003 File Manager
Current Path:
/usr/src/contrib/llvm-project/clang/lib/StaticAnalyzer/Checkers
usr
/
src
/
contrib
/
llvm-project
/
clang
/
lib
/
StaticAnalyzer
/
Checkers
/
📁
..
📄
AllocationState.h
(1.41 KB)
📄
AnalysisOrderChecker.cpp
(8.62 KB)
📄
AnalyzerStatsChecker.cpp
(5.04 KB)
📄
ArrayBoundChecker.cpp
(3.22 KB)
📄
ArrayBoundCheckerV2.cpp
(13.07 KB)
📄
BasicObjCFoundationChecks.cpp
(43.82 KB)
📄
BlockInCriticalSectionChecker.cpp
(6.69 KB)
📄
BoolAssignmentChecker.cpp
(3.45 KB)
📄
BuiltinFunctionChecker.cpp
(5 KB)
📄
CStringChecker.cpp
(93.24 KB)
📄
CStringSyntaxChecker.cpp
(9.8 KB)
📄
CXXSelfAssignmentChecker.cpp
(3.08 KB)
📄
CallAndMessageChecker.cpp
(26.57 KB)
📄
CastSizeChecker.cpp
(4.96 KB)
📄
CastToStructChecker.cpp
(4.43 KB)
📄
CastValueChecker.cpp
(19.65 KB)
📄
CheckObjCDealloc.cpp
(37.83 KB)
📄
CheckObjCInstMethSignature.cpp
(4.8 KB)
📄
CheckPlacementNew.cpp
(11.91 KB)
📄
CheckSecuritySyntaxOnly.cpp
(38.79 KB)
📄
CheckSizeofPointer.cpp
(3.16 KB)
📄
CheckerDocumentation.cpp
(14.64 KB)
📄
ChrootChecker.cpp
(4.88 KB)
📄
CloneChecker.cpp
(8.28 KB)
📄
ContainerModeling.cpp
(39.85 KB)
📄
ConversionChecker.cpp
(7.11 KB)
📄
DeadStoresChecker.cpp
(17.82 KB)
📄
DebugCheckers.cpp
(10.41 KB)
📄
DebugContainerModeling.cpp
(4.94 KB)
📄
DebugIteratorModeling.cpp
(5.15 KB)
📄
DeleteWithNonVirtualDtorChecker.cpp
(5.35 KB)
📄
DereferenceChecker.cpp
(10.54 KB)
📄
DirectIvarAssignment.cpp
(8.02 KB)
📄
DivZeroChecker.cpp
(3.42 KB)
📄
DynamicTypeChecker.cpp
(7.31 KB)
📄
DynamicTypePropagation.cpp
(42.11 KB)
📄
EnumCastOutOfRangeChecker.cpp
(5.75 KB)
📄
ExprInspectionChecker.cpp
(15.6 KB)
📄
FixedAddressChecker.cpp
(2.33 KB)
📄
FuchsiaHandleChecker.cpp
(23.1 KB)
📄
GCDAntipatternChecker.cpp
(7.85 KB)
📄
GTestChecker.cpp
(10.52 KB)
📄
GenericTaintChecker.cpp
(34.31 KB)
📄
IdenticalExprChecker.cpp
(18.88 KB)
📄
InnerPointerChecker.cpp
(11.54 KB)
📄
InterCheckerAPI.h
(1.09 KB)
📄
InvalidatedIteratorChecker.cpp
(4.93 KB)
📄
Iterator.cpp
(10.62 KB)
📄
Iterator.h
(6.32 KB)
📄
IteratorModeling.cpp
(31.33 KB)
📄
IteratorRangeChecker.cpp
(12.64 KB)
📄
IvarInvalidationChecker.cpp
(27.63 KB)
📄
LLVMConventionsChecker.cpp
(9.9 KB)
📄
LocalizationChecker.cpp
(52.38 KB)
📄
MIGChecker.cpp
(11.3 KB)
📁
MPI-Checker
📄
MacOSKeychainAPIChecker.cpp
(25.21 KB)
📄
MacOSXAPIChecker.cpp
(6.61 KB)
📄
MallocChecker.cpp
(127.38 KB)
📄
MallocOverflowSecurityChecker.cpp
(11.91 KB)
📄
MallocSizeofChecker.cpp
(8.03 KB)
📄
MismatchedIteratorChecker.cpp
(11.01 KB)
📄
MmapWriteExecChecker.cpp
(3.22 KB)
📄
Move.h
(1.07 KB)
📄
MoveChecker.cpp
(27 KB)
📄
NSAutoreleasePoolChecker.cpp
(2.93 KB)
📄
NSErrorChecker.cpp
(10.6 KB)
📄
NoReturnFunctionChecker.cpp
(5.48 KB)
📄
NonNullParamChecker.cpp
(11.22 KB)
📄
NonnullGlobalConstantsChecker.cpp
(5.09 KB)
📄
NullabilityChecker.cpp
(46.95 KB)
📄
NumberObjectConversionChecker.cpp
(13.69 KB)
📄
OSObjectCStyleCast.cpp
(3.14 KB)
📄
ObjCAtSyncChecker.cpp
(3.34 KB)
📄
ObjCAutoreleaseWriteChecker.cpp
(8.62 KB)
📄
ObjCContainersASTChecker.cpp
(5.5 KB)
📄
ObjCContainersChecker.cpp
(6.71 KB)
📄
ObjCMissingSuperCallChecker.cpp
(9.23 KB)
📄
ObjCPropertyChecker.cpp
(3.03 KB)
📄
ObjCSelfInitChecker.cpp
(16.21 KB)
📄
ObjCSuperDeallocChecker.cpp
(9.33 KB)
📄
ObjCUnusedIVarsChecker.cpp
(6.01 KB)
📄
PaddingChecker.cpp
(14.26 KB)
📄
PointerArithChecker.cpp
(12.18 KB)
📄
PointerIterationChecker.cpp
(3.79 KB)
📄
PointerSortingChecker.cpp
(4.5 KB)
📄
PointerSubChecker.cpp
(2.56 KB)
📄
PthreadLockChecker.cpp
(28.42 KB)
📁
RetainCountChecker
📄
ReturnPointerRangeChecker.cpp
(3.39 KB)
📄
ReturnUndefChecker.cpp
(4.1 KB)
📄
ReturnValueChecker.cpp
(5.79 KB)
📄
RunLoopAutoreleaseLeakChecker.cpp
(7.2 KB)
📄
STLAlgorithmModeling.cpp
(7 KB)
📄
SimpleStreamChecker.cpp
(9.43 KB)
📄
SmartPtr.h
(1.17 KB)
📄
SmartPtrChecker.cpp
(2.68 KB)
📄
SmartPtrModeling.cpp
(8.05 KB)
📄
StackAddrEscapeChecker.cpp
(15 KB)
📄
StdLibraryFunctionsChecker.cpp
(74.86 KB)
📄
StreamChecker.cpp
(37.36 KB)
📄
Taint.cpp
(9.04 KB)
📄
Taint.h
(4.19 KB)
📄
TaintTesterChecker.cpp
(2.17 KB)
📄
TestAfterDivZeroChecker.cpp
(8.19 KB)
📄
TraversalChecker.cpp
(4.38 KB)
📄
TrustNonnullChecker.cpp
(9.12 KB)
📄
UndefBranchChecker.cpp
(3.82 KB)
📄
UndefCapturedBlockVarChecker.cpp
(3.64 KB)
📄
UndefResultChecker.cpp
(7.19 KB)
📄
UndefinedArraySubscriptChecker.cpp
(2.36 KB)
📄
UndefinedAssignmentChecker.cpp
(3.74 KB)
📁
UninitializedObject
📄
UnixAPIChecker.cpp
(18.05 KB)
📄
UnreachableCodeChecker.cpp
(9.59 KB)
📄
VLASizeChecker.cpp
(10.95 KB)
📄
ValistChecker.cpp
(15.65 KB)
📄
VforkChecker.cpp
(7.67 KB)
📄
VirtualCallChecker.cpp
(8.11 KB)
📁
WebKit
📄
Yaml.h
(2.06 KB)
📁
cert
Editing: ObjCAutoreleaseWriteChecker.cpp
//===- ObjCAutoreleaseWriteChecker.cpp ----------------------------*- C++ -*-==// // // Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions. // See https://llvm.org/LICENSE.txt for license information. // SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception // //===----------------------------------------------------------------------===// // // This file defines ObjCAutoreleaseWriteChecker which warns against writes // into autoreleased out parameters which cause crashes. // An example of a problematic write is a write to {@code error} in the example // below: // // - (BOOL) mymethod:(NSError *__autoreleasing *)error list:(NSArray*) list { // [list enumerateObjectsUsingBlock:^(id obj, NSUInteger idx, BOOL *stop) { // NSString *myString = obj; // if ([myString isEqualToString:@"error"] && error) // *error = [NSError errorWithDomain:@"MyDomain" code:-1]; // }]; // return false; // } // // Such code will crash on read from `*error` due to the autorelease pool // in `enumerateObjectsUsingBlock` implementation freeing the error object // on exit from the function. // //===----------------------------------------------------------------------===// #include "clang/StaticAnalyzer/Checkers/BuiltinCheckerRegistration.h" #include "clang/ASTMatchers/ASTMatchFinder.h" #include "clang/StaticAnalyzer/Core/BugReporter/BugReporter.h" #include "clang/StaticAnalyzer/Core/BugReporter/BugType.h" #include "clang/StaticAnalyzer/Core/BugReporter/CommonBugCategories.h" #include "clang/StaticAnalyzer/Core/Checker.h" #include "clang/StaticAnalyzer/Core/PathSensitive/AnalysisManager.h" #include "llvm/ADT/Twine.h" using namespace clang; using namespace ento; using namespace ast_matchers; namespace { const char *ProblematicWriteBind = "problematicwrite"; const char *CapturedBind = "capturedbind"; const char *ParamBind = "parambind"; const char *IsMethodBind = "ismethodbind"; const char *IsARPBind = "isautoreleasepoolbind"; class ObjCAutoreleaseWriteChecker : public Checker<check::ASTCodeBody> { public: void checkASTCodeBody(const Decl *D, AnalysisManager &AM, BugReporter &BR) const; private: std::vector<std::string> SelectorsWithAutoreleasingPool = { // Common to NSArray, NSSet, NSOrderedSet "enumerateObjectsUsingBlock:", "enumerateObjectsWithOptions:usingBlock:", // Common to NSArray and NSOrderedSet "enumerateObjectsAtIndexes:options:usingBlock:", "indexOfObjectAtIndexes:options:passingTest:", "indexesOfObjectsAtIndexes:options:passingTest:", "indexOfObjectPassingTest:", "indexOfObjectWithOptions:passingTest:", "indexesOfObjectsPassingTest:", "indexesOfObjectsWithOptions:passingTest:", // NSDictionary "enumerateKeysAndObjectsUsingBlock:", "enumerateKeysAndObjectsWithOptions:usingBlock:", "keysOfEntriesPassingTest:", "keysOfEntriesWithOptions:passingTest:", // NSSet "objectsPassingTest:", "objectsWithOptions:passingTest:", "enumerateIndexPathsWithOptions:usingBlock:", // NSIndexSet "enumerateIndexesWithOptions:usingBlock:", "enumerateIndexesUsingBlock:", "enumerateIndexesInRange:options:usingBlock:", "enumerateRangesUsingBlock:", "enumerateRangesWithOptions:usingBlock:", "enumerateRangesInRange:options:usingBlock:", "indexPassingTest:", "indexesPassingTest:", "indexWithOptions:passingTest:", "indexesWithOptions:passingTest:", "indexInRange:options:passingTest:", "indexesInRange:options:passingTest:" }; std::vector<std::string> FunctionsWithAutoreleasingPool = { "dispatch_async", "dispatch_group_async", "dispatch_barrier_async"}; }; } static inline std::vector<llvm::StringRef> toRefs(std::vector<std::string> V) { return std::vector<llvm::StringRef>(V.begin(), V.end()); } static decltype(auto) callsNames(std::vector<std::string> FunctionNames) { return callee(functionDecl(hasAnyName(toRefs(FunctionNames)))); } static void emitDiagnostics(BoundNodes &Match, const Decl *D, BugReporter &BR, AnalysisManager &AM, const ObjCAutoreleaseWriteChecker *Checker) { AnalysisDeclContext *ADC = AM.getAnalysisDeclContext(D); const auto *PVD = Match.getNodeAs<ParmVarDecl>(ParamBind); QualType Ty = PVD->getType(); if (Ty->getPointeeType().getObjCLifetime() != Qualifiers::OCL_Autoreleasing) return; const char *ActionMsg = "Write to"; const auto *MarkedStmt = Match.getNodeAs<Expr>(ProblematicWriteBind); bool IsCapture = false; // Prefer to warn on write, but if not available, warn on capture. if (!MarkedStmt) { MarkedStmt = Match.getNodeAs<Expr>(CapturedBind); assert(MarkedStmt); ActionMsg = "Capture of"; IsCapture = true; } SourceRange Range = MarkedStmt->getSourceRange(); PathDiagnosticLocation Location = PathDiagnosticLocation::createBegin( MarkedStmt, BR.getSourceManager(), ADC); bool IsMethod = Match.getNodeAs<ObjCMethodDecl>(IsMethodBind) != nullptr; const char *FunctionDescription = IsMethod ? "method" : "function"; bool IsARP = Match.getNodeAs<ObjCAutoreleasePoolStmt>(IsARPBind) != nullptr; llvm::SmallString<128> BugNameBuf; llvm::raw_svector_ostream BugName(BugNameBuf); BugName << ActionMsg << " autoreleasing out parameter inside autorelease pool"; llvm::SmallString<128> BugMessageBuf; llvm::raw_svector_ostream BugMessage(BugMessageBuf); BugMessage << ActionMsg << " autoreleasing out parameter "; if (IsCapture) BugMessage << "'" + PVD->getName() + "' "; BugMessage << "inside "; if (IsARP) BugMessage << "locally-scoped autorelease pool;"; else BugMessage << "autorelease pool that may exit before " << FunctionDescription << " returns;"; BugMessage << " consider writing first to a strong local variable" " declared outside "; if (IsARP) BugMessage << "of the autorelease pool"; else BugMessage << "of the block"; BR.EmitBasicReport(ADC->getDecl(), Checker, BugName.str(), categories::MemoryRefCount, BugMessage.str(), Location, Range); } void ObjCAutoreleaseWriteChecker::checkASTCodeBody(const Decl *D, AnalysisManager &AM, BugReporter &BR) const { auto DoublePointerParamM = parmVarDecl(hasType(hasCanonicalType(pointerType( pointee(hasCanonicalType(objcObjectPointerType())))))) .bind(ParamBind); auto ReferencedParamM = declRefExpr(to(parmVarDecl(DoublePointerParamM))).bind(CapturedBind); // Write into a binded object, e.g. *ParamBind = X. auto WritesIntoM = binaryOperator( hasLHS(unaryOperator( hasOperatorName("*"), hasUnaryOperand( ignoringParenImpCasts(ReferencedParamM)) )), hasOperatorName("=") ).bind(ProblematicWriteBind); auto ArgumentCaptureM = hasAnyArgument( ignoringParenImpCasts(ReferencedParamM)); auto CapturedInParamM = stmt(anyOf( callExpr(ArgumentCaptureM), objcMessageExpr(ArgumentCaptureM))); // WritesIntoM happens inside a block passed as an argument. auto WritesOrCapturesInBlockM = hasAnyArgument(allOf( hasType(hasCanonicalType(blockPointerType())), forEachDescendant( stmt(anyOf(WritesIntoM, CapturedInParamM)) ))); auto BlockPassedToMarkedFuncM = stmt(anyOf( callExpr(allOf( callsNames(FunctionsWithAutoreleasingPool), WritesOrCapturesInBlockM)), objcMessageExpr(allOf( hasAnySelector(toRefs(SelectorsWithAutoreleasingPool)), WritesOrCapturesInBlockM)) )); // WritesIntoM happens inside an explicit @autoreleasepool. auto WritesOrCapturesInPoolM = autoreleasePoolStmt( forEachDescendant(stmt(anyOf(WritesIntoM, CapturedInParamM)))) .bind(IsARPBind); auto HasParamAndWritesInMarkedFuncM = allOf(hasAnyParameter(DoublePointerParamM), anyOf(forEachDescendant(BlockPassedToMarkedFuncM), forEachDescendant(WritesOrCapturesInPoolM))); auto MatcherM = decl(anyOf( objcMethodDecl(HasParamAndWritesInMarkedFuncM).bind(IsMethodBind), functionDecl(HasParamAndWritesInMarkedFuncM), blockDecl(HasParamAndWritesInMarkedFuncM))); auto Matches = match(MatcherM, *D, AM.getASTContext()); for (BoundNodes Match : Matches) emitDiagnostics(Match, D, BR, AM, this); } void ento::registerAutoreleaseWriteChecker(CheckerManager &Mgr) { Mgr.registerChecker<ObjCAutoreleaseWriteChecker>(); } bool ento::shouldRegisterAutoreleaseWriteChecker(const CheckerManager &mgr) { return true; }
Upload File
Create Folder