diff options
author | Ted Kremenek <kremenek@apple.com> | 2010-12-23 19:38:26 +0000 |
---|---|---|
committer | Ted Kremenek <kremenek@apple.com> | 2010-12-23 19:38:26 +0000 |
commit | d99bd55a5e092774214ba31fc5a871bfc31e711c (patch) | |
tree | 65f5bf2f5455dc003214c9ef9f6375bd5acac160 /clang/lib/StaticAnalyzer/EntoSA/Checkers/CheckSizeofPointer.cpp | |
parent | 2a0a3b43d741fe366d141691c690e0be94963a2a (diff) | |
download | bcm5719-llvm-d99bd55a5e092774214ba31fc5a871bfc31e711c.tar.gz bcm5719-llvm-d99bd55a5e092774214ba31fc5a871bfc31e711c.zip |
Chris Lattner has strong opinions about directory
layout. :)
Rename the 'EntoSA' directories to 'StaticAnalyzer'.
Internally we will still use the 'ento' namespace
for the analyzer engine (unless there are further
sabre rattlings...).
llvm-svn: 122514
Diffstat (limited to 'clang/lib/StaticAnalyzer/EntoSA/Checkers/CheckSizeofPointer.cpp')
-rw-r--r-- | clang/lib/StaticAnalyzer/EntoSA/Checkers/CheckSizeofPointer.cpp | 72 |
1 files changed, 72 insertions, 0 deletions
diff --git a/clang/lib/StaticAnalyzer/EntoSA/Checkers/CheckSizeofPointer.cpp b/clang/lib/StaticAnalyzer/EntoSA/Checkers/CheckSizeofPointer.cpp new file mode 100644 index 00000000000..ed060b27fb4 --- /dev/null +++ b/clang/lib/StaticAnalyzer/EntoSA/Checkers/CheckSizeofPointer.cpp @@ -0,0 +1,72 @@ +//==- CheckSizeofPointer.cpp - Check for sizeof on pointers ------*- C++ -*-==// +// +// The LLVM Compiler Infrastructure +// +// This file is distributed under the University of Illinois Open Source +// License. See LICENSE.TXT for details. +// +//===----------------------------------------------------------------------===// +// +// This file defines a check for unintended use of sizeof() on pointer +// expressions. +// +//===----------------------------------------------------------------------===// + +#include "clang/StaticAnalyzer/BugReporter/BugReporter.h" +#include "clang/AST/StmtVisitor.h" +#include "clang/StaticAnalyzer/Checkers/LocalCheckers.h" + +using namespace clang; +using namespace ento; + +namespace { +class WalkAST : public StmtVisitor<WalkAST> { + BugReporter &BR; + +public: + WalkAST(BugReporter &br) : BR(br) {} + void VisitSizeOfAlignOfExpr(SizeOfAlignOfExpr *E); + void VisitStmt(Stmt *S) { VisitChildren(S); } + void VisitChildren(Stmt *S); +}; +} + +void WalkAST::VisitChildren(Stmt *S) { + for (Stmt::child_iterator I = S->child_begin(), E = S->child_end(); I!=E; ++I) + if (Stmt *child = *I) + Visit(child); +} + +// CWE-467: Use of sizeof() on a Pointer Type +void WalkAST::VisitSizeOfAlignOfExpr(SizeOfAlignOfExpr *E) { + if (!E->isSizeOf()) + return; + + // If an explicit type is used in the code, usually the coder knows what he is + // doing. + if (E->isArgumentType()) + return; + + QualType T = E->getTypeOfArgument(); + if (T->isPointerType()) { + + // Many false positives have the form 'sizeof *p'. This is reasonable + // because people know what they are doing when they intentionally + // dereference the pointer. + Expr *ArgEx = E->getArgumentExpr(); + if (!isa<DeclRefExpr>(ArgEx->IgnoreParens())) + return; + + SourceRange R = ArgEx->getSourceRange(); + BR.EmitBasicReport("Potential unintended use of sizeof() on pointer type", + "Logic", + "The code calls sizeof() on a pointer type. " + "This can produce an unexpected result.", + E->getLocStart(), &R, 1); + } +} + +void ento::CheckSizeofPointer(const Decl *D, BugReporter &BR) { + WalkAST walker(BR); + walker.Visit(D->getBody()); +} |