Balazs Benics 068d76b480
[analyzer] Fix crash when casting the result of a malformed fptr call (#111390)
Ideally, we wouldn't workaround our current cast-modeling, but the
experimental "support-symbolic-integer-casts" is not finished so we need
to live with our current modeling.

Ideally, we could probably bind `UndefinedVal` as the result of the call
even without evaluating the call, as the result types mismatch between
the static type of the `CallExpr` and the actually function that happens
to be called.

Nevertheless, let's not crash.
https://compiler-explorer.com/z/WvcqK6MbY

CPP-5768
2024-10-09 11:39:56 +02:00

166 lines
4.3 KiB
C

// This test checks that intersecting ranges does not cause 'system is over constrained' assertions in the case of eg: 32 bits unsigned integers getting their range from 64 bits signed integers.
// RUN: %clang_analyze_cc1 -triple x86_64-pc-linux-gnu -analyzer-checker=core,debug.ExprInspection -verify %s
void clang_analyzer_warnIfReached(void);
void f1(long foo)
{
unsigned index = -1;
if (index < foo) index = foo;
if (index + 1 == 0) // because of foo range, index is in range [0; UINT_MAX]
clang_analyzer_warnIfReached(); // expected-warning{{REACHABLE}}
else
clang_analyzer_warnIfReached(); // expected-warning{{REACHABLE}}
}
void f2(unsigned long foo)
{
int index = -1;
if (index < foo) index = foo; // index equals ULONG_MAX
if (index + 1 == 0)
clang_analyzer_warnIfReached(); // expected-warning{{REACHABLE}}
else
clang_analyzer_warnIfReached(); // no-warning
}
void f3(unsigned long foo)
{
unsigned index = -1;
if (index < foo) index = foo;
if (index + 1 == 0)
clang_analyzer_warnIfReached(); // expected-warning{{REACHABLE}}
else
clang_analyzer_warnIfReached(); // expected-warning{{REACHABLE}}
}
void f4(long foo)
{
int index = -1;
if (index < foo) index = foo;
if (index + 1 == 0)
clang_analyzer_warnIfReached(); // expected-warning{{REACHABLE}}
else
clang_analyzer_warnIfReached(); // expected-warning{{REACHABLE}}
}
void f5(long foo)
{
unsigned index = -1;
if (index < foo) index = foo;
if (index == -1)
clang_analyzer_warnIfReached(); // expected-warning{{REACHABLE}}
else
clang_analyzer_warnIfReached(); // expected-warning{{REACHABLE}}
}
void f6(long foo)
{
unsigned index = -1;
if (index < foo) index = foo;
if (index == -1)
clang_analyzer_warnIfReached(); // expected-warning{{REACHABLE}}
else
clang_analyzer_warnIfReached(); // expected-warning{{REACHABLE}}
}
void f7(long foo)
{
unsigned index = -1;
if (index < foo) index = foo;
if (index - 1 == 0) // Was not reached prior fix.
clang_analyzer_warnIfReached(); // expected-warning{{REACHABLE}}
else
clang_analyzer_warnIfReached(); // expected-warning{{REACHABLE}}
}
void f8(long foo)
{
unsigned index = -1;
if (index < foo) index = foo;
if (index + 1L == 0L)
clang_analyzer_warnIfReached(); // no-warning
else
clang_analyzer_warnIfReached(); // expected-warning{{REACHABLE}}
}
void f9(long foo)
{
unsigned index = -1;
if (index < foo) index = foo;
if (index - 1L == 0L) // Was not reached prior fix.
clang_analyzer_warnIfReached(); // expected-warning{{REACHABLE}}
else
clang_analyzer_warnIfReached(); // expected-warning{{REACHABLE}}
}
void f10(long foo)
{
unsigned index = -1;
if (index < foo) index = foo;
if (index + 1 == 0L)
clang_analyzer_warnIfReached(); // expected-warning{{REACHABLE}}
else
clang_analyzer_warnIfReached(); // expected-warning{{REACHABLE}}
}
void f11(long foo)
{
unsigned index = -1;
if (index < foo) index = foo;
if (index + 1UL == 0L)
clang_analyzer_warnIfReached(); // no-warning
else
clang_analyzer_warnIfReached(); // expected-warning{{REACHABLE}}
}
void f12(long foo)
{
unsigned index = -1;
if (index < foo) index = foo;
if (index - 1UL == 0L) // Was not reached prior fix.
clang_analyzer_warnIfReached(); // expected-warning{{REACHABLE}}
else
clang_analyzer_warnIfReached(); // expected-warning{{REACHABLE}}
}
void f13(int foo)
{
unsigned short index = -1;
if (index < foo) index = foo;
if (index + 1 == 0)
clang_analyzer_warnIfReached(); // no-warning
else
clang_analyzer_warnIfReached(); // expected-warning{{REACHABLE}}
}
void f14(long foo)
{
unsigned index = -1;
if (index < foo) index = foo;
long bar = foo;
if (index + 1 == 0)
clang_analyzer_warnIfReached(); // expected-warning{{REACHABLE}}
else
clang_analyzer_warnIfReached(); // expected-warning{{REACHABLE}}
}
void f15(long foo)
{
unsigned index = -1;
if (index < foo) index = foo;
unsigned int tmp = index + 1;
if (tmp == 0)
clang_analyzer_warnIfReached(); // expected-warning{{REACHABLE}}
else
clang_analyzer_warnIfReached(); // expected-warning{{REACHABLE}}
}
int *getIntPtr(void) {
extern int *intPtr;
return intPtr;
}
char call_malformed_fptr() {
int (*fptr)(void) = (int (*)(void))getIntPtr;
return fptr(); // no-crash
}