2009-03-19 20:55:50 +01:00
|
|
|
/*
|
|
|
|
* Cppcheck - A tool for static C/C++ code analysis
|
2011-01-09 20:33:36 +01:00
|
|
|
* Copyright (C) 2007-2011 Daniel Marjamäki and Cppcheck team.
|
2009-03-19 20:55:50 +01:00
|
|
|
*
|
|
|
|
* This program is free software: you can redistribute it and/or modify
|
|
|
|
* it under the terms of the GNU General Public License as published by
|
|
|
|
* the Free Software Foundation, either version 3 of the License, or
|
|
|
|
* (at your option) any later version.
|
|
|
|
*
|
|
|
|
* This program is distributed in the hope that it will be useful,
|
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
* GNU General Public License for more details.
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU General Public License
|
2009-09-27 17:08:31 +02:00
|
|
|
* along with this program. If not, see <http://www.gnu.org/licenses/>.
|
2009-03-19 20:55:50 +01:00
|
|
|
*/
|
|
|
|
|
|
|
|
//---------------------------------------------------------------------------
|
2009-05-22 07:51:30 +02:00
|
|
|
// Auto variables checks
|
2009-03-19 20:55:50 +01:00
|
|
|
//---------------------------------------------------------------------------
|
|
|
|
|
|
|
|
#include "checkautovariables.h"
|
2011-01-16 19:57:29 +01:00
|
|
|
#include "symboldatabase.h"
|
2009-03-19 20:55:50 +01:00
|
|
|
|
|
|
|
#include <sstream>
|
|
|
|
#include <iostream>
|
|
|
|
#include <string>
|
|
|
|
|
|
|
|
//---------------------------------------------------------------------------
|
|
|
|
|
|
|
|
|
|
|
|
// Register this check class into cppcheck by creating a static instance of it..
|
|
|
|
namespace
|
|
|
|
{
|
|
|
|
static CheckAutoVariables instance;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2009-03-22 08:01:48 +01:00
|
|
|
bool CheckAutoVariables::errorAv(const Token* left, const Token* right)
|
2009-03-19 20:55:50 +01:00
|
|
|
{
|
2011-04-23 15:50:56 +02:00
|
|
|
const Variable *var = _tokenizer->getSymbolDatabase()->getVariableFromVarId(left->varId());
|
|
|
|
|
|
|
|
if (!var || !var->isArgument())
|
2009-03-22 08:01:48 +01:00
|
|
|
return false;
|
2009-03-19 20:55:50 +01:00
|
|
|
|
2009-08-16 11:10:42 +02:00
|
|
|
return isAutoVar(right->varId());
|
2009-03-19 20:55:50 +01:00
|
|
|
}
|
2009-07-27 19:34:17 +02:00
|
|
|
|
2009-08-16 10:46:52 +02:00
|
|
|
bool CheckAutoVariables::isAutoVar(unsigned int varId)
|
2009-03-19 20:55:50 +01:00
|
|
|
{
|
2011-04-23 15:50:56 +02:00
|
|
|
const Variable *var = _tokenizer->getSymbolDatabase()->getVariableFromVarId(varId);
|
2009-08-16 11:43:04 +02:00
|
|
|
|
2011-04-23 15:50:56 +02:00
|
|
|
if (!var || !var->isLocal() || var->isStatic() || var->isArray())
|
2009-08-16 11:43:04 +02:00
|
|
|
return false;
|
|
|
|
|
2011-04-23 15:50:56 +02:00
|
|
|
return true;
|
2009-08-09 15:40:04 +02:00
|
|
|
}
|
|
|
|
|
2011-04-23 15:50:56 +02:00
|
|
|
bool CheckAutoVariables::isAutoVarArray(unsigned int varId)
|
2009-03-21 18:36:41 +01:00
|
|
|
{
|
2011-04-23 15:50:56 +02:00
|
|
|
const Variable *var = _tokenizer->getSymbolDatabase()->getVariableFromVarId(varId);
|
2009-07-27 19:34:17 +02:00
|
|
|
|
2011-04-23 15:50:56 +02:00
|
|
|
if (!var || !var->isLocal() || var->isStatic() || !var->isArray())
|
|
|
|
return false;
|
2009-07-27 19:34:17 +02:00
|
|
|
|
2011-04-23 15:50:56 +02:00
|
|
|
return true;
|
2009-08-09 15:40:04 +02:00
|
|
|
}
|
|
|
|
|
2009-03-19 20:55:50 +01:00
|
|
|
void CheckAutoVariables::autoVariables()
|
|
|
|
{
|
2011-02-08 01:26:34 +01:00
|
|
|
const SymbolDatabase *symbolDatabase = _tokenizer->getSymbolDatabase();
|
2009-03-19 20:55:50 +01:00
|
|
|
|
2011-03-11 01:43:29 +01:00
|
|
|
std::list<Scope>::const_iterator scope;
|
2010-10-22 21:12:28 +02:00
|
|
|
|
2011-03-11 01:43:29 +01:00
|
|
|
for (scope = symbolDatabase->scopeList.begin(); scope != symbolDatabase->scopeList.end(); ++scope)
|
2009-03-19 20:55:50 +01:00
|
|
|
{
|
2011-02-08 01:26:34 +01:00
|
|
|
// only check functions
|
|
|
|
if (scope->type != Scope::eFunction)
|
2009-08-16 12:53:29 +02:00
|
|
|
continue;
|
|
|
|
|
2011-02-08 01:26:34 +01:00
|
|
|
unsigned int indentlevel = 0;
|
|
|
|
// Which variables have an unknown type?
|
|
|
|
std::set<unsigned int> unknown_type;
|
2011-04-23 15:50:56 +02:00
|
|
|
for (const Token *tok = scope->classDef->next()->link(); tok; tok = tok->next())
|
2009-06-09 19:45:58 +02:00
|
|
|
{
|
2011-02-08 01:26:34 +01:00
|
|
|
// indentlevel..
|
2010-04-02 07:30:58 +02:00
|
|
|
if (tok->str() == "{")
|
2009-06-09 19:45:58 +02:00
|
|
|
++indentlevel;
|
2010-04-02 07:30:58 +02:00
|
|
|
else if (tok->str() == "}")
|
2009-06-09 19:45:58 +02:00
|
|
|
{
|
2011-02-08 01:26:34 +01:00
|
|
|
if (indentlevel <= 1)
|
|
|
|
break;
|
2009-06-09 19:45:58 +02:00
|
|
|
--indentlevel;
|
|
|
|
}
|
|
|
|
|
2011-02-08 01:26:34 +01:00
|
|
|
//Critical assignment
|
2011-04-23 15:50:56 +02:00
|
|
|
if (Token::Match(tok, "[;{}] %var% = & %var%") && errorAv(tok->tokAt(1), tok->tokAt(4)))
|
2009-06-09 19:45:58 +02:00
|
|
|
{
|
2011-02-08 01:26:34 +01:00
|
|
|
errorAutoVariableAssignment(tok);
|
|
|
|
}
|
|
|
|
else if (Token::Match(tok, "[;{}] * %var% = & %var%") && errorAv(tok->tokAt(2), tok->tokAt(5)) &&
|
|
|
|
unknown_type.find(tok->tokAt(5)->varId()) == unknown_type.end())
|
|
|
|
{
|
|
|
|
errorAutoVariableAssignment(tok);
|
|
|
|
}
|
|
|
|
else if (Token::Match(tok, "[;{}] %var% [ %any% ] = & %var%") && errorAv(tok->tokAt(1), tok->tokAt(7)))
|
|
|
|
{
|
|
|
|
errorAutoVariableAssignment(tok);
|
|
|
|
}
|
|
|
|
// Critical return
|
|
|
|
else if (Token::Match(tok, "return & %var% ;") && isAutoVar(tok->tokAt(2)->varId()))
|
|
|
|
{
|
|
|
|
reportError(tok, Severity::error, "autoVariables", "Return of the address of an auto-variable");
|
|
|
|
}
|
|
|
|
// Invalid pointer deallocation
|
|
|
|
else if (Token::Match(tok, "free ( %var% ) ;") && isAutoVarArray(tok->tokAt(2)->varId()))
|
|
|
|
{
|
|
|
|
reportError(tok, Severity::error, "autoVariables", "Invalid deallocation");
|
2009-06-09 19:45:58 +02:00
|
|
|
}
|
|
|
|
}
|
2011-02-08 01:26:34 +01:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
//---------------------------------------------------------------------------
|
|
|
|
|
|
|
|
void CheckAutoVariables::returnPointerToLocalArray()
|
|
|
|
{
|
|
|
|
const SymbolDatabase *symbolDatabase = _tokenizer->getSymbolDatabase();
|
|
|
|
|
2011-03-11 01:43:29 +01:00
|
|
|
std::list<Scope>::const_iterator scope;
|
2011-02-08 01:26:34 +01:00
|
|
|
|
2011-03-11 01:43:29 +01:00
|
|
|
for (scope = symbolDatabase->scopeList.begin(); scope != symbolDatabase->scopeList.end(); ++scope)
|
2011-02-08 01:26:34 +01:00
|
|
|
{
|
|
|
|
// only check functions
|
|
|
|
if (scope->type != Scope::eFunction)
|
|
|
|
continue;
|
|
|
|
|
|
|
|
const Token *tok = scope->classDef;
|
|
|
|
|
|
|
|
// skip any qualification
|
|
|
|
while (Token::Match(tok->tokAt(-2), "%type% ::"))
|
|
|
|
tok = tok->tokAt(-2);
|
|
|
|
|
|
|
|
// have we reached a function that returns a pointer
|
|
|
|
if (Token::Match(tok->tokAt(-2), "%type% *"))
|
|
|
|
{
|
|
|
|
// go to the '('
|
|
|
|
const Token *tok2 = scope->classDef->next();
|
|
|
|
|
|
|
|
// go to the ')'
|
|
|
|
tok2 = tok2->next()->link();
|
|
|
|
|
|
|
|
unsigned int indentlevel = 0;
|
|
|
|
for (; tok2; tok2 = tok2->next())
|
|
|
|
{
|
|
|
|
// indentlevel..
|
|
|
|
if (tok2->str() == "{")
|
|
|
|
++indentlevel;
|
|
|
|
else if (tok2->str() == "}")
|
|
|
|
{
|
|
|
|
if (indentlevel <= 1)
|
|
|
|
break;
|
|
|
|
--indentlevel;
|
|
|
|
}
|
2009-06-09 19:45:58 +02:00
|
|
|
|
2011-02-08 01:26:34 +01:00
|
|
|
// Return pointer to local array variable..
|
|
|
|
if (Token::Match(tok2, "return %var% ;"))
|
|
|
|
{
|
|
|
|
const unsigned int varid = tok2->next()->varId();
|
2011-03-03 03:21:46 +01:00
|
|
|
const Variable *var = symbolDatabase->getVariableFromVarId(varid);
|
|
|
|
|
|
|
|
if (var && var->isLocal() && !var->isStatic() && var->isArray())
|
2011-02-08 01:26:34 +01:00
|
|
|
{
|
|
|
|
errorReturnPointerToLocalArray(tok2);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
2009-06-09 19:45:58 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
void CheckAutoVariables::errorReturnPointerToLocalArray(const Token *tok)
|
|
|
|
{
|
2009-07-13 10:16:31 +02:00
|
|
|
reportError(tok, Severity::error, "returnLocalVariable", "Returning pointer to local array variable");
|
2009-06-09 19:45:58 +02:00
|
|
|
}
|
|
|
|
|
2009-10-04 11:45:45 +02:00
|
|
|
void CheckAutoVariables::errorAutoVariableAssignment(const Token *tok)
|
|
|
|
{
|
2010-12-04 08:55:20 +01:00
|
|
|
reportError(tok, Severity::error, "autoVariables",
|
|
|
|
"Assigning address of local auto-variable to a function parameter.\n"
|
|
|
|
"Dangerous assignment - function parameter takes the address of a local "
|
|
|
|
"auto-variable. Local auto-variables are reserved from the stack. And the "
|
|
|
|
"stack is freed when the function ends. So the pointer to a local variable "
|
|
|
|
"is invalid after the function ends.");
|
2009-10-04 11:45:45 +02:00
|
|
|
}
|
2009-03-19 20:55:50 +01:00
|
|
|
|
2011-02-08 01:26:34 +01:00
|
|
|
//---------------------------------------------------------------------------
|
|
|
|
|
2010-01-27 19:16:32 +01:00
|
|
|
// return temporary?
|
|
|
|
bool CheckAutoVariables::returnTemporary(const Token *tok) const
|
|
|
|
{
|
2010-04-02 07:30:58 +02:00
|
|
|
if (!Token::Match(tok, "return %var% ("))
|
2010-01-27 19:16:32 +01:00
|
|
|
return false;
|
|
|
|
return bool(0 != Token::findmatch(_tokenizer->tokens(), ("std :: string " + tok->next()->str() + " (").c_str()));
|
|
|
|
}
|
|
|
|
|
2011-02-08 01:26:34 +01:00
|
|
|
//---------------------------------------------------------------------------
|
2010-01-27 19:16:32 +01:00
|
|
|
|
2010-01-23 20:39:12 +01:00
|
|
|
void CheckAutoVariables::returnReference()
|
|
|
|
{
|
2011-02-08 01:26:34 +01:00
|
|
|
const SymbolDatabase *symbolDatabase = _tokenizer->getSymbolDatabase();
|
|
|
|
|
2011-03-11 01:43:29 +01:00
|
|
|
std::list<Scope>::const_iterator scope;
|
2011-02-08 01:26:34 +01:00
|
|
|
|
2011-03-11 01:43:29 +01:00
|
|
|
for (scope = symbolDatabase->scopeList.begin(); scope != symbolDatabase->scopeList.end(); ++scope)
|
2010-01-23 20:39:12 +01:00
|
|
|
{
|
2011-02-08 01:26:34 +01:00
|
|
|
// only check functions
|
|
|
|
if (scope->type != Scope::eFunction)
|
2010-01-23 20:39:12 +01:00
|
|
|
continue;
|
2011-02-08 01:26:34 +01:00
|
|
|
|
|
|
|
const Token *tok = scope->classDef;
|
|
|
|
|
|
|
|
// skip any qualification
|
|
|
|
while (Token::Match(tok->tokAt(-2), "%type% ::"))
|
|
|
|
tok = tok->tokAt(-2);
|
2010-01-23 20:39:12 +01:00
|
|
|
|
|
|
|
// have we reached a function that returns a reference?
|
2011-02-08 01:26:34 +01:00
|
|
|
if (Token::Match(tok->tokAt(-2), "%type% &") ||
|
|
|
|
Token::Match(tok->tokAt(-2), "> &"))
|
2010-01-23 20:39:12 +01:00
|
|
|
{
|
|
|
|
// go to the '('
|
2011-02-08 01:26:34 +01:00
|
|
|
const Token *tok2 = scope->classDef->next();
|
2010-01-23 20:39:12 +01:00
|
|
|
|
|
|
|
// go to the ')'
|
|
|
|
tok2 = tok2->link();
|
|
|
|
|
2011-02-08 01:26:34 +01:00
|
|
|
unsigned int indentlevel = 0;
|
|
|
|
for (; tok2; tok2 = tok2->next())
|
2010-01-23 20:39:12 +01:00
|
|
|
{
|
2011-02-08 01:26:34 +01:00
|
|
|
// indentlevel..
|
|
|
|
if (tok2->str() == "{")
|
|
|
|
++indentlevel;
|
|
|
|
else if (tok2->str() == "}")
|
2010-01-23 20:39:12 +01:00
|
|
|
{
|
2011-02-08 01:26:34 +01:00
|
|
|
if (indentlevel <= 1)
|
|
|
|
break;
|
|
|
|
--indentlevel;
|
|
|
|
}
|
2010-01-23 20:39:12 +01:00
|
|
|
|
2011-02-08 01:26:34 +01:00
|
|
|
// return..
|
2011-03-03 03:21:46 +01:00
|
|
|
if (Token::Match(tok2, "return %var% ;"))
|
2011-02-08 01:26:34 +01:00
|
|
|
{
|
|
|
|
// is the returned variable a local variable?
|
2011-03-03 03:21:46 +01:00
|
|
|
const unsigned int varid = tok2->next()->varId();
|
|
|
|
const Variable *var = symbolDatabase->getVariableFromVarId(varid);
|
|
|
|
|
|
|
|
if (var && var->isLocal() && !var->isStatic())
|
2010-01-27 19:16:32 +01:00
|
|
|
{
|
|
|
|
// report error..
|
2011-02-08 01:26:34 +01:00
|
|
|
errorReturnReference(tok2);
|
2010-01-27 19:16:32 +01:00
|
|
|
}
|
2010-01-23 20:39:12 +01:00
|
|
|
}
|
2011-02-08 01:26:34 +01:00
|
|
|
|
|
|
|
// return reference to temporary..
|
|
|
|
else if (returnTemporary(tok2))
|
|
|
|
{
|
|
|
|
// report error..
|
|
|
|
errorReturnTempReference(tok2);
|
|
|
|
}
|
2010-01-23 20:39:12 +01:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
void CheckAutoVariables::errorReturnReference(const Token *tok)
|
|
|
|
{
|
|
|
|
reportError(tok, Severity::error, "returnReference", "Returning reference to auto variable");
|
|
|
|
}
|
|
|
|
|
2010-01-27 19:16:32 +01:00
|
|
|
void CheckAutoVariables::errorReturnTempReference(const Token *tok)
|
|
|
|
{
|
|
|
|
reportError(tok, Severity::error, "returnTempReference", "Returning reference to temporary");
|
|
|
|
}
|
|
|
|
|
2011-02-08 01:26:34 +01:00
|
|
|
//---------------------------------------------------------------------------
|
2010-01-23 20:39:12 +01:00
|
|
|
|
2010-01-26 22:11:34 +01:00
|
|
|
// Return c_str
|
|
|
|
void CheckAutoVariables::returncstr()
|
|
|
|
{
|
|
|
|
// locate function that returns a const char *..
|
2011-02-08 01:26:34 +01:00
|
|
|
const SymbolDatabase *symbolDatabase = _tokenizer->getSymbolDatabase();
|
|
|
|
|
2011-03-11 01:43:29 +01:00
|
|
|
std::list<Scope>::const_iterator scope;
|
2011-02-08 01:26:34 +01:00
|
|
|
|
2011-03-11 01:43:29 +01:00
|
|
|
for (scope = symbolDatabase->scopeList.begin(); scope != symbolDatabase->scopeList.end(); ++scope)
|
2010-01-26 22:11:34 +01:00
|
|
|
{
|
2011-02-08 01:26:34 +01:00
|
|
|
// only check functions
|
|
|
|
if (scope->type != Scope::eFunction)
|
2010-01-26 22:11:34 +01:00
|
|
|
continue;
|
|
|
|
|
2011-02-08 01:26:34 +01:00
|
|
|
const Token *tok = scope->classDef;
|
|
|
|
|
|
|
|
// skip any qualification
|
|
|
|
while (Token::Match(tok->tokAt(-2), "%type% ::"))
|
|
|
|
tok = tok->tokAt(-2);
|
|
|
|
|
|
|
|
// have we reached a function that returns a const char *
|
|
|
|
if (Token::simpleMatch(tok->tokAt(-3), "const char *"))
|
2010-01-26 22:11:34 +01:00
|
|
|
{
|
|
|
|
// go to the '('
|
2011-02-08 01:26:34 +01:00
|
|
|
const Token *tok2 = scope->classDef->next();
|
2010-01-26 22:11:34 +01:00
|
|
|
|
|
|
|
// go to the ')'
|
2010-11-13 15:38:21 +01:00
|
|
|
tok2 = tok2->next()->link();
|
2010-01-26 22:11:34 +01:00
|
|
|
|
2011-02-08 01:26:34 +01:00
|
|
|
unsigned int indentlevel = 0;
|
|
|
|
for (; tok2; tok2 = tok2->next())
|
2010-01-26 22:11:34 +01:00
|
|
|
{
|
2011-02-08 01:26:34 +01:00
|
|
|
// indentlevel..
|
|
|
|
if (tok2->str() == "{")
|
|
|
|
++indentlevel;
|
|
|
|
else if (tok2->str() == "}")
|
2010-01-26 22:11:34 +01:00
|
|
|
{
|
2011-02-08 01:26:34 +01:00
|
|
|
if (indentlevel <= 1)
|
|
|
|
break;
|
|
|
|
--indentlevel;
|
|
|
|
}
|
2010-01-26 22:11:34 +01:00
|
|
|
|
2011-02-08 01:26:34 +01:00
|
|
|
// return..
|
2011-03-03 03:21:46 +01:00
|
|
|
if (Token::Match(tok2, "return %var% . c_str ( ) ;"))
|
2011-02-08 01:26:34 +01:00
|
|
|
{
|
|
|
|
// is the returned variable a local variable?
|
2011-03-03 03:21:46 +01:00
|
|
|
const unsigned int varid = tok2->next()->varId();
|
|
|
|
const Variable *var = symbolDatabase->getVariableFromVarId(varid);
|
|
|
|
|
|
|
|
if (var && var->isLocal() && !var->isStatic())
|
2010-01-27 19:16:32 +01:00
|
|
|
{
|
|
|
|
// report error..
|
2011-02-08 01:26:34 +01:00
|
|
|
errorReturnAutocstr(tok2);
|
2010-01-27 19:16:32 +01:00
|
|
|
}
|
2010-01-26 22:11:34 +01:00
|
|
|
}
|
2011-02-08 01:26:34 +01:00
|
|
|
|
|
|
|
// return pointer to temporary..
|
|
|
|
else if (returnTemporary(tok2))
|
|
|
|
{
|
|
|
|
// report error..
|
|
|
|
errorReturnTempPointer(tok2);
|
|
|
|
}
|
2010-01-26 22:11:34 +01:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
void CheckAutoVariables::errorReturnAutocstr(const Token *tok)
|
|
|
|
{
|
|
|
|
reportError(tok, Severity::error, "returnAutocstr", "Returning pointer to auto variable");
|
|
|
|
}
|
|
|
|
|
2010-01-27 19:16:32 +01:00
|
|
|
void CheckAutoVariables::errorReturnTempPointer(const Token *tok)
|
|
|
|
{
|
|
|
|
reportError(tok, Severity::error, "returnTempPointer", "Returning pointer to temporary");
|
|
|
|
}
|