173
|
1 // RUN: %clang_analyze_cc1 -triple i386-apple-darwin10 -verify %s \
|
|
2 // RUN: -analyzer-checker=core.builtin \
|
|
3 // RUN: -analyzer-checker=debug.ExprInspection \
|
|
4 // RUN: -analyzer-checker=unix.cstring \
|
|
5 // RUN: -analyzer-config display-checker-name=false
|
150
|
6
|
|
7 typedef unsigned long size_t;
|
|
8
|
|
9 struct S {
|
|
10 struct S3 {
|
|
11 int y[10];
|
|
12 };
|
|
13 struct S2 : S3 {
|
|
14 int *x;
|
|
15 } s2[10];
|
|
16 int z;
|
|
17 };
|
|
18
|
|
19
|
|
20 void clang_analyzer_explain(int);
|
|
21 void clang_analyzer_explain(void *);
|
|
22 void clang_analyzer_explain(S);
|
|
23
|
|
24 size_t clang_analyzer_getExtent(void *);
|
|
25
|
|
26 size_t strlen(const char *);
|
|
27
|
|
28 int conjure();
|
|
29 S conjure_S();
|
|
30
|
|
31 int glob;
|
|
32 static int stat_glob;
|
|
33 void *glob_ptr;
|
|
34
|
|
35 // Test strings are regex'ed because we need to match exact string
|
|
36 // rather than a substring.
|
|
37
|
|
38 void test_1(int param, void *ptr) {
|
|
39 clang_analyzer_explain(&glob); // expected-warning-re{{{{^pointer to global variable 'glob'$}}}}
|
|
40 clang_analyzer_explain(param); // expected-warning-re{{{{^argument 'param'$}}}}
|
|
41 clang_analyzer_explain(ptr); // expected-warning-re{{{{^argument 'ptr'$}}}}
|
|
42 if (param == 42)
|
|
43 clang_analyzer_explain(param); // expected-warning-re{{{{^signed 32-bit integer '42'$}}}}
|
|
44 }
|
|
45
|
|
46 void test_2(char *ptr, int ext) {
|
|
47 clang_analyzer_explain((void *) "asdf"); // expected-warning-re{{{{^pointer to element of type 'char' with index 0 of string literal "asdf"$}}}}
|
|
48 clang_analyzer_explain(strlen(ptr)); // expected-warning-re{{{{^metadata of type 'unsigned long' tied to pointee of argument 'ptr'$}}}}
|
|
49 clang_analyzer_explain(conjure()); // expected-warning-re{{{{^symbol of type 'int' conjured at statement 'conjure\(\)'$}}}}
|
|
50 clang_analyzer_explain(glob); // expected-warning-re{{{{^value derived from \(symbol of type 'int' conjured at statement 'conjure\(\)'\) for global variable 'glob'$}}}}
|
|
51 clang_analyzer_explain(glob_ptr); // expected-warning-re{{{{^value derived from \(symbol of type 'int' conjured at statement 'conjure\(\)'\) for global variable 'glob_ptr'$}}}}
|
|
52 clang_analyzer_explain(clang_analyzer_getExtent(ptr)); // expected-warning-re{{{{^extent of pointee of argument 'ptr'$}}}}
|
|
53 int *x = new int[ext];
|
|
54 clang_analyzer_explain(x); // expected-warning-re{{{{^pointer to element of type 'int' with index 0 of heap segment that starts at symbol of type 'int \*' conjured at statement 'new int \[ext\]'$}}}}
|
|
55 // Sic! What gets computed is the extent of the element-region.
|
|
56 clang_analyzer_explain(clang_analyzer_getExtent(x)); // expected-warning-re{{{{^signed 32-bit integer '4'$}}}}
|
|
57 delete[] x;
|
|
58 }
|
|
59
|
|
60 void test_3(S s) {
|
|
61 clang_analyzer_explain(&s); // expected-warning-re{{{{^pointer to parameter 's'$}}}}
|
|
62 clang_analyzer_explain(s.z); // expected-warning-re{{{{^initial value of field 'z' of parameter 's'$}}}}
|
|
63 clang_analyzer_explain(&s.s2[5].y[3]); // expected-warning-re{{{{^pointer to element of type 'int' with index 3 of field 'y' of base object 'S::S3' inside element of type 'struct S::S2' with index 5 of field 's2' of parameter 's'$}}}}
|
|
64 if (!s.s2[7].x) {
|
|
65 clang_analyzer_explain(s.s2[7].x); // expected-warning-re{{{{^concrete memory address '0'$}}}}
|
|
66 // FIXME: we need to be explaining '1' rather than '0' here; not explainer bug.
|
|
67 clang_analyzer_explain(s.s2[7].x + 1); // expected-warning-re{{{{^concrete memory address '0'$}}}}
|
|
68 }
|
|
69 }
|
|
70
|
|
71 void test_4(int x, int y) {
|
|
72 int z;
|
|
73 static int stat;
|
|
74 clang_analyzer_explain(x + 1); // expected-warning-re{{{{^\(argument 'x'\) \+ 1$}}}}
|
|
75 clang_analyzer_explain(1 + y); // expected-warning-re{{{{^\(argument 'y'\) \+ 1$}}}}
|
|
76 clang_analyzer_explain(x + y); // expected-warning-re{{{{^\(argument 'x'\) \+ \(argument 'y'\)$}}}}
|
|
77 clang_analyzer_explain(z); // expected-warning-re{{{{^undefined value$}}}}
|
|
78 clang_analyzer_explain(&z); // expected-warning-re{{{{^pointer to local variable 'z'$}}}}
|
|
79 clang_analyzer_explain(stat); // expected-warning-re{{{{^signed 32-bit integer '0'$}}}}
|
|
80 clang_analyzer_explain(&stat); // expected-warning-re{{{{^pointer to static local variable 'stat'$}}}}
|
|
81 clang_analyzer_explain(stat_glob); // expected-warning-re{{{{^initial value of global variable 'stat_glob'$}}}}
|
|
82 clang_analyzer_explain(&stat_glob); // expected-warning-re{{{{^pointer to global variable 'stat_glob'$}}}}
|
|
83 clang_analyzer_explain((int[]){1, 2, 3}); // expected-warning-re{{{{^pointer to element of type 'int' with index 0 of temporary object constructed at statement '\(int \[3\]\)\{1, 2, 3\}'$}}}}
|
|
84 }
|
|
85
|
|
86 namespace {
|
|
87 class C {
|
|
88 int x[10];
|
|
89
|
|
90 public:
|
|
91 void test_5(int i) {
|
|
92 clang_analyzer_explain(this); // expected-warning-re{{{{^pointer to 'this' object$}}}}
|
|
93 clang_analyzer_explain(&x[i]); // expected-warning-re{{{{^pointer to element of type 'int' with index 'argument 'i'' of field 'x' of 'this' object$}}}}
|
|
94 clang_analyzer_explain(__builtin_alloca(i)); // expected-warning-re{{{{^pointer to region allocated by '__builtin_alloca\(i\)'$}}}}
|
|
95 }
|
|
96 };
|
|
97 } // end of anonymous namespace
|
|
98
|
|
99 void test_6() {
|
|
100 clang_analyzer_explain(conjure_S()); // expected-warning-re{{{{^lazily frozen compound value of temporary object constructed at statement 'conjure_S\(\)'$}}}}
|
|
101 clang_analyzer_explain(conjure_S().z); // expected-warning-re{{{{^value derived from \(symbol of type 'int' conjured at statement 'conjure_S\(\)'\) for field 'z' of temporary object constructed at statement 'conjure_S\(\)'$}}}}
|
|
102 }
|