summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorTed Kremenek <kremenek@apple.com>2010-04-07 00:46:49 +0000
committerTed Kremenek <kremenek@apple.com>2010-04-07 00:46:49 +0000
commit6e95bfc6a5bfd659ab6166a840a190e077ff5067 (patch)
treedc6f11e5a17a54ebc964b6daad4e0156a1919677
parent8e36d53e34be6d74ce4fa76b2b5cb586d32da51b (diff)
downloadbcm5719-llvm-6e95bfc6a5bfd659ab6166a840a190e077ff5067.tar.gz
bcm5719-llvm-6e95bfc6a5bfd659ab6166a840a190e077ff5067.zip
Fix crash in StoreManager::CastRegion() when the base region is a type with 0 size.
llvm-svn: 100594
-rw-r--r--clang/lib/Checker/Store.cpp15
-rw-r--r--clang/test/Analysis/misc-ps-region-store.m8
2 files changed, 16 insertions, 7 deletions
diff --git a/clang/lib/Checker/Store.cpp b/clang/lib/Checker/Store.cpp
index e524cb3d7cc..80b6586b8b9 100644
--- a/clang/lib/Checker/Store.cpp
+++ b/clang/lib/Checker/Store.cpp
@@ -170,13 +170,14 @@ const MemRegion *StoreManager::CastRegion(const MemRegion *R, QualType CastToTy)
if (IsCompleteType(Ctx, PointeeTy)) {
// Compute the size in **bytes**.
CharUnits pointeeTySize = Ctx.getTypeSizeInChars(PointeeTy);
-
- // Is the offset a multiple of the size? If so, we can layer the
- // ElementRegion (with elementType == PointeeTy) directly on top of
- // the base region.
- if (off % pointeeTySize == 0) {
- newIndex = off / pointeeTySize;
- newSuperR = baseR;
+ if (!pointeeTySize.isZero()) {
+ // Is the offset a multiple of the size? If so, we can layer the
+ // ElementRegion (with elementType == PointeeTy) directly on top of
+ // the base region.
+ if (off % pointeeTySize == 0) {
+ newIndex = off / pointeeTySize;
+ newSuperR = baseR;
+ }
}
}
diff --git a/clang/test/Analysis/misc-ps-region-store.m b/clang/test/Analysis/misc-ps-region-store.m
index 0e305bf1dfb..3f64a085c83 100644
--- a/clang/test/Analysis/misc-ps-region-store.m
+++ b/clang/test/Analysis/misc-ps-region-store.m
@@ -976,3 +976,11 @@ void rdar7817800_qux(void*);
}
@end
+// PR 6036 - This test case triggered a crash inside StoreManager::CastRegion because the size
+// of 'unsigned long (*)[0]' is 0.
+struct pr6036_a { int pr6036_b; };
+struct pr6036_c;
+void u132monitk (struct pr6036_c *pr6036_d) {
+ (void) ((struct pr6036_a *) (unsigned long (*)[0]) ((char *) pr6036_d - 1))->pr6036_b; // expected-warning{{Casting a non-structure type to a structure type and accessing a field can lead to memory access errors or data corruption}}
+}
+
OpenPOWER on IntegriCloud