diff options
| author | Tim Lange <mail@tim-lange.me> | 2022-08-12 10:27:16 +0200 | 
|---|---|---|
| committer | Tim Lange <mail@tim-lange.me> | 2022-08-12 10:46:12 +0200 | 
| commit | 7e3b45befdbbf1a1f9ff728fa2bac31b4756907c (patch) | |
| tree | 6312f12e99ee27d3827ce85d61bc2036dca97c92 /libcpp/identifiers.cc | |
| parent | 2b75b3b6a4ddc0d65a84a0cc4b00c47ae70e52c0 (diff) | |
| download | gcc-7e3b45befdbbf1a1f9ff728fa2bac31b4756907c.zip gcc-7e3b45befdbbf1a1f9ff728fa2bac31b4756907c.tar.gz gcc-7e3b45befdbbf1a1f9ff728fa2bac31b4756907c.tar.bz2 | |
analyzer: out-of-bounds checker [PR106000]
This patch adds an experimental out-of-bounds checker to the analyzer.
The checker was tested on coreutils, curl, httpd and openssh. It is mostly
accurate but does produce false-positives on yacc-generated files and
sometimes when the analyzer misses an invariant. These cases will be
documented in bugzilla.
Regression-tested on Linux x86-64, further ran the analyzer tests with
the -m32 option.
2022-08-11  Tim Lange  <mail@tim-lange.me>
gcc/analyzer/ChangeLog:
	PR analyzer/106000
	* analyzer.opt: Add Wanalyzer-out-of-bounds.
	* region-model.cc (class out_of_bounds): Diagnostics base class
	for all out-of-bounds diagnostics.
	(class past_the_end): Base class derived from out_of_bounds for
	the buffer_overflow and buffer_overread diagnostics.
	(class buffer_overflow): Buffer overflow diagnostics.
	(class buffer_overread): Buffer overread diagnostics.
	(class buffer_underflow): Buffer underflow diagnostics.
	(class buffer_underread): Buffer overread diagnostics.
	(region_model::check_region_bounds): New function to check region
	bounds for out-of-bounds accesses.
	(region_model::check_region_access):
	Add call to check_region_bounds.
	(region_model::get_representative_tree): New function that accepts
	a region instead of an svalue.
	* region-model.h (class region_model):
	Add region_model::check_region_bounds.
	* region.cc (region::symbolic_p): New predicate.
	(offset_region::get_byte_size_sval): Only return the remaining
	byte size on offset_regions.
	* region.h: Add region::symbolic_p.
	* store.cc (byte_range::intersects_p):
	Add new function equivalent to bit_range::intersects_p.
	(byte_range::exceeds_p): New function.
	(byte_range::falls_short_of_p): New function.
	* store.h (struct byte_range): Add byte_range::intersects_p,
	byte_range::exceeds_p and byte_range::falls_short_of_p.
gcc/ChangeLog:
	PR analyzer/106000
	* doc/invoke.texi: Add Wanalyzer-out-of-bounds.
gcc/testsuite/ChangeLog:
	PR analyzer/106000
	* g++.dg/analyzer/pr100244.C: Disable out-of-bounds warning.
	* gcc.dg/analyzer/allocation-size-3.c:
	Disable out-of-bounds warning.
	* gcc.dg/analyzer/memcpy-2.c: Disable out-of-bounds warning.
	* gcc.dg/analyzer/pr101962.c: Add dg-warning.
	* gcc.dg/analyzer/pr96764.c: Disable out-of-bounds warning.
	* gcc.dg/analyzer/pr97029.c:
	Add dummy buffer to prevent an out-of-bounds warning.
	* gcc.dg/analyzer/realloc-5.c: Add dg-warning.
	* gcc.dg/analyzer/test-setjmp.h:
	Add dummy buffer to prevent an out-of-bounds warning.
	* gcc.dg/analyzer/zlib-3.c: Add dg-bogus.
	* g++.dg/analyzer/out-of-bounds-placement-new.C: New test.
	* gcc.dg/analyzer/out-of-bounds-1.c: New test.
	* gcc.dg/analyzer/out-of-bounds-2.c: New test.
	* gcc.dg/analyzer/out-of-bounds-3.c: New test.
	* gcc.dg/analyzer/out-of-bounds-container_of.c: New test.
	* gcc.dg/analyzer/out-of-bounds-coreutils.c: New test.
	* gcc.dg/analyzer/out-of-bounds-curl.c: New test.
Diffstat (limited to 'libcpp/identifiers.cc')
0 files changed, 0 insertions, 0 deletions
