clang  6.0.0svn
UndefinedAssignmentChecker.cpp
Go to the documentation of this file.
1 //===--- UndefinedAssignmentChecker.h ---------------------------*- C++ -*--==//
2 //
3 // The LLVM Compiler Infrastructure
4 //
5 // This file is distributed under the University of Illinois Open Source
6 // License. See LICENSE.TXT for details.
7 //
8 //===----------------------------------------------------------------------===//
9 //
10 // This defines UndefinedAssignmentChecker, a builtin check in ExprEngine that
11 // checks for assigning undefined values.
12 //
13 //===----------------------------------------------------------------------===//
14 
15 #include "ClangSACheckers.h"
20 
21 using namespace clang;
22 using namespace ento;
23 
24 namespace {
25 class UndefinedAssignmentChecker
26  : public Checker<check::Bind> {
27  mutable std::unique_ptr<BugType> BT;
28 
29 public:
30  void checkBind(SVal location, SVal val, const Stmt *S,
31  CheckerContext &C) const;
32 };
33 }
34 
35 void UndefinedAssignmentChecker::checkBind(SVal location, SVal val,
36  const Stmt *StoreE,
37  CheckerContext &C) const {
38  if (!val.isUndef())
39  return;
40 
41  // Do not report assignments of uninitialized values inside swap functions.
42  // This should allow to swap partially uninitialized structs
43  // (radar://14129997)
44  if (const FunctionDecl *EnclosingFunctionDecl =
45  dyn_cast<FunctionDecl>(C.getStackFrame()->getDecl()))
46  if (C.getCalleeName(EnclosingFunctionDecl) == "swap")
47  return;
48 
50 
51  if (!N)
52  return;
53 
54  const char *str = "Assigned value is garbage or undefined";
55 
56  if (!BT)
57  BT.reset(new BuiltinBug(this, str));
58 
59  // Generate a report for this bug.
60  const Expr *ex = nullptr;
61 
62  while (StoreE) {
63  if (const UnaryOperator *U = dyn_cast<UnaryOperator>(StoreE)) {
64  str = "The expression is an uninitialized value. "
65  "The computed value will also be garbage";
66 
67  ex = U->getSubExpr();
68  break;
69  }
70 
71  if (const BinaryOperator *B = dyn_cast<BinaryOperator>(StoreE)) {
72  if (B->isCompoundAssignmentOp()) {
74  if (state->getSVal(B->getLHS(), C.getLocationContext()).isUndef()) {
75  str = "The left expression of the compound assignment is an "
76  "uninitialized value. The computed value will also be garbage";
77  ex = B->getLHS();
78  break;
79  }
80  }
81 
82  ex = B->getRHS();
83  break;
84  }
85 
86  if (const DeclStmt *DS = dyn_cast<DeclStmt>(StoreE)) {
87  const VarDecl *VD = dyn_cast<VarDecl>(DS->getSingleDecl());
88  ex = VD->getInit();
89  }
90 
91  break;
92  }
93 
94  auto R = llvm::make_unique<BugReport>(*BT, str, N);
95  if (ex) {
96  R->addRange(ex->getSourceRange());
98  }
99  C.emitReport(std::move(R));
100 }
101 
102 void ento::registerUndefinedAssignmentChecker(CheckerManager &mgr) {
103  mgr.registerChecker<UndefinedAssignmentChecker>();
104 }
FunctionDecl - An instance of this class is created to represent a function declaration or definition...
Definition: Decl.h:1698
ExplodedNode * generateErrorNode(ProgramStateRef State=nullptr, const ProgramPointTag *Tag=nullptr)
Generate a transition to a node that will be used to report an error.
Stmt - This represents one statement.
Definition: Stmt.h:66
VarDecl - An instance of this class is created to represent a variable declaration or definition...
Definition: Decl.h:807
StringRef getCalleeName(const FunctionDecl *FunDecl) const
Get the name of the called function (path-sensitive).
i32 captured_struct **param SharedsTy A type which contains references the shared variables *param Shareds Context with the list of shared variables from the p *TaskFunction *param Data Additional data for task generation like final * state
A builtin binary operation expression such as "x + y" or "x <= y".
Definition: Expr.h:2985
Expr - This represents one expression.
Definition: Expr.h:106
UnaryOperator - This represents the unary-expression&#39;s (except sizeof and alignof), the postinc/postdec operators from postfix-expression, and various extensions.
Definition: Expr.h:1717
void emitReport(std::unique_ptr< BugReport > R)
Emit the diagnostics report.
CHECKER * registerChecker()
Used to register checkers.
DeclStmt - Adaptor class for mixing declarations with statements and expressions. ...
Definition: Stmt.h:487
SVal - This represents a symbolic expression, which can be either an L-value or an R-value...
Definition: SVals.h:63
Dataflow Directional Tag Classes.
const Expr * getInit() const
Definition: Decl.h:1213
const Decl * getDecl() const
const StackFrameContext * getStackFrame() const
const ProgramStateRef & getState() const
bool trackNullOrUndefValue(const ExplodedNode *N, const Stmt *S, BugReport &R, bool IsArg=false, bool EnableNullFPSuppression=true)
Attempts to add visitors to trace a null or undefined value back to its point of origin, whether it is a symbol constrained to null or an explicit assignment.
SourceRange getSourceRange() const LLVM_READONLY
SourceLocation tokens are not useful in isolation - they are low level value objects created/interpre...
Definition: Stmt.cpp:265
bool isUndef() const
Definition: SVals.h:129
const LocationContext * getLocationContext() const