2001-03-22 Alexandre Petit-Bianco <apbianco@redhat.com>
[official-gcc.git] / gcc / c-format.c
blobb6270e2ae2769dea25f2252c40acc78110831091
1 /* Check calls to formatted I/O functions (-Wformat).
2 Copyright (C) 1992, 1993, 1994, 1995, 1996, 1997, 1998, 1999, 2000, 2001
3 Free Software Foundation, Inc.
5 This file is part of GNU CC.
7 GNU CC is free software; you can redistribute it and/or modify
8 it under the terms of the GNU General Public License as published by
9 the Free Software Foundation; either version 2, or (at your option)
10 any later version.
12 GNU CC is distributed in the hope that it will be useful,
13 but WITHOUT ANY WARRANTY; without even the implied warranty of
14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 GNU General Public License for more details.
17 You should have received a copy of the GNU General Public License
18 along with GNU CC; see the file COPYING. If not, write to
19 the Free Software Foundation, 59 Temple Place - Suite 330,
20 Boston, MA 02111-1307, USA. */
22 #include "config.h"
23 #include "system.h"
24 #include "tree.h"
25 #include "flags.h"
26 #include "toplev.h"
27 #include "c-common.h"
28 #include "intl.h"
29 #include "diagnostic.h"
32 /* Command line options and their associated flags. */
34 /* Warn about format/argument anomalies in calls to formatted I/O functions
35 (*printf, *scanf, strftime, strfmon, etc.). */
37 int warn_format;
39 /* Warn about Y2K problems with strftime formats. */
41 int warn_format_y2k;
43 /* Warn about excess arguments to formats. */
45 int warn_format_extra_args;
47 /* Warn about non-literal format arguments. */
49 int warn_format_nonliteral;
51 /* Warn about possible security problems with calls to format functions. */
53 int warn_format_security;
55 /* Set format warning options according to a -Wformat=n option. */
57 void
58 set_Wformat (setting)
59 int setting;
61 warn_format = setting;
62 warn_format_y2k = setting;
63 warn_format_extra_args = setting;
64 if (setting != 1)
66 warn_format_nonliteral = setting;
67 warn_format_security = setting;
72 /* Handle attributes associated with format checking. */
74 /* This must be in the same order as format_types, with format_type_error
75 last. */
76 enum format_type { printf_format_type, scanf_format_type,
77 strftime_format_type, strfmon_format_type,
78 format_type_error };
80 static enum format_type decode_format_type PARAMS ((const char *));
81 static void record_function_format PARAMS ((tree, tree, enum format_type,
82 int, int));
83 static void record_international_format PARAMS ((tree, tree, int));
85 /* Handle the format attribute (with arguments ARGS) attached to the decl
86 DECL. It is already verified that DECL is a decl and ARGS contains
87 exactly three arguments. */
89 void
90 decl_handle_format_attribute (decl, args)
91 tree decl, args;
93 tree type = TREE_TYPE (decl);
94 tree format_type_id = TREE_VALUE (args);
95 tree format_num_expr = TREE_VALUE (TREE_CHAIN (args));
96 tree first_arg_num_expr
97 = TREE_VALUE (TREE_CHAIN (TREE_CHAIN (args)));
98 unsigned HOST_WIDE_INT format_num, first_arg_num;
99 enum format_type format_type;
100 tree argument;
101 unsigned int arg_num;
103 if (TREE_CODE (decl) != FUNCTION_DECL)
105 error_with_decl (decl,
106 "argument format specified for non-function `%s'");
107 return;
110 if (TREE_CODE (format_type_id) != IDENTIFIER_NODE)
112 error ("unrecognized format specifier");
113 return;
115 else
117 const char *p = IDENTIFIER_POINTER (format_type_id);
119 format_type = decode_format_type (p);
121 if (format_type == format_type_error)
123 warning ("`%s' is an unrecognized format function type", p);
124 return;
128 /* Strip any conversions from the string index and first arg number
129 and verify they are constants. */
130 while (TREE_CODE (format_num_expr) == NOP_EXPR
131 || TREE_CODE (format_num_expr) == CONVERT_EXPR
132 || TREE_CODE (format_num_expr) == NON_LVALUE_EXPR)
133 format_num_expr = TREE_OPERAND (format_num_expr, 0);
135 while (TREE_CODE (first_arg_num_expr) == NOP_EXPR
136 || TREE_CODE (first_arg_num_expr) == CONVERT_EXPR
137 || TREE_CODE (first_arg_num_expr) == NON_LVALUE_EXPR)
138 first_arg_num_expr = TREE_OPERAND (first_arg_num_expr, 0);
140 if (TREE_CODE (format_num_expr) != INTEGER_CST
141 || TREE_INT_CST_HIGH (format_num_expr) != 0
142 || TREE_CODE (first_arg_num_expr) != INTEGER_CST
143 || TREE_INT_CST_HIGH (first_arg_num_expr) != 0)
145 error ("format string has invalid operand number");
146 return;
149 format_num = TREE_INT_CST_LOW (format_num_expr);
150 first_arg_num = TREE_INT_CST_LOW (first_arg_num_expr);
151 if (first_arg_num != 0 && first_arg_num <= format_num)
153 error ("format string arg follows the args to be formatted");
154 return;
157 /* If a parameter list is specified, verify that the format_num
158 argument is actually a string, in case the format attribute
159 is in error. */
160 argument = TYPE_ARG_TYPES (type);
161 if (argument)
163 for (arg_num = 1; argument != 0 && arg_num != format_num;
164 ++arg_num, argument = TREE_CHAIN (argument))
167 if (! argument
168 || TREE_CODE (TREE_VALUE (argument)) != POINTER_TYPE
169 || (TYPE_MAIN_VARIANT (TREE_TYPE (TREE_VALUE (argument)))
170 != char_type_node))
172 error ("format string arg not a string type");
173 return;
176 else if (first_arg_num != 0)
178 /* Verify that first_arg_num points to the last arg,
179 the ... */
180 while (argument)
181 arg_num++, argument = TREE_CHAIN (argument);
183 if (arg_num != first_arg_num)
185 error ("args to be formatted is not '...'");
186 return;
191 if (format_type == strftime_format_type && first_arg_num != 0)
193 error ("strftime formats cannot format arguments");
194 return;
197 record_function_format (DECL_NAME (decl), DECL_ASSEMBLER_NAME (decl),
198 format_type, format_num, first_arg_num);
202 /* Handle the format_arg attribute (with arguments ARGS) attached to
203 the decl DECL. It is already verified that DECL is a decl and
204 ARGS contains exactly one argument. */
206 void
207 decl_handle_format_arg_attribute (decl, args)
208 tree decl, args;
210 tree type = TREE_TYPE (decl);
211 tree format_num_expr = TREE_VALUE (args);
212 unsigned HOST_WIDE_INT format_num;
213 unsigned int arg_num;
214 tree argument;
216 if (TREE_CODE (decl) != FUNCTION_DECL)
218 error_with_decl (decl,
219 "argument format specified for non-function `%s'");
220 return;
223 /* Strip any conversions from the first arg number and verify it
224 is a constant. */
225 while (TREE_CODE (format_num_expr) == NOP_EXPR
226 || TREE_CODE (format_num_expr) == CONVERT_EXPR
227 || TREE_CODE (format_num_expr) == NON_LVALUE_EXPR)
228 format_num_expr = TREE_OPERAND (format_num_expr, 0);
230 if (TREE_CODE (format_num_expr) != INTEGER_CST
231 || TREE_INT_CST_HIGH (format_num_expr) != 0)
233 error ("format string has invalid operand number");
234 return;
237 format_num = TREE_INT_CST_LOW (format_num_expr);
239 /* If a parameter list is specified, verify that the format_num
240 argument is actually a string, in case the format attribute
241 is in error. */
242 argument = TYPE_ARG_TYPES (type);
243 if (argument)
245 for (arg_num = 1; argument != 0 && arg_num != format_num;
246 ++arg_num, argument = TREE_CHAIN (argument))
249 if (! argument
250 || TREE_CODE (TREE_VALUE (argument)) != POINTER_TYPE
251 || (TYPE_MAIN_VARIANT (TREE_TYPE (TREE_VALUE (argument)))
252 != char_type_node))
254 error ("format string arg not a string type");
255 return;
259 if (TREE_CODE (TREE_TYPE (TREE_TYPE (decl))) != POINTER_TYPE
260 || (TYPE_MAIN_VARIANT (TREE_TYPE (TREE_TYPE (TREE_TYPE (decl))))
261 != char_type_node))
263 error ("function does not return string type");
264 return;
267 record_international_format (DECL_NAME (decl), DECL_ASSEMBLER_NAME (decl),
268 format_num);
271 typedef struct function_format_info
273 struct function_format_info *next; /* next structure on the list */
274 tree name; /* identifier such as "printf" */
275 tree assembler_name; /* optional mangled identifier (for C++) */
276 enum format_type format_type; /* type of format (printf, scanf, etc.) */
277 int format_num; /* number of format argument */
278 int first_arg_num; /* number of first arg (zero for varargs) */
279 } function_format_info;
281 static function_format_info *function_format_list = NULL;
283 typedef struct international_format_info
285 struct international_format_info *next; /* next structure on the list */
286 tree name; /* identifier such as "gettext" */
287 tree assembler_name; /* optional mangled identifier (for C++) */
288 int format_num; /* number of format argument */
289 } international_format_info;
291 static international_format_info *international_format_list = NULL;
293 /* Initialize the table of functions to perform format checking on.
294 The ISO C functions are always checked (whether <stdio.h> is
295 included or not), since it is common to call printf without
296 including <stdio.h>. There shouldn't be a problem with this,
297 since ISO C reserves these function names whether you include the
298 header file or not. In any case, the checking is harmless. With
299 -ffreestanding, these default attributes are disabled, and must be
300 specified manually if desired.
302 Also initialize the name of function that modify the format string for
303 internationalization purposes. */
305 void
306 init_function_format_info ()
308 if (flag_hosted)
310 /* Functions from ISO/IEC 9899:1990. */
311 record_function_format (get_identifier ("printf"), NULL_TREE,
312 printf_format_type, 1, 2);
313 record_function_format (get_identifier ("__builtin_printf"), NULL_TREE,
314 printf_format_type, 1, 2);
315 record_function_format (get_identifier ("fprintf"), NULL_TREE,
316 printf_format_type, 2, 3);
317 record_function_format (get_identifier ("__builtin_fprintf"), NULL_TREE,
318 printf_format_type, 2, 3);
319 record_function_format (get_identifier ("sprintf"), NULL_TREE,
320 printf_format_type, 2, 3);
321 record_function_format (get_identifier ("scanf"), NULL_TREE,
322 scanf_format_type, 1, 2);
323 record_function_format (get_identifier ("fscanf"), NULL_TREE,
324 scanf_format_type, 2, 3);
325 record_function_format (get_identifier ("sscanf"), NULL_TREE,
326 scanf_format_type, 2, 3);
327 record_function_format (get_identifier ("vprintf"), NULL_TREE,
328 printf_format_type, 1, 0);
329 record_function_format (get_identifier ("vfprintf"), NULL_TREE,
330 printf_format_type, 2, 0);
331 record_function_format (get_identifier ("vsprintf"), NULL_TREE,
332 printf_format_type, 2, 0);
333 record_function_format (get_identifier ("strftime"), NULL_TREE,
334 strftime_format_type, 3, 0);
337 if (flag_hosted && flag_isoc99)
339 /* ISO C99 adds the snprintf and vscanf family functions. */
340 record_function_format (get_identifier ("snprintf"), NULL_TREE,
341 printf_format_type, 3, 4);
342 record_function_format (get_identifier ("vsnprintf"), NULL_TREE,
343 printf_format_type, 3, 0);
344 record_function_format (get_identifier ("vscanf"), NULL_TREE,
345 scanf_format_type, 1, 0);
346 record_function_format (get_identifier ("vfscanf"), NULL_TREE,
347 scanf_format_type, 2, 0);
348 record_function_format (get_identifier ("vsscanf"), NULL_TREE,
349 scanf_format_type, 2, 0);
352 if (flag_hosted && flag_noniso_default_format_attributes)
354 /* Uniforum/GNU gettext functions, not in ISO C. */
355 record_international_format (get_identifier ("gettext"), NULL_TREE, 1);
356 record_international_format (get_identifier ("dgettext"), NULL_TREE, 2);
357 record_international_format (get_identifier ("dcgettext"), NULL_TREE, 2);
358 /* X/Open strfmon function. */
359 record_function_format (get_identifier ("strfmon"), NULL_TREE,
360 strfmon_format_type, 3, 4);
364 /* Record information for argument format checking. FUNCTION_IDENT is
365 the identifier node for the name of the function to check (its decl
366 need not exist yet).
367 FORMAT_TYPE specifies the type of format checking. FORMAT_NUM is the number
368 of the argument which is the format control string (starting from 1).
369 FIRST_ARG_NUM is the number of the first actual argument to check
370 against the format string, or zero if no checking is not be done
371 (e.g. for varargs such as vfprintf). */
373 static void
374 record_function_format (name, assembler_name, format_type,
375 format_num, first_arg_num)
376 tree name;
377 tree assembler_name;
378 enum format_type format_type;
379 int format_num;
380 int first_arg_num;
382 function_format_info *info;
384 /* Re-use existing structure if it's there. */
386 for (info = function_format_list; info; info = info->next)
388 if (info->name == name && info->assembler_name == assembler_name)
389 break;
391 if (! info)
393 info = (function_format_info *) xmalloc (sizeof (function_format_info));
394 info->next = function_format_list;
395 function_format_list = info;
397 info->name = name;
398 info->assembler_name = assembler_name;
401 info->format_type = format_type;
402 info->format_num = format_num;
403 info->first_arg_num = first_arg_num;
406 /* Record information for the names of function that modify the format
407 argument to format functions. FUNCTION_IDENT is the identifier node for
408 the name of the function (its decl need not exist yet) and FORMAT_NUM is
409 the number of the argument which is the format control string (starting
410 from 1). */
412 static void
413 record_international_format (name, assembler_name, format_num)
414 tree name;
415 tree assembler_name;
416 int format_num;
418 international_format_info *info;
420 /* Re-use existing structure if it's there. */
422 for (info = international_format_list; info; info = info->next)
424 if (info->name == name && info->assembler_name == assembler_name)
425 break;
428 if (! info)
430 info
431 = (international_format_info *)
432 xmalloc (sizeof (international_format_info));
433 info->next = international_format_list;
434 international_format_list = info;
436 info->name = name;
437 info->assembler_name = assembler_name;
440 info->format_num = format_num;
446 /* Check a call to a format function against a parameter list. */
448 /* The meaningfully distinct length modifiers for format checking recognised
449 by GCC. */
450 enum format_lengths
452 FMT_LEN_none,
453 FMT_LEN_hh,
454 FMT_LEN_h,
455 FMT_LEN_l,
456 FMT_LEN_ll,
457 FMT_LEN_L,
458 FMT_LEN_z,
459 FMT_LEN_t,
460 FMT_LEN_j,
461 FMT_LEN_MAX
465 /* The standard versions in which various format features appeared. */
466 enum format_std_version
468 STD_C89,
469 STD_C94,
470 STD_C9L, /* C99, but treat as C89 if -Wno-long-long. */
471 STD_C99,
472 STD_EXT
475 /* The C standard version C++ is treated as equivalent to
476 or inheriting from, for the purpose of format features supported. */
477 #define CPLUSPLUS_STD_VER STD_C89
478 /* The C standard version we are checking formats against when pedantic. */
479 #define C_STD_VER ((int)(c_language == clk_cplusplus \
480 ? CPLUSPLUS_STD_VER \
481 : (flag_isoc99 \
482 ? STD_C99 \
483 : (flag_isoc94 ? STD_C94 : STD_C89))))
484 /* The name to give to the standard version we are warning about when
485 pedantic. FEATURE_VER is the version in which the feature warned out
486 appeared, which is higher than C_STD_VER. */
487 #define C_STD_NAME(FEATURE_VER) (c_language == clk_cplusplus \
488 ? "ISO C++" \
489 : ((FEATURE_VER) == STD_EXT \
490 ? "ISO C" \
491 : "ISO C89"))
492 /* Adjust a C standard version, which may be STD_C9L, to account for
493 -Wno-long-long. Returns other standard versions unchanged. */
494 #define ADJ_STD(VER) ((int)((VER) == STD_C9L \
495 ? (warn_long_long ? STD_C99 : STD_C89) \
496 : (VER)))
498 /* Flags that may apply to a particular kind of format checked by GCC. */
499 enum
501 /* This format converts arguments of types determined by the
502 format string. */
503 FMT_FLAG_ARG_CONVERT = 1,
504 /* The scanf allocation 'a' kludge applies to this format kind. */
505 FMT_FLAG_SCANF_A_KLUDGE = 2,
506 /* A % during parsing a specifier is allowed to be a modified % rather
507 that indicating the format is broken and we are out-of-sync. */
508 FMT_FLAG_FANCY_PERCENT_OK = 4,
509 /* With $ operand numbers, it is OK to reference the same argument more
510 than once. */
511 FMT_FLAG_DOLLAR_MULTIPLE = 8,
512 /* This format type uses $ operand numbers (strfmon doesn't). */
513 FMT_FLAG_USE_DOLLAR = 16,
514 /* Zero width is bad in this type of format (scanf). */
515 FMT_FLAG_ZERO_WIDTH_BAD = 32,
516 /* Empty precision specification is OK in this type of format (printf). */
517 FMT_FLAG_EMPTY_PREC_OK = 64
518 /* Not included here: details of whether width or precision may occur
519 (controlled by width_char and precision_char); details of whether
520 '*' can be used for these (width_type and precision_type); details
521 of whether length modifiers can occur (length_char_specs). */
525 /* Structure describing a length modifier supported in format checking, and
526 possibly a doubled version such as "hh". */
527 typedef struct
529 /* Name of the single-character length modifier. */
530 const char *name;
531 /* Index into a format_char_info.types array. */
532 enum format_lengths index;
533 /* Standard version this length appears in. */
534 enum format_std_version std;
535 /* Same, if the modifier can be repeated, or NULL if it can't. */
536 const char *double_name;
537 enum format_lengths double_index;
538 enum format_std_version double_std;
539 } format_length_info;
542 /* Structure desribing the combination of a conversion specifier
543 (or a set of specifiers which act identically) and a length modifier. */
544 typedef struct
546 /* The standard version this combination of length and type appeared in.
547 This is only relevant if greater than those for length and type
548 individually; otherwise it is ignored. */
549 enum format_std_version std;
550 /* The name to use for the type, if different from that generated internally
551 (e.g., "signed size_t"). */
552 const char *name;
553 /* The type itself. */
554 tree *type;
555 } format_type_detail;
558 /* Macros to fill out tables of these. */
559 #define BADLEN { 0, NULL, NULL }
560 #define NOLENGTHS { BADLEN, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN }
563 /* Structure desribing a format conversion specifier (or a set of specifiers
564 which act identically), and the length modifiers used with it. */
565 typedef struct
567 const char *format_chars;
568 int pointer_count;
569 enum format_std_version std;
570 /* Types accepted for each length modifier. */
571 format_type_detail types[FMT_LEN_MAX];
572 /* List of other modifier characters allowed with these specifiers.
573 This lists flags, and additionally "w" for width, "p" for precision
574 (right precision, for strfmon), "#" for left precision (strfmon),
575 "a" for scanf "a" allocation extension (not applicable in C99 mode),
576 "*" for scanf suppression, and "E" and "O" for those strftime
577 modifiers. */
578 const char *flag_chars;
579 /* List of additional flags describing these conversion specifiers.
580 "c" for generic character pointers being allowed, "2" for strftime
581 two digit year formats, "3" for strftime formats giving two digit
582 years in some locales, "4" for "2" which becomes "3" with an "E" modifier,
583 "o" if use of strftime "O" is a GNU extension beyond C99,
584 "W" if the argument is a pointer which is dereferenced and written into,
585 "R" if the argument is a pointer which is dereferenced and read from,
586 "i" for printf integer formats where the '0' flag is ignored with
587 precision, and "[" for the starting character of a scanf scanset. */
588 const char *flags2;
589 } format_char_info;
592 /* Structure describing a flag accepted by some kind of format. */
593 typedef struct
595 /* The flag character in question (0 for end of array). */
596 int flag_char;
597 /* Zero if this entry describes the flag character in general, or a
598 non-zero character that may be found in flags2 if it describes the
599 flag when used with certain formats only. If the latter, only
600 the first such entry found that applies to the current conversion
601 specifier is used; the values of `name' and `long_name' it supplies
602 will be used, if non-NULL and the standard version is higher than
603 the unpredicated one, for any pedantic warning. For example, 'o'
604 for strftime formats (meaning 'O' is an extension over C99). */
605 int predicate;
606 /* Nonzero if the next character after this flag in the format should
607 be skipped ('=' in strfmon), zero otherwise. */
608 int skip_next_char;
609 /* The name to use for this flag in diagnostic messages. For example,
610 N_("`0' flag"), N_("field width"). */
611 const char *name;
612 /* Long name for this flag in diagnostic messages; currently only used for
613 "ISO C does not support ...". For example, N_("the `I' printf flag"). */
614 const char *long_name;
615 /* The standard version in which it appeared. */
616 enum format_std_version std;
617 } format_flag_spec;
620 /* Structure describing a combination of flags that is bad for some kind
621 of format. */
622 typedef struct
624 /* The first flag character in question (0 for end of array). */
625 int flag_char1;
626 /* The second flag character. */
627 int flag_char2;
628 /* Non-zero if the message should say that the first flag is ignored with
629 the second, zero if the combination should simply be objected to. */
630 int ignored;
631 /* Zero if this entry applies whenever this flag combination occurs,
632 a non-zero character from flags2 if it only applies in some
633 circumstances (e.g. 'i' for printf formats ignoring 0 with precision). */
634 int predicate;
635 } format_flag_pair;
638 /* Structure describing a particular kind of format processed by GCC. */
639 typedef struct
641 /* The name of this kind of format, for use in diagnostics. Also
642 the name of the attribute (without preceding and following __). */
643 const char *name;
644 /* Specifications of the length modifiers accepted; possibly NULL. */
645 const format_length_info *length_char_specs;
646 /* Details of the conversion specification characters accepted. */
647 const format_char_info *conversion_specs;
648 /* String listing the flag characters that are accepted. */
649 const char *flag_chars;
650 /* String listing modifier characters (strftime) accepted. May be NULL. */
651 const char *modifier_chars;
652 /* Details of the flag characters, including pseudo-flags. */
653 const format_flag_spec *flag_specs;
654 /* Details of bad combinations of flags. */
655 const format_flag_pair *bad_flag_pairs;
656 /* Flags applicable to this kind of format. */
657 int flags;
658 /* Flag character to treat a width as, or 0 if width not used. */
659 int width_char;
660 /* Flag character to treat a left precision (strfmon) as,
661 or 0 if left precision not used. */
662 int left_precision_char;
663 /* Flag character to treat a precision (for strfmon, right precision) as,
664 or 0 if precision not used. */
665 int precision_char;
666 /* If a flag character has the effect of suppressing the conversion of
667 an argument ('*' in scanf), that flag character, otherwise 0. */
668 int suppression_char;
669 /* Flag character to treat a length modifier as (ignored if length
670 modifiers not used). Need not be placed in flag_chars for conversion
671 specifiers, but is used to check for bad combinations such as length
672 modifier with assignment suppression in scanf. */
673 int length_code_char;
674 /* Pointer to type of argument expected if '*' is used for a width,
675 or NULL if '*' not used for widths. */
676 tree *width_type;
677 /* Pointer to type of argument expected if '*' is used for a precision,
678 or NULL if '*' not used for precisions. */
679 tree *precision_type;
680 } format_kind_info;
683 /* Structure describing details of a type expected in format checking,
684 and the type to check against it. */
685 typedef struct format_wanted_type
687 /* The type wanted. */
688 tree wanted_type;
689 /* The name of this type to use in diagnostics. */
690 const char *wanted_type_name;
691 /* The level of indirection through pointers at which this type occurs. */
692 int pointer_count;
693 /* Whether, when pointer_count is 1, to allow any character type when
694 pedantic, rather than just the character or void type specified. */
695 int char_lenient_flag;
696 /* Whether the argument, dereferenced once, is written into and so the
697 argument must not be a pointer to a const-qualified type. */
698 int writing_in_flag;
699 /* Whether the argument, dereferenced once, is read from and so
700 must not be a NULL pointer. */
701 int reading_from_flag;
702 /* If warnings should be of the form "field precision is not type int",
703 the name to use (in this case "field precision"), otherwise NULL,
704 for "%s format, %s arg" type messages. If (in an extension), this
705 is a pointer type, wanted_type_name should be set to include the
706 terminating '*' characters of the type name to give a correct
707 message. */
708 const char *name;
709 /* The actual parameter to check against the wanted type. */
710 tree param;
711 /* The argument number of that parameter. */
712 int arg_num;
713 /* The next type to check for this format conversion, or NULL if none. */
714 struct format_wanted_type *next;
715 } format_wanted_type;
718 static const format_length_info printf_length_specs[] =
720 { "h", FMT_LEN_h, STD_C89, "hh", FMT_LEN_hh, STD_C99 },
721 { "l", FMT_LEN_l, STD_C89, "ll", FMT_LEN_ll, STD_C9L },
722 { "q", FMT_LEN_ll, STD_EXT, NULL, 0, 0 },
723 { "L", FMT_LEN_L, STD_C89, NULL, 0, 0 },
724 { "z", FMT_LEN_z, STD_C99, NULL, 0, 0 },
725 { "Z", FMT_LEN_z, STD_EXT, NULL, 0, 0 },
726 { "t", FMT_LEN_t, STD_C99, NULL, 0, 0 },
727 { "j", FMT_LEN_j, STD_C99, NULL, 0, 0 },
728 { NULL, 0, 0, NULL, 0, 0 }
732 /* This differs from printf_length_specs only in that "Z" is not accepted. */
733 static const format_length_info scanf_length_specs[] =
735 { "h", FMT_LEN_h, STD_C89, "hh", FMT_LEN_hh, STD_C99 },
736 { "l", FMT_LEN_l, STD_C89, "ll", FMT_LEN_ll, STD_C9L },
737 { "q", FMT_LEN_ll, STD_EXT, NULL, 0, 0 },
738 { "L", FMT_LEN_L, STD_C89, NULL, 0, 0 },
739 { "z", FMT_LEN_z, STD_C99, NULL, 0, 0 },
740 { "t", FMT_LEN_t, STD_C99, NULL, 0, 0 },
741 { "j", FMT_LEN_j, STD_C99, NULL, 0, 0 },
742 { NULL, 0, 0, NULL, 0, 0 }
746 /* All tables for strfmon use STD_C89 everywhere, since -pedantic warnings
747 make no sense for a format type not part of any C standard version. */
748 static const format_length_info strfmon_length_specs[] =
750 /* A GNU extension. */
751 { "L", FMT_LEN_L, STD_C89, NULL, 0, 0 },
752 { NULL, 0, 0, NULL, 0, 0 }
755 static const format_flag_spec printf_flag_specs[] =
757 { ' ', 0, 0, N_("` ' flag"), N_("the ` ' printf flag"), STD_C89 },
758 { '+', 0, 0, N_("`+' flag"), N_("the `+' printf flag"), STD_C89 },
759 { '#', 0, 0, N_("`#' flag"), N_("the `#' printf flag"), STD_C89 },
760 { '0', 0, 0, N_("`0' flag"), N_("the `0' printf flag"), STD_C89 },
761 { '-', 0, 0, N_("`-' flag"), N_("the `-' printf flag"), STD_C89 },
762 { '\'', 0, 0, N_("`'' flag"), N_("the `'' printf flag"), STD_EXT },
763 { 'I', 0, 0, N_("`I' flag"), N_("the `I' printf flag"), STD_EXT },
764 { 'w', 0, 0, N_("field width"), N_("field width in printf format"), STD_C89 },
765 { 'p', 0, 0, N_("precision"), N_("precision in printf format"), STD_C89 },
766 { 'L', 0, 0, N_("length modifier"), N_("length modifier in printf format"), STD_C89 },
767 { 0, 0, 0, NULL, NULL, 0 }
771 static const format_flag_pair printf_flag_pairs[] =
773 { ' ', '+', 1, 0 },
774 { '0', '-', 1, 0 },
775 { '0', 'p', 1, 'i' },
776 { 0, 0, 0, 0 }
780 static const format_flag_spec scanf_flag_specs[] =
782 { '*', 0, 0, N_("assignment suppression"), N_("assignment suppression"), STD_C89 },
783 { 'a', 0, 0, N_("`a' flag"), N_("the `a' scanf flag"), STD_EXT },
784 { 'w', 0, 0, N_("field width"), N_("field width in scanf format"), STD_C89 },
785 { 'L', 0, 0, N_("length modifier"), N_("length modifier in scanf format"), STD_C89 },
786 { '\'', 0, 0, N_("`'' flag"), N_("the `'' scanf flag"), STD_EXT },
787 { 'I', 0, 0, N_("`I' flag"), N_("the `I' scanf flag"), STD_EXT },
788 { 0, 0, 0, NULL, NULL, 0 }
792 static const format_flag_pair scanf_flag_pairs[] =
794 { '*', 'L', 0, 0 },
795 { 0, 0, 0, 0 }
799 static const format_flag_spec strftime_flag_specs[] =
801 { '_', 0, 0, N_("`_' flag"), N_("the `_' strftime flag"), STD_EXT },
802 { '-', 0, 0, N_("`-' flag"), N_("the `-' strftime flag"), STD_EXT },
803 { '0', 0, 0, N_("`0' flag"), N_("the `0' strftime flag"), STD_EXT },
804 { '^', 0, 0, N_("`^' flag"), N_("the `^' strftime flag"), STD_EXT },
805 { '#', 0, 0, N_("`#' flag"), N_("the `#' strftime flag"), STD_EXT },
806 { 'w', 0, 0, N_("field width"), N_("field width in strftime format"), STD_EXT },
807 { 'E', 0, 0, N_("`E' modifier"), N_("the `E' strftime modifier"), STD_C99 },
808 { 'O', 0, 0, N_("`O' modifier"), N_("the `O' strftime modifier"), STD_C99 },
809 { 'O', 'o', 0, NULL, N_("the `O' modifier"), STD_EXT },
810 { 0, 0, 0, NULL, NULL, 0 }
814 static const format_flag_pair strftime_flag_pairs[] =
816 { 'E', 'O', 0, 0 },
817 { '_', '-', 0, 0 },
818 { '_', '0', 0, 0 },
819 { '-', '0', 0, 0 },
820 { '^', '#', 0, 0 },
821 { 0, 0, 0, 0 }
825 static const format_flag_spec strfmon_flag_specs[] =
827 { '=', 0, 1, N_("fill character"), N_("fill character in strfmon format"), STD_C89 },
828 { '^', 0, 0, N_("`^' flag"), N_("the `^' strfmon flag"), STD_C89 },
829 { '+', 0, 0, N_("`+' flag"), N_("the `+' strfmon flag"), STD_C89 },
830 { '(', 0, 0, N_("`(' flag"), N_("the `(' strfmon flag"), STD_C89 },
831 { '!', 0, 0, N_("`!' flag"), N_("the `!' strfmon flag"), STD_C89 },
832 { '-', 0, 0, N_("`-' flag"), N_("the `-' strfmon flag"), STD_C89 },
833 { 'w', 0, 0, N_("field width"), N_("field width in strfmon format"), STD_C89 },
834 { '#', 0, 0, N_("left precision"), N_("left precision in strfmon format"), STD_C89 },
835 { 'p', 0, 0, N_("right precision"), N_("right precision in strfmon format"), STD_C89 },
836 { 'L', 0, 0, N_("length modifier"), N_("length modifier in strfmon format"), STD_C89 },
837 { 0, 0, 0, NULL, NULL, 0 }
840 static const format_flag_pair strfmon_flag_pairs[] =
842 { '+', '(', 0, 0 },
843 { 0, 0, 0, 0 }
847 #define T_I &integer_type_node
848 #define T89_I { STD_C89, NULL, T_I }
849 #define T99_I { STD_C99, NULL, T_I }
850 #define T_L &long_integer_type_node
851 #define T89_L { STD_C89, NULL, T_L }
852 #define T_LL &long_long_integer_type_node
853 #define T9L_LL { STD_C9L, NULL, T_LL }
854 #define TEX_LL { STD_EXT, NULL, T_LL }
855 #define T_S &short_integer_type_node
856 #define T89_S { STD_C89, NULL, T_S }
857 #define T_UI &unsigned_type_node
858 #define T89_UI { STD_C89, NULL, T_UI }
859 #define T99_UI { STD_C99, NULL, T_UI }
860 #define T_UL &long_unsigned_type_node
861 #define T89_UL { STD_C89, NULL, T_UL }
862 #define T_ULL &long_long_unsigned_type_node
863 #define T9L_ULL { STD_C9L, NULL, T_ULL }
864 #define TEX_ULL { STD_EXT, NULL, T_ULL }
865 #define T_US &short_unsigned_type_node
866 #define T89_US { STD_C89, NULL, T_US }
867 #define T_F &float_type_node
868 #define T89_F { STD_C89, NULL, T_F }
869 #define T99_F { STD_C99, NULL, T_F }
870 #define T_D &double_type_node
871 #define T89_D { STD_C89, NULL, T_D }
872 #define T99_D { STD_C99, NULL, T_D }
873 #define T_LD &long_double_type_node
874 #define T89_LD { STD_C89, NULL, T_LD }
875 #define T99_LD { STD_C99, NULL, T_LD }
876 #define T_C &char_type_node
877 #define T89_C { STD_C89, NULL, T_C }
878 #define T_SC &signed_char_type_node
879 #define T99_SC { STD_C99, NULL, T_SC }
880 #define T_UC &unsigned_char_type_node
881 #define T99_UC { STD_C99, NULL, T_UC }
882 #define T_V &void_type_node
883 #define T89_V { STD_C89, NULL, T_V }
884 #define T_W &wchar_type_node
885 #define T94_W { STD_C94, "wchar_t", T_W }
886 #define TEX_W { STD_EXT, "wchar_t", T_W }
887 #define T_WI &wint_type_node
888 #define T94_WI { STD_C94, "wint_t", T_WI }
889 #define TEX_WI { STD_EXT, "wint_t", T_WI }
890 #define T_ST &c_size_type_node
891 #define T99_ST { STD_C99, "size_t", T_ST }
892 #define T_SST &signed_size_type_node
893 #define T99_SST { STD_C99, "signed size_t", T_SST }
894 #define T_PD &ptrdiff_type_node
895 #define T99_PD { STD_C99, "ptrdiff_t", T_PD }
896 #define T_UPD &unsigned_ptrdiff_type_node
897 #define T99_UPD { STD_C99, "unsigned ptrdiff_t", T_UPD }
898 #define T_IM &intmax_type_node
899 #define T99_IM { STD_C99, "intmax_t", T_IM }
900 #define T_UIM &uintmax_type_node
901 #define T99_UIM { STD_C99, "uintmax_t", T_UIM }
903 static const format_char_info print_char_table[] =
905 /* C89 conversion specifiers. */
906 { "di", 0, STD_C89, { T89_I, T99_SC, T89_S, T89_L, T9L_LL, TEX_LL, T99_SST, T99_PD, T99_IM }, "-wp0 +'I", "i" },
907 { "oxX", 0, STD_C89, { T89_UI, T99_UC, T89_US, T89_UL, T9L_ULL, TEX_ULL, T99_ST, T99_UPD, T99_UIM }, "-wp0#", "i" },
908 { "u", 0, STD_C89, { T89_UI, T99_UC, T89_US, T89_UL, T9L_ULL, TEX_ULL, T99_ST, T99_UPD, T99_UIM }, "-wp0'I", "i" },
909 { "fgG", 0, STD_C89, { T89_D, BADLEN, BADLEN, T99_D, BADLEN, T89_LD, BADLEN, BADLEN, BADLEN }, "-wp0 +#'", "" },
910 { "eE", 0, STD_C89, { T89_D, BADLEN, BADLEN, T99_D, BADLEN, T89_LD, BADLEN, BADLEN, BADLEN }, "-wp0 +#", "" },
911 { "c", 0, STD_C89, { T89_I, BADLEN, BADLEN, T94_WI, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN }, "-w", "" },
912 { "s", 1, STD_C89, { T89_C, BADLEN, BADLEN, T94_W, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN }, "-wp", "cR" },
913 { "p", 1, STD_C89, { T89_V, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN }, "-w", "c" },
914 { "n", 1, STD_C89, { T89_I, T99_SC, T89_S, T89_L, T9L_LL, BADLEN, T99_SST, T99_PD, T99_IM }, "", "W" },
915 /* C99 conversion specifiers. */
916 { "F", 0, STD_C99, { T99_D, BADLEN, BADLEN, T99_D, BADLEN, T99_LD, BADLEN, BADLEN, BADLEN }, "-wp0 +#'", "" },
917 { "aA", 0, STD_C99, { T99_D, BADLEN, BADLEN, T99_D, BADLEN, T99_LD, BADLEN, BADLEN, BADLEN }, "-wp0 +#", "" },
918 /* X/Open conversion specifiers. */
919 { "C", 0, STD_EXT, { TEX_WI, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN }, "-w", "" },
920 { "S", 1, STD_EXT, { TEX_W, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN }, "-wp", "R" },
921 /* GNU conversion specifiers. */
922 { "m", 0, STD_EXT, { T89_V, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN }, "-wp", "" },
923 { NULL, 0, 0, NOLENGTHS, NULL, NULL }
926 static const format_char_info scan_char_table[] =
928 /* C89 conversion specifiers. */
929 { "di", 1, STD_C89, { T89_I, T99_SC, T89_S, T89_L, T9L_LL, TEX_LL, T99_SST, T99_PD, T99_IM }, "*w'I", "W" },
930 { "u", 1, STD_C89, { T89_UI, T99_UC, T89_US, T89_UL, T9L_ULL, TEX_ULL, T99_ST, T99_UPD, T99_UIM }, "*w'I", "W" },
931 { "oxX", 1, STD_C89, { T89_UI, T99_UC, T89_US, T89_UL, T9L_ULL, TEX_ULL, T99_ST, T99_UPD, T99_UIM }, "*w", "W" },
932 { "efgEG", 1, STD_C89, { T89_F, BADLEN, BADLEN, T89_D, BADLEN, T89_LD, BADLEN, BADLEN, BADLEN }, "*w'", "W" },
933 { "c", 1, STD_C89, { T89_C, BADLEN, BADLEN, T94_W, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN }, "*w", "cW" },
934 { "s", 1, STD_C89, { T89_C, BADLEN, BADLEN, T94_W, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN }, "*aw", "cW" },
935 { "[", 1, STD_C89, { T89_C, BADLEN, BADLEN, T94_W, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN }, "*aw", "cW[" },
936 { "p", 2, STD_C89, { T89_V, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN }, "*w", "W" },
937 { "n", 1, STD_C89, { T89_I, T99_SC, T89_S, T89_L, T9L_LL, BADLEN, T99_SST, T99_PD, T99_IM }, "", "W" },
938 /* C99 conversion specifiers. */
939 { "FaA", 1, STD_C99, { T99_F, BADLEN, BADLEN, T99_D, BADLEN, T99_LD, BADLEN, BADLEN, BADLEN }, "*w'", "W" },
940 /* X/Open conversion specifiers. */
941 { "C", 1, STD_EXT, { TEX_W, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN }, "*w", "W" },
942 { "S", 1, STD_EXT, { TEX_W, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN, BADLEN }, "*aw", "W" },
943 { NULL, 0, 0, NOLENGTHS, NULL, NULL }
946 static const format_char_info time_char_table[] =
948 /* C89 conversion specifiers. */
949 { "ABZab", 0, STD_C89, NOLENGTHS, "^#", "" },
950 { "cx", 0, STD_C89, NOLENGTHS, "E", "3" },
951 { "HIMSUWdmw", 0, STD_C89, NOLENGTHS, "-_0Ow", "" },
952 { "j", 0, STD_C89, NOLENGTHS, "-_0Ow", "o" },
953 { "p", 0, STD_C89, NOLENGTHS, "#", "" },
954 { "X", 0, STD_C89, NOLENGTHS, "E", "" },
955 { "y", 0, STD_C89, NOLENGTHS, "EO-_0w", "4" },
956 { "Y", 0, STD_C89, NOLENGTHS, "-_0EOw", "o" },
957 { "%", 0, STD_C89, NOLENGTHS, "", "" },
958 /* C99 conversion specifiers. */
959 { "C", 0, STD_C99, NOLENGTHS, "-_0EOw", "o" },
960 { "D", 0, STD_C99, NOLENGTHS, "", "2" },
961 { "eVu", 0, STD_C99, NOLENGTHS, "-_0Ow", "" },
962 { "FRTnrt", 0, STD_C99, NOLENGTHS, "", "" },
963 { "g", 0, STD_C99, NOLENGTHS, "O-_0w", "2o" },
964 { "G", 0, STD_C99, NOLENGTHS, "-_0Ow", "o" },
965 { "h", 0, STD_C99, NOLENGTHS, "^#", "" },
966 { "z", 0, STD_C99, NOLENGTHS, "O", "o" },
967 /* GNU conversion specifiers. */
968 { "kls", 0, STD_EXT, NOLENGTHS, "-_0Ow", "" },
969 { "P", 0, STD_EXT, NOLENGTHS, "", "" },
970 { NULL, 0, 0, NOLENGTHS, NULL, NULL }
973 static const format_char_info monetary_char_table[] =
975 { "in", 0, STD_C89, { T89_D, BADLEN, BADLEN, BADLEN, BADLEN, T89_LD, BADLEN, BADLEN, BADLEN }, "=^+(!-w#p", "" },
976 { NULL, 0, 0, NOLENGTHS, NULL, NULL }
980 /* This must be in the same order as enum format_type. */
981 static const format_kind_info format_types[] =
983 { "printf", printf_length_specs, print_char_table, " +#0-'I", NULL,
984 printf_flag_specs, printf_flag_pairs,
985 FMT_FLAG_ARG_CONVERT|FMT_FLAG_DOLLAR_MULTIPLE|FMT_FLAG_USE_DOLLAR|FMT_FLAG_EMPTY_PREC_OK,
986 'w', 0, 'p', 0, 'L',
987 &integer_type_node, &integer_type_node
989 { "scanf", scanf_length_specs, scan_char_table, "*'I", NULL,
990 scanf_flag_specs, scanf_flag_pairs,
991 FMT_FLAG_ARG_CONVERT|FMT_FLAG_SCANF_A_KLUDGE|FMT_FLAG_USE_DOLLAR|FMT_FLAG_ZERO_WIDTH_BAD,
992 'w', 0, 0, '*', 'L',
993 NULL, NULL
995 { "strftime", NULL, time_char_table, "_-0^#", "EO",
996 strftime_flag_specs, strftime_flag_pairs,
997 FMT_FLAG_FANCY_PERCENT_OK, 'w', 0, 0, 0, 0,
998 NULL, NULL
1000 { "strfmon", strfmon_length_specs, monetary_char_table, "=^+(!-", NULL,
1001 strfmon_flag_specs, strfmon_flag_pairs,
1002 FMT_FLAG_ARG_CONVERT, 'w', '#', 'p', 0, 'L',
1003 NULL, NULL
1008 /* Structure detailing the results of checking a format function call
1009 where the format expression may be a conditional expression with
1010 many leaves resulting from nested conditional expressions. */
1011 typedef struct
1013 /* Number of leaves of the format argument that could not be checked
1014 as they were not string literals. */
1015 int number_non_literal;
1016 /* Number of leaves of the format argument that were null pointers or
1017 string literals, but had extra format arguments. */
1018 int number_extra_args;
1019 /* Number of leaves of the format argument that were null pointers or
1020 string literals, but had extra format arguments and used $ operand
1021 numbers. */
1022 int number_dollar_extra_args;
1023 /* Number of leaves of the format argument that were wide string
1024 literals. */
1025 int number_wide;
1026 /* Number of leaves of the format argument that were empty strings. */
1027 int number_empty;
1028 /* Number of leaves of the format argument that were unterminated
1029 strings. */
1030 int number_unterminated;
1031 /* Number of leaves of the format argument that were not counted above. */
1032 int number_other;
1033 } format_check_results;
1035 static void check_format_info PARAMS ((int *, function_format_info *, tree));
1036 static void check_format_info_recurse PARAMS ((int *, format_check_results *,
1037 function_format_info *, tree,
1038 tree, int));
1039 static void check_format_info_main PARAMS ((int *, format_check_results *,
1040 function_format_info *,
1041 const char *, int, tree, int));
1042 static void status_warning PARAMS ((int *, const char *, ...))
1043 ATTRIBUTE_PRINTF_2;
1045 static void init_dollar_format_checking PARAMS ((int, tree));
1046 static int maybe_read_dollar_number PARAMS ((int *, const char **, int,
1047 tree, tree *,
1048 const format_kind_info *));
1049 static void finish_dollar_format_checking PARAMS ((int *, format_check_results *));
1051 static const format_flag_spec *get_flag_spec PARAMS ((const format_flag_spec *,
1052 int, const char *));
1054 static void check_format_types PARAMS ((int *, format_wanted_type *));
1056 /* Decode a format type from a string, returning the type, or
1057 format_type_error if not valid, in which case the caller should print an
1058 error message. */
1059 static enum format_type
1060 decode_format_type (s)
1061 const char *s;
1063 int i;
1064 int slen;
1065 slen = strlen (s);
1066 for (i = 0; i < (int) format_type_error; i++)
1068 int alen;
1069 if (!strcmp (s, format_types[i].name))
1070 break;
1071 alen = strlen (format_types[i].name);
1072 if (slen == alen + 4 && s[0] == '_' && s[1] == '_'
1073 && s[slen - 1] == '_' && s[slen - 2] == '_'
1074 && !strncmp (s + 2, format_types[i].name, alen))
1075 break;
1077 return ((enum format_type) i);
1081 /* Check the argument list of a call to printf, scanf, etc.
1082 NAME is the function identifier.
1083 ASSEMBLER_NAME is the function's assembler identifier.
1084 (Either NAME or ASSEMBLER_NAME, but not both, may be NULL_TREE.)
1085 PARAMS is the list of argument values. Also, if -Wmissing-format-attribute,
1086 warn for calls to vprintf or vscanf in functions with no such format
1087 attribute themselves. */
1089 void
1090 check_function_format (status, name, assembler_name, params)
1091 int *status;
1092 tree name;
1093 tree assembler_name;
1094 tree params;
1096 function_format_info *info;
1098 /* See if this function is a format function. */
1099 for (info = function_format_list; info; info = info->next)
1101 if (info->assembler_name
1102 ? (info->assembler_name == assembler_name)
1103 : (info->name == name))
1105 /* Yup; check it. */
1106 check_format_info (status, info, params);
1107 if (warn_missing_format_attribute && info->first_arg_num == 0
1108 && (format_types[info->format_type].flags
1109 & (int) FMT_FLAG_ARG_CONVERT))
1111 function_format_info *info2;
1112 for (info2 = function_format_list; info2; info2 = info2->next)
1113 if ((info2->assembler_name
1114 ? (info2->assembler_name == DECL_ASSEMBLER_NAME (current_function_decl))
1115 : (info2->name == DECL_NAME (current_function_decl)))
1116 && info2->format_type == info->format_type)
1117 break;
1118 if (info2 == NULL)
1120 /* Check if the current function has a parameter to which
1121 the format attribute could be attached; if not, it
1122 can't be a candidate for a format attribute, despite
1123 the vprintf-like or vscanf-like call. */
1124 tree args;
1125 for (args = DECL_ARGUMENTS (current_function_decl);
1126 args != 0;
1127 args = TREE_CHAIN (args))
1129 if (TREE_CODE (TREE_TYPE (args)) == POINTER_TYPE
1130 && (TYPE_MAIN_VARIANT (TREE_TYPE (TREE_TYPE (args)))
1131 == char_type_node))
1132 break;
1134 if (args != 0)
1135 warning ("function might be possible candidate for `%s' format attribute",
1136 format_types[info->format_type].name);
1139 break;
1144 /* This function replaces `warning' inside the printf format checking
1145 functions. If the `status' parameter is non-NULL, then it is
1146 dereferenced and set to 1 whenever a warning is caught. Otherwise
1147 it warns as usual by replicating the innards of the warning
1148 function from diagnostic.c. */
1149 static void
1150 status_warning VPARAMS ((int *status, const char *msgid, ...))
1152 #ifndef ANSI_PROTOTYPES
1153 int *status;
1154 const char *msgid;
1155 #endif
1156 va_list ap;
1157 diagnostic_context dc;
1159 VA_START (ap, msgid);
1161 #ifndef ANSI_PROTOTYPES
1162 status = va_arg (ap, int *);
1163 msgid = va_arg (ap, const char *);
1164 #endif
1166 if (status)
1167 *status = 1;
1168 else
1170 /* This duplicates the warning function behavior. */
1171 set_diagnostic_context
1172 (&dc, msgid, &ap, input_filename, lineno, /* warn = */ 1);
1173 report_diagnostic (&dc);
1176 va_end (ap);
1179 /* Variables used by the checking of $ operand number formats. */
1180 static char *dollar_arguments_used = NULL;
1181 static int dollar_arguments_alloc = 0;
1182 static int dollar_arguments_count;
1183 static int dollar_first_arg_num;
1184 static int dollar_max_arg_used;
1185 static int dollar_format_warned;
1187 /* Initialize the checking for a format string that may contain $
1188 parameter number specifications; we will need to keep track of whether
1189 each parameter has been used. FIRST_ARG_NUM is the number of the first
1190 argument that is a parameter to the format, or 0 for a vprintf-style
1191 function; PARAMS is the list of arguments starting at this argument. */
1193 static void
1194 init_dollar_format_checking (first_arg_num, params)
1195 int first_arg_num;
1196 tree params;
1198 dollar_first_arg_num = first_arg_num;
1199 dollar_arguments_count = 0;
1200 dollar_max_arg_used = 0;
1201 dollar_format_warned = 0;
1202 if (first_arg_num > 0)
1204 while (params)
1206 dollar_arguments_count++;
1207 params = TREE_CHAIN (params);
1210 if (dollar_arguments_alloc < dollar_arguments_count)
1212 if (dollar_arguments_used)
1213 free (dollar_arguments_used);
1214 dollar_arguments_alloc = dollar_arguments_count;
1215 dollar_arguments_used = xmalloc (dollar_arguments_alloc);
1217 if (dollar_arguments_alloc)
1218 memset (dollar_arguments_used, 0, dollar_arguments_alloc);
1222 /* Look for a decimal number followed by a $ in *FORMAT. If DOLLAR_NEEDED
1223 is set, it is an error if one is not found; otherwise, it is OK. If
1224 such a number is found, check whether it is within range and mark that
1225 numbered operand as being used for later checking. Returns the operand
1226 number if found and within range, zero if no such number was found and
1227 this is OK, or -1 on error. PARAMS points to the first operand of the
1228 format; PARAM_PTR is made to point to the parameter referred to. If
1229 a $ format is found, *FORMAT is updated to point just after it. */
1231 static int
1232 maybe_read_dollar_number (status, format, dollar_needed, params, param_ptr,
1233 fki)
1234 int *status;
1235 const char **format;
1236 int dollar_needed;
1237 tree params;
1238 tree *param_ptr;
1239 const format_kind_info *fki;
1241 int argnum;
1242 int overflow_flag;
1243 const char *fcp = *format;
1244 if (*fcp < '0' || *fcp > '9')
1246 if (dollar_needed)
1248 status_warning (status, "missing $ operand number in format");
1249 return -1;
1251 else
1252 return 0;
1254 argnum = 0;
1255 overflow_flag = 0;
1256 while (*fcp >= '0' && *fcp <= '9')
1258 int nargnum;
1259 nargnum = 10 * argnum + (*fcp - '0');
1260 if (nargnum < 0 || nargnum / 10 != argnum)
1261 overflow_flag = 1;
1262 argnum = nargnum;
1263 fcp++;
1265 if (*fcp != '$')
1267 if (dollar_needed)
1269 status_warning (status, "missing $ operand number in format");
1270 return -1;
1272 else
1273 return 0;
1275 *format = fcp + 1;
1276 if (pedantic && !dollar_format_warned)
1278 status_warning (status,
1279 "%s does not support %%n$ operand number formats",
1280 C_STD_NAME (STD_EXT));
1281 dollar_format_warned = 1;
1283 if (overflow_flag || argnum == 0
1284 || (dollar_first_arg_num && argnum > dollar_arguments_count))
1286 status_warning (status, "operand number out of range in format");
1287 return -1;
1289 if (argnum > dollar_max_arg_used)
1290 dollar_max_arg_used = argnum;
1291 /* For vprintf-style functions we may need to allocate more memory to
1292 track which arguments are used. */
1293 while (dollar_arguments_alloc < dollar_max_arg_used)
1295 int nalloc;
1296 nalloc = 2 * dollar_arguments_alloc + 16;
1297 dollar_arguments_used = xrealloc (dollar_arguments_used, nalloc);
1298 memset (dollar_arguments_used + dollar_arguments_alloc, 0,
1299 nalloc - dollar_arguments_alloc);
1300 dollar_arguments_alloc = nalloc;
1302 if (!(fki->flags & (int) FMT_FLAG_DOLLAR_MULTIPLE)
1303 && dollar_arguments_used[argnum - 1] == 1)
1305 dollar_arguments_used[argnum - 1] = 2;
1306 status_warning (status,
1307 "format argument %d used more than once in %s format",
1308 argnum, fki->name);
1310 else
1311 dollar_arguments_used[argnum - 1] = 1;
1312 if (dollar_first_arg_num)
1314 int i;
1315 *param_ptr = params;
1316 for (i = 1; i < argnum && *param_ptr != 0; i++)
1317 *param_ptr = TREE_CHAIN (*param_ptr);
1319 if (*param_ptr == 0)
1321 /* This case shouldn't be caught here. */
1322 abort ();
1325 else
1326 *param_ptr = 0;
1327 return argnum;
1331 /* Finish the checking for a format string that used $ operand number formats
1332 instead of non-$ formats. We check for unused operands before used ones
1333 (a serious error, since the implementation of the format function
1334 can't know what types to pass to va_arg to find the later arguments).
1335 and for unused operands at the end of the format (if we know how many
1336 arguments the format had, so not for vprintf). If there were operand
1337 numbers out of range on a non-vprintf-style format, we won't have reached
1338 here. */
1340 static void
1341 finish_dollar_format_checking (status, res)
1342 int *status;
1343 format_check_results *res;
1345 int i;
1346 for (i = 0; i < dollar_max_arg_used; i++)
1348 if (!dollar_arguments_used[i])
1349 status_warning (status, "format argument %d unused before used argument %d in $-style format",
1350 i + 1, dollar_max_arg_used);
1352 if (dollar_first_arg_num && dollar_max_arg_used < dollar_arguments_count)
1354 res->number_other--;
1355 res->number_dollar_extra_args++;
1360 /* Retrieve the specification for a format flag. SPEC contains the
1361 specifications for format flags for the applicable kind of format.
1362 FLAG is the flag in question. If PREDICATES is NULL, the basic
1363 spec for that flag must be retrieved and this function aborts if
1364 it cannot be found. If PREDICATES is not NULL, it is a string listing
1365 possible predicates for the spec entry; if an entry predicated on any
1366 of these is found, it is returned, otherwise NULL is returned. */
1368 static const format_flag_spec *
1369 get_flag_spec (spec, flag, predicates)
1370 const format_flag_spec *spec;
1371 int flag;
1372 const char *predicates;
1374 int i;
1375 for (i = 0; spec[i].flag_char != 0; i++)
1377 if (spec[i].flag_char != flag)
1378 continue;
1379 if (predicates != NULL)
1381 if (spec[i].predicate != 0
1382 && strchr (predicates, spec[i].predicate) != 0)
1383 return &spec[i];
1385 else if (spec[i].predicate == 0)
1386 return &spec[i];
1388 if (predicates == NULL)
1389 abort ();
1390 else
1391 return NULL;
1395 /* Check the argument list of a call to printf, scanf, etc.
1396 INFO points to the function_format_info structure.
1397 PARAMS is the list of argument values. */
1399 static void
1400 check_format_info (status, info, params)
1401 int *status;
1402 function_format_info *info;
1403 tree params;
1405 int arg_num;
1406 tree format_tree;
1407 format_check_results res;
1408 /* Skip to format argument. If the argument isn't available, there's
1409 no work for us to do; prototype checking will catch the problem. */
1410 for (arg_num = 1; ; ++arg_num)
1412 if (params == 0)
1413 return;
1414 if (arg_num == info->format_num)
1415 break;
1416 params = TREE_CHAIN (params);
1418 format_tree = TREE_VALUE (params);
1419 params = TREE_CHAIN (params);
1420 if (format_tree == 0)
1421 return;
1423 res.number_non_literal = 0;
1424 res.number_extra_args = 0;
1425 res.number_dollar_extra_args = 0;
1426 res.number_wide = 0;
1427 res.number_empty = 0;
1428 res.number_unterminated = 0;
1429 res.number_other = 0;
1431 check_format_info_recurse (status, &res, info, format_tree, params, arg_num);
1433 if (res.number_non_literal > 0)
1435 /* Functions taking a va_list normally pass a non-literal format
1436 string. These functions typically are declared with
1437 first_arg_num == 0, so avoid warning in those cases. */
1438 if (!(format_types[info->format_type].flags & (int) FMT_FLAG_ARG_CONVERT))
1440 /* For strftime-like formats, warn for not checking the format
1441 string; but there are no arguments to check. */
1442 if (warn_format_nonliteral)
1443 status_warning (status, "format not a string literal, format string not checked");
1445 else if (info->first_arg_num != 0)
1447 /* If there are no arguments for the format at all, we may have
1448 printf (foo) which is likely to be a security hole. */
1449 while (arg_num + 1 < info->first_arg_num)
1451 if (params == 0)
1452 break;
1453 params = TREE_CHAIN (params);
1454 ++arg_num;
1456 if (params == 0 && (warn_format_nonliteral || warn_format_security))
1457 status_warning (status, "format not a string literal and no format arguments");
1458 else if (warn_format_nonliteral)
1459 status_warning (status, "format not a string literal, argument types not checked");
1463 /* If there were extra arguments to the format, normally warn. However,
1464 the standard does say extra arguments are ignored, so in the specific
1465 case where we have multiple leaves (conditional expressions or
1466 ngettext) allow extra arguments if at least one leaf didn't have extra
1467 arguments, but was otherwise OK (either non-literal or checked OK).
1468 If the format is an empty string, this should be counted similarly to the
1469 case of extra format arguments. */
1470 if (res.number_extra_args > 0 && res.number_non_literal == 0
1471 && res.number_other == 0 && warn_format_extra_args)
1472 status_warning (status, "too many arguments for format");
1473 if (res.number_dollar_extra_args > 0 && res.number_non_literal == 0
1474 && res.number_other == 0 && warn_format_extra_args)
1475 status_warning (status, "unused arguments in $-style format");
1476 if (res.number_empty > 0 && res.number_non_literal == 0
1477 && res.number_other == 0)
1478 status_warning (status, "zero-length format string");
1480 if (res.number_wide > 0)
1481 status_warning (status, "format is a wide character string");
1483 if (res.number_unterminated > 0)
1484 status_warning (status, "unterminated format string");
1488 /* Recursively check a call to a format function. FORMAT_TREE is the
1489 format parameter, which may be a conditional expression in which
1490 both halves should be checked. ARG_NUM is the number of the
1491 format argument; PARAMS points just after it in the argument list. */
1493 static void
1494 check_format_info_recurse (status, res, info, format_tree, params, arg_num)
1495 int *status;
1496 format_check_results *res;
1497 function_format_info *info;
1498 tree format_tree;
1499 tree params;
1500 int arg_num;
1502 int format_length;
1503 const char *format_chars;
1504 tree array_size = 0;
1505 tree array_init;
1507 if (TREE_CODE (format_tree) == NOP_EXPR)
1509 /* Strip coercion. */
1510 check_format_info_recurse (status, res, info,
1511 TREE_OPERAND (format_tree, 0), params,
1512 arg_num);
1513 return;
1516 if (TREE_CODE (format_tree) == CALL_EXPR
1517 && TREE_CODE (TREE_OPERAND (format_tree, 0)) == ADDR_EXPR
1518 && (TREE_CODE (TREE_OPERAND (TREE_OPERAND (format_tree, 0), 0))
1519 == FUNCTION_DECL))
1521 tree function = TREE_OPERAND (TREE_OPERAND (format_tree, 0), 0);
1523 /* See if this is a call to a known internationalization function
1524 that modifies the format arg. */
1525 international_format_info *iinfo;
1527 for (iinfo = international_format_list; iinfo; iinfo = iinfo->next)
1528 if (iinfo->assembler_name
1529 ? (iinfo->assembler_name == DECL_ASSEMBLER_NAME (function))
1530 : (iinfo->name == DECL_NAME (function)))
1532 tree inner_args;
1533 int i;
1535 for (inner_args = TREE_OPERAND (format_tree, 1), i = 1;
1536 inner_args != 0;
1537 inner_args = TREE_CHAIN (inner_args), i++)
1538 if (i == iinfo->format_num)
1540 /* FIXME: with Marc Espie's __attribute__((nonnull))
1541 patch in GCC, we will have chained attributes,
1542 and be able to handle functions like ngettext
1543 with multiple format_arg attributes properly. */
1544 check_format_info_recurse (status, res, info,
1545 TREE_VALUE (inner_args), params,
1546 arg_num);
1547 return;
1552 if (TREE_CODE (format_tree) == COND_EXPR)
1554 /* Check both halves of the conditional expression. */
1555 check_format_info_recurse (status, res, info,
1556 TREE_OPERAND (format_tree, 1), params,
1557 arg_num);
1558 check_format_info_recurse (status, res, info,
1559 TREE_OPERAND (format_tree, 2), params,
1560 arg_num);
1561 return;
1564 if (integer_zerop (format_tree))
1566 /* FIXME: this warning should go away once Marc Espie's
1567 __attribute__((nonnull)) patch is in. Instead, checking for
1568 nonnull attributes should probably change this function to act
1569 specially if info == NULL and add a res->number_null entry for
1570 that case, or maybe add a function pointer to be called at
1571 the end instead of hardcoding check_format_info_main. */
1572 status_warning (status, "null format string");
1574 /* Skip to first argument to check, so we can see if this format
1575 has any arguments (it shouldn't). */
1576 while (arg_num + 1 < info->first_arg_num)
1578 if (params == 0)
1579 return;
1580 params = TREE_CHAIN (params);
1581 ++arg_num;
1584 if (params == 0)
1585 res->number_other++;
1586 else
1587 res->number_extra_args++;
1589 return;
1592 if (TREE_CODE (format_tree) != ADDR_EXPR)
1594 res->number_non_literal++;
1595 return;
1597 format_tree = TREE_OPERAND (format_tree, 0);
1598 if (TREE_CODE (format_tree) == VAR_DECL
1599 && TREE_CODE (TREE_TYPE (format_tree)) == ARRAY_TYPE
1600 && (array_init = decl_constant_value (format_tree)) != format_tree
1601 && TREE_CODE (array_init) == STRING_CST)
1603 /* Extract the string constant initializer. Note that this may include
1604 a trailing NUL character that is not in the array (e.g.
1605 const char a[3] = "foo";). */
1606 array_size = DECL_SIZE_UNIT (format_tree);
1607 format_tree = array_init;
1609 if (TREE_CODE (format_tree) != STRING_CST)
1611 res->number_non_literal++;
1612 return;
1614 if (TYPE_MAIN_VARIANT (TREE_TYPE (TREE_TYPE (format_tree))) != char_type_node)
1616 res->number_wide++;
1617 return;
1619 format_chars = TREE_STRING_POINTER (format_tree);
1620 format_length = TREE_STRING_LENGTH (format_tree);
1621 if (array_size != 0)
1623 /* Variable length arrays can't be initialized. */
1624 if (TREE_CODE (array_size) != INTEGER_CST)
1625 abort ();
1626 if (host_integerp (array_size, 0))
1628 HOST_WIDE_INT array_size_value = TREE_INT_CST_LOW (array_size);
1629 if (array_size_value > 0
1630 && array_size_value == (int) array_size_value
1631 && format_length > array_size_value)
1632 format_length = array_size_value;
1635 if (format_length < 1)
1637 res->number_unterminated++;
1638 return;
1640 if (format_length == 1)
1642 res->number_empty++;
1643 return;
1645 if (format_chars[--format_length] != 0)
1647 res->number_unterminated++;
1648 return;
1651 /* Skip to first argument to check. */
1652 while (arg_num + 1 < info->first_arg_num)
1654 if (params == 0)
1655 return;
1656 params = TREE_CHAIN (params);
1657 ++arg_num;
1659 /* Provisionally increment res->number_other; check_format_info_main
1660 will decrement it if it finds there are extra arguments, but this way
1661 need not adjust it for every return. */
1662 res->number_other++;
1663 check_format_info_main (status, res, info, format_chars, format_length,
1664 params, arg_num);
1668 /* Do the main part of checking a call to a format function. FORMAT_CHARS
1669 is the NUL-terminated format string (which at this point may contain
1670 internal NUL characters); FORMAT_LENGTH is its length (excluding the
1671 terminating NUL character). ARG_NUM is one less than the number of
1672 the first format argument to check; PARAMS points to that format
1673 argument in the list of arguments. */
1675 static void
1676 check_format_info_main (status, res, info, format_chars, format_length,
1677 params, arg_num)
1678 int *status;
1679 format_check_results *res;
1680 function_format_info *info;
1681 const char *format_chars;
1682 int format_length;
1683 tree params;
1684 int arg_num;
1686 const char *orig_format_chars = format_chars;
1687 tree first_fillin_param = params;
1689 const format_kind_info *fki = &format_types[info->format_type];
1690 const format_flag_spec *flag_specs = fki->flag_specs;
1691 const format_flag_pair *bad_flag_pairs = fki->bad_flag_pairs;
1693 /* -1 if no conversions taking an operand have been found; 0 if one has
1694 and it didn't use $; 1 if $ formats are in use. */
1695 int has_operand_number = -1;
1697 init_dollar_format_checking (info->first_arg_num, first_fillin_param);
1699 while (1)
1701 int i;
1702 int suppressed = FALSE;
1703 const char *length_chars = NULL;
1704 enum format_lengths length_chars_val = FMT_LEN_none;
1705 enum format_std_version length_chars_std = STD_C89;
1706 int format_char;
1707 tree cur_param;
1708 tree wanted_type;
1709 int main_arg_num = 0;
1710 tree main_arg_params = 0;
1711 enum format_std_version wanted_type_std;
1712 const char *wanted_type_name;
1713 format_wanted_type width_wanted_type;
1714 format_wanted_type precision_wanted_type;
1715 format_wanted_type main_wanted_type;
1716 format_wanted_type *first_wanted_type = NULL;
1717 format_wanted_type *last_wanted_type = NULL;
1718 const format_length_info *fli = NULL;
1719 const format_char_info *fci = NULL;
1720 char flag_chars[256];
1721 int aflag = 0;
1722 if (*format_chars == 0)
1724 if (format_chars - orig_format_chars != format_length)
1725 status_warning (status, "embedded `\\0' in format");
1726 if (info->first_arg_num != 0 && params != 0
1727 && has_operand_number <= 0)
1729 res->number_other--;
1730 res->number_extra_args++;
1732 if (has_operand_number > 0)
1733 finish_dollar_format_checking (status, res);
1734 return;
1736 if (*format_chars++ != '%')
1737 continue;
1738 if (*format_chars == 0)
1740 status_warning (status, "spurious trailing `%%' in format");
1741 continue;
1743 if (*format_chars == '%')
1745 ++format_chars;
1746 continue;
1748 flag_chars[0] = 0;
1750 if ((fki->flags & (int) FMT_FLAG_USE_DOLLAR) && has_operand_number != 0)
1752 /* Possibly read a $ operand number at the start of the format.
1753 If one was previously used, one is required here. If one
1754 is not used here, we can't immediately conclude this is a
1755 format without them, since it could be printf %m or scanf %*. */
1756 int opnum;
1757 opnum = maybe_read_dollar_number (status, &format_chars, 0,
1758 first_fillin_param,
1759 &main_arg_params, fki);
1760 if (opnum == -1)
1761 return;
1762 else if (opnum > 0)
1764 has_operand_number = 1;
1765 main_arg_num = opnum + info->first_arg_num - 1;
1769 /* Read any format flags, but do not yet validate them beyond removing
1770 duplicates, since in general validation depends on the rest of
1771 the format. */
1772 while (*format_chars != 0
1773 && strchr (fki->flag_chars, *format_chars) != 0)
1775 const format_flag_spec *s = get_flag_spec (flag_specs,
1776 *format_chars, NULL);
1777 if (strchr (flag_chars, *format_chars) != 0)
1779 status_warning (status, "repeated %s in format", _(s->name));
1781 else
1783 i = strlen (flag_chars);
1784 flag_chars[i++] = *format_chars;
1785 flag_chars[i] = 0;
1787 if (s->skip_next_char)
1789 ++format_chars;
1790 if (*format_chars == 0)
1792 status_warning (status, "missing fill character at end of strfmon format");
1793 return;
1796 ++format_chars;
1799 /* Read any format width, possibly * or *m$. */
1800 if (fki->width_char != 0)
1802 if (fki->width_type != NULL && *format_chars == '*')
1804 i = strlen (flag_chars);
1805 flag_chars[i++] = fki->width_char;
1806 flag_chars[i] = 0;
1807 /* "...a field width...may be indicated by an asterisk.
1808 In this case, an int argument supplies the field width..." */
1809 ++format_chars;
1810 if (params == 0)
1812 status_warning (status, "too few arguments for format");
1813 return;
1815 if (has_operand_number != 0)
1817 int opnum;
1818 opnum = maybe_read_dollar_number (status, &format_chars,
1819 has_operand_number == 1,
1820 first_fillin_param,
1821 &params, fki);
1822 if (opnum == -1)
1823 return;
1824 else if (opnum > 0)
1826 has_operand_number = 1;
1827 arg_num = opnum + info->first_arg_num - 1;
1829 else
1830 has_operand_number = 0;
1832 if (info->first_arg_num != 0)
1834 cur_param = TREE_VALUE (params);
1835 if (has_operand_number <= 0)
1837 params = TREE_CHAIN (params);
1838 ++arg_num;
1840 width_wanted_type.wanted_type = *fki->width_type;
1841 width_wanted_type.wanted_type_name = NULL;
1842 width_wanted_type.pointer_count = 0;
1843 width_wanted_type.char_lenient_flag = 0;
1844 width_wanted_type.writing_in_flag = 0;
1845 width_wanted_type.reading_from_flag = 0;
1846 width_wanted_type.name = _("field width");
1847 width_wanted_type.param = cur_param;
1848 width_wanted_type.arg_num = arg_num;
1849 width_wanted_type.next = NULL;
1850 if (last_wanted_type != 0)
1851 last_wanted_type->next = &width_wanted_type;
1852 if (first_wanted_type == 0)
1853 first_wanted_type = &width_wanted_type;
1854 last_wanted_type = &width_wanted_type;
1857 else
1859 /* Possibly read a numeric width. If the width is zero,
1860 we complain if appropriate. */
1861 int non_zero_width_char = FALSE;
1862 int found_width = FALSE;
1863 while (ISDIGIT (*format_chars))
1865 found_width = TRUE;
1866 if (*format_chars != '0')
1867 non_zero_width_char = TRUE;
1868 ++format_chars;
1870 if (found_width && !non_zero_width_char &&
1871 (fki->flags & (int) FMT_FLAG_ZERO_WIDTH_BAD))
1872 status_warning (status, "zero width in %s format",
1873 fki->name);
1874 if (found_width)
1876 i = strlen (flag_chars);
1877 flag_chars[i++] = fki->width_char;
1878 flag_chars[i] = 0;
1883 /* Read any format left precision (must be a number, not *). */
1884 if (fki->left_precision_char != 0 && *format_chars == '#')
1886 ++format_chars;
1887 i = strlen (flag_chars);
1888 flag_chars[i++] = fki->left_precision_char;
1889 flag_chars[i] = 0;
1890 if (!ISDIGIT (*format_chars))
1891 status_warning (status, "empty left precision in %s format",
1892 fki->name);
1893 while (ISDIGIT (*format_chars))
1894 ++format_chars;
1897 /* Read any format precision, possibly * or *m$. */
1898 if (fki->precision_char != 0 && *format_chars == '.')
1900 ++format_chars;
1901 i = strlen (flag_chars);
1902 flag_chars[i++] = fki->precision_char;
1903 flag_chars[i] = 0;
1904 if (fki->precision_type != NULL && *format_chars == '*')
1906 /* "...a...precision...may be indicated by an asterisk.
1907 In this case, an int argument supplies the...precision." */
1908 ++format_chars;
1909 if (has_operand_number != 0)
1911 int opnum;
1912 opnum = maybe_read_dollar_number (status, &format_chars,
1913 has_operand_number == 1,
1914 first_fillin_param,
1915 &params, fki);
1916 if (opnum == -1)
1917 return;
1918 else if (opnum > 0)
1920 has_operand_number = 1;
1921 arg_num = opnum + info->first_arg_num - 1;
1923 else
1924 has_operand_number = 0;
1926 if (info->first_arg_num != 0)
1928 if (params == 0)
1930 status_warning (status, "too few arguments for format");
1931 return;
1933 cur_param = TREE_VALUE (params);
1934 if (has_operand_number <= 0)
1936 params = TREE_CHAIN (params);
1937 ++arg_num;
1939 precision_wanted_type.wanted_type = *fki->precision_type;
1940 precision_wanted_type.wanted_type_name = NULL;
1941 precision_wanted_type.pointer_count = 0;
1942 precision_wanted_type.char_lenient_flag = 0;
1943 precision_wanted_type.writing_in_flag = 0;
1944 precision_wanted_type.reading_from_flag = 0;
1945 precision_wanted_type.name = _("field precision");
1946 precision_wanted_type.param = cur_param;
1947 precision_wanted_type.arg_num = arg_num;
1948 precision_wanted_type.next = NULL;
1949 if (last_wanted_type != 0)
1950 last_wanted_type->next = &precision_wanted_type;
1951 if (first_wanted_type == 0)
1952 first_wanted_type = &precision_wanted_type;
1953 last_wanted_type = &precision_wanted_type;
1956 else
1958 if (!(fki->flags & (int) FMT_FLAG_EMPTY_PREC_OK)
1959 && !ISDIGIT (*format_chars))
1960 status_warning (status, "empty precision in %s format",
1961 fki->name);
1962 while (ISDIGIT (*format_chars))
1963 ++format_chars;
1967 /* Read any length modifier, if this kind of format has them. */
1968 fli = fki->length_char_specs;
1969 length_chars = NULL;
1970 length_chars_val = FMT_LEN_none;
1971 length_chars_std = STD_C89;
1972 if (fli)
1974 while (fli->name != 0 && fli->name[0] != *format_chars)
1975 fli++;
1976 if (fli->name != 0)
1978 format_chars++;
1979 if (fli->double_name != 0 && fli->name[0] == *format_chars)
1981 format_chars++;
1982 length_chars = fli->double_name;
1983 length_chars_val = fli->double_index;
1984 length_chars_std = fli->double_std;
1986 else
1988 length_chars = fli->name;
1989 length_chars_val = fli->index;
1990 length_chars_std = fli->std;
1992 i = strlen (flag_chars);
1993 flag_chars[i++] = fki->length_code_char;
1994 flag_chars[i] = 0;
1996 if (pedantic)
1998 /* Warn if the length modifier is non-standard. */
1999 if (ADJ_STD (length_chars_std) > C_STD_VER)
2000 status_warning (status, "%s does not support the `%s' %s length modifier",
2001 C_STD_NAME (length_chars_std), length_chars,
2002 fki->name);
2006 /* Read any modifier (strftime E/O). */
2007 if (fki->modifier_chars != NULL)
2009 while (*format_chars != 0
2010 && strchr (fki->modifier_chars, *format_chars) != 0)
2012 if (strchr (flag_chars, *format_chars) != 0)
2014 const format_flag_spec *s = get_flag_spec (flag_specs,
2015 *format_chars, NULL);
2016 status_warning (status, "repeated %s in format", _(s->name));
2018 else
2020 i = strlen (flag_chars);
2021 flag_chars[i++] = *format_chars;
2022 flag_chars[i] = 0;
2024 ++format_chars;
2028 /* Handle the scanf allocation kludge. */
2029 if (fki->flags & (int) FMT_FLAG_SCANF_A_KLUDGE)
2031 if (*format_chars == 'a' && !flag_isoc99)
2033 if (format_chars[1] == 's' || format_chars[1] == 'S'
2034 || format_chars[1] == '[')
2036 /* `a' is used as a flag. */
2037 i = strlen (flag_chars);
2038 flag_chars[i++] = 'a';
2039 flag_chars[i] = 0;
2040 format_chars++;
2045 format_char = *format_chars;
2046 if (format_char == 0
2047 || (!(fki->flags & (int) FMT_FLAG_FANCY_PERCENT_OK)
2048 && format_char == '%'))
2050 status_warning (status, "conversion lacks type at end of format");
2051 continue;
2053 format_chars++;
2054 fci = fki->conversion_specs;
2055 while (fci->format_chars != 0
2056 && strchr (fci->format_chars, format_char) == 0)
2057 ++fci;
2058 if (fci->format_chars == 0)
2060 if (ISGRAPH(format_char))
2061 status_warning (status, "unknown conversion type character `%c' in format",
2062 format_char);
2063 else
2064 status_warning (status, "unknown conversion type character 0x%x in format",
2065 format_char);
2066 continue;
2068 if (pedantic)
2070 if (ADJ_STD (fci->std) > C_STD_VER)
2071 status_warning (status, "%s does not support the `%%%c' %s format",
2072 C_STD_NAME (fci->std), format_char, fki->name);
2075 /* Validate the individual flags used, removing any that are invalid. */
2077 int d = 0;
2078 for (i = 0; flag_chars[i] != 0; i++)
2080 const format_flag_spec *s = get_flag_spec (flag_specs,
2081 flag_chars[i], NULL);
2082 flag_chars[i - d] = flag_chars[i];
2083 if (flag_chars[i] == fki->length_code_char)
2084 continue;
2085 if (strchr (fci->flag_chars, flag_chars[i]) == 0)
2087 status_warning (status, "%s used with `%%%c' %s format",
2088 _(s->name), format_char, fki->name);
2089 d++;
2090 continue;
2092 if (pedantic)
2094 const format_flag_spec *t;
2095 if (ADJ_STD (s->std) > C_STD_VER)
2096 status_warning (status, "%s does not support %s",
2097 C_STD_NAME (s->std), _(s->long_name));
2098 t = get_flag_spec (flag_specs, flag_chars[i], fci->flags2);
2099 if (t != NULL && ADJ_STD (t->std) > ADJ_STD (s->std))
2101 const char *long_name = (t->long_name != NULL
2102 ? t->long_name
2103 : s->long_name);
2104 if (ADJ_STD (t->std) > C_STD_VER)
2105 status_warning (status, "%s does not support %s with the `%%%c' %s format",
2106 C_STD_NAME (t->std), _(long_name),
2107 format_char, fki->name);
2111 flag_chars[i - d] = 0;
2114 if ((fki->flags & (int) FMT_FLAG_SCANF_A_KLUDGE)
2115 && strchr (flag_chars, 'a') != 0)
2116 aflag = 1;
2118 if (fki->suppression_char
2119 && strchr (flag_chars, fki->suppression_char) != 0)
2120 suppressed = 1;
2122 /* Validate the pairs of flags used. */
2123 for (i = 0; bad_flag_pairs[i].flag_char1 != 0; i++)
2125 const format_flag_spec *s, *t;
2126 if (strchr (flag_chars, bad_flag_pairs[i].flag_char1) == 0)
2127 continue;
2128 if (strchr (flag_chars, bad_flag_pairs[i].flag_char2) == 0)
2129 continue;
2130 if (bad_flag_pairs[i].predicate != 0
2131 && strchr (fci->flags2, bad_flag_pairs[i].predicate) == 0)
2132 continue;
2133 s = get_flag_spec (flag_specs, bad_flag_pairs[i].flag_char1, NULL);
2134 t = get_flag_spec (flag_specs, bad_flag_pairs[i].flag_char2, NULL);
2135 if (bad_flag_pairs[i].ignored)
2137 if (bad_flag_pairs[i].predicate != 0)
2138 status_warning (status, "%s ignored with %s and `%%%c' %s format",
2139 _(s->name), _(t->name), format_char,
2140 fki->name);
2141 else
2142 status_warning (status, "%s ignored with %s in %s format",
2143 _(s->name), _(t->name), fki->name);
2145 else
2147 if (bad_flag_pairs[i].predicate != 0)
2148 status_warning (status, "use of %s and %s together with `%%%c' %s format",
2149 _(s->name), _(t->name), format_char,
2150 fki->name);
2151 else
2152 status_warning (status, "use of %s and %s together in %s format",
2153 _(s->name), _(t->name), fki->name);
2157 /* Give Y2K warnings. */
2158 if (warn_format_y2k)
2160 int y2k_level = 0;
2161 if (strchr (fci->flags2, '4') != 0)
2162 if (strchr (flag_chars, 'E') != 0)
2163 y2k_level = 3;
2164 else
2165 y2k_level = 2;
2166 else if (strchr (fci->flags2, '3') != 0)
2167 y2k_level = 3;
2168 else if (strchr (fci->flags2, '2') != 0)
2169 y2k_level = 2;
2170 if (y2k_level == 3)
2171 status_warning (status, "`%%%c' yields only last 2 digits of year in some locales",
2172 format_char);
2173 else if (y2k_level == 2)
2174 status_warning (status, "`%%%c' yields only last 2 digits of year", format_char);
2177 if (strchr (fci->flags2, '[') != 0)
2179 /* Skip over scan set, in case it happens to have '%' in it. */
2180 if (*format_chars == '^')
2181 ++format_chars;
2182 /* Find closing bracket; if one is hit immediately, then
2183 it's part of the scan set rather than a terminator. */
2184 if (*format_chars == ']')
2185 ++format_chars;
2186 while (*format_chars && *format_chars != ']')
2187 ++format_chars;
2188 if (*format_chars != ']')
2189 /* The end of the format string was reached. */
2190 status_warning (status, "no closing `]' for `%%[' format");
2193 wanted_type = 0;
2194 wanted_type_name = 0;
2195 if (fki->flags & (int) FMT_FLAG_ARG_CONVERT)
2197 wanted_type = (fci->types[length_chars_val].type
2198 ? *fci->types[length_chars_val].type : 0);
2199 wanted_type_name = fci->types[length_chars_val].name;
2200 wanted_type_std = fci->types[length_chars_val].std;
2201 if (wanted_type == 0)
2203 status_warning (status, "use of `%s' length modifier with `%c' type character",
2204 length_chars, format_char);
2205 /* Heuristic: skip one argument when an invalid length/type
2206 combination is encountered. */
2207 arg_num++;
2208 if (params == 0)
2210 status_warning (status, "too few arguments for format");
2211 return;
2213 params = TREE_CHAIN (params);
2214 continue;
2216 else if (pedantic
2217 /* Warn if non-standard, provided it is more non-standard
2218 than the length and type characters that may already
2219 have been warned for. */
2220 && ADJ_STD (wanted_type_std) > ADJ_STD (length_chars_std)
2221 && ADJ_STD (wanted_type_std) > ADJ_STD (fci->std))
2223 if (ADJ_STD (wanted_type_std) > C_STD_VER)
2224 status_warning (status, "%s does not support the `%%%s%c' %s format",
2225 C_STD_NAME (wanted_type_std), length_chars,
2226 format_char, fki->name);
2230 /* Finally. . .check type of argument against desired type! */
2231 if (info->first_arg_num == 0)
2232 continue;
2233 if ((fci->pointer_count == 0 && wanted_type == void_type_node)
2234 || suppressed)
2236 if (main_arg_num != 0)
2238 if (suppressed)
2239 status_warning (status, "operand number specified with suppressed assignment");
2240 else
2241 status_warning (status, "operand number specified for format taking no argument");
2244 else
2246 if (main_arg_num != 0)
2248 arg_num = main_arg_num;
2249 params = main_arg_params;
2251 else
2253 ++arg_num;
2254 if (has_operand_number > 0)
2256 status_warning (status, "missing $ operand number in format");
2257 return;
2259 else
2260 has_operand_number = 0;
2261 if (params == 0)
2263 status_warning (status, "too few arguments for format");
2264 return;
2267 cur_param = TREE_VALUE (params);
2268 params = TREE_CHAIN (params);
2269 main_wanted_type.wanted_type = wanted_type;
2270 main_wanted_type.wanted_type_name = wanted_type_name;
2271 main_wanted_type.pointer_count = fci->pointer_count + aflag;
2272 main_wanted_type.char_lenient_flag = 0;
2273 if (strchr (fci->flags2, 'c') != 0)
2274 main_wanted_type.char_lenient_flag = 1;
2275 main_wanted_type.writing_in_flag = 0;
2276 main_wanted_type.reading_from_flag = 0;
2277 if (aflag)
2278 main_wanted_type.writing_in_flag = 1;
2279 else
2281 if (strchr (fci->flags2, 'W') != 0)
2282 main_wanted_type.writing_in_flag = 1;
2283 if (strchr (fci->flags2, 'R') != 0)
2284 main_wanted_type.reading_from_flag = 1;
2286 main_wanted_type.name = NULL;
2287 main_wanted_type.param = cur_param;
2288 main_wanted_type.arg_num = arg_num;
2289 main_wanted_type.next = NULL;
2290 if (last_wanted_type != 0)
2291 last_wanted_type->next = &main_wanted_type;
2292 if (first_wanted_type == 0)
2293 first_wanted_type = &main_wanted_type;
2294 last_wanted_type = &main_wanted_type;
2297 if (first_wanted_type != 0)
2298 check_format_types (status, first_wanted_type);
2304 /* Check the argument types from a single format conversion (possibly
2305 including width and precision arguments). */
2306 static void
2307 check_format_types (status, types)
2308 int *status;
2309 format_wanted_type *types;
2311 for (; types != 0; types = types->next)
2313 tree cur_param;
2314 tree cur_type;
2315 tree orig_cur_type;
2316 tree wanted_type;
2317 tree promoted_type;
2318 int arg_num;
2319 int i;
2320 int char_type_flag;
2321 cur_param = types->param;
2322 cur_type = TREE_TYPE (cur_param);
2323 if (cur_type == error_mark_node)
2324 continue;
2325 char_type_flag = 0;
2326 wanted_type = types->wanted_type;
2327 arg_num = types->arg_num;
2329 /* The following should not occur here. */
2330 if (wanted_type == 0)
2331 abort ();
2332 if (wanted_type == void_type_node && types->pointer_count == 0)
2333 abort ();
2335 if (types->pointer_count == 0)
2337 promoted_type = simple_type_promotes_to (wanted_type);
2338 if (promoted_type != NULL_TREE)
2339 wanted_type = promoted_type;
2342 STRIP_NOPS (cur_param);
2344 /* Check the types of any additional pointer arguments
2345 that precede the "real" argument. */
2346 for (i = 0; i < types->pointer_count; ++i)
2348 if (TREE_CODE (cur_type) == POINTER_TYPE)
2350 cur_type = TREE_TYPE (cur_type);
2351 if (cur_type == error_mark_node)
2352 break;
2354 /* Check for writing through a NULL pointer. */
2355 if (types->writing_in_flag
2356 && i == 0
2357 && cur_param != 0
2358 && integer_zerop (cur_param))
2359 status_warning (status,
2360 "writing through null pointer (arg %d)",
2361 arg_num);
2363 /* Check for reading through a NULL pointer. */
2364 if (types->reading_from_flag
2365 && i == 0
2366 && cur_param != 0
2367 && integer_zerop (cur_param))
2368 status_warning (status,
2369 "reading through null pointer (arg %d)",
2370 arg_num);
2372 if (cur_param != 0 && TREE_CODE (cur_param) == ADDR_EXPR)
2373 cur_param = TREE_OPERAND (cur_param, 0);
2374 else
2375 cur_param = 0;
2377 /* See if this is an attempt to write into a const type with
2378 scanf or with printf "%n". Note: the writing in happens
2379 at the first indirection only, if for example
2380 void * const * is passed to scanf %p; passing
2381 const void ** is simply passing an incompatible type. */
2382 if (types->writing_in_flag
2383 && i == 0
2384 && (TYPE_READONLY (cur_type)
2385 || (cur_param != 0
2386 && (TREE_CODE_CLASS (TREE_CODE (cur_param)) == 'c'
2387 || (DECL_P (cur_param)
2388 && TREE_READONLY (cur_param))))))
2389 status_warning (status, "writing into constant object (arg %d)", arg_num);
2391 /* If there are extra type qualifiers beyond the first
2392 indirection, then this makes the types technically
2393 incompatible. */
2394 if (i > 0
2395 && pedantic
2396 && (TYPE_READONLY (cur_type)
2397 || TYPE_VOLATILE (cur_type)
2398 || TYPE_RESTRICT (cur_type)))
2399 status_warning (status, "extra type qualifiers in format argument (arg %d)",
2400 arg_num);
2403 else
2405 if (types->pointer_count == 1)
2406 status_warning (status, "format argument is not a pointer (arg %d)", arg_num);
2407 else
2408 status_warning (status, "format argument is not a pointer to a pointer (arg %d)", arg_num);
2409 break;
2413 if (i < types->pointer_count)
2414 continue;
2416 orig_cur_type = cur_type;
2417 cur_type = TYPE_MAIN_VARIANT (cur_type);
2419 /* Check whether the argument type is a character type. This leniency
2420 only applies to certain formats, flagged with 'c'.
2422 if (types->char_lenient_flag)
2423 char_type_flag = (cur_type == char_type_node
2424 || cur_type == signed_char_type_node
2425 || cur_type == unsigned_char_type_node);
2427 /* Check the type of the "real" argument, if there's a type we want. */
2428 if (wanted_type == cur_type)
2429 continue;
2430 /* If we want `void *', allow any pointer type.
2431 (Anything else would already have got a warning.)
2432 With -pedantic, only allow pointers to void and to character
2433 types. */
2434 if (wanted_type == void_type_node
2435 && (!pedantic || (i == 1 && char_type_flag)))
2436 continue;
2437 /* Don't warn about differences merely in signedness, unless
2438 -pedantic. With -pedantic, warn if the type is a pointer
2439 target and not a character type, and for character types at
2440 a second level of indirection. */
2441 if (TREE_CODE (wanted_type) == INTEGER_TYPE
2442 && TREE_CODE (cur_type) == INTEGER_TYPE
2443 && (! pedantic || i == 0 || (i == 1 && char_type_flag))
2444 && (TREE_UNSIGNED (wanted_type)
2445 ? wanted_type == unsigned_type (cur_type)
2446 : wanted_type == signed_type (cur_type)))
2447 continue;
2448 /* Likewise, "signed char", "unsigned char" and "char" are
2449 equivalent but the above test won't consider them equivalent. */
2450 if (wanted_type == char_type_node
2451 && (! pedantic || i < 2)
2452 && char_type_flag)
2453 continue;
2454 /* Now we have a type mismatch. */
2456 register const char *this;
2457 register const char *that;
2459 this = IDENTIFIER_POINTER (DECL_NAME (TYPE_NAME (wanted_type)));
2460 that = 0;
2461 if (TYPE_NAME (orig_cur_type) != 0
2462 && TREE_CODE (orig_cur_type) != INTEGER_TYPE
2463 && !(TREE_CODE (orig_cur_type) == POINTER_TYPE
2464 && TREE_CODE (TREE_TYPE (orig_cur_type)) == INTEGER_TYPE))
2466 if (TREE_CODE (TYPE_NAME (orig_cur_type)) == TYPE_DECL
2467 && DECL_NAME (TYPE_NAME (orig_cur_type)) != 0)
2468 that = IDENTIFIER_POINTER (DECL_NAME (TYPE_NAME (orig_cur_type)));
2469 else
2470 that = IDENTIFIER_POINTER (TYPE_NAME (orig_cur_type));
2473 /* A nameless type can't possibly match what the format wants.
2474 So there will be a warning for it.
2475 Make up a string to describe vaguely what it is. */
2476 if (that == 0)
2478 if (TREE_CODE (orig_cur_type) == POINTER_TYPE)
2479 that = "pointer";
2480 else
2481 that = "different type";
2484 /* Make the warning better in case of mismatch of int vs long. */
2485 if (TREE_CODE (orig_cur_type) == INTEGER_TYPE
2486 && TREE_CODE (wanted_type) == INTEGER_TYPE
2487 && TYPE_PRECISION (orig_cur_type) == TYPE_PRECISION (wanted_type)
2488 && TYPE_NAME (orig_cur_type) != 0
2489 && TREE_CODE (TYPE_NAME (orig_cur_type)) == TYPE_DECL)
2490 that = IDENTIFIER_POINTER (DECL_NAME (TYPE_NAME (orig_cur_type)));
2492 if (strcmp (this, that) != 0)
2494 /* There may be a better name for the format, e.g. size_t,
2495 but we should allow for programs with a perverse typedef
2496 making size_t something other than what the compiler
2497 thinks. */
2498 if (types->wanted_type_name != 0
2499 && strcmp (types->wanted_type_name, that) != 0)
2500 this = types->wanted_type_name;
2501 if (types->name != 0)
2502 status_warning (status, "%s is not type %s (arg %d)", types->name, this,
2503 arg_num);
2504 else
2505 status_warning (status, "%s format, %s arg (arg %d)", this, that, arg_num);