1 // UndefCapturedBlockVarChecker.cpp - Uninitialized captured vars -*- C++ -*-=//
3 // Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
4 // See https://llvm.org/LICENSE.txt for license information.
5 // SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
7 //===----------------------------------------------------------------------===//
9 // This checker detects blocks that capture uninitialized values.
11 //===----------------------------------------------------------------------===//
13 #include "clang/StaticAnalyzer/Checkers/BuiltinCheckerRegistration.h"
14 #include "clang/AST/Attr.h"
15 #include "clang/StaticAnalyzer/Core/BugReporter/BugType.h"
16 #include "clang/StaticAnalyzer/Core/Checker.h"
17 #include "clang/StaticAnalyzer/Core/CheckerManager.h"
18 #include "clang/StaticAnalyzer/Core/PathSensitive/CheckerContext.h"
19 #include "clang/StaticAnalyzer/Core/PathSensitive/ExprEngine.h"
20 #include "llvm/ADT/SmallString.h"
21 #include "llvm/Support/raw_ostream.h"
24 using namespace clang
;
28 class UndefCapturedBlockVarChecker
29 : public Checker
< check::PostStmt
<BlockExpr
> > {
30 mutable std::unique_ptr
<BugType
> BT
;
33 void checkPostStmt(const BlockExpr
*BE
, CheckerContext
&C
) const;
35 } // end anonymous namespace
37 static const DeclRefExpr
*FindBlockDeclRefExpr(const Stmt
*S
,
39 if (const DeclRefExpr
*BR
= dyn_cast
<DeclRefExpr
>(S
))
40 if (BR
->getDecl() == VD
)
43 for (const Stmt
*Child
: S
->children())
45 if (const DeclRefExpr
*BR
= FindBlockDeclRefExpr(Child
, VD
))
52 UndefCapturedBlockVarChecker::checkPostStmt(const BlockExpr
*BE
,
53 CheckerContext
&C
) const {
54 if (!BE
->getBlockDecl()->hasCaptures())
57 ProgramStateRef state
= C
.getState();
58 auto *R
= cast
<BlockDataRegion
>(C
.getSVal(BE
).getAsRegion());
60 BlockDataRegion::referenced_vars_iterator I
= R
->referenced_vars_begin(),
61 E
= R
->referenced_vars_end();
64 // This VarRegion is the region associated with the block; we need
65 // the one associated with the encompassing context.
66 const VarRegion
*VR
= I
.getCapturedRegion();
67 const VarDecl
*VD
= VR
->getDecl();
69 if (VD
->hasAttr
<BlocksAttr
>() || !VD
->hasLocalStorage())
72 // Get the VarRegion associated with VD in the local stack frame.
73 if (std::optional
<UndefinedVal
> V
=
74 state
->getSVal(I
.getOriginalRegion()).getAs
<UndefinedVal
>()) {
75 if (ExplodedNode
*N
= C
.generateErrorNode()) {
78 new BuiltinBug(this, "uninitialized variable captured by block"));
80 // Generate a bug report.
82 llvm::raw_svector_ostream
os(buf
);
84 os
<< "Variable '" << VD
->getName()
85 << "' is uninitialized when captured by block";
87 auto R
= std::make_unique
<PathSensitiveBugReport
>(*BT
, os
.str(), N
);
88 if (const Expr
*Ex
= FindBlockDeclRefExpr(BE
->getBody(), VD
))
89 R
->addRange(Ex
->getSourceRange());
90 bugreporter::trackStoredValue(*V
, VR
, *R
,
91 {bugreporter::TrackingKind::Thorough
,
92 /*EnableNullFPSuppression*/ false});
93 R
->disablePathPruning();
94 // need location of block
95 C
.emitReport(std::move(R
));
101 void ento::registerUndefCapturedBlockVarChecker(CheckerManager
&mgr
) {
102 mgr
.registerChecker
<UndefCapturedBlockVarChecker
>();
105 bool ento::shouldRegisterUndefCapturedBlockVarChecker(const CheckerManager
&mgr
) {