2 * Copyright (C) 2009 Dan Carpenter.
4 * This program is free software; you can redistribute it and/or
5 * modify it under the terms of the GNU General Public License
6 * as published by the Free Software Foundation; either version 2
7 * of the License, or (at your option) any later version.
9 * This program is distributed in the hope that it will be useful,
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 * GNU General Public License for more details.
14 * You should have received a copy of the GNU General Public License
15 * along with this program; if not, see http://www.gnu.org/copyleft/gpl.txt
19 * Check for things which are signed but probably should be unsigned.
21 * Hm... It seems like at this point in the processing, sparse makes all
22 * bitfields unsigned. Which is logical but not what GCC does.
27 #include "smatch_extra.h"
31 #define VAR_ON_RIGHT 0
34 static void match_assign(struct expression
*expr
)
40 char *left_name
, *right_name
;
44 if (is_fake_var_assign(expr
))
46 if (expr
->op
== SPECIAL_AND_ASSIGN
|| expr
->op
== SPECIAL_OR_ASSIGN
)
49 sym
= get_type(expr
->left
);
50 if (!sym
|| sym
->type
!= SYM_BASETYPE
) {
51 //sm_msg("could not get type");
54 if (type_bits(sym
) < 0 || type_bits(sym
) >= 32) /* max_val limits this */
56 if (!get_implied_value(expr
->right
, &sval
))
58 max
= sval_type_max(sym
);
59 if (sym
!= &bool_ctype
&& sym
!= &uchar_ctype
&&
60 sval_cmp(max
, sval
) < 0 &&
61 !(sval
.value
< 256 && max
.value
== 127)) {
62 left_name
= expr_to_str(expr
->left
);
63 right_name
= expr_to_str(expr
->right
);
64 sm_warning("'%s' %s can't fit into %s '%s'",
65 right_name
, sval_to_numstr(sval
), sval_to_numstr(max
), left_name
);
66 free_string(left_name
);
68 min
= sval_type_min(sym
);
69 if (sval_cmp_t(&llong_ctype
, min
, sval
) > 0) {
70 if (min
.value
== 0 && sval
.value
== -1) /* assigning -1 to unsigned variables is idiomatic */
72 if (expr
->right
->type
== EXPR_PREOP
&& expr
->right
->op
== '~')
74 if (expr
->op
== SPECIAL_SUB_ASSIGN
|| expr
->op
== SPECIAL_ADD_ASSIGN
)
76 if (sval_positive_bits(sval
) == 7)
78 left_name
= expr_to_str(expr
->left
);
80 sm_warning("assigning %s to unsigned variable '%s'",
81 sval_to_str(sval
), left_name
);
83 sm_warning("value %s can't fit into %s '%s'",
84 sval_to_str(sval
), sval_to_str(min
), left_name
);
86 free_string(left_name
);
90 static int cap_gt_zero_and_lt(struct expression
*expr
)
93 struct expression
*var
= expr
->left
;
94 struct expression
*tmp
;
101 if (!get_value(expr
->right
, &known
) || known
.value
!= 0)
105 FOR_EACH_PTR_REVERSE(big_expression_stack
, tmp
) {
108 if (tmp
->op
== SPECIAL_LOGICAL_AND
) {
109 struct expression
*right
= strip_expr(tmp
->right
);
111 if (right
->op
!= '<' &&
112 right
->op
!= SPECIAL_UNSIGNED_LT
&&
113 right
->op
!= SPECIAL_LTE
&&
114 right
->op
!= SPECIAL_UNSIGNED_LTE
)
117 name1
= expr_to_str(var
);
121 name2
= expr_to_str(right
->left
);
124 if (!strcmp(name1
, name2
))
130 } END_FOR_EACH_PTR_REVERSE(tmp
);
138 static int cap_lt_zero_or_gt(struct expression
*expr
)
141 struct expression
*var
= expr
->left
;
142 struct expression
*tmp
;
149 if (!get_value(expr
->right
, &known
) || known
.value
!= 0)
153 FOR_EACH_PTR_REVERSE(big_expression_stack
, tmp
) {
156 if (tmp
->op
== SPECIAL_LOGICAL_OR
) {
157 struct expression
*right
= strip_expr(tmp
->right
);
159 if (right
->op
!= '>' &&
160 right
->op
!= SPECIAL_UNSIGNED_GT
&&
161 right
->op
!= SPECIAL_GTE
&&
162 right
->op
!= SPECIAL_UNSIGNED_GTE
)
165 name1
= expr_to_str(var
);
169 name2
= expr_to_str(right
->left
);
172 if (!strcmp(name1
, name2
))
178 } END_FOR_EACH_PTR_REVERSE(tmp
);
186 static int cap_both_sides(struct expression
*expr
)
190 case SPECIAL_UNSIGNED_LT
:
192 case SPECIAL_UNSIGNED_LTE
:
193 return cap_lt_zero_or_gt(expr
);
195 case SPECIAL_UNSIGNED_GT
:
197 case SPECIAL_UNSIGNED_GTE
:
198 return cap_gt_zero_and_lt(expr
);
203 static int compare_against_macro(struct expression
*expr
)
207 if (expr
->op
!= SPECIAL_UNSIGNED_LT
)
210 if (!get_value(expr
->right
, &known
) || known
.value
!= 0)
212 return !!get_macro_name(expr
->right
->pos
);
215 static int print_unsigned_never_less_than_zero(struct expression
*expr
)
220 if (expr
->op
!= SPECIAL_UNSIGNED_LT
)
223 if (!get_value(expr
->right
, &known
) || known
.value
!= 0)
226 name
= expr_to_str(expr
->left
);
227 sm_warning("unsigned '%s' is never less than zero.", name
);
232 static bool check_is_ulong_max_recursive(struct expression
*expr
)
236 expr
= strip_expr(expr
);
238 if (!get_value(expr
, &sval
))
241 if (expr
->type
== EXPR_BINOP
) {
242 if (check_is_ulong_max_recursive(expr
->left
))
247 if (sval_cmp(sval
, sval_type_max(&ulong_ctype
)) == 0)
252 static bool is_u64_vs_ulongmax(struct expression
*expr
)
254 struct symbol
*left
, *right
;
256 if (expr
->op
!= '>' && expr
->op
!= SPECIAL_UNSIGNED_GT
)
258 if (!check_is_ulong_max_recursive(expr
->right
))
261 left
= get_type(expr
->left
);
262 right
= get_type(expr
->right
);
266 if (type_positive_bits(left
) < type_positive_bits(right
))
269 if (type_bits(left
) != 64)
271 if (right
!= &ulong_ctype
&& right
!= &uint_ctype
)
277 static void match_condition(struct expression
*expr
)
282 struct range_list
*rl_left_orig
, *rl_right_orig
;
283 struct range_list
*rl_left
, *rl_right
;
285 if (expr
->type
!= EXPR_COMPARE
)
288 type
= get_type(expr
);
292 /* screw it. I am writing this to mark yoda code as buggy.
293 * Valid comparisons between an unsigned and zero are:
295 * 2) foo < LOWER_BOUND where LOWER_BOUND is a macro.
296 * 3) foo < 0 || foo > X in exactly this format. No Yoda.
297 * 4) foo >= 0 && foo < X
299 if (get_macro_name(expr
->pos
))
301 if (compare_against_macro(expr
))
303 if (cap_both_sides(expr
))
306 /* This is a special case for the common error */
307 if (print_unsigned_never_less_than_zero(expr
))
310 /* check that one and only one side is known */
311 if (get_value(expr
->left
, &known
)) {
312 if (get_value(expr
->right
, &known
))
314 rl_left_orig
= alloc_rl(known
, known
);
315 rl_left
= cast_rl(type
, rl_left_orig
);
317 min
= sval_type_min(get_type(expr
->right
));
318 max
= sval_type_max(get_type(expr
->right
));
319 rl_right_orig
= alloc_rl(min
, max
);
320 rl_right
= cast_rl(type
, rl_right_orig
);
321 } else if (get_value(expr
->right
, &known
)) {
322 rl_right_orig
= alloc_rl(known
, known
);
323 rl_right
= cast_rl(type
, rl_right_orig
);
325 min
= sval_type_min(get_type(expr
->left
));
326 max
= sval_type_max(get_type(expr
->left
));
327 rl_left_orig
= alloc_rl(min
, max
);
328 rl_left
= cast_rl(type
, rl_left_orig
);
333 if (!possibly_true_rl(rl_left
, expr
->op
, rl_right
) &&
334 !is_u64_vs_ulongmax(expr
)) {
335 char *name
= expr_to_str(expr
);
337 sm_warning("impossible condition '(%s) => (%s %s %s)'", name
,
338 show_rl(rl_left
), show_special(expr
->op
),
343 if (!possibly_false_rl(rl_left
, expr
->op
, rl_right
) &&
344 !is_unconstant_macro(expr
->left
) &&
345 !is_unconstant_macro(expr
->right
)) {
346 char *name
= expr_to_str(expr
);
348 sm_warning("always true condition '(%s) => (%s %s %s)'", name
,
349 show_rl(rl_left_orig
), show_special(expr
->op
),
350 show_rl(rl_right_orig
));
355 void check_signed(int id
)
359 add_hook(&match_assign
, ASSIGNMENT_HOOK
);
360 add_hook(&match_condition
, CONDITION_HOOK
);