*new* check_macros: find macro precedence bugs
[smatch.git] / check_signed.c
blobf3c5670750e24fd535336f5981c39b5560377ae5
1 /*
2 * sparse/check_signed.c
4 * Copyright (C) 2009 Dan Carpenter.
6 * Licensed under the Open Software License version 1.1
8 */
11 * Check for things which are signed but probably should be unsigned.
13 * Hm... It seems like at this point in the processing, sparse makes all
14 * bitfields unsigned. Which is logical but not what GCC does.
18 #include "smatch.h"
20 static int my_id;
22 #define VAR_ON_RIGHT 0
23 #define VAR_ON_LEFT 1
25 static long long eqneq_max(struct symbol *base_type)
27 long long ret = whole_range.max;
28 int bits;
30 if (!base_type || !base_type->bit_size)
31 return ret;
32 bits = base_type->bit_size;
33 if (bits == 64)
34 return ret;
35 if (bits < 32)
36 return type_max(base_type);
37 ret >>= (63 - bits);
38 return ret;
41 static long long eqneq_min(struct symbol *base_type)
43 long long ret = whole_range.min;
44 int bits;
46 if (!base_type || !base_type->bit_size)
47 return ret;
48 if (base_type->bit_size < 32)
49 return type_min(base_type);
50 ret = whole_range.max;
51 bits = base_type->bit_size - 1;
52 ret >>= (63 - bits);
53 return -(ret + 1);
56 static void match_assign(struct expression *expr)
58 struct symbol *sym;
59 long long val;
60 long long max;
61 long long min;
62 char *name;
64 if (expr->op == SPECIAL_AND_ASSIGN || expr->op == SPECIAL_OR_ASSIGN)
65 return;
67 sym = get_type(expr->left);
68 if (!sym) {
69 //sm_msg("could not get type");
70 return;
72 if (sym->bit_size >= 32) /* max_val limits this */
73 return;
74 if (!get_implied_value(expr->right, &val))
75 return;
76 max = type_max(sym);
77 if (max < val) {
78 name = get_variable_from_expr_complex(expr->left, NULL);
79 sm_msg("warn: value %lld can't fit into %lld '%s'", val, max, name);
80 free_string(name);
82 min = type_min(sym);
83 if (min > val) {
84 if (min == 0 && val == -1) /* assigning -1 to unsigned variables is idiomatic */
85 return;
86 if (expr->right->type == EXPR_PREOP && expr->right->op == '~')
87 return;
88 name = get_variable_from_expr_complex(expr->left, NULL);
89 if (min == 0)
90 sm_msg("warn: assigning %lld to unsigned variable '%s'", val, name);
91 else
92 sm_msg("warn: value %lld can't fit into %lld '%s'", val, min, name);
93 free_string(name);
98 static const char *get_tf(long long variable, long long known, int var_pos, int op)
100 if (op == SPECIAL_EQUAL)
101 return "false";
102 if (op == SPECIAL_NOTEQUAL)
103 return "true";
104 if (var_pos == VAR_ON_LEFT) {
105 if (variable > known && (op == '<' || op == SPECIAL_LTE))
106 return "false";
107 if (variable > known && (op == '>' || op == SPECIAL_GTE))
108 return "true";
109 if (variable < known && (op == '<' || op == SPECIAL_LTE))
110 return "true";
111 if (variable < known && (op == '>' || op == SPECIAL_GTE))
112 return "false";
114 if (var_pos == VAR_ON_RIGHT) {
115 if (known > variable && (op == '<' || op == SPECIAL_LTE))
116 return "false";
117 if (known > variable && (op == '>' || op == SPECIAL_GTE))
118 return "true";
119 if (known < variable && (op == '<' || op == SPECIAL_LTE))
120 return "true";
121 if (known < variable && (op == '>' || op == SPECIAL_GTE))
122 return "false";
124 return "the same";
127 static void match_condition(struct expression *expr)
129 long long known;
130 struct expression *var = NULL;
131 struct symbol *var_type = NULL;
132 struct symbol *known_type = NULL;
133 long long max;
134 long long min;
135 int lr;
136 char *name;
138 if (expr->type != EXPR_COMPARE)
139 return;
141 if (get_value(expr->left, &known)) {
142 if (get_value(expr->right, &max))
143 return; /* both sides known */
144 lr = VAR_ON_RIGHT;
145 var = expr->right;
146 known_type = get_type(expr->left);
147 } else if (get_value(expr->right, &known)) {
148 lr = VAR_ON_LEFT;
149 var = expr->left;
150 known_type = get_type(expr->right);
151 } else {
152 return;
155 var_type = get_type(var);
156 if (!var_type)
157 return;
158 if (var_type->bit_size >= 32 && !option_spammy)
159 return;
161 name = get_variable_from_expr_complex(var, NULL);
163 if (expr->op == SPECIAL_EQUAL || expr->op == SPECIAL_NOTEQUAL) {
164 if (eqneq_max(var_type) < known || eqneq_min(var_type) > known)
165 sm_msg("error: %s is never equal to %lld (wrong type %lld - %lld).",
166 name, known, eqneq_min(var_type), eqneq_max(var_type));
167 goto free;
170 max = type_max(var_type);
171 min = type_min(var_type);
173 if (max < known) {
174 const char *tf = get_tf(max, known, lr, expr->op);
176 sm_msg("warn: %lld is more than %lld (max '%s' can be) so this is always %s.",
177 known, max, name, tf);
180 if (known == 0 && type_unsigned(var_type)) {
181 if ((lr && expr->op == '<') || (!lr && expr->op == '>'))
182 sm_msg("warn: unsigned '%s' is never less than zero.", name);
183 goto free;
186 if (type_unsigned(var_type) && known_type && !type_unsigned(known_type) && known < 0) {
187 sm_msg("warn: unsigned '%s' is never less than zero (%lld).", name, known);
188 goto free;
191 if (min < 0 && min > known) {
192 const char *tf = get_tf(min, known, lr, expr->op);
194 sm_msg("warn: %lld is less than %lld (min '%s' can be) so this is always %s.",
195 known, min, name, tf);
197 free:
198 free_string(name);
201 void check_signed(int id)
203 my_id = id;
205 add_hook(&match_assign, ASSIGNMENT_HOOK);
206 add_hook(&match_condition, CONDITION_HOOK);