aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorAnkur Saini <arsenic@sourceware.org>2021-08-15 19:19:07 +0530
committerAnkur Saini <arsenic@sourceware.org>2021-08-18 23:10:31 +0530
commit1b34248527472496ca3fe2a07183beac8cf69041 (patch)
tree1db91dcc90b960c5c65ab77c87625a0be9c42292
parentaef703cf982072427e74034f4c460a11c5e04b8e (diff)
downloadgcc-1b34248527472496ca3fe2a07183beac8cf69041.zip
gcc-1b34248527472496ca3fe2a07183beac8cf69041.tar.gz
gcc-1b34248527472496ca3fe2a07183beac8cf69041.tar.bz2
analyzer: detect and analyze virtual function calls
2021-08-15 Ankur Saini <arsenic@sourceware.org> gcc/analyzer/ChangeLog: PR analyzer/97114 * region-model.cc (region_model::get_rvalue_1): Add case for OBJ_TYPE_REF. gcc/testsuite/ChangeLog: PR analyzer/97114 * g++.dg/analyzer/vfunc-2.C: New test. * g++.dg/analyzer/vfunc-3.C: New test. * g++.dg/analyzer/vfunc-4.C: New test. * g++.dg/analyzer/vfunc-5.C: New test.
-rw-r--r--gcc/analyzer/region-model.cc5
-rw-r--r--gcc/testsuite/g++.dg/analyzer/vfunc-2.C44
-rw-r--r--gcc/testsuite/g++.dg/analyzer/vfunc-3.C32
-rw-r--r--gcc/testsuite/g++.dg/analyzer/vfunc-4.C28
-rw-r--r--gcc/testsuite/g++.dg/analyzer/vfunc-5.C103
5 files changed, 212 insertions, 0 deletions
diff --git a/gcc/analyzer/region-model.cc b/gcc/analyzer/region-model.cc
index 2316fbe..822e893 100644
--- a/gcc/analyzer/region-model.cc
+++ b/gcc/analyzer/region-model.cc
@@ -1841,6 +1841,11 @@ region_model::get_rvalue_1 (path_var pv, region_model_context *ctxt) const
const region *ref_reg = get_lvalue (pv, ctxt);
return get_store_value (ref_reg, ctxt);
}
+ case OBJ_TYPE_REF:
+ {
+ tree expr = OBJ_TYPE_REF_EXPR (pv.m_tree);
+ return get_rvalue (expr, ctxt);
+ }
}
}
diff --git a/gcc/testsuite/g++.dg/analyzer/vfunc-2.C b/gcc/testsuite/g++.dg/analyzer/vfunc-2.C
new file mode 100644
index 0000000..46b68e5
--- /dev/null
+++ b/gcc/testsuite/g++.dg/analyzer/vfunc-2.C
@@ -0,0 +1,44 @@
+#include <cstdio>
+#include <cstdlib>
+
+struct A
+{
+ int m_data;
+ A() {m_data = 0;}
+ virtual int deallocate (void)
+ {
+ return 42;
+ }
+};
+
+struct B: public A
+{
+ int *ptr;
+ int m_data_b;
+ B() {m_data_b = 0;}
+ void allocate ()
+ {
+ ptr = (int*)malloc(sizeof(int));
+ }
+ int deallocate (void)
+ {
+ free(ptr);
+ return 0;
+ }
+};
+
+void foo(A *a_ptr)
+{
+ printf("%d\n",a_ptr->deallocate());
+}
+
+void test()
+{
+ B b;
+ A a, *aptr;
+ aptr = &b;
+ b.allocate();
+ foo(aptr);
+ aptr = &a;
+ foo(aptr);
+}
diff --git a/gcc/testsuite/g++.dg/analyzer/vfunc-3.C b/gcc/testsuite/g++.dg/analyzer/vfunc-3.C
new file mode 100644
index 0000000..03d3cdc
--- /dev/null
+++ b/gcc/testsuite/g++.dg/analyzer/vfunc-3.C
@@ -0,0 +1,32 @@
+#include <cstdlib>
+
+struct A
+{
+ virtual int foo (void)
+ {
+ return 42;
+ }
+};
+
+struct B: public A
+{
+ int *ptr;
+ void alloc ()
+ {
+ ptr = (int*)malloc(sizeof(int));
+ }
+ int foo (void)
+ {
+ free(ptr); /* { dg-warning "double-'free' of 'b.B::ptr'" } */
+ return 0;
+ }
+};
+
+int test ()
+{
+ struct B b, *bptr=&b;
+ b.alloc ();
+ bptr->foo (); /* { dg-message "\\(6\\) calling 'B::foo' from 'test'" "event 6" } */
+ /* { dg-message "\\(9\\) returning to 'test' from 'B::foo'" "event 9" { target *-*-* } .-1 } */
+ return bptr->foo ();
+}
diff --git a/gcc/testsuite/g++.dg/analyzer/vfunc-4.C b/gcc/testsuite/g++.dg/analyzer/vfunc-4.C
new file mode 100644
index 0000000..9751084
--- /dev/null
+++ b/gcc/testsuite/g++.dg/analyzer/vfunc-4.C
@@ -0,0 +1,28 @@
+#include "../../gcc.dg/analyzer/analyzer-decls.h"
+
+struct A
+{
+ int m_data;
+ virtual char foo ()
+ {
+ return 'A';
+ }
+};
+
+struct B: public A
+{
+ int m_data_b;
+ char foo ()
+ {
+ return 'B';
+ }
+};
+
+void test()
+{
+ A a, *a_ptr = &a;
+ B b;
+ __analyzer_eval (a_ptr->foo () == 'A'); /* { dg-warning "TRUE" } */
+ a_ptr = &b;
+ __analyzer_eval (a_ptr->foo () == 'B'); /* { dg-warning "TRUE" } */
+}
diff --git a/gcc/testsuite/g++.dg/analyzer/vfunc-5.C b/gcc/testsuite/g++.dg/analyzer/vfunc-5.C
new file mode 100644
index 0000000..2af8465
--- /dev/null
+++ b/gcc/testsuite/g++.dg/analyzer/vfunc-5.C
@@ -0,0 +1,103 @@
+/* { dg-additional-options "-fdiagnostics-show-line-numbers -fdiagnostics-path-format=inline-events -fanalyzer-checker=malloc -fdiagnostics-show-caret" } */
+/* { dg-enable-nn-line-numbers "" } */
+
+#include <cstdlib>
+
+struct Base
+{
+ virtual void allocate ();
+ virtual void deallocate ();
+};
+
+struct Derived: public Base
+{
+ int *ptr;
+ void allocate ()
+ {
+ ptr = (int*)malloc(sizeof(int));
+ }
+ void deallocate ()
+ {
+ free(ptr);
+ }
+};
+
+void test()
+{
+ Derived D;
+ Base B, *base_ptr;
+ base_ptr = &D;
+
+ D.allocate();
+ base_ptr->deallocate();
+ int n = *D.ptr; /* { dg-warning "use after 'free' of 'D.Derived::ptr'" } */
+}
+
+/* use after 'free' */
+/* { dg-begin-multiline-output "" }
+ NN | int n = *D.ptr;
+ | ^
+ 'void test()': events 1-2
+ |
+ | NN | void test()
+ | | ^~~~
+ | | |
+ | | (1) entry to 'test'
+ |......
+ | NN | D.allocate();
+ | | ~~~~~~~~~~~~
+ | | |
+ | | (2) calling 'Derived::allocate' from 'test'
+ |
+ +--> 'virtual void Derived::allocate()': events 3-4
+ |
+ | NN | void allocate ()
+ | | ^~~~~~~~
+ | | |
+ | | (3) entry to 'Derived::allocate'
+ | NN | {
+ | NN | ptr = (int*)malloc(sizeof(int));
+ | | ~~~~~~~~~~~~~~~~~~~
+ | | |
+ | | (4) allocated here
+ |
+ <------+
+ |
+ 'void test()': events 5-6
+ |
+ | NN | D.allocate();
+ | | ~~~~~~~~~~^~
+ | | |
+ | | (5) returning to 'test' from 'Derived::allocate'
+ | NN | base_ptr->deallocate();
+ | | ~~~~~~~~~~~~~~~~~~~~~~
+ | | |
+ | | (6) calling 'Derived::deallocate' from 'test'
+ |
+ +--> 'virtual void Derived::deallocate()': events 7-8
+ |
+ | NN | void deallocate ()
+ | | ^~~~~~~~~~
+ | | |
+ | | (7) entry to 'Derived::deallocate'
+ | NN | {
+ | NN | free(ptr);
+ | | ~~~~~~~~~
+ | | |
+ | | (8) freed here
+ |
+ <------+
+ |
+ 'void test()': events 9-10
+ |
+ | NN | base_ptr->deallocate();
+ | | ~~~~~~~~~~~~~~~~~~~~^~
+ | | |
+ | | (9) returning to 'test' from 'Derived::deallocate'
+ | NN | int n = *D.ptr;
+ | | ~
+ | | |
+ | | (10) use after 'free' of 'D.Derived::ptr'; freed at (8)
+ |
+ { dg-end-multiline-output "" } */
+