Home | History | Annotate | Download | only in Analysis
      1 // RUN: %clang_cc1 -triple i386-apple-darwin10 -analyze -analyzer-checker=core.builtin,debug.ExprInspection,unix.cstring -verify %s
      2 
      3 typedef unsigned long size_t;
      4 
      5 struct S {
      6   struct S3 {
      7     int y[10];
      8   };
      9   struct S2 : S3 {
     10     int *x;
     11   } s2[10];
     12   int z;
     13 };
     14 
     15 
     16 void clang_analyzer_explain(int);
     17 void clang_analyzer_explain(void *);
     18 void clang_analyzer_explain(S);
     19 
     20 size_t clang_analyzer_getExtent(void *);
     21 
     22 size_t strlen(const char *);
     23 
     24 int conjure();
     25 S conjure_S();
     26 
     27 int glob;
     28 static int stat_glob;
     29 void *glob_ptr;
     30 
     31 // Test strings are regex'ed because we need to match exact string
     32 // rather than a substring.
     33 
     34 void test_1(int param, void *ptr) {
     35   clang_analyzer_explain(&glob); // expected-warning-re{{{{^pointer to global variable 'glob'$}}}}
     36   clang_analyzer_explain(param); // expected-warning-re{{{{^argument 'param'$}}}}
     37   clang_analyzer_explain(ptr); // expected-warning-re{{{{^argument 'ptr'$}}}}
     38   if (param == 42)
     39     clang_analyzer_explain(param); // expected-warning-re{{{{^signed 32-bit integer '42'$}}}}
     40 }
     41 
     42 void test_2(char *ptr, int ext) {
     43   clang_analyzer_explain((void *) "asdf"); // expected-warning-re{{{{^pointer to element of type 'char' with index 0 of string literal "asdf"$}}}}
     44   clang_analyzer_explain(strlen(ptr)); // expected-warning-re{{{{^metadata of type 'unsigned long' tied to pointee of argument 'ptr'$}}}}
     45   clang_analyzer_explain(conjure()); // expected-warning-re{{{{^symbol of type 'int' conjured at statement 'conjure\(\)'$}}}}
     46   clang_analyzer_explain(glob); // expected-warning-re{{{{^value derived from \(symbol of type 'int' conjured at statement 'conjure\(\)'\) for global variable 'glob'$}}}}
     47   clang_analyzer_explain(glob_ptr); // expected-warning-re{{{{^value derived from \(symbol of type 'int' conjured at statement 'conjure\(\)'\) for global variable 'glob_ptr'$}}}}
     48   clang_analyzer_explain(clang_analyzer_getExtent(ptr)); // expected-warning-re{{{{^extent of pointee of argument 'ptr'$}}}}
     49   int *x = new int[ext];
     50   clang_analyzer_explain(x); // expected-warning-re{{{{^pointer to element of type 'int' with index 0 of pointee of symbol of type 'int \*' conjured at statement 'new int \[ext\]'$}}}}
     51   // Sic! What gets computed is the extent of the element-region.
     52   clang_analyzer_explain(clang_analyzer_getExtent(x)); // expected-warning-re{{{{^signed 32-bit integer '4'$}}}}
     53   delete[] x;
     54 }
     55 
     56 void test_3(S s) {
     57   clang_analyzer_explain(&s); // expected-warning-re{{{{^pointer to parameter 's'$}}}}
     58   clang_analyzer_explain(s.z); // expected-warning-re{{{{^initial value of field 'z' of parameter 's'$}}}}
     59   clang_analyzer_explain(&s.s2[5].y[3]); // expected-warning-re{{{{^pointer to element of type 'int' with index 3 of field 'y' of base object 'S::S3' inside element of type 'struct S::S2' with index 5 of field 's2' of parameter 's'$}}}}
     60   if (!s.s2[7].x) {
     61     clang_analyzer_explain(s.s2[7].x); // expected-warning-re{{{{^concrete memory address '0'$}}}}
     62     // FIXME: we need to be explaining '1' rather than '0' here; not explainer bug.
     63     clang_analyzer_explain(s.s2[7].x + 1); // expected-warning-re{{{{^concrete memory address '0'$}}}}
     64   }
     65 }
     66 
     67 void test_4(int x, int y) {
     68   int z;
     69   static int stat;
     70   clang_analyzer_explain(x + 1); // expected-warning-re{{{{^\(argument 'x'\) \+ 1$}}}}
     71   clang_analyzer_explain(1 + y); // expected-warning-re{{{{^\(argument 'y'\) \+ 1$}}}}
     72   clang_analyzer_explain(x + y); // expected-warning-re{{{{^unknown value$}}}}
     73   clang_analyzer_explain(z); // expected-warning-re{{{{^undefined value$}}}}
     74   clang_analyzer_explain(&z); // expected-warning-re{{{{^pointer to local variable 'z'$}}}}
     75   clang_analyzer_explain(stat); // expected-warning-re{{{{^signed 32-bit integer '0'$}}}}
     76   clang_analyzer_explain(&stat); // expected-warning-re{{{{^pointer to static local variable 'stat'$}}}}
     77   clang_analyzer_explain(stat_glob); // expected-warning-re{{{{^initial value of global variable 'stat_glob'$}}}}
     78   clang_analyzer_explain(&stat_glob); // expected-warning-re{{{{^pointer to global variable 'stat_glob'$}}}}
     79   clang_analyzer_explain((int[]){1, 2, 3}); // expected-warning-re{{{{^pointer to element of type 'int' with index 0 of compound literal \(int \[3\]\)\{1, 2, 3\}$}}}}
     80 }
     81 
     82 namespace {
     83 class C {
     84   int x[10];
     85 
     86 public:
     87   void test_5(int i) {
     88     clang_analyzer_explain(this); // expected-warning-re{{{{^pointer to 'this' object$}}}}
     89     clang_analyzer_explain(&x[i]); // expected-warning-re{{{{^pointer to element of type 'int' with index 'argument 'i'' of field 'x' of 'this' object$}}}}
     90     clang_analyzer_explain(__builtin_alloca(i)); // expected-warning-re{{{{^pointer to region allocated by '__builtin_alloca\(i\)'$}}}}
     91   }
     92 };
     93 } // end of anonymous namespace
     94 
     95 void test_6() {
     96   clang_analyzer_explain(conjure_S()); // expected-warning-re{{{{^lazily frozen compound value of temporary object constructed at statement 'conjure_S\(\)'$}}}}
     97   clang_analyzer_explain(conjure_S().z); // expected-warning-re{{{{^value derived from \(symbol of type 'struct S' conjured at statement 'conjure_S\(\)'\) for field 'z' of temporary object constructed at statement 'conjure_S\(\)'$}}}}
     98 }
     99