1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225
|
// RUN: %clang_analyze_cc1 -analyzer-checker=core,debug.ExprInspection -std=c++17 -verify %s
void clang_analyzer_eval(bool);
void array_init() {
int arr[] = {1, 2, 3, 4, 5};
auto [a, b, c, d, e] = arr;
clang_analyzer_eval(a == 1); // expected-warning{{TRUE}}
clang_analyzer_eval(b == 2); // expected-warning{{TRUE}}
clang_analyzer_eval(c == 3); // expected-warning{{TRUE}}
clang_analyzer_eval(d == 4); // expected-warning{{TRUE}}
clang_analyzer_eval(e == 5); // expected-warning{{TRUE}}
}
void array_uninit() {
int arr[5];
auto [a, b, c, d, e] = arr;
int x = e; // expected-warning{{Assigned value is garbage or undefined}}
}
void lambda_init() {
int arr[] = {1, 2, 3, 4, 5};
auto l = [arr] { return arr[0]; }();
clang_analyzer_eval(l == 1); // expected-warning{{TRUE}}
l = [arr] { return arr[1]; }();
clang_analyzer_eval(l == 2); // expected-warning{{TRUE}}
l = [arr] { return arr[2]; }();
clang_analyzer_eval(l == 3); // expected-warning{{TRUE}}
l = [arr] { return arr[3]; }();
clang_analyzer_eval(l == 4); // expected-warning{{TRUE}}
l = [arr] { return arr[4]; }();
clang_analyzer_eval(l == 5); // expected-warning{{TRUE}}
}
void lambda_uninit() {
int arr[5];
// FIXME: These should be Undefined, but we fail to read Undefined from a lazyCompoundVal
int l = [arr] { return arr[0]; }();
clang_analyzer_eval(l); // expected-warning{{UNKNOWN}}
l = [arr] { return arr[1]; }();
clang_analyzer_eval(l); // expected-warning{{UNKNOWN}}
l = [arr] { return arr[2]; }();
clang_analyzer_eval(l); // expected-warning{{UNKNOWN}}
l = [arr] { return arr[3]; }();
clang_analyzer_eval(l); // expected-warning{{UNKNOWN}}
l = [arr] { return arr[4]; }();
clang_analyzer_eval(l); // expected-warning{{UNKNOWN}}
}
struct S {
int arr[5];
};
void copy_ctor_init() {
S orig;
orig.arr[0] = 1;
orig.arr[1] = 2;
orig.arr[2] = 3;
orig.arr[3] = 4;
orig.arr[4] = 5;
S copy = orig;
clang_analyzer_eval(copy.arr[0] == 1); // expected-warning{{TRUE}}
clang_analyzer_eval(copy.arr[1] == 2); // expected-warning{{TRUE}}
clang_analyzer_eval(copy.arr[2] == 3); // expected-warning{{TRUE}}
clang_analyzer_eval(copy.arr[3] == 4); // expected-warning{{TRUE}}
clang_analyzer_eval(copy.arr[4] == 5); // expected-warning{{TRUE}}
}
void copy_ctor_uninit() {
S orig;
S copy = orig;
// FIXME: These should be Undefined, but we fail to read Undefined from a lazyCompoundVal.
// If the struct is not considered a small struct, instead of a copy, we store a lazy compound value.
// As the struct has an array data member, it is not considered small.
clang_analyzer_eval(copy.arr[0]); // expected-warning{{UNKNOWN}}
clang_analyzer_eval(copy.arr[1]); // expected-warning{{UNKNOWN}}
clang_analyzer_eval(copy.arr[2]); // expected-warning{{UNKNOWN}}
clang_analyzer_eval(copy.arr[3]); // expected-warning{{UNKNOWN}}
clang_analyzer_eval(copy.arr[4]); // expected-warning{{UNKNOWN}}
}
void move_ctor_init() {
S orig;
orig.arr[0] = 1;
orig.arr[1] = 2;
orig.arr[2] = 3;
orig.arr[3] = 4;
orig.arr[4] = 5;
S moved = (S &&) orig;
clang_analyzer_eval(moved.arr[0] == 1); // expected-warning{{TRUE}}
clang_analyzer_eval(moved.arr[1] == 2); // expected-warning{{TRUE}}
clang_analyzer_eval(moved.arr[2] == 3); // expected-warning{{TRUE}}
clang_analyzer_eval(moved.arr[3] == 4); // expected-warning{{TRUE}}
clang_analyzer_eval(moved.arr[4] == 5); // expected-warning{{TRUE}}
}
void move_ctor_uninit() {
S orig;
S moved = (S &&) orig;
// FIXME: These should be Undefined, but we fail to read Undefined from a lazyCompoundVal.
clang_analyzer_eval(moved.arr[0]); // expected-warning{{UNKNOWN}}
clang_analyzer_eval(moved.arr[1]); // expected-warning{{UNKNOWN}}
clang_analyzer_eval(moved.arr[2]); // expected-warning{{UNKNOWN}}
clang_analyzer_eval(moved.arr[3]); // expected-warning{{UNKNOWN}}
clang_analyzer_eval(moved.arr[4]); // expected-warning{{UNKNOWN}}
}
// The struct has a user defined copy and move ctor, which allow us to
// track the values more precisely when an array of this struct is being
// copy/move initialized by ArrayInitLoopExpr.
struct S2 {
inline static int c = 0;
int i;
S2() : i(++c) {}
S2(const S2 ©) {
i = copy.i + 1;
}
S2(S2 &&move) {
i = move.i + 2;
}
};
void array_init_non_pod() {
S2::c = 0;
S2 arr[4];
auto [a, b, c, d] = arr;
clang_analyzer_eval(a.i == 2); // expected-warning{{TRUE}}
clang_analyzer_eval(b.i == 3); // expected-warning{{TRUE}}
clang_analyzer_eval(c.i == 4); // expected-warning{{TRUE}}
clang_analyzer_eval(d.i == 5); // expected-warning{{TRUE}}
}
struct S3 {
int i;
};
// The duplicate is required to emit a warning at 2 different places.
struct S3_duplicate {
int i;
};
void array_uninit_non_pod() {
S3 arr[1];
auto [a] = arr; // expected-warning@159{{ in implicit constructor is garbage or undefined }}
}
void lambda_init_non_pod() {
S2::c = 0;
S2 arr[4];
auto l = [arr] { return arr[0].i; }();
clang_analyzer_eval(l == 2); // expected-warning{{TRUE}}
l = [arr] { return arr[1].i; }();
clang_analyzer_eval(l == 3); // expected-warning{{TRUE}}
l = [arr] { return arr[2].i; }();
clang_analyzer_eval(l == 4); // expected-warning{{TRUE}}
l = [arr] { return arr[3].i; }();
clang_analyzer_eval(l == 5); // expected-warning{{TRUE}}
}
void lambda_uninit_non_pod() {
S3_duplicate arr[4];
int l = [arr] { return arr[3].i; }(); // expected-warning@164{{ in implicit constructor is garbage or undefined }}
}
// If this struct is being copy/move constructed by the implicit ctors, ArrayInitLoopExpr
// is responsible for the initialization of 'arr' by copy/move constructing each of the
// elements.
struct S5 {
S2 arr[4];
};
void copy_ctor_init_non_pod() {
S2::c = 0;
S5 orig;
S5 copy = orig;
clang_analyzer_eval(copy.arr[0].i == 2); // expected-warning{{TRUE}}
clang_analyzer_eval(copy.arr[1].i == 3); // expected-warning{{TRUE}}
clang_analyzer_eval(copy.arr[2].i == 4); // expected-warning{{TRUE}}
clang_analyzer_eval(copy.arr[3].i == 5); // expected-warning{{TRUE}}
}
void move_ctor_init_non_pod() {
S2::c = 0;
S5 orig;
S5 moved = (S5 &&) orig;
clang_analyzer_eval(moved.arr[0].i == 3); // expected-warning{{TRUE}}
clang_analyzer_eval(moved.arr[1].i == 4); // expected-warning{{TRUE}}
clang_analyzer_eval(moved.arr[2].i == 5); // expected-warning{{TRUE}}
clang_analyzer_eval(moved.arr[3].i == 6); // expected-warning{{TRUE}}
}
|