceLocation tokens are not useful in isolation - they are low level value objects created/interpre...
CHECKER * registerChecker(AT &&... Args)
Used to register checkers.
bool isValid() const =delete
ElementRegion is used to represent both array elements and casts.
QualType getValueType() const override
MemRegion - The root abstract class for all memory regions.
virtual const llvm::APSInt * getKnownValue(ProgramStateRef state, SVal val)=0
Evaluates a given SVal.
SVal - This represents a symbolic expression, which can be either an L-value or an R-value.
T castAs() const
Convert to the specified SVal type, asserting that this SVal is of the desired type.
LLVM_ATTRIBUTE_RETURNS_NONNULL const MemRegion * getSuperRegion() const
bool trackExpressionValue(const ExplodedNode *N, const Expr *E, PathSensitiveBugReport &R, TrackingOptions Opts={})
Attempts to add visitors to track expression value back to its point of origin.
DefinedOrUnknownSVal getDynamicElementCount(ProgramStateRef State, const MemRegion *MR, SValBuilder &SVB, QualType Ty)
@ C
Languages that the frontend can parse and compile.