1 /* Predicate aware uninitialized variable warning.
2 Copyright (C) 2001-2022 Free Software Foundation, Inc.
3 Contributed by Xinliang David Li <davidxl@google.com>
5 This file is part of GCC.
7 GCC is free software; you can redistribute it and/or modify
8 it under the terms of the GNU General Public License as published by
9 the Free Software Foundation; either version 3, or (at your option)
12 GCC is distributed in the hope that it will be useful,
13 but WITHOUT ANY WARRANTY; without even the implied warranty of
14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 GNU General Public License for more details.
17 You should have received a copy of the GNU General Public License
18 along with GCC; see the file COPYING3. If not see
19 <http://www.gnu.org/licenses/>. */
21 #define INCLUDE_STRING
24 #include "coretypes.h"
28 #include "tree-pass.h"
30 #include "gimple-pretty-print.h"
31 #include "diagnostic-core.h"
32 #include "fold-const.h"
33 #include "gimple-iterator.h"
40 #include "gimple-range.h"
41 #include "gimple-predicate-analysis.h"
43 #include "tree-ssa-sccvn.h"
45 /* This implements the pass that does predicate aware warning on uses of
46 possibly uninitialized variables. The pass first collects the set of
47 possibly uninitialized SSA names. For each such name, it walks through
48 all its immediate uses. For each immediate use, it rebuilds the condition
49 expression (the predicate) that guards the use. The predicate is then
50 examined to see if the variable is always defined under that same condition.
51 This is done either by pruning the unrealizable paths that lead to the
52 default definitions or by checking if the predicate set that guards the
53 defining paths is a superset of the use predicate. */
55 /* Pointer set of potentially undefined ssa names, i.e.,
56 ssa names that are defined by phi with operands that
57 are not defined or potentially undefined. */
58 static hash_set
<tree
> *possibly_undefined_names
= 0;
60 /* Returns the first bit position (starting from LSB)
61 in mask that is non zero. Returns -1 if the mask is empty. */
63 get_mask_first_set_bit (unsigned mask
)
69 while ((mask
& (1 << pos
)) == 0)
74 #define MASK_FIRST_SET_BIT(mask) get_mask_first_set_bit (mask)
76 /* Return true if T, an SSA_NAME, has an undefined value. */
78 has_undefined_value_p (tree t
)
80 return (ssa_undefined_value_p (t
)
81 || (possibly_undefined_names
82 && possibly_undefined_names
->contains (t
)));
85 /* Return true if EXPR should suppress either uninitialized warning. */
88 get_no_uninit_warning (tree expr
)
90 return warning_suppressed_p (expr
, OPT_Wuninitialized
);
93 /* Suppress both uninitialized warnings for EXPR. */
96 set_no_uninit_warning (tree expr
)
98 suppress_warning (expr
, OPT_Wuninitialized
);
101 /* Like has_undefined_value_p, but don't return true if the no-warning
102 bit is set on SSA_NAME_VAR for either uninit warning. */
105 uninit_undefined_value_p (tree t
)
107 if (!has_undefined_value_p (t
))
109 if (!SSA_NAME_VAR (t
))
111 return !get_no_uninit_warning (SSA_NAME_VAR (t
));
114 /* Emit warnings for uninitialized variables. This is done in two passes.
116 The first pass notices real uses of SSA names with undefined values.
117 Such uses are unconditionally uninitialized, and we can be certain that
118 such a use is a mistake. This pass is run before most optimizations,
119 so that we catch as many as we can.
121 The second pass follows PHI nodes to find uses that are potentially
122 uninitialized. In this case we can't necessarily prove that the use
123 is really uninitialized. This pass is run after most optimizations,
124 so that we thread as many jumps and possible, and delete as much dead
125 code as possible, in order to reduce false positives. We also look
126 again for plain uninitialized variables, since optimization may have
127 changed conditionally uninitialized to unconditionally uninitialized. */
129 /* Emit warning OPT for variable VAR at the point in the program where
130 the SSA_NAME T is being used uninitialized. The warning text is in
131 MSGID and STMT is the statement that does the uninitialized read.
132 PHI_ARG_LOC is the location of the PHI argument if T and VAR are one,
133 or UNKNOWN_LOCATION otherwise. */
136 warn_uninit (opt_code opt
, tree t
, tree var
, gimple
*context
,
137 location_t phi_arg_loc
= UNKNOWN_LOCATION
)
139 /* Bail if the value isn't provably uninitialized. */
140 if (!has_undefined_value_p (t
))
143 /* Ignore COMPLEX_EXPR as initializing only a part of a complex
144 turns in a COMPLEX_EXPR with the not initialized part being
145 set to its previous (undefined) value. */
146 if (is_gimple_assign (context
)
147 && gimple_assign_rhs_code (context
) == COMPLEX_EXPR
)
150 /* Ignore REALPART_EXPR or IMAGPART_EXPR if its operand is a call to
151 .DEFERRED_INIT. This is for handling the following case correctly:
153 1 typedef _Complex float C;
166 with -ftrivial-auto-var-init, compiler will insert the following
167 artificial initialization at line 4:
168 f = .DEFERRED_INIT (f, 2);
169 _1 = REALPART_EXPR <f>;
171 without the following special handling, _1 = REALPART_EXPR <f> will
172 be treated as the uninitialized use point, which is incorrect. (the
173 real uninitialized use point is at line 11). */
174 if (is_gimple_assign (context
)
175 && (gimple_assign_rhs_code (context
) == REALPART_EXPR
176 || gimple_assign_rhs_code (context
) == IMAGPART_EXPR
))
178 tree v
= gimple_assign_rhs1 (context
);
179 if (TREE_CODE (TREE_OPERAND (v
, 0)) == SSA_NAME
180 && gimple_call_internal_p (SSA_NAME_DEF_STMT (TREE_OPERAND (v
, 0)),
185 /* Anonymous SSA_NAMEs shouldn't be uninitialized, but ssa_undefined_value_p
186 can return true if the def stmt of an anonymous SSA_NAME is
187 1. A COMPLEX_EXPR created for conversion from scalar to complex. Use the
188 underlying var of the COMPLEX_EXPRs real part in that case. See PR71581.
192 2. A call to .DEFERRED_INIT internal function. Since the original variable
193 has been eliminated by optimziation, we need to get the variable name,
194 and variable declaration location from this call. We recorded variable
195 name into VAR_NAME_STR, and will get location info and record warning
196 suppressed info to VAR_DEF_STMT, which is the .DEFERRED_INIT call. */
198 const char *var_name_str
= NULL
;
199 gimple
*var_def_stmt
= NULL
;
201 if (!var
&& !SSA_NAME_VAR (t
))
203 var_def_stmt
= SSA_NAME_DEF_STMT (t
);
205 if (is_gimple_assign (var_def_stmt
)
206 && gimple_assign_rhs_code (var_def_stmt
) == COMPLEX_EXPR
)
208 tree v
= gimple_assign_rhs1 (var_def_stmt
);
209 if (TREE_CODE (v
) == SSA_NAME
210 && has_undefined_value_p (v
)
211 && zerop (gimple_assign_rhs2 (var_def_stmt
)))
212 var
= SSA_NAME_VAR (v
);
215 if (gimple_call_internal_p (var_def_stmt
, IFN_DEFERRED_INIT
))
217 /* Ignore the call to .DEFERRED_INIT that define the original
218 var itself as the following case:
219 temp = .DEFERRED_INIT (4, 2, “alt_reloc");
221 In order to avoid generating warning for the fake usage
224 tree lhs_var
= NULL_TREE
;
225 tree lhs_var_name
= NULL_TREE
;
226 const char *lhs_var_name_str
= NULL
;
228 /* Get the variable name from the 3rd argument of call. */
229 tree var_name
= gimple_call_arg (var_def_stmt
, 2);
230 var_name
= TREE_OPERAND (TREE_OPERAND (var_name
, 0), 0);
231 var_name_str
= TREE_STRING_POINTER (var_name
);
233 if (is_gimple_assign (context
))
235 if (TREE_CODE (gimple_assign_lhs (context
)) == VAR_DECL
)
236 lhs_var
= gimple_assign_lhs (context
);
237 else if (TREE_CODE (gimple_assign_lhs (context
)) == SSA_NAME
)
238 lhs_var
= SSA_NAME_VAR (gimple_assign_lhs (context
));
241 && (lhs_var_name
= DECL_NAME (lhs_var
))
242 && (lhs_var_name_str
= IDENTIFIER_POINTER (lhs_var_name
))
243 && (strcmp (lhs_var_name_str
, var_name_str
) == 0))
245 gcc_assert (var_name_str
&& var_def_stmt
);
249 if (var
== NULL_TREE
&& var_name_str
== NULL
)
252 /* Avoid warning if we've already done so or if the warning has been
254 if (((warning_suppressed_p (context
, OPT_Wuninitialized
)
255 || (gimple_assign_single_p (context
)
256 && get_no_uninit_warning (gimple_assign_rhs1 (context
)))))
257 || (var
&& get_no_uninit_warning (var
))
259 && warning_suppressed_p (var_def_stmt
, OPT_Wuninitialized
)))
262 /* Use either the location of the read statement or that of the PHI
263 argument, or that of the uninitialized variable, in that order,
264 whichever is valid. */
265 location_t location
= UNKNOWN_LOCATION
;
266 if (gimple_has_location (context
))
267 location
= gimple_location (context
);
268 else if (phi_arg_loc
!= UNKNOWN_LOCATION
)
269 location
= phi_arg_loc
;
271 location
= DECL_SOURCE_LOCATION (var
);
272 else if (var_name_str
)
273 location
= gimple_location (var_def_stmt
);
275 location
= linemap_resolve_location (line_table
, location
,
276 LRK_SPELLING_LOCATION
, NULL
);
278 auto_diagnostic_group d
;
279 gcc_assert (opt
== OPT_Wuninitialized
|| opt
== OPT_Wmaybe_uninitialized
);
282 if ((opt
== OPT_Wuninitialized
283 && !warning_at (location
, opt
, "%qD is used uninitialized", var
))
284 || (opt
== OPT_Wmaybe_uninitialized
285 && !warning_at (location
, opt
, "%qD may be used uninitialized",
289 else if (var_name_str
)
291 if ((opt
== OPT_Wuninitialized
292 && !warning_at (location
, opt
, "%qs is used uninitialized",
294 || (opt
== OPT_Wmaybe_uninitialized
295 && !warning_at (location
, opt
, "%qs may be used uninitialized",
300 /* Avoid subsequent warnings for reads of the same variable again. */
302 suppress_warning (var
, opt
);
303 else if (var_name_str
)
304 suppress_warning (var_def_stmt
, opt
);
306 /* Issue a note pointing to the read variable unless the warning
307 is at the same location. */
308 location_t var_loc
= var
? DECL_SOURCE_LOCATION (var
)
309 : gimple_location (var_def_stmt
);
310 if (location
== var_loc
)
314 inform (var_loc
, "%qD was declared here", var
);
315 else if (var_name_str
)
316 inform (var_loc
, "%qs was declared here", var_name_str
);
319 struct check_defs_data
321 /* If we found any may-defs besides must-def clobbers. */
325 /* Return true if STMT is a call to built-in function all of whose
326 by-reference arguments are const-qualified (i.e., the function can
327 be assumed not to modify them). */
330 builtin_call_nomodifying_p (gimple
*stmt
)
332 if (!gimple_call_builtin_p (stmt
, BUILT_IN_NORMAL
))
335 tree fndecl
= gimple_call_fndecl (stmt
);
339 tree fntype
= TREE_TYPE (fndecl
);
343 /* Check the called function's signature for non-constc pointers.
344 If one is found, return false. */
347 function_args_iterator it
;
348 FOREACH_FUNCTION_ARGS (fntype
, argtype
, it
)
350 if (VOID_TYPE_P (argtype
))
355 if (!POINTER_TYPE_P (argtype
))
358 if (TYPE_READONLY (TREE_TYPE (argtype
)))
364 /* If the number of actual arguments to the call is less than or
365 equal to the number of parameters, return false. */
366 unsigned nargs
= gimple_call_num_args (stmt
);
370 /* Check arguments passed through the ellipsis in calls to variadic
371 functions for pointers. If one is found that's a non-constant
372 pointer, return false. */
373 for (; argno
< nargs
; ++argno
)
375 tree arg
= gimple_call_arg (stmt
, argno
);
376 argtype
= TREE_TYPE (arg
);
377 if (!POINTER_TYPE_P (argtype
))
380 if (TYPE_READONLY (TREE_TYPE (argtype
)))
389 /* If ARG is a FNDECL parameter declared with attribute access none or
390 write_only issue a warning for its read access via PTR. */
393 maybe_warn_read_write_only (tree fndecl
, gimple
*stmt
, tree arg
, tree ptr
)
398 if (get_no_uninit_warning (arg
))
401 tree fntype
= TREE_TYPE (fndecl
);
405 /* Initialize a map of attribute access specifications for arguments
406 to the function call. */
408 init_attr_rdwr_indices (&rdwr_idx
, TYPE_ATTRIBUTES (fntype
));
411 tree parms
= DECL_ARGUMENTS (fndecl
);
412 for (tree parm
= parms
; parm
; parm
= TREE_CHAIN (parm
), ++argno
)
417 const attr_access
* access
= rdwr_idx
.get (argno
);
421 if (access
->mode
!= access_none
422 && access
->mode
!= access_write_only
)
426 = linemap_resolve_location (line_table
, gimple_location (stmt
),
427 LRK_SPELLING_LOCATION
, NULL
);
429 if (!warning_at (stmtloc
, OPT_Wmaybe_uninitialized
,
430 "%qE may be used uninitialized", ptr
))
433 suppress_warning (arg
, OPT_Wmaybe_uninitialized
);
435 const char* const access_str
=
436 TREE_STRING_POINTER (access
->to_external_string ());
438 location_t parmloc
= DECL_SOURCE_LOCATION (parm
);
439 inform (parmloc
, "accessing argument %u of a function declared with "
441 argno
+ 1, access_str
);
447 /* Callback for walk_aliased_vdefs. */
450 check_defs (ao_ref
*ref
, tree vdef
, void *data_
)
452 check_defs_data
*data
= (check_defs_data
*)data_
;
453 gimple
*def_stmt
= SSA_NAME_DEF_STMT (vdef
);
455 /* Ignore the vdef if the definition statement is a call
456 to .DEFERRED_INIT function. */
457 if (gimple_call_internal_p (def_stmt
, IFN_DEFERRED_INIT
))
460 /* For address taken variable, a temporary variable is added between
461 the variable and the call to .DEFERRED_INIT function as:
462 _1 = .DEFERRED_INIT (4, 2, &"i1"[0]);
464 Ignore this vdef as well. */
465 if (is_gimple_assign (def_stmt
)
466 && gimple_assign_rhs_code (def_stmt
) == SSA_NAME
)
468 tree tmp_var
= gimple_assign_rhs1 (def_stmt
);
469 if (gimple_call_internal_p (SSA_NAME_DEF_STMT (tmp_var
),
474 /* The ASAN_MARK intrinsic doesn't modify the variable. */
475 if (is_gimple_call (def_stmt
))
477 /* The ASAN_MARK intrinsic doesn't modify the variable. */
478 if (gimple_call_internal_p (def_stmt
)
479 && gimple_call_internal_fn (def_stmt
) == IFN_ASAN_MARK
)
482 if (tree fndecl
= gimple_call_fndecl (def_stmt
))
484 /* Some sanitizer calls pass integer arguments to built-ins
485 that expect pointets. Avoid using gimple_call_builtin_p()
486 which fails for such calls. */
487 if (DECL_BUILT_IN_CLASS (fndecl
) == BUILT_IN_NORMAL
)
489 built_in_function fncode
= DECL_FUNCTION_CODE (fndecl
);
490 if (fncode
> BEGIN_SANITIZER_BUILTINS
491 && fncode
< END_SANITIZER_BUILTINS
)
497 /* End of VLA scope is not a kill. */
498 if (gimple_call_builtin_p (def_stmt
, BUILT_IN_STACK_RESTORE
))
501 /* If this is a clobber then if it is not a kill walk past it. */
502 if (gimple_clobber_p (def_stmt
))
504 if (stmt_kills_ref_p (def_stmt
, ref
))
509 if (builtin_call_nomodifying_p (def_stmt
))
512 /* Found a may-def on this path. */
513 data
->found_may_defs
= true;
517 /* Counters and limits controlling the depth of analysis and
518 strictness of the warning. */
521 /* Number of VDEFs encountered. */
522 unsigned int vdef_cnt
;
523 /* Number of statements examined by walk_aliased_vdefs. */
524 unsigned int oracle_cnt
;
525 /* Limit on the number of statements visited by walk_aliased_vdefs. */
527 /* Set when basic block with statement is executed unconditionally. */
528 bool always_executed
;
529 /* Set to issue -Wmaybe-uninitialized. */
533 /* Determine if REF references an uninitialized operand and diagnose
534 it if so. STMS is the referencing statement. LHS is the result
535 of the access and may be null. RHS is the variable referenced by
536 the access; it may not be null. */
539 maybe_warn_operand (ao_ref
&ref
, gimple
*stmt
, tree lhs
, tree rhs
,
542 bool has_bit_insert
= false;
543 use_operand_p luse_p
;
544 imm_use_iterator liter
;
546 if (get_no_uninit_warning (rhs
))
549 /* Do not warn if the base was marked so or this is a
550 hard register var. */
551 tree base
= ao_ref_base (&ref
);
553 && DECL_HARD_REGISTER (base
))
554 || get_no_uninit_warning (base
))
557 /* Do not warn if the access is zero size or if it's fully outside
559 poly_int64 decl_size
;
560 if (known_size_p (ref
.size
)
561 && known_eq (ref
.max_size
, ref
.size
)
562 && (known_eq (ref
.size
, 0)
563 || known_le (ref
.offset
+ ref
.size
, 0)))
567 && known_ge (ref
.offset
, 0)
569 && poly_int_tree_p (DECL_SIZE (base
), &decl_size
)
570 && known_le (decl_size
, ref
.offset
))
573 /* Do not warn if the result of the access is then used for
574 a BIT_INSERT_EXPR. */
575 if (lhs
&& TREE_CODE (lhs
) == SSA_NAME
)
576 FOR_EACH_IMM_USE_FAST (luse_p
, liter
, lhs
)
578 gimple
*use_stmt
= USE_STMT (luse_p
);
579 /* BIT_INSERT_EXPR first operand should not be considered
580 a use for the purpose of uninit warnings. */
581 if (gassign
*ass
= dyn_cast
<gassign
*> (use_stmt
))
583 if (gimple_assign_rhs_code (ass
) == BIT_INSERT_EXPR
584 && luse_p
->use
== gimple_assign_rhs1_ptr (ass
))
586 has_bit_insert
= true;
595 /* Limit the walking to a constant number of stmts after
596 we overcommit quadratic behavior for small functions
597 and O(n) behavior. */
598 if (wlims
.oracle_cnt
> 128 * 128
599 && wlims
.oracle_cnt
> wlims
.vdef_cnt
* 2)
602 check_defs_data data
;
603 bool fentry_reached
= false;
604 data
.found_may_defs
= false;
605 tree use
= gimple_vuse (stmt
);
608 int res
= walk_aliased_vdefs (&ref
, use
,
609 check_defs
, &data
, NULL
,
610 &fentry_reached
, wlims
.limit
);
613 wlims
.oracle_cnt
+= wlims
.limit
;
617 wlims
.oracle_cnt
+= res
;
618 if (data
.found_may_defs
)
621 bool found_alloc
= false;
625 if (TREE_CODE (base
) == MEM_REF
)
626 base
= TREE_OPERAND (base
, 0);
628 /* Follow the chain of SSA_NAME assignments looking for an alloca
629 call (or VLA) or malloc/realloc, or for decls. If any is found
630 (and in the latter case, the operand is a local variable) issue
632 while (TREE_CODE (base
) == SSA_NAME
)
634 gimple
*def_stmt
= SSA_NAME_DEF_STMT (base
);
636 if (is_gimple_call (def_stmt
)
637 && gimple_call_builtin_p (def_stmt
))
639 /* Detect uses of uninitialized alloca/VLAs. */
640 tree fndecl
= gimple_call_fndecl (def_stmt
);
641 const built_in_function fncode
= DECL_FUNCTION_CODE (fndecl
);
642 if (fncode
== BUILT_IN_ALLOCA
643 || fncode
== BUILT_IN_ALLOCA_WITH_ALIGN
644 || fncode
== BUILT_IN_MALLOC
)
649 if (!is_gimple_assign (def_stmt
))
652 tree_code code
= gimple_assign_rhs_code (def_stmt
);
653 if (code
!= ADDR_EXPR
&& code
!= POINTER_PLUS_EXPR
)
656 base
= gimple_assign_rhs1 (def_stmt
);
657 if (TREE_CODE (base
) == ADDR_EXPR
)
658 base
= TREE_OPERAND (base
, 0);
661 || TREE_CODE (base
) == COMPONENT_REF
)
664 if (TREE_CODE (base
) == MEM_REF
)
665 base
= TREE_OPERAND (base
, 0);
667 if (tree ba
= get_base_address (base
))
671 /* Replace the RHS expression with BASE so that it
672 refers to it in the diagnostic (instead of to
676 && TREE_CODE (rhs
) != COMPONENT_REF
)
680 /* Do not warn if it can be initialized outside this function.
681 If we did not reach function entry then we found killing
682 clobbers on all paths to entry. */
683 if (!found_alloc
&& fentry_reached
)
685 if (TREE_CODE (base
) == SSA_NAME
)
687 tree var
= SSA_NAME_VAR (base
);
688 if (var
&& TREE_CODE (var
) == PARM_DECL
)
690 maybe_warn_read_write_only (cfun
->decl
, stmt
, var
, rhs
);
696 || is_global_var (base
))
697 /* ??? We'd like to use ref_may_alias_global_p but that
698 excludes global readonly memory and thus we get bogus
699 warnings from p = cond ? "a" : "b" for example. */
703 /* Strip the address-of expression from arrays passed to functions. */
704 if (TREE_CODE (rhs
) == ADDR_EXPR
)
705 rhs
= TREE_OPERAND (rhs
, 0);
707 /* Check again since RHS may have changed above. */
708 if (get_no_uninit_warning (rhs
))
711 /* Avoid warning about empty types such as structs with no members.
712 The first_field() test is important for C++ where the predicate
713 alone isn't always sufficient. */
714 tree rhstype
= TREE_TYPE (rhs
);
715 if (POINTER_TYPE_P (rhstype
))
716 rhstype
= TREE_TYPE (rhstype
);
717 if (is_empty_type (rhstype
))
721 /* We didn't find any may-defs so on all paths either
722 reached function entry or a killing clobber. */
724 = linemap_resolve_location (line_table
, gimple_location (stmt
),
725 LRK_SPELLING_LOCATION
, NULL
);
726 if (wlims
.always_executed
)
728 if (warning_at (location
, OPT_Wuninitialized
,
729 "%qE is used uninitialized", rhs
))
731 /* ??? This is only effective for decls as in
732 gcc.dg/uninit-B-O0.c. Avoid doing this for maybe-uninit
733 uses or accesses by functions as it may hide important
736 set_no_uninit_warning (rhs
);
740 else if (wlims
.wmaybe_uninit
)
741 warned
= warning_at (location
, OPT_Wmaybe_uninitialized
,
742 "%qE may be used uninitialized", rhs
);
744 return warned
? base
: NULL_TREE
;
748 /* Diagnose passing addresses of uninitialized objects to either const
749 pointer arguments to functions, or to functions declared with attribute
750 access implying read access to those objects. */
753 maybe_warn_pass_by_reference (gcall
*stmt
, wlimits
&wlims
)
755 if (!wlims
.wmaybe_uninit
)
758 unsigned nargs
= gimple_call_num_args (stmt
);
762 tree fndecl
= gimple_call_fndecl (stmt
);
763 tree fntype
= gimple_call_fntype (stmt
);
767 /* Const function do not read their arguments. */
768 if (gimple_call_flags (stmt
) & ECF_CONST
)
771 const built_in_function fncode
772 = (fndecl
&& gimple_call_builtin_p (stmt
, BUILT_IN_NORMAL
)
773 ? DECL_FUNCTION_CODE (fndecl
) : (built_in_function
)BUILT_IN_LAST
);
775 if (fncode
== BUILT_IN_MEMCPY
|| fncode
== BUILT_IN_MEMMOVE
)
776 /* Avoid diagnosing calls to raw memory functions (this is overly
777 permissive; consider tightening it up). */
780 /* Save the current warning setting and replace it either a "maybe"
781 when passing addresses of uninitialized variables to const-qualified
782 pointers or arguments declared with attribute read_write, or with
783 a "certain" when passing them to arguments declared with attribute
785 const bool save_always_executed
= wlims
.always_executed
;
787 /* Initialize a map of attribute access specifications for arguments
788 to the function call. */
790 init_attr_rdwr_indices (&rdwr_idx
, TYPE_ATTRIBUTES (fntype
));
794 function_args_iterator it
;
796 FOREACH_FUNCTION_ARGS (fntype
, argtype
, it
)
800 if (!POINTER_TYPE_P (argtype
))
803 tree access_size
= NULL_TREE
;
804 const attr_access
* access
= rdwr_idx
.get (argno
- 1);
807 if (access
->mode
== access_none
808 || access
->mode
== access_write_only
)
811 if (access
->mode
== access_deferred
812 && !TYPE_READONLY (TREE_TYPE (argtype
)))
815 if (save_always_executed
&& access
->mode
== access_read_only
)
816 /* Attribute read_only arguments imply read access. */
817 wlims
.always_executed
= true;
819 /* Attribute read_write arguments are documented as requiring
820 initialized objects but it's expected that aggregates may
821 be only partially initialized regardless. */
822 wlims
.always_executed
= false;
824 if (access
->sizarg
< nargs
)
825 access_size
= gimple_call_arg (stmt
, access
->sizarg
);
827 else if (!TYPE_READONLY (TREE_TYPE (argtype
)))
829 else if (save_always_executed
&& fncode
!= BUILT_IN_LAST
)
830 /* Const-qualified arguments to built-ins imply read access. */
831 wlims
.always_executed
= true;
833 /* Const-qualified arguments to ordinary functions imply a likely
834 (but not definitive) read access. */
835 wlims
.always_executed
= false;
837 /* Ignore args we are not going to read from. */
838 if (gimple_call_arg_flags (stmt
, argno
- 1)
839 & (EAF_UNUSED
| EAF_NO_DIRECT_READ
))
842 tree arg
= gimple_call_arg (stmt
, argno
- 1);
843 if (!POINTER_TYPE_P (TREE_TYPE (arg
)))
844 /* Avoid actual arguments with invalid types. */
848 ao_ref_init_from_ptr_and_size (&ref
, arg
, access_size
);
849 tree argbase
= maybe_warn_operand (ref
, stmt
, NULL_TREE
, arg
, wlims
);
853 if (access
&& access
->mode
!= access_deferred
)
855 const char* const access_str
=
856 TREE_STRING_POINTER (access
->to_external_string ());
860 location_t loc
= DECL_SOURCE_LOCATION (fndecl
);
861 inform (loc
, "in a call to %qD declared with "
862 "attribute %<%s%> here", fndecl
, access_str
);
866 /* Handle calls through function pointers. */
867 location_t loc
= gimple_location (stmt
);
868 inform (loc
, "in a call to %qT declared with "
869 "attribute %<%s%>", fntype
, access_str
);
874 /* For a declaration with no relevant attribute access create
875 a dummy object and use the formatting function to avoid
876 having to complicate things here. */
877 attr_access ptr_access
= { };
879 access
= &ptr_access
;
880 const std::string argtypestr
= access
->array_as_string (argtype
);
883 location_t
loc (DECL_SOURCE_LOCATION (fndecl
));
884 inform (loc
, "by argument %u of type %s to %qD "
886 argno
, argtypestr
.c_str (), fndecl
);
890 /* Handle calls through function pointers. */
891 location_t
loc (gimple_location (stmt
));
892 inform (loc
, "by argument %u of type %s to %qT",
893 argno
, argtypestr
.c_str (), fntype
);
897 if (DECL_P (argbase
))
899 location_t loc
= DECL_SOURCE_LOCATION (argbase
);
900 inform (loc
, "%qD declared here", argbase
);
904 wlims
.always_executed
= save_always_executed
;
907 /* Warn about an uninitialized PHI argument on the fallthru path to
908 an always executed block BB. */
911 warn_uninit_phi_uses (basic_block bb
)
914 edge e
, found
= NULL
, found_back
= NULL
;
915 /* Look for a fallthru and possibly a single backedge. */
916 FOR_EACH_EDGE (e
, ei
, bb
->preds
)
918 /* Ignore backedges. */
919 if (dominated_by_p (CDI_DOMINATORS
, e
->src
, bb
))
939 basic_block succ
= single_succ (ENTRY_BLOCK_PTR_FOR_FN (cfun
));
940 for (gphi_iterator si
= gsi_start_phis (bb
); !gsi_end_p (si
);
943 gphi
*phi
= si
.phi ();
944 tree def
= PHI_ARG_DEF_FROM_EDGE (phi
, found
);
945 if (TREE_CODE (def
) != SSA_NAME
946 || !SSA_NAME_IS_DEFAULT_DEF (def
)
947 || virtual_operand_p (def
))
949 /* If there's a default def on the fallthru edge PHI
950 value and there's a use that post-dominates entry
951 then that use is uninitialized and we can warn. */
952 imm_use_iterator iter
;
954 gimple
*use_stmt
= NULL
;
955 FOR_EACH_IMM_USE_FAST (use_p
, iter
, gimple_phi_result (phi
))
957 use_stmt
= USE_STMT (use_p
);
958 if (gimple_location (use_stmt
) != UNKNOWN_LOCATION
959 && dominated_by_p (CDI_POST_DOMINATORS
, succ
,
960 gimple_bb (use_stmt
))
961 /* If we found a non-fallthru edge make sure the
962 use is inside the loop, otherwise the backedge
963 can serve as initialization. */
965 || dominated_by_p (CDI_DOMINATORS
, found_back
->src
,
966 gimple_bb (use_stmt
))))
971 warn_uninit (OPT_Wuninitialized
, def
,
972 SSA_NAME_VAR (def
), use_stmt
);
976 /* Issue warnings about reads of uninitialized variables. WMAYBE_UNINIT
977 is true to issue -Wmaybe-uninitialized, otherwise -Wuninitialized. */
980 warn_uninitialized_vars (bool wmaybe_uninit
)
982 /* Counters and limits controlling the depth of the warning. */
984 wlims
.wmaybe_uninit
= wmaybe_uninit
;
986 gimple_stmt_iterator gsi
;
988 FOR_EACH_BB_FN (bb
, cfun
)
992 FOR_EACH_EDGE (e
, ei
, bb
->preds
)
993 if (e
->flags
& EDGE_EXECUTABLE
)
995 /* Skip unreachable blocks. For early analysis we use VN to
996 determine edge executability when wmaybe_uninit. */
1000 basic_block succ
= single_succ (ENTRY_BLOCK_PTR_FOR_FN (cfun
));
1001 /* ??? This could be improved when we use a greedy walk and have
1002 some edges marked as not executable. */
1003 wlims
.always_executed
= dominated_by_p (CDI_POST_DOMINATORS
, succ
, bb
);
1005 if (wlims
.always_executed
)
1006 warn_uninit_phi_uses (bb
);
1008 for (gsi
= gsi_start_bb (bb
); !gsi_end_p (gsi
); gsi_next (&gsi
))
1010 gimple
*stmt
= gsi_stmt (gsi
);
1012 /* The call is an artificial use, will not provide meaningful
1013 error message. If the result of the call is used somewhere
1014 else, we warn there instead. */
1015 if (gimple_call_internal_p (stmt
, IFN_DEFERRED_INIT
))
1018 if (is_gimple_debug (stmt
))
1021 /* We only do data flow with SSA_NAMEs, so that's all we
1023 use_operand_p use_p
;
1024 ssa_op_iter op_iter
;
1025 FOR_EACH_SSA_USE_OPERAND (use_p
, stmt
, op_iter
, SSA_OP_USE
)
1027 /* BIT_INSERT_EXPR first operand should not be considered
1028 a use for the purpose of uninit warnings. */
1029 if (gassign
*ass
= dyn_cast
<gassign
*> (stmt
))
1031 if (gimple_assign_rhs_code (ass
) == BIT_INSERT_EXPR
1032 && use_p
->use
== gimple_assign_rhs1_ptr (ass
))
1035 tree use
= USE_FROM_PTR (use_p
);
1036 if (wlims
.always_executed
)
1037 warn_uninit (OPT_Wuninitialized
, use
,
1038 SSA_NAME_VAR (use
), stmt
);
1039 else if (wmaybe_uninit
)
1040 warn_uninit (OPT_Wmaybe_uninitialized
, use
,
1041 SSA_NAME_VAR (use
), stmt
);
1044 /* For limiting the alias walk below we count all
1045 vdefs in the function. */
1046 if (gimple_vdef (stmt
))
1049 if (gcall
*call
= dyn_cast
<gcall
*> (stmt
))
1050 maybe_warn_pass_by_reference (call
, wlims
);
1051 else if (gimple_assign_load_p (stmt
)
1052 && gimple_has_location (stmt
))
1054 tree rhs
= gimple_assign_rhs1 (stmt
);
1055 tree lhs
= gimple_assign_lhs (stmt
);
1058 ao_ref_init (&ref
, rhs
);
1059 tree var
= maybe_warn_operand (ref
, stmt
, lhs
, rhs
, wlims
);
1065 location_t loc
= DECL_SOURCE_LOCATION (var
);
1066 inform (loc
, "%qD declared here", var
);
1073 /* Checks if the operand OPND of PHI is defined by
1074 another phi with one operand defined by this PHI,
1075 but the rest operands are all defined. If yes,
1076 returns true to skip this operand as being
1077 redundant. Can be enhanced to be more general. */
1080 can_skip_redundant_opnd (tree opnd
, gimple
*phi
)
1082 tree phi_def
= gimple_phi_result (phi
);
1083 gimple
*op_def
= SSA_NAME_DEF_STMT (opnd
);
1084 if (gimple_code (op_def
) != GIMPLE_PHI
)
1087 unsigned n
= gimple_phi_num_args (op_def
);
1088 for (unsigned i
= 0; i
< n
; ++i
)
1090 tree op
= gimple_phi_arg_def (op_def
, i
);
1091 if (TREE_CODE (op
) != SSA_NAME
)
1093 if (op
!= phi_def
&& uninit_undefined_value_p (op
))
1100 /* Return a bitset holding the positions of arguments in PHI with empty
1101 (or possibly empty) definitions. */
1104 compute_uninit_opnds_pos (gphi
*phi
)
1106 unsigned uninit_opnds
= 0;
1108 unsigned n
= gimple_phi_num_args (phi
);
1109 /* Bail out for phi with too many args. */
1110 if (n
> predicate::func_t::max_phi_args
)
1113 for (unsigned i
= 0; i
< n
; ++i
)
1115 tree op
= gimple_phi_arg_def (phi
, i
);
1116 if (TREE_CODE (op
) == SSA_NAME
1117 && uninit_undefined_value_p (op
)
1118 && !can_skip_redundant_opnd (op
, phi
))
1120 if (cfun
->has_nonlocal_label
|| cfun
->calls_setjmp
)
1122 /* Ignore SSA_NAMEs that appear on abnormal edges
1124 if (SSA_NAME_OCCURS_IN_ABNORMAL_PHI (op
))
1127 MASK_SET_BIT (uninit_opnds
, i
);
1130 return uninit_opnds
;
1133 /* Function object type used to determine whether an expression
1134 is of interest to the predicate analyzer. */
1136 struct uninit_undef_val_t
: public predicate::func_t
1138 virtual bool operator()(tree
) override
;
1139 virtual unsigned phi_arg_set (gphi
*) override
;
1142 /* Return true if the argument is an expression of interest. */
1145 uninit_undef_val_t::operator()(tree val
)
1147 if (TREE_CODE (val
) == SSA_NAME
)
1148 return uninit_undefined_value_p (val
);
1153 /* Return a bitset of PHI arguments of interest. */
1156 uninit_undef_val_t::phi_arg_set (gphi
*phi
)
1158 return compute_uninit_opnds_pos (phi
);
1161 /* Searches through all uses of a potentially
1162 uninitialized variable defined by PHI and returns a use
1163 statement if the use is not properly guarded. It returns
1164 NULL if all uses are guarded. UNINIT_OPNDS is a bitvector
1165 holding the position(s) of uninit PHI operands. WORKLIST
1166 is the vector of candidate phis that may be updated by this
1167 function. ADDED_TO_WORKLIST is the pointer set tracking
1168 if the new phi is already in the worklist. */
1171 find_uninit_use (gphi
*phi
, unsigned uninit_opnds
,
1172 vec
<gphi
*> *worklist
, hash_set
<gphi
*> *added_to_worklist
)
1174 /* The Boolean predicate guarding the PHI definition. Initialized
1175 lazily from PHI in the first call to is_use_guarded() and cached
1176 for subsequent iterations. */
1177 uninit_undef_val_t eval
;
1178 predicate
def_preds (eval
);
1180 use_operand_p use_p
;
1181 imm_use_iterator iter
;
1182 tree phi_result
= gimple_phi_result (phi
);
1183 FOR_EACH_IMM_USE_FAST (use_p
, iter
, phi_result
)
1185 gimple
*use_stmt
= USE_STMT (use_p
);
1186 if (is_gimple_debug (use_stmt
))
1190 if (gphi
*use_phi
= dyn_cast
<gphi
*> (use_stmt
))
1191 use_bb
= gimple_phi_arg_edge (use_phi
,
1192 PHI_ARG_INDEX_FROM_USE (use_p
))->src
;
1194 use_bb
= gimple_bb (use_stmt
);
1196 if (def_preds
.is_use_guarded (use_stmt
, use_bb
, phi
, uninit_opnds
))
1199 if (dump_file
&& (dump_flags
& TDF_DETAILS
))
1201 fprintf (dump_file
, "Found unguarded use in bb %u: ",
1203 print_gimple_stmt (dump_file
, use_stmt
, 0);
1205 /* Found one real use, return. */
1206 if (gimple_code (use_stmt
) != GIMPLE_PHI
)
1209 /* Found a phi use that is not guarded,
1210 add the phi to the worklist. */
1211 if (!added_to_worklist
->add (as_a
<gphi
*> (use_stmt
)))
1213 if (dump_file
&& (dump_flags
& TDF_DETAILS
))
1215 fprintf (dump_file
, "[WORKLIST]: Update worklist with phi: ");
1216 print_gimple_stmt (dump_file
, use_stmt
, 0);
1219 worklist
->safe_push (as_a
<gphi
*> (use_stmt
));
1220 possibly_undefined_names
->add (phi_result
);
1227 /* Look for inputs to PHI that are SSA_NAMEs that have empty definitions
1228 and gives warning if there exists a runtime path from the entry to a
1229 use of the PHI def that does not contain a definition. In other words,
1230 the warning is on the real use. The more dead paths that can be pruned
1231 by the compiler, the fewer false positives the warning is. WORKLIST
1232 is a vector of candidate phis to be examined. ADDED_TO_WORKLIST is
1233 a pointer set tracking if the new phi is added to the worklist or not. */
1236 warn_uninitialized_phi (gphi
*phi
, vec
<gphi
*> *worklist
,
1237 hash_set
<gphi
*> *added_to_worklist
)
1239 /* Don't look at virtual operands. */
1240 if (virtual_operand_p (gimple_phi_result (phi
)))
1243 unsigned uninit_opnds
= compute_uninit_opnds_pos (phi
);
1244 if (MASK_EMPTY (uninit_opnds
))
1247 if (dump_file
&& (dump_flags
& TDF_DETAILS
))
1249 fprintf (dump_file
, "Examining phi: ");
1250 print_gimple_stmt (dump_file
, phi
, 0);
1253 gimple
*uninit_use_stmt
= find_uninit_use (phi
, uninit_opnds
,
1254 worklist
, added_to_worklist
);
1256 /* All uses are properly guarded but a new PHI may have been added
1258 if (!uninit_use_stmt
)
1261 unsigned phiarg_index
= MASK_FIRST_SET_BIT (uninit_opnds
);
1262 tree uninit_op
= gimple_phi_arg_def (phi
, phiarg_index
);
1263 if (SSA_NAME_VAR (uninit_op
) == NULL_TREE
)
1266 location_t loc
= UNKNOWN_LOCATION
;
1267 if (gimple_phi_arg_has_location (phi
, phiarg_index
))
1268 loc
= gimple_phi_arg_location (phi
, phiarg_index
);
1271 tree arg_def
= gimple_phi_arg_def (phi
, phiarg_index
);
1272 if (TREE_CODE (arg_def
) == SSA_NAME
)
1274 gimple
*def_stmt
= SSA_NAME_DEF_STMT (arg_def
);
1275 if (gphi
*arg_phi
= dyn_cast
<gphi
*> (def_stmt
))
1277 unsigned uop
= compute_uninit_opnds_pos (arg_phi
);
1278 unsigned idx
= MASK_FIRST_SET_BIT (uop
);
1279 if (idx
< gimple_phi_num_args (arg_phi
)
1280 && gimple_phi_arg_has_location (arg_phi
, idx
))
1281 loc
= gimple_phi_arg_location (arg_phi
, idx
);
1286 warn_uninit (OPT_Wmaybe_uninitialized
, uninit_op
,
1287 SSA_NAME_VAR (uninit_op
),
1288 uninit_use_stmt
, loc
);
1292 gate_warn_uninitialized (void)
1294 return warn_uninitialized
|| warn_maybe_uninitialized
;
1299 const pass_data pass_data_late_warn_uninitialized
=
1301 GIMPLE_PASS
, /* type */
1302 "uninit", /* name */
1303 OPTGROUP_NONE
, /* optinfo_flags */
1304 TV_NONE
, /* tv_id */
1305 PROP_ssa
, /* properties_required */
1306 0, /* properties_provided */
1307 0, /* properties_destroyed */
1308 0, /* todo_flags_start */
1309 0, /* todo_flags_finish */
1312 class pass_late_warn_uninitialized
: public gimple_opt_pass
1315 pass_late_warn_uninitialized (gcc::context
*ctxt
)
1316 : gimple_opt_pass (pass_data_late_warn_uninitialized
, ctxt
)
1319 /* opt_pass methods: */
1320 opt_pass
*clone () { return new pass_late_warn_uninitialized (m_ctxt
); }
1321 virtual bool gate (function
*) { return gate_warn_uninitialized (); }
1322 virtual unsigned int execute (function
*);
1324 }; // class pass_late_warn_uninitialized
1327 execute_late_warn_uninitialized (function
*fun
)
1331 vec
<gphi
*> worklist
= vNULL
;
1333 calculate_dominance_info (CDI_DOMINATORS
);
1334 calculate_dominance_info (CDI_POST_DOMINATORS
);
1336 /* Mark all edges executable, warn_uninitialized_vars will skip
1337 unreachable blocks. */
1338 set_all_edges_as_executable (fun
);
1340 /* Re-do the plain uninitialized variable check, as optimization may have
1341 straightened control flow. Do this first so that we don't accidentally
1342 get a "may be" warning when we'd have seen an "is" warning later. */
1343 warn_uninitialized_vars (/*warn_maybe_uninitialized=*/1);
1345 timevar_push (TV_TREE_UNINIT
);
1347 possibly_undefined_names
= new hash_set
<tree
>;
1348 hash_set
<gphi
*> added_to_worklist
;
1350 /* Initialize worklist */
1351 FOR_EACH_BB_FN (bb
, fun
)
1352 for (gsi
= gsi_start_phis (bb
); !gsi_end_p (gsi
); gsi_next (&gsi
))
1354 gphi
*phi
= gsi
.phi ();
1356 /* Don't look at virtual operands. */
1357 if (virtual_operand_p (gimple_phi_result (phi
)))
1360 unsigned n
= gimple_phi_num_args (phi
);
1361 for (unsigned i
= 0; i
< n
; ++i
)
1363 tree op
= gimple_phi_arg_def (phi
, i
);
1364 if (TREE_CODE (op
) == SSA_NAME
&& uninit_undefined_value_p (op
))
1366 worklist
.safe_push (phi
);
1367 added_to_worklist
.add (phi
);
1368 if (dump_file
&& (dump_flags
& TDF_DETAILS
))
1370 fprintf (dump_file
, "[WORKLIST]: add to initial list "
1371 "for operand %u of: ", i
);
1372 print_gimple_stmt (dump_file
, phi
, 0);
1379 while (worklist
.length () != 0)
1382 cur_phi
= worklist
.pop ();
1383 warn_uninitialized_phi (cur_phi
, &worklist
, &added_to_worklist
);
1386 worklist
.release ();
1387 delete possibly_undefined_names
;
1388 possibly_undefined_names
= NULL
;
1389 free_dominance_info (CDI_POST_DOMINATORS
);
1390 timevar_pop (TV_TREE_UNINIT
);
1394 pass_late_warn_uninitialized::execute (function
*fun
)
1396 execute_late_warn_uninitialized (fun
);
1403 make_pass_late_warn_uninitialized (gcc::context
*ctxt
)
1405 return new pass_late_warn_uninitialized (ctxt
);
1409 execute_early_warn_uninitialized (struct function
*fun
)
1411 /* Currently, this pass runs always but
1412 execute_late_warn_uninitialized only runs with optimization. With
1413 optimization we want to warn about possible uninitialized as late
1414 as possible, thus don't do it here. However, without
1415 optimization we need to warn here about "may be uninitialized". */
1416 calculate_dominance_info (CDI_DOMINATORS
);
1417 calculate_dominance_info (CDI_POST_DOMINATORS
);
1419 /* Use VN in its cheapest incarnation and without doing any
1420 elimination to compute edge reachability. Don't bother when
1421 we only warn for unconditionally executed code though. */
1424 do_rpo_vn (fun
, NULL
, NULL
, false, false, VN_NOWALK
);
1428 set_all_edges_as_executable (fun
);
1430 warn_uninitialized_vars (/*warn_maybe_uninitialized=*/!optimize
);
1432 /* Post-dominator information cannot be reliably updated. Free it
1435 free_dominance_info (CDI_POST_DOMINATORS
);
1441 const pass_data pass_data_early_warn_uninitialized
=
1443 GIMPLE_PASS
, /* type */
1444 "early_uninit", /* name */
1445 OPTGROUP_NONE
, /* optinfo_flags */
1446 TV_TREE_UNINIT
, /* tv_id */
1447 PROP_ssa
, /* properties_required */
1448 0, /* properties_provided */
1449 0, /* properties_destroyed */
1450 0, /* todo_flags_start */
1451 0, /* todo_flags_finish */
1454 class pass_early_warn_uninitialized
: public gimple_opt_pass
1457 pass_early_warn_uninitialized (gcc::context
*ctxt
)
1458 : gimple_opt_pass (pass_data_early_warn_uninitialized
, ctxt
)
1461 /* opt_pass methods: */
1462 virtual bool gate (function
*) { return gate_warn_uninitialized (); }
1463 virtual unsigned int execute (function
*fun
)
1465 return execute_early_warn_uninitialized (fun
);
1468 }; // class pass_early_warn_uninitialized
1473 make_pass_early_warn_uninitialized (gcc::context
*ctxt
)
1475 return new pass_early_warn_uninitialized (ctxt
);