2009-11-03 14:59:59 +08:00
|
|
|
//=- NSErrorCheckerer.cpp - Coding conventions for uses of NSError -*- C++ -*-==//
|
2008-09-18 14:33:41 +08:00
|
|
|
//
|
|
|
|
// The LLVM Compiler Infrastructure
|
|
|
|
//
|
|
|
|
// This file is distributed under the University of Illinois Open Source
|
|
|
|
// License. See LICENSE.TXT for details.
|
|
|
|
//
|
|
|
|
//===----------------------------------------------------------------------===//
|
|
|
|
//
|
|
|
|
// This file defines a CheckNSError, a flow-insenstive check
|
|
|
|
// that determines if an Objective-C class interface correctly returns
|
|
|
|
// a non-void return type.
|
|
|
|
//
|
|
|
|
// File under feature request PR 2600.
|
|
|
|
//
|
|
|
|
//===----------------------------------------------------------------------===//
|
|
|
|
|
2010-12-24 03:38:26 +08:00
|
|
|
#include "clang/StaticAnalyzer/Checkers/LocalCheckers.h"
|
2011-02-10 09:03:03 +08:00
|
|
|
#include "clang/StaticAnalyzer/Core/BugReporter/BugType.h"
|
|
|
|
#include "clang/StaticAnalyzer/Core/PathSensitive/ExprEngine.h"
|
2010-12-24 03:38:26 +08:00
|
|
|
#include "clang/StaticAnalyzer/Checkers/DereferenceChecker.h"
|
2008-09-19 05:25:13 +08:00
|
|
|
#include "BasicObjCFoundationChecks.h"
|
2008-09-18 14:33:41 +08:00
|
|
|
#include "clang/AST/DeclObjC.h"
|
2008-09-19 05:25:13 +08:00
|
|
|
#include "clang/AST/Decl.h"
|
|
|
|
#include "llvm/ADT/SmallVector.h"
|
2008-09-18 14:33:41 +08:00
|
|
|
|
|
|
|
using namespace clang;
|
2010-12-23 15:20:52 +08:00
|
|
|
using namespace ento;
|
2008-09-18 14:33:41 +08:00
|
|
|
|
2008-09-19 05:25:13 +08:00
|
|
|
namespace {
|
2009-11-28 14:07:30 +08:00
|
|
|
class NSErrorChecker : public BugType {
|
2009-08-21 10:18:44 +08:00
|
|
|
const Decl &CodeDecl;
|
2009-02-05 07:49:09 +08:00
|
|
|
const bool isNSErrorWarning;
|
|
|
|
IdentifierInfo * const II;
|
2010-12-23 02:53:44 +08:00
|
|
|
ExprEngine &Eng;
|
2009-09-09 23:08:12 +08:00
|
|
|
|
2009-08-21 10:18:44 +08:00
|
|
|
void CheckSignature(const ObjCMethodDecl& MD, QualType& ResultTy,
|
2009-02-05 07:49:09 +08:00
|
|
|
llvm::SmallVectorImpl<VarDecl*>& ErrorParams);
|
2009-09-09 23:08:12 +08:00
|
|
|
|
2009-08-21 10:18:44 +08:00
|
|
|
void CheckSignature(const FunctionDecl& MD, QualType& ResultTy,
|
2009-02-05 07:49:09 +08:00
|
|
|
llvm::SmallVectorImpl<VarDecl*>& ErrorParams);
|
2008-09-19 05:25:13 +08:00
|
|
|
|
2009-02-05 07:49:09 +08:00
|
|
|
bool CheckNSErrorArgument(QualType ArgTy);
|
|
|
|
bool CheckCFErrorArgument(QualType ArgTy);
|
2009-09-09 23:08:12 +08:00
|
|
|
|
2009-08-22 06:28:32 +08:00
|
|
|
void CheckParamDeref(const VarDecl *V, const LocationContext *LC,
|
|
|
|
const GRState *state, BugReporter& BR);
|
2009-09-09 23:08:12 +08:00
|
|
|
|
2009-08-21 10:18:44 +08:00
|
|
|
void EmitRetTyWarning(BugReporter& BR, const Decl& CodeDecl);
|
2009-09-09 23:08:12 +08:00
|
|
|
|
2008-09-19 05:25:13 +08:00
|
|
|
public:
|
2010-12-23 02:53:44 +08:00
|
|
|
NSErrorChecker(const Decl &D, bool isNSError, ExprEngine& eng)
|
2009-09-09 23:08:12 +08:00
|
|
|
: BugType(isNSError ? "NSError** null dereference"
|
2009-08-21 10:18:44 +08:00
|
|
|
: "CFErrorRef* null dereference",
|
2009-09-01 08:17:12 +08:00
|
|
|
"Coding conventions (Apple)"),
|
2009-08-21 10:18:44 +08:00
|
|
|
CodeDecl(D),
|
2009-09-09 23:08:12 +08:00
|
|
|
isNSErrorWarning(isNSError),
|
2009-02-05 07:49:09 +08:00
|
|
|
II(&eng.getContext().Idents.get(isNSErrorWarning ? "NSError":"CFErrorRef")),
|
|
|
|
Eng(eng) {}
|
2009-09-09 23:08:12 +08:00
|
|
|
|
2009-02-05 07:49:09 +08:00
|
|
|
void FlushReports(BugReporter& BR);
|
2009-09-09 23:08:12 +08:00
|
|
|
};
|
|
|
|
|
2008-09-19 05:25:13 +08:00
|
|
|
} // end anonymous namespace
|
2008-09-18 14:33:41 +08:00
|
|
|
|
2010-12-23 15:20:52 +08:00
|
|
|
void ento::RegisterNSErrorChecks(BugReporter& BR, ExprEngine &Eng,
|
2009-08-21 10:18:44 +08:00
|
|
|
const Decl &D) {
|
2009-11-03 14:59:59 +08:00
|
|
|
BR.Register(new NSErrorChecker(D, true, Eng));
|
|
|
|
BR.Register(new NSErrorChecker(D, false, Eng));
|
2008-09-19 05:25:13 +08:00
|
|
|
}
|
2008-09-18 14:33:41 +08:00
|
|
|
|
2009-11-03 14:59:59 +08:00
|
|
|
void NSErrorChecker::FlushReports(BugReporter& BR) {
|
2008-09-19 05:25:13 +08:00
|
|
|
// Get the analysis engine and the exploded analysis graph.
|
2009-08-06 20:48:26 +08:00
|
|
|
ExplodedGraph& G = Eng.getGraph();
|
2009-09-09 23:08:12 +08:00
|
|
|
|
2008-09-19 05:25:13 +08:00
|
|
|
// Get the ASTContext, which is useful for querying type information.
|
|
|
|
ASTContext &Ctx = BR.getContext();
|
2008-09-18 14:33:41 +08:00
|
|
|
|
2008-09-19 05:25:13 +08:00
|
|
|
QualType ResultTy;
|
2009-02-05 07:49:09 +08:00
|
|
|
llvm::SmallVector<VarDecl*, 5> ErrorParams;
|
2008-10-02 07:24:09 +08:00
|
|
|
|
2009-08-21 10:18:44 +08:00
|
|
|
if (const ObjCMethodDecl* MD = dyn_cast<ObjCMethodDecl>(&CodeDecl))
|
2009-02-05 07:49:09 +08:00
|
|
|
CheckSignature(*MD, ResultTy, ErrorParams);
|
2009-08-21 10:18:44 +08:00
|
|
|
else if (const FunctionDecl* FD = dyn_cast<FunctionDecl>(&CodeDecl))
|
2009-02-05 07:49:09 +08:00
|
|
|
CheckSignature(*FD, ResultTy, ErrorParams);
|
2008-10-02 07:24:09 +08:00
|
|
|
else
|
|
|
|
return;
|
2009-09-09 23:08:12 +08:00
|
|
|
|
2009-02-05 07:49:09 +08:00
|
|
|
if (ErrorParams.empty())
|
2008-09-19 05:25:13 +08:00
|
|
|
return;
|
2009-09-09 23:08:12 +08:00
|
|
|
|
2009-02-05 07:49:09 +08:00
|
|
|
if (ResultTy == Ctx.VoidTy) EmitRetTyWarning(BR, CodeDecl);
|
2009-09-09 23:08:12 +08:00
|
|
|
|
|
|
|
for (ExplodedGraph::roots_iterator RI=G.roots_begin(), RE=G.roots_end();
|
2009-08-06 20:48:26 +08:00
|
|
|
RI!=RE; ++RI) {
|
2009-02-05 07:49:09 +08:00
|
|
|
// Scan the parameters for an implicit null dereference.
|
|
|
|
for (llvm::SmallVectorImpl<VarDecl*>::iterator I=ErrorParams.begin(),
|
2009-09-09 23:08:12 +08:00
|
|
|
E=ErrorParams.end(); I!=E; ++I)
|
2009-08-22 06:28:32 +08:00
|
|
|
CheckParamDeref(*I, (*RI)->getLocationContext(), (*RI)->getState(), BR);
|
2008-10-02 07:24:09 +08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2009-11-03 14:59:59 +08:00
|
|
|
void NSErrorChecker::EmitRetTyWarning(BugReporter& BR, const Decl& CodeDecl) {
|
2009-02-05 07:49:09 +08:00
|
|
|
std::string sbuf;
|
|
|
|
llvm::raw_string_ostream os(sbuf);
|
2009-09-09 23:08:12 +08:00
|
|
|
|
2008-10-02 07:24:09 +08:00
|
|
|
if (isa<ObjCMethodDecl>(CodeDecl))
|
|
|
|
os << "Method";
|
|
|
|
else
|
2009-09-09 23:08:12 +08:00
|
|
|
os << "Function";
|
|
|
|
|
2008-10-02 07:24:09 +08:00
|
|
|
os << " accepting ";
|
|
|
|
os << (isNSErrorWarning ? "NSError**" : "CFErrorRef*");
|
|
|
|
os << " should have a non-void return value to indicate whether or not an "
|
2009-08-06 13:01:36 +08:00
|
|
|
"error occurred";
|
2009-09-09 23:08:12 +08:00
|
|
|
|
2008-10-02 07:24:09 +08:00
|
|
|
BR.EmitBasicReport(isNSErrorWarning
|
|
|
|
? "Bad return type when passing NSError**"
|
|
|
|
: "Bad return type when passing CFError*",
|
2009-11-30 02:27:55 +08:00
|
|
|
getCategory(), os.str(),
|
2009-02-05 07:49:09 +08:00
|
|
|
CodeDecl.getLocation());
|
2008-09-18 14:33:41 +08:00
|
|
|
}
|
2008-09-19 05:25:13 +08:00
|
|
|
|
2008-10-02 07:24:09 +08:00
|
|
|
void
|
2009-11-03 14:59:59 +08:00
|
|
|
NSErrorChecker::CheckSignature(const ObjCMethodDecl& M, QualType& ResultTy,
|
2009-02-05 07:49:09 +08:00
|
|
|
llvm::SmallVectorImpl<VarDecl*>& ErrorParams) {
|
2008-09-19 05:25:13 +08:00
|
|
|
|
|
|
|
ResultTy = M.getResultType();
|
2009-09-09 23:08:12 +08:00
|
|
|
|
|
|
|
for (ObjCMethodDecl::param_iterator I=M.param_begin(),
|
2008-10-02 07:24:09 +08:00
|
|
|
E=M.param_end(); I!=E; ++I) {
|
|
|
|
|
2009-09-09 23:08:12 +08:00
|
|
|
QualType T = (*I)->getType();
|
2008-10-02 07:24:09 +08:00
|
|
|
|
2009-02-05 07:49:09 +08:00
|
|
|
if (isNSErrorWarning) {
|
|
|
|
if (CheckNSErrorArgument(T)) ErrorParams.push_back(*I);
|
|
|
|
}
|
|
|
|
else if (CheckCFErrorArgument(T))
|
|
|
|
ErrorParams.push_back(*I);
|
2008-10-02 07:24:09 +08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
void
|
2009-11-03 14:59:59 +08:00
|
|
|
NSErrorChecker::CheckSignature(const FunctionDecl& F, QualType& ResultTy,
|
2009-02-05 07:49:09 +08:00
|
|
|
llvm::SmallVectorImpl<VarDecl*>& ErrorParams) {
|
2009-09-09 23:08:12 +08:00
|
|
|
|
2008-10-02 07:24:09 +08:00
|
|
|
ResultTy = F.getResultType();
|
2009-09-09 23:08:12 +08:00
|
|
|
|
|
|
|
for (FunctionDecl::param_const_iterator I = F.param_begin(),
|
2009-08-21 10:18:44 +08:00
|
|
|
E = F.param_end(); I != E; ++I) {
|
2009-09-09 23:08:12 +08:00
|
|
|
|
|
|
|
QualType T = (*I)->getType();
|
|
|
|
|
2009-02-05 07:49:09 +08:00
|
|
|
if (isNSErrorWarning) {
|
|
|
|
if (CheckNSErrorArgument(T)) ErrorParams.push_back(*I);
|
|
|
|
}
|
|
|
|
else if (CheckCFErrorArgument(T))
|
|
|
|
ErrorParams.push_back(*I);
|
2008-10-02 07:24:09 +08:00
|
|
|
}
|
2008-09-19 05:25:13 +08:00
|
|
|
}
|
|
|
|
|
2008-10-02 07:24:09 +08:00
|
|
|
|
2009-11-03 14:59:59 +08:00
|
|
|
bool NSErrorChecker::CheckNSErrorArgument(QualType ArgTy) {
|
2009-09-09 23:08:12 +08:00
|
|
|
|
2009-07-30 05:53:49 +08:00
|
|
|
const PointerType* PPT = ArgTy->getAs<PointerType>();
|
2009-07-11 07:34:53 +08:00
|
|
|
if (!PPT)
|
|
|
|
return false;
|
2009-09-09 23:08:12 +08:00
|
|
|
|
2009-07-11 07:34:53 +08:00
|
|
|
const ObjCObjectPointerType* PT =
|
2009-09-22 07:43:11 +08:00
|
|
|
PPT->getPointeeType()->getAs<ObjCObjectPointerType>();
|
2009-07-11 07:34:53 +08:00
|
|
|
|
|
|
|
if (!PT)
|
|
|
|
return false;
|
2009-09-09 23:08:12 +08:00
|
|
|
|
2009-07-11 07:34:53 +08:00
|
|
|
const ObjCInterfaceDecl *ID = PT->getInterfaceDecl();
|
2009-09-09 23:08:12 +08:00
|
|
|
|
2009-07-11 07:34:53 +08:00
|
|
|
// FIXME: Can ID ever be NULL?
|
|
|
|
if (ID)
|
|
|
|
return II == ID->getIdentifier();
|
2009-09-09 23:08:12 +08:00
|
|
|
|
2009-07-11 07:34:53 +08:00
|
|
|
return false;
|
2008-09-19 05:25:13 +08:00
|
|
|
}
|
2008-09-19 07:09:54 +08:00
|
|
|
|
2009-11-03 14:59:59 +08:00
|
|
|
bool NSErrorChecker::CheckCFErrorArgument(QualType ArgTy) {
|
2009-09-09 23:08:12 +08:00
|
|
|
|
2009-07-30 05:53:49 +08:00
|
|
|
const PointerType* PPT = ArgTy->getAs<PointerType>();
|
2008-10-02 07:24:09 +08:00
|
|
|
if (!PPT) return false;
|
2009-09-09 23:08:12 +08:00
|
|
|
|
2009-09-22 07:43:11 +08:00
|
|
|
const TypedefType* TT = PPT->getPointeeType()->getAs<TypedefType>();
|
2008-10-02 07:24:09 +08:00
|
|
|
if (!TT) return false;
|
|
|
|
|
2009-02-05 07:49:09 +08:00
|
|
|
return TT->getDecl()->getIdentifier() == II;
|
2008-10-02 07:24:09 +08:00
|
|
|
}
|
|
|
|
|
2009-11-03 14:59:59 +08:00
|
|
|
void NSErrorChecker::CheckParamDeref(const VarDecl *Param,
|
2009-08-22 06:28:32 +08:00
|
|
|
const LocationContext *LC,
|
|
|
|
const GRState *rootState,
|
2009-02-05 07:49:09 +08:00
|
|
|
BugReporter& BR) {
|
2009-09-09 23:08:12 +08:00
|
|
|
|
2009-08-22 06:28:32 +08:00
|
|
|
SVal ParamL = rootState->getLValue(Param, LC);
|
2008-10-18 04:28:54 +08:00
|
|
|
const MemRegion* ParamR = cast<loc::MemRegionVal>(ParamL).getRegionAs<VarRegion>();
|
|
|
|
assert (ParamR && "Parameters always have VarRegions.");
|
2010-02-09 00:18:51 +08:00
|
|
|
SVal ParamSVal = rootState->getSVal(ParamR);
|
2009-09-09 23:08:12 +08:00
|
|
|
|
2008-10-17 13:57:07 +08:00
|
|
|
// FIXME: For now assume that ParamSVal is symbolic. We need to generalize
|
2008-09-19 07:09:54 +08:00
|
|
|
// this later.
|
2009-03-31 03:53:37 +08:00
|
|
|
SymbolRef ParamSym = ParamSVal.getAsLocSymbol();
|
|
|
|
if (!ParamSym)
|
|
|
|
return;
|
2009-09-09 23:08:12 +08:00
|
|
|
|
2008-09-19 07:09:54 +08:00
|
|
|
// Iterate over the implicit-null dereferences.
|
2009-11-11 11:26:34 +08:00
|
|
|
ExplodedNode *const* I, *const* E;
|
|
|
|
llvm::tie(I, E) = GetImplicitNullDereferences(Eng);
|
|
|
|
for ( ; I != E; ++I) {
|
2009-06-18 06:28:13 +08:00
|
|
|
const GRState *state = (*I)->getState();
|
2010-02-09 00:18:51 +08:00
|
|
|
SVal location = state->getSVal((*I)->getLocationAs<StmtPoint>()->getStmt());
|
2009-11-11 11:26:34 +08:00
|
|
|
if (location.getAsSymbol() != ParamSym)
|
2009-03-31 03:53:37 +08:00
|
|
|
continue;
|
2008-09-19 07:09:54 +08:00
|
|
|
|
2009-03-31 03:53:37 +08:00
|
|
|
// Emit an error.
|
2009-02-05 07:49:09 +08:00
|
|
|
std::string sbuf;
|
|
|
|
llvm::raw_string_ostream os(sbuf);
|
2008-10-02 07:24:09 +08:00
|
|
|
os << "Potential null dereference. According to coding standards ";
|
2009-09-09 23:08:12 +08:00
|
|
|
|
2008-10-02 07:24:09 +08:00
|
|
|
if (isNSErrorWarning)
|
|
|
|
os << "in 'Creating and Returning NSError Objects' the parameter '";
|
|
|
|
else
|
|
|
|
os << "documented in CoreFoundation/CFError.h the parameter '";
|
2009-09-09 23:08:12 +08:00
|
|
|
|
2010-04-17 17:33:03 +08:00
|
|
|
os << Param << "' may be null.";
|
2009-09-09 23:08:12 +08:00
|
|
|
|
2009-11-30 02:03:28 +08:00
|
|
|
BugReport *report = new BugReport(*this, os.str(), *I);
|
2009-02-05 07:49:09 +08:00
|
|
|
// FIXME: Notable symbols are now part of the report. We should
|
|
|
|
// add support for notable symbols in BugReport.
|
|
|
|
// BR.addNotableSymbol(SV->getSymbol());
|
|
|
|
BR.EmitReport(report);
|
2008-09-19 07:09:54 +08:00
|
|
|
}
|
|
|
|
}
|