diff options
author | Ted Kremenek <kremenek@apple.com> | 2011-10-28 19:05:10 +0000 |
---|---|---|
committer | Ted Kremenek <kremenek@apple.com> | 2011-10-28 19:05:10 +0000 |
commit | a98358ea13fcf4960e20c1ceafc6f8d909ca8e27 (patch) | |
tree | 24f329616734d9d2f0638b2b21e397b50f600e42 /clang/lib/StaticAnalyzer/Checkers/CallAndMessageChecker.cpp | |
parent | 280bc553b38014bd459b55cc56b78a413058bc2d (diff) | |
download | bcm5719-llvm-a98358ea13fcf4960e20c1ceafc6f8d909ca8e27.tar.gz bcm5719-llvm-a98358ea13fcf4960e20c1ceafc6f8d909ca8e27.zip |
[analyzer] ObjC message sends to nil receivers that return structs are now okay (compiler zeroes out the data). Fixes <rdar://problem/9151319>.
llvm-svn: 143215
Diffstat (limited to 'clang/lib/StaticAnalyzer/Checkers/CallAndMessageChecker.cpp')
-rw-r--r-- | clang/lib/StaticAnalyzer/Checkers/CallAndMessageChecker.cpp | 18 |
1 files changed, 4 insertions, 14 deletions
diff --git a/clang/lib/StaticAnalyzer/Checkers/CallAndMessageChecker.cpp b/clang/lib/StaticAnalyzer/Checkers/CallAndMessageChecker.cpp index 8a7f48b6f8c..944bff6626c 100644 --- a/clang/lib/StaticAnalyzer/Checkers/CallAndMessageChecker.cpp +++ b/clang/lib/StaticAnalyzer/Checkers/CallAndMessageChecker.cpp @@ -297,26 +297,16 @@ void CallAndMessageChecker::HandleNilReceiver(CheckerContext &C, // Check the return type of the message expression. A message to nil will // return different values depending on the return type and the architecture. QualType RetTy = msg.getType(Ctx); - CanQualType CanRetTy = Ctx.getCanonicalType(RetTy); if (CanRetTy->isStructureOrClassType()) { - // FIXME: At some point we shouldn't rely on isConsumedExpr(), but instead - // have the "use of undefined value" be smarter about where the - // undefined value came from. - if (C.getPredecessor()->getParentMap().isConsumedExpr(msg.getOriginExpr())){ - if (ExplodedNode *N = C.generateSink(state)) - emitNilReceiverBug(C, msg, N); - return; - } - - // The result is not consumed by a surrounding expression. Just propagate - // the current state. - C.addTransition(state); + // Structure returns are safe since the compiler zeroes them out. + SVal V = C.getSValBuilder().makeZeroVal(msg.getType(Ctx)); + C.addTransition(state->BindExpr(msg.getOriginExpr(), V)); return; } - // Other cases: check if the return type is smaller than void*. + // Other cases: check if sizeof(return type) > sizeof(void*) if (CanRetTy != Ctx.VoidTy && C.getPredecessor()->getParentMap().isConsumedExpr(msg.getOriginExpr())) { // Compute: sizeof(void *) and sizeof(return type) |