File: ReturnConstRefFromParameterCheck.cpp

package info (click to toggle)
llvm-toolchain-19 1%3A19.1.7-3
  • links: PTS, VCS
  • area: main
  • in suites: forky, sid, trixie
  • size: 1,998,520 kB
  • sloc: cpp: 6,951,680; ansic: 1,486,157; asm: 913,598; python: 232,024; f90: 80,126; objc: 75,281; lisp: 37,276; pascal: 16,990; sh: 10,009; ml: 5,058; perl: 4,724; awk: 3,523; makefile: 3,167; javascript: 2,504; xml: 892; fortran: 664; cs: 573
file content (102 lines) | stat: -rw-r--r-- 3,675 bytes parent folder | download | duplicates (3)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
//===--- ReturnConstRefFromParameterCheck.cpp - clang-tidy ----------------===//
//
// Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
// See https://llvm.org/LICENSE.txt for license information.
// SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
//
//===----------------------------------------------------------------------===//

#include "ReturnConstRefFromParameterCheck.h"
#include "clang/ASTMatchers/ASTMatchFinder.h"
#include "clang/ASTMatchers/ASTMatchers.h"

using namespace clang::ast_matchers;

namespace clang::tidy::bugprone {

void ReturnConstRefFromParameterCheck::registerMatchers(MatchFinder *Finder) {
  Finder->addMatcher(
      returnStmt(
          hasReturnValue(declRefExpr(
              to(parmVarDecl(hasType(hasCanonicalType(
                                 qualType(lValueReferenceType(pointee(
                                              qualType(isConstQualified()))))
                                     .bind("type"))))
                     .bind("param")))),
          hasAncestor(
              functionDecl(hasReturnTypeLoc(loc(qualType(
                               hasCanonicalType(equalsBoundNode("type"))))))
                  .bind("func")))
          .bind("ret"),
      this);
}

static bool isSameTypeIgnoringConst(QualType A, QualType B) {
  return A.getCanonicalType().withConst() == B.getCanonicalType().withConst();
}

static bool isSameTypeIgnoringConstRef(QualType A, QualType B) {
  return isSameTypeIgnoringConst(A.getCanonicalType().getNonReferenceType(),
                                 B.getCanonicalType().getNonReferenceType());
}

static bool hasSameParameterTypes(const FunctionDecl &FD, const FunctionDecl &O,
                                  const ParmVarDecl &PD) {
  if (FD.getNumParams() != O.getNumParams())
    return false;
  for (unsigned I = 0, E = FD.getNumParams(); I < E; ++I) {
    const ParmVarDecl *DPD = FD.getParamDecl(I);
    const QualType OPT = O.getParamDecl(I)->getType();
    if (DPD == &PD) {
      if (!llvm::isa<RValueReferenceType>(OPT) ||
          !isSameTypeIgnoringConstRef(DPD->getType(), OPT))
        return false;
    } else {
      if (!isSameTypeIgnoringConst(DPD->getType(), OPT))
        return false;
    }
  }
  return true;
}

static const Decl *findRVRefOverload(const FunctionDecl &FD,
                                     const ParmVarDecl &PD) {
  // Actually it would be better to do lookup in caller site.
  // But in most of cases, overloads of LVRef and RVRef will appear together.
  // FIXME:
  // 1. overload in anonymous namespace
  // 2. forward reference
  DeclContext::lookup_result LookupResult =
      FD.getParent()->lookup(FD.getNameInfo().getName());
  if (LookupResult.isSingleResult()) {
    return nullptr;
  }
  for (const Decl *Overload : LookupResult) {
    if (Overload == &FD)
      continue;
    if (const auto *O = dyn_cast<FunctionDecl>(Overload))
      if (hasSameParameterTypes(FD, *O, PD))
        return O;
  }
  return nullptr;
}

void ReturnConstRefFromParameterCheck::check(
    const MatchFinder::MatchResult &Result) {
  const auto *FD = Result.Nodes.getNodeAs<FunctionDecl>("func");
  const auto *PD = Result.Nodes.getNodeAs<ParmVarDecl>("param");
  const auto *R = Result.Nodes.getNodeAs<ReturnStmt>("ret");
  const SourceRange Range = R->getRetValue()->getSourceRange();
  if (Range.isInvalid())
    return;

  if (findRVRefOverload(*FD, *PD) != nullptr)
    return;

  diag(Range.getBegin(),
       "returning a constant reference parameter may cause use-after-free "
       "when the parameter is constructed from a temporary")
      << Range;
}

} // namespace clang::tidy::bugprone