Skip to content

[-Wunsafe-buffer-usage] Add findUnsafePointers #135421

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions clang/include/clang/Analysis/Analyses/UnsafeBufferUsage.h
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,7 @@
#include "clang/AST/Stmt.h"
#include "clang/Basic/SourceLocation.h"
#include "llvm/Support/Debug.h"
#include <set>

namespace clang {

Expand Down Expand Up @@ -186,6 +187,8 @@ namespace internal {
bool anyConflict(const llvm::SmallVectorImpl<FixItHint> &FixIts,
const SourceManager &SM);
} // namespace internal

std::set<const Expr *> findUnsafePointers(const FunctionDecl *FD);
} // end namespace clang

#endif /* LLVM_CLANG_ANALYSIS_ANALYSES_UNSAFEBUFFERUSAGE_H */
75 changes: 75 additions & 0 deletions clang/lib/Analysis/UnsafeBufferUsage.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -1163,6 +1163,8 @@ class WarningGadget : public Gadget {
virtual void handleUnsafeOperation(UnsafeBufferUsageHandler &Handler,
bool IsRelatedToDecl,
ASTContext &Ctx) const = 0;

virtual SmallVector<const Expr *, 1> getUnsafePtrs() const = 0;
};

/// Fixable gadgets correspond to code patterns that aren't always unsafe but
Expand Down Expand Up @@ -1245,6 +1247,10 @@ class IncrementGadget : public WarningGadget {

return std::move(Uses);
}

SmallVector<const Expr *, 1> getUnsafePtrs() const override {
return {Op->getSubExpr()->IgnoreParenImpCasts()};
}
};

/// A decrement of a pointer-type value is unsafe as it may run the pointer
Expand Down Expand Up @@ -1288,6 +1294,10 @@ class DecrementGadget : public WarningGadget {

return {};
}

SmallVector<const Expr *, 1> getUnsafePtrs() const override {
return {Op->getSubExpr()->IgnoreParenImpCasts()};
}
};

/// Array subscript expressions on raw pointers as if they're arrays. Unsafe as
Expand Down Expand Up @@ -1337,6 +1347,10 @@ class ArraySubscriptGadget : public WarningGadget {

return {};
}

SmallVector<const Expr *, 1> getUnsafePtrs() const override {
return {ASE->getBase()->IgnoreParenImpCasts()};
}
};

/// A pointer arithmetic expression of one of the forms:
Expand Down Expand Up @@ -1400,6 +1414,11 @@ class PointerArithmeticGadget : public WarningGadget {

return {};
}

SmallVector<const Expr *, 1> getUnsafePtrs() const override {
return {Ptr->IgnoreParenImpCasts()};
}

// FIXME: pointer adding zero should be fine
// FIXME: this gadge will need a fix-it
};
Expand Down Expand Up @@ -1457,6 +1476,8 @@ class SpanTwoParamConstructorGadget : public WarningGadget {
}
return {};
}

SmallVector<const Expr *, 1> getUnsafePtrs() const override { return {}; }
};

/// A pointer initialization expression of the form:
Expand Down Expand Up @@ -1689,6 +1710,8 @@ class UnsafeBufferUsageAttrGadget : public WarningGadget {
SourceLocation getSourceLoc() const override { return Op->getBeginLoc(); }

DeclUseList getClaimedVarUseSites() const override { return {}; }

SmallVector<const Expr *, 1> getUnsafePtrs() const override { return {}; }
};

/// A call of a constructor that performs unchecked buffer operations
Expand Down Expand Up @@ -1727,6 +1750,8 @@ class UnsafeBufferUsageCtorAttrGadget : public WarningGadget {
SourceLocation getSourceLoc() const override { return Op->getBeginLoc(); }

DeclUseList getClaimedVarUseSites() const override { return {}; }

SmallVector<const Expr *, 1> getUnsafePtrs() const override { return {}; }
};

// Warning gadget for unsafe invocation of span::data method.
Expand Down Expand Up @@ -1793,6 +1818,8 @@ class DataInvocationGadget : public WarningGadget {
return true;
return false;
}

SmallVector<const Expr *, 1> getUnsafePtrs() const override { return {}; }
};

class UnsafeLibcFunctionCallGadget : public WarningGadget {
Expand Down Expand Up @@ -1896,6 +1923,8 @@ class UnsafeLibcFunctionCallGadget : public WarningGadget {
}

DeclUseList getClaimedVarUseSites() const override { return {}; }

SmallVector<const Expr *, 1> getUnsafePtrs() const override { return {}; }
};

// Represents expressions of the form `DRE[*]` in the Unspecified Lvalue
Expand Down Expand Up @@ -2467,6 +2496,52 @@ template <typename NodeTy> struct CompareNode {
}
};

std::set<const Expr *> clang::findUnsafePointers(const FunctionDecl *FD) {
class MockReporter : public UnsafeBufferUsageHandler {
public:
MockReporter() {}
void handleUnsafeOperation(const Stmt *, bool, ASTContext &) override {}
void handleUnsafeLibcCall(const CallExpr *, unsigned, ASTContext &,
const Expr *UnsafeArg = nullptr) override {}
void handleUnsafeOperationInContainer(const Stmt *, bool,
ASTContext &) override {}
void handleUnsafeVariableGroup(const VarDecl *,
const VariableGroupsManager &, FixItList &&,
const Decl *,
const FixitStrategy &) override {}
bool isSafeBufferOptOut(const SourceLocation &) const override {
return false;
}
bool ignoreUnsafeBufferInContainer(const SourceLocation &) const override {
return false;
}
bool ignoreUnsafeBufferInLibcCall(const SourceLocation &) const override {
return false;
}
std::string getUnsafeBufferUsageAttributeTextAt(
SourceLocation, StringRef WSSuffix = "") const override {
return "";
}
};

FixableGadgetList FixableGadgets;
WarningGadgetList WarningGadgets;
DeclUseTracker Tracker;
MockReporter IgnoreHandler;

findGadgets(FD->getBody(), FD->getASTContext(), IgnoreHandler, false,
FixableGadgets, WarningGadgets, Tracker);

std::set<const Expr *> Result;
for (auto &G : WarningGadgets) {
for (const Expr *E : G->getUnsafePtrs()) {
Result.insert(E);
}
}

return Result;
}

struct WarningGadgetSets {
std::map<const VarDecl *, std::set<const WarningGadget *>,
// To keep keys sorted by their locations in the map so that the
Expand Down