1//=======- ASTUtis.h ---------------------------------------------*- C++ -*-==//
2//
3// Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
4// See https://llvm.org/LICENSE.txt for license information.
5// SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
6//
7//===----------------------------------------------------------------------===//
8
9#ifndef LLVM_CLANG_ANALYZER_WEBKIT_ASTUTILS_H
10#define LLVM_CLANG_ANALYZER_WEBKIT_ASTUTILS_H
11
12#include "clang/AST/Decl.h"
13#include "llvm/ADT/APInt.h"
14#include "llvm/Support/Casting.h"
15
16#include <functional>
17#include <string>
18#include <utility>
19
20namespace clang {
21class Expr;
22
23/// This function de-facto defines a set of transformations that we consider
24/// safe (in heuristical sense). These transformation if passed a safe value as
25/// an input should provide a safe value (or an object that provides safe
26/// values).
27///
28/// For more context see Static Analyzer checkers documentation - specifically
29/// webkit.UncountedCallArgsChecker checker. Allowed list of transformations:
30/// - constructors of ref-counted types (including factory methods)
31/// - getters of ref-counted types
32/// - member overloaded operators
33/// - casts
34/// - unary operators like ``&`` or ``*``
35///
36/// If passed expression is of type uncounted pointer/reference we try to find
37/// the "origin" of the pointer value.
38/// Origin can be for example a local variable, nullptr, constant or
39/// this-pointer.
40///
41/// Certain subexpression nodes represent transformations that don't affect
42/// where the memory address originates from. We try to traverse such
43/// subexpressions to get to the relevant child nodes. Whenever we encounter a
44/// subexpression that either can't be ignored, we don't model its semantics or
45/// that has multiple children we stop.
46///
47/// \p E is an expression of uncounted pointer/reference type.
48/// If \p StopAtFirstRefCountedObj is true and we encounter a subexpression that
49/// represents ref-counted object during the traversal we return relevant
50/// sub-expression and true.
51///
52/// Calls \p callback for each origin the traversal reaches, passing the
53/// subexpression, whether the traversal recognized it as a safe origin,
54/// whether the path to it passed through a temporary that dies at the end of
55/// the full-expression (in that case the origin's lifetime guarantee cannot
56/// be assumed to extend past the full-expression), and whether the path to it
57/// followed at least one [[clang::lifetimebound]] edge. Returns false if any
58/// of calls to callbacks returned false. Otherwise true.
59///
60/// If \p FollowLifetimeBound is true, f(x [[clang::lifetimebound]])
61/// traverses into x.
62bool tryToFindPtrOrigin(
63 const clang::Expr *E, bool StopAtFirstRefCountedObj,
64 bool FollowLifetimeBound,
65 std::function<bool(const clang::CXXRecordDecl *)> isSafePtr,
66 std::function<bool(const clang::QualType)> isSafePtrType,
67 std::function<bool(const clang::Decl *)> isSafeGlobalDecl,
68 std::function<bool(const clang::Expr *, bool /*IsSafe*/,
69 bool /*OriginDependsOnFullExpressionTemporary*/,
70 bool /*PtrIsLifetimeBoundToOrigin*/)>
71 callback);
72
73/// For \p E referring to a ref-countable/-counted pointer/reference we return
74/// whether the pointee outlives the current function call. Examples: function
75/// parameter or this-pointer. Outliving the call is not by itself sufficient
76/// evidence of safety for a model that checks for interior destruction.
77///
78/// \returns Whether the pointee of \p E outlives the current function call.
79bool originOutlivesCall(const clang::Expr *E);
80
81/// \returns true if E is nullptr or __null.
82bool isNullPtr(const clang::Expr *E);
83
84/// \returns true if E is a MemberExpr accessing a const smart pointer type.
85bool isConstOwnerPtrMemberExpr(const clang::Expr *E);
86
87/// \returns true if E is a MemberExpr accessing a member variable which
88/// supports CheckedPtr.
89bool isExprToGetCheckedPtrCapableMember(const clang::Expr *E);
90
91/// \returns true if \p E is a [[alloc] init] pattern expression.
92/// Sets \p InnerExpr to the inner function call or selector invocation.
93bool isAllocInit(const Expr *E, const Expr **InnerExpr = nullptr);
94
95/// \returns ObjCInterfaceDecl from a pointer type.
96ObjCInterfaceDecl *getObjCDeclFromObjCPtr(const Type *TypePtr);
97
98/// \returns true if E is a CXXMemberCallExpr which returns a const smart
99/// pointer type.
100class EnsureFunctionAnalysis {
101 using CacheTy = llvm::DenseMap<const FunctionDecl *, bool>;
102 mutable CacheTy Cache{};
103
104public:
105 bool isACallToEnsureFn(const Expr *E) const;
106};
107
108/// \returns name of AST node or empty string.
109template <typename T> std::string safeGetName(const T *ASTNode) {
110 const auto *const ND = llvm::dyn_cast_or_null<clang::NamedDecl>(ASTNode);
111 if (!ND)
112 return "";
113
114 // In case F is for example "operator|" the getName() method below would
115 // assert.
116 if (!ND->getDeclName().isIdentifier())
117 return "";
118
119 return ND->getName().str();
120}
121
122} // namespace clang
123
124#endif
125