xref: /netbsd-src/usr.bin/xlint/lint1/func.c (revision 867d70fc718005c0918b8b8b2f9d7f2d52d0a0db)
1 /*	$NetBSD: func.c,v 1.145 2022/10/01 09:42:40 rillig Exp $	*/
2 
3 /*
4  * Copyright (c) 1994, 1995 Jochen Pohl
5  * All Rights Reserved.
6  *
7  * Redistribution and use in source and binary forms, with or without
8  * modification, are permitted provided that the following conditions
9  * are met:
10  * 1. Redistributions of source code must retain the above copyright
11  *    notice, this list of conditions and the following disclaimer.
12  * 2. Redistributions in binary form must reproduce the above copyright
13  *    notice, this list of conditions and the following disclaimer in the
14  *    documentation and/or other materials provided with the distribution.
15  * 3. All advertising materials mentioning features or use of this software
16  *    must display the following acknowledgement:
17  *      This product includes software developed by Jochen Pohl for
18  *	The NetBSD Project.
19  * 4. The name of the author may not be used to endorse or promote products
20  *    derived from this software without specific prior written permission.
21  *
22  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
23  * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
24  * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
25  * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
26  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
27  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
28  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
29  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
30  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
31  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
32  */
33 
34 #if HAVE_NBTOOL_CONFIG_H
35 #include "nbtool_config.h"
36 #endif
37 
38 #include <sys/cdefs.h>
39 #if defined(__RCSID)
40 __RCSID("$NetBSD: func.c,v 1.145 2022/10/01 09:42:40 rillig Exp $");
41 #endif
42 
43 #include <stdlib.h>
44 #include <string.h>
45 
46 #include "lint1.h"
47 #include "cgram.h"
48 
49 /*
50  * Contains a pointer to the symbol table entry of the current function
51  * definition.
52  */
53 sym_t	*funcsym;
54 
55 /* Is set as long as a statement can be reached. Must be set at level 0. */
56 bool	reached = true;
57 
58 /*
59  * Is true by default, can be cleared by NOTREACHED.
60  * Is reset to true whenever 'reached' changes.
61  */
62 bool	warn_about_unreachable;
63 
64 /*
65  * In conjunction with 'reached', controls printing of "fallthrough on ..."
66  * warnings.
67  * Reset by each statement and set by FALLTHROUGH, switch (switch1())
68  * and case (label()).
69  *
70  * Control statements if, for, while and switch do not reset seen_fallthrough
71  * because this must be done by the controlled statement. At least for if this
72  * is important because ** FALLTHROUGH ** after "if (expr) statement" is
73  * evaluated before the following token, which causes reduction of above.
74  * This means that ** FALLTHROUGH ** after "if ..." would always be ignored.
75  */
76 bool	seen_fallthrough;
77 
78 /* The innermost control statement */
79 control_statement *cstmt;
80 
81 /*
82  * Number of arguments which will be checked for usage in following
83  * function definition. -1 stands for all arguments.
84  *
85  * The position of the last ARGSUSED comment is stored in argsused_pos.
86  */
87 int	nargusg = -1;
88 pos_t	argsused_pos;
89 
90 /*
91  * Number of arguments of the following function definition whose types
92  * shall be checked by lint2. -1 stands for all arguments.
93  *
94  * The position of the last VARARGS comment is stored in vapos.
95  */
96 int	nvararg = -1;
97 pos_t	vapos;
98 
99 /*
100  * Both printflike_argnum and scanflike_argnum contain the 1-based number
101  * of the string argument which shall be used to check the types of remaining
102  * arguments (for PRINTFLIKE and SCANFLIKE).
103  *
104  * printflike_pos and scanflike_pos are the positions of the last PRINTFLIKE
105  * or SCANFLIKE comment.
106  */
107 int	printflike_argnum = -1;
108 int	scanflike_argnum = -1;
109 pos_t	printflike_pos;
110 pos_t	scanflike_pos;
111 
112 /*
113  * If both plibflg and llibflg are set, prototypes are written as function
114  * definitions to the output file.
115  */
116 bool	plibflg;
117 
118 /*
119  * True means that no warnings about constants in conditional
120  * context are printed.
121  */
122 bool	constcond_flag;
123 
124 /*
125  * Whether a lint library shall be created. The effect of this flag is that
126  * all defined symbols are treated as used.
127  * (The LINTLIBRARY comment also resets vflag.)
128  */
129 bool	llibflg;
130 
131 /*
132  * Determines the warnings that are suppressed by a LINTED directive.  For
133  * globally suppressed warnings, see 'msgset'.
134  *
135  * LWARN_ALL:	all warnings are enabled
136  * LWARN_NONE:	all warnings are suppressed
137  * n >= 0:	warning n is ignored, the others are active
138  */
139 int	lwarn = LWARN_ALL;
140 
141 /*
142  * Whether bitfield type errors are suppressed by a BITFIELDTYPE
143  * directive.
144  */
145 bool	bitfieldtype_ok;
146 
147 /*
148  * Whether complaints about use of "long long" are suppressed in
149  * the next statement or declaration.
150  */
151 bool	quadflg;
152 
153 /*
154  * Puts a new element at the top of the stack used for control statements.
155  */
156 void
157 begin_control_statement(control_statement_kind kind)
158 {
159 	control_statement *cs;
160 
161 	cs = xcalloc(1, sizeof(*cs));
162 	cs->c_kind = kind;
163 	cs->c_surrounding = cstmt;
164 	cstmt = cs;
165 }
166 
167 /*
168  * Removes the top element of the stack used for control statements.
169  */
170 void
171 end_control_statement(control_statement_kind kind)
172 {
173 	control_statement *cs;
174 	case_label_t *cl, *next;
175 
176 	lint_assert(cstmt != NULL);
177 
178 	while (cstmt->c_kind != kind)
179 		cstmt = cstmt->c_surrounding;
180 
181 	cs = cstmt;
182 	cstmt = cs->c_surrounding;
183 
184 	for (cl = cs->c_case_labels; cl != NULL; cl = next) {
185 		next = cl->cl_next;
186 		free(cl);
187 	}
188 
189 	free(cs->c_switch_type);
190 	free(cs);
191 }
192 
193 static void
194 set_reached(bool new_reached)
195 {
196 	debug_step("%s -> %s",
197 	    reached ? "reachable" : "unreachable",
198 	    new_reached ? "reachable" : "unreachable");
199 	reached = new_reached;
200 	warn_about_unreachable = true;
201 }
202 
203 /*
204  * Prints a warning if a statement cannot be reached.
205  */
206 void
207 check_statement_reachable(void)
208 {
209 	if (!reached && warn_about_unreachable) {
210 		/* statement not reached */
211 		warning(193);
212 		warn_about_unreachable = false;
213 	}
214 }
215 
216 /*
217  * Called after a function declaration which introduces a function definition
218  * and before an (optional) old-style argument declaration list.
219  *
220  * Puts all symbols declared in the prototype or in an old-style argument
221  * list back to the symbol table.
222  *
223  * Does the usual checking of storage class, type (return value),
224  * redeclaration, etc.
225  */
226 void
227 funcdef(sym_t *fsym)
228 {
229 	int	n;
230 	bool	dowarn;
231 	sym_t	*arg, *sym, *rdsym;
232 
233 	funcsym = fsym;
234 
235 	/*
236 	 * Put all symbols declared in the argument list back to the
237 	 * symbol table.
238 	 */
239 	for (sym = dcs->d_func_proto_syms; sym != NULL;
240 	    sym = sym->s_level_next) {
241 		if (sym->s_block_level != -1) {
242 			lint_assert(sym->s_block_level == 1);
243 			inssym(1, sym);
244 		}
245 	}
246 
247 	/*
248 	 * In old_style_function() we did not know whether it is an old
249 	 * style function definition or only an old-style declaration,
250 	 * if there are no arguments inside the argument list ("f()").
251 	 */
252 	if (!fsym->s_type->t_proto && fsym->u.s_old_style_args == NULL)
253 		fsym->s_osdef = true;
254 
255 	check_type(fsym);
256 
257 	/*
258 	 * check_type() checks for almost all possible errors, but not for
259 	 * incomplete return values (these are allowed in declarations)
260 	 */
261 	if (fsym->s_type->t_subt->t_tspec != VOID &&
262 	    is_incomplete(fsym->s_type->t_subt)) {
263 		/* cannot return incomplete type */
264 		error(67);
265 	}
266 
267 	fsym->s_def = DEF;
268 
269 	if (fsym->s_scl == TYPEDEF) {
270 		fsym->s_scl = EXTERN;
271 		/* illegal storage class */
272 		error(8);
273 	}
274 
275 	if (dcs->d_inline)
276 		fsym->s_inline = true;
277 
278 	/*
279 	 * Arguments in new style function declarations need a name.
280 	 * (void is already removed from the list of arguments)
281 	 */
282 	n = 1;
283 	for (arg = fsym->s_type->t_args; arg != NULL; arg = arg->s_next) {
284 		if (arg->s_scl == ABSTRACT) {
285 			lint_assert(arg->s_name == unnamed);
286 			/* formal parameter #%d lacks name */
287 			error(59, n);
288 		} else {
289 			lint_assert(arg->s_name != unnamed);
290 		}
291 		n++;
292 	}
293 
294 	/*
295 	 * We must also remember the position. s_def_pos is overwritten
296 	 * if this is an old-style definition and we had already a
297 	 * prototype.
298 	 */
299 	dcs->d_func_def_pos = fsym->s_def_pos;
300 
301 	if ((rdsym = dcs->d_redeclared_symbol) != NULL) {
302 
303 		if (!check_redeclaration(fsym, (dowarn = false, &dowarn))) {
304 
305 			/*
306 			 * Print nothing if the newly defined function
307 			 * is defined in old style. A better warning will
308 			 * be printed in check_func_lint_directives().
309 			 */
310 			if (dowarn && !fsym->s_osdef) {
311 				/* TODO: error in C99 mode as well? */
312 				if (!allow_trad && !allow_c99)
313 					/* redeclaration of '%s' */
314 					error(27, fsym->s_name);
315 				else
316 					/* redeclaration of '%s' */
317 					warning(27, fsym->s_name);
318 				print_previous_declaration(rdsym);
319 			}
320 
321 			copy_usage_info(fsym, rdsym);
322 
323 			/*
324 			 * If the old symbol was a prototype and the new
325 			 * one is none, overtake the position of the
326 			 * declaration of the prototype.
327 			 */
328 			if (fsym->s_osdef && rdsym->s_type->t_proto)
329 				fsym->s_def_pos = rdsym->s_def_pos;
330 
331 			complete_type(fsym, rdsym);
332 
333 			if (rdsym->s_inline)
334 				fsym->s_inline = true;
335 
336 		}
337 
338 		/* remove the old symbol from the symbol table */
339 		rmsym(rdsym);
340 
341 	}
342 
343 	if (fsym->s_osdef && !fsym->s_type->t_proto) {
344 		/* TODO: Make this an error in C99 mode as well. */
345 		if ((!allow_trad && !allow_c99) && hflag &&
346 		    strcmp(fsym->s_name, "main") != 0)
347 			/* function definition is not a prototype */
348 			warning(286);
349 	}
350 
351 	if (dcs->d_notyp)
352 		fsym->s_return_type_implicit_int = true;
353 
354 	set_reached(true);
355 }
356 
357 static void
358 check_missing_return_value(void)
359 {
360 	if (funcsym->s_type->t_subt->t_tspec == VOID)
361 		return;
362 	if (funcsym->s_return_type_implicit_int)
363 		return;
364 
365 	/* C99 5.1.2.2.3 "Program termination" p1 */
366 	if (allow_c99 && strcmp(funcsym->s_name, "main") == 0)
367 		return;
368 
369 	/* function '%s' falls off bottom without returning value */
370 	warning(217, funcsym->s_name);
371 }
372 
373 /*
374  * Called at the end of a function definition.
375  */
376 void
377 funcend(void)
378 {
379 	sym_t	*arg;
380 	int	n;
381 
382 	if (reached) {
383 		cstmt->c_had_return_noval = true;
384 		check_missing_return_value();
385 	}
386 
387 	/*
388 	 * This warning is printed only if the return value was implicitly
389 	 * declared to be int. Otherwise the wrong return statement
390 	 * has already printed a warning.
391 	 */
392 	if (cstmt->c_had_return_noval && cstmt->c_had_return_value &&
393 	    funcsym->s_return_type_implicit_int)
394 		/* function '%s' has 'return expr' and 'return' */
395 		warning(216, funcsym->s_name);
396 
397 	/* Print warnings for unused arguments */
398 	arg = dcs->d_func_args;
399 	n = 0;
400 	while (arg != NULL && (nargusg == -1 || n < nargusg)) {
401 		check_usage_sym(dcs->d_asm, arg);
402 		arg = arg->s_next;
403 		n++;
404 	}
405 	nargusg = -1;
406 
407 	/*
408 	 * write the information about the function definition to the
409 	 * output file
410 	 * inline functions explicitly declared extern are written as
411 	 * declarations only.
412 	 */
413 	if (dcs->d_scl == EXTERN && funcsym->s_inline) {
414 		outsym(funcsym, funcsym->s_scl, DECL);
415 	} else {
416 		outfdef(funcsym, &dcs->d_func_def_pos,
417 		    cstmt->c_had_return_value, funcsym->s_osdef,
418 		    dcs->d_func_args);
419 	}
420 
421 	/* clean up after syntax errors, see test stmt_for.c. */
422 	while (dcs->d_enclosing != NULL)
423 		dcs = dcs->d_enclosing;
424 
425 	/*
426 	 * remove all symbols declared during argument declaration from
427 	 * the symbol table
428 	 */
429 	lint_assert(dcs->d_enclosing == NULL);
430 	lint_assert(dcs->d_kind == DK_EXTERN);
431 	rmsyms(dcs->d_func_proto_syms);
432 
433 	/* must be set on level 0 */
434 	set_reached(true);
435 }
436 
437 void
438 named_label(sym_t *sym)
439 {
440 
441 	if (sym->s_set) {
442 		/* label '%s' redefined */
443 		error(194, sym->s_name);
444 	} else {
445 		mark_as_set(sym);
446 	}
447 
448 	set_reached(true);
449 }
450 
451 static void
452 check_case_label_bitand(const tnode_t *case_expr, const tnode_t *switch_expr)
453 {
454 	uint64_t case_value, mask;
455 
456 	if (switch_expr->tn_op != BITAND ||
457 	    switch_expr->tn_right->tn_op != CON)
458 		return;
459 
460 	lint_assert(case_expr->tn_op == CON);
461 	case_value = case_expr->tn_val->v_quad;
462 	mask = switch_expr->tn_right->tn_val->v_quad;
463 
464 	if ((case_value & ~mask) != 0) {
465 		/* statement not reached */
466 		warning(193);
467 	}
468 }
469 
470 static void
471 check_case_label_enum(const tnode_t *tn, const control_statement *cs)
472 {
473 	/* similar to typeok_enum in tree.c */
474 
475 	if (!(tn->tn_type->t_is_enum || cs->c_switch_type->t_is_enum))
476 		return;
477 	if (tn->tn_type->t_is_enum && cs->c_switch_type->t_is_enum &&
478 	    tn->tn_type->t_enum == cs->c_switch_type->t_enum)
479 		return;
480 
481 #if 0 /* not yet ready, see msg_130.c */
482 	/* enum type mismatch: '%s' '%s' '%s' */
483 	warning(130, type_name(cs->c_switch_type), op_name(EQ),
484 	    type_name(tn->tn_type));
485 #endif
486 }
487 
488 static void
489 check_case_label(tnode_t *tn, control_statement *cs)
490 {
491 	case_label_t *cl;
492 	val_t	*v;
493 	val_t	nv;
494 	tspec_t	t;
495 
496 	if (cs == NULL) {
497 		/* case not in switch */
498 		error(195);
499 		return;
500 	}
501 
502 	if (tn != NULL && tn->tn_op != CON) {
503 		/* non-constant case expression */
504 		error(197);
505 		return;
506 	}
507 
508 	if (tn != NULL && !is_integer(tn->tn_type->t_tspec)) {
509 		/* non-integral case expression */
510 		error(198);
511 		return;
512 	}
513 
514 	check_case_label_bitand(tn, cs->c_switch_expr);
515 	check_case_label_enum(tn, cs);
516 
517 	lint_assert(cs->c_switch_type != NULL);
518 
519 	if (reached && !seen_fallthrough) {
520 		if (hflag)
521 			/* fallthrough on case statement */
522 			warning(220);
523 	}
524 
525 	t = tn->tn_type->t_tspec;
526 	if (t == LONG || t == ULONG ||
527 	    t == QUAD || t == UQUAD) {
528 		if (!allow_c90)
529 			/* case label must be of type 'int' in traditional C */
530 			warning(203);
531 	}
532 
533 	/*
534 	 * get the value of the expression and convert it
535 	 * to the type of the switch expression
536 	 */
537 	v = constant(tn, true);
538 	(void)memset(&nv, 0, sizeof(nv));
539 	convert_constant(CASE, 0, cs->c_switch_type, &nv, v);
540 	free(v);
541 
542 	/* look if we had this value already */
543 	for (cl = cs->c_case_labels; cl != NULL; cl = cl->cl_next) {
544 		if (cl->cl_val.v_quad == nv.v_quad)
545 			break;
546 	}
547 	if (cl != NULL && is_uinteger(nv.v_tspec)) {
548 		/* duplicate case in switch: %lu */
549 		error(200, (unsigned long)nv.v_quad);
550 	} else if (cl != NULL) {
551 		/* duplicate case in switch: %ld */
552 		error(199, (long)nv.v_quad);
553 	} else {
554 		check_getopt_case_label(nv.v_quad);
555 
556 		/* append the value to the list of case values */
557 		cl = xcalloc(1, sizeof(*cl));
558 		cl->cl_val = nv;
559 		cl->cl_next = cs->c_case_labels;
560 		cs->c_case_labels = cl;
561 	}
562 }
563 
564 void
565 case_label(tnode_t *tn)
566 {
567 	control_statement *cs;
568 
569 	/* find the innermost switch statement */
570 	for (cs = cstmt; cs != NULL && !cs->c_switch; cs = cs->c_surrounding)
571 		continue;
572 
573 	check_case_label(tn, cs);
574 
575 	expr_free_all();
576 
577 	set_reached(true);
578 }
579 
580 void
581 default_label(void)
582 {
583 	control_statement *cs;
584 
585 	/* find the innermost switch statement */
586 	for (cs = cstmt; cs != NULL && !cs->c_switch; cs = cs->c_surrounding)
587 		continue;
588 
589 	if (cs == NULL) {
590 		/* default outside switch */
591 		error(201);
592 	} else if (cs->c_default) {
593 		/* duplicate default in switch */
594 		error(202);
595 	} else {
596 		if (reached && !seen_fallthrough) {
597 			if (hflag)
598 				/* fallthrough on default statement */
599 				warning(284);
600 		}
601 		cs->c_default = true;
602 	}
603 
604 	set_reached(true);
605 }
606 
607 static tnode_t *
608 check_controlling_expression(tnode_t *tn)
609 {
610 
611 	tn = cconv(tn);
612 	if (tn != NULL)
613 		tn = promote(NOOP, false, tn);
614 
615 	if (tn != NULL && !is_scalar(tn->tn_type->t_tspec)) {
616 		/* C99 6.5.15p4 for the ?: operator; see typeok:QUEST */
617 		/* C99 6.8.4.1p1 for if statements */
618 		/* C99 6.8.5p2 for while, do and for loops */
619 		/* controlling expressions must have scalar type */
620 		error(204);
621 		return NULL;
622 	}
623 
624 	if (tn != NULL && Tflag && !is_typeok_bool_compares_with_zero(tn)) {
625 		/* controlling expression must be bool, not '%s' */
626 		error(333, tspec_name(tn->tn_type->t_tspec));
627 	}
628 
629 	return tn;
630 }
631 
632 /*
633  * T_IF T_LPAREN expr T_RPAREN
634  */
635 void
636 if1(tnode_t *tn)
637 {
638 
639 	if (tn != NULL)
640 		tn = check_controlling_expression(tn);
641 	if (tn != NULL)
642 		expr(tn, false, true, false, false);
643 	begin_control_statement(CS_IF);
644 
645 	if (tn != NULL && tn->tn_op == CON && !tn->tn_system_dependent) {
646 		/* XXX: what if inside 'if (0)'? */
647 		set_reached(constant_is_nonzero(tn));
648 		/* XXX: what about always_else? */
649 		cstmt->c_always_then = reached;
650 	}
651 }
652 
653 /*
654  * if_without_else
655  * if_without_else T_ELSE
656  */
657 void
658 if2(void)
659 {
660 
661 	cstmt->c_reached_end_of_then = reached;
662 	/* XXX: what if inside 'if (0)'? */
663 	set_reached(!cstmt->c_always_then);
664 }
665 
666 /*
667  * if_without_else
668  * if_without_else T_ELSE statement
669  */
670 void
671 if3(bool els)
672 {
673 	if (cstmt->c_reached_end_of_then)
674 		set_reached(true);
675 	else if (cstmt->c_always_then)
676 		set_reached(false);
677 	else if (!els)
678 		set_reached(true);
679 
680 	end_control_statement(CS_IF);
681 }
682 
683 /*
684  * T_SWITCH T_LPAREN expr T_RPAREN
685  */
686 void
687 switch1(tnode_t *tn)
688 {
689 	tspec_t	t;
690 	type_t	*tp;
691 
692 	if (tn != NULL)
693 		tn = cconv(tn);
694 	if (tn != NULL)
695 		tn = promote(NOOP, false, tn);
696 	if (tn != NULL && !is_integer(tn->tn_type->t_tspec)) {
697 		/* switch expression must have integral type */
698 		error(205);
699 		tn = NULL;
700 	}
701 	if (tn != NULL && !allow_c90) {
702 		t = tn->tn_type->t_tspec;
703 		if (t == LONG || t == ULONG || t == QUAD || t == UQUAD) {
704 			/* switch expression must be of type 'int' in ... */
705 			warning(271);
706 		}
707 	}
708 
709 	/*
710 	 * Remember the type of the expression. Because it's possible
711 	 * that (*tp) is allocated on tree memory, the type must be
712 	 * duplicated. This is not too complicated because it is
713 	 * only an integer type.
714 	 */
715 	tp = xcalloc(1, sizeof(*tp));
716 	if (tn != NULL) {
717 		tp->t_tspec = tn->tn_type->t_tspec;
718 		if ((tp->t_is_enum = tn->tn_type->t_is_enum) != false)
719 			tp->t_enum = tn->tn_type->t_enum;
720 	} else {
721 		tp->t_tspec = INT;
722 	}
723 
724 	/* leak the memory, for check_case_label_bitand */
725 	(void)expr_save_memory();
726 
727 	check_getopt_begin_switch();
728 	expr(tn, true, false, false, false);
729 
730 	begin_control_statement(CS_SWITCH);
731 	cstmt->c_switch = true;
732 	cstmt->c_switch_type = tp;
733 	cstmt->c_switch_expr = tn;
734 
735 	set_reached(false);
736 	seen_fallthrough = true;
737 }
738 
739 /*
740  * switch_expr statement
741  */
742 void
743 switch2(void)
744 {
745 	int	nenum = 0, nclab = 0;
746 	sym_t	*esym;
747 	case_label_t *cl;
748 
749 	lint_assert(cstmt->c_switch_type != NULL);
750 
751 	if (cstmt->c_switch_type->t_is_enum) {
752 		/*
753 		 * Warn if the number of case labels is different from the
754 		 * number of enumerators.
755 		 */
756 		nenum = nclab = 0;
757 		lint_assert(cstmt->c_switch_type->t_enum != NULL);
758 		for (esym = cstmt->c_switch_type->t_enum->en_first_enumerator;
759 		     esym != NULL; esym = esym->s_next) {
760 			nenum++;
761 		}
762 		for (cl = cstmt->c_case_labels; cl != NULL; cl = cl->cl_next)
763 			nclab++;
764 		if (hflag && eflag && nclab < nenum && !cstmt->c_default) {
765 			/* enumeration value(s) not handled in switch */
766 			warning(206);
767 		}
768 	}
769 
770 	check_getopt_end_switch();
771 
772 	if (cstmt->c_break) {
773 		/*
774 		 * The end of the switch statement is always reached since
775 		 * c_break is only set if a break statement can actually
776 		 * be reached.
777 		 */
778 		set_reached(true);
779 	} else if (cstmt->c_default ||
780 		   (hflag && cstmt->c_switch_type->t_is_enum &&
781 		    nenum == nclab)) {
782 		/*
783 		 * The end of the switch statement is reached if the end
784 		 * of the last statement inside it is reached.
785 		 */
786 	} else {
787 		/*
788 		 * There are possible values that are not handled in the
789 		 * switch statement.
790 		 */
791 		set_reached(true);
792 	}
793 
794 	end_control_statement(CS_SWITCH);
795 }
796 
797 /*
798  * T_WHILE T_LPAREN expr T_RPAREN
799  */
800 void
801 while1(tnode_t *tn)
802 {
803 	bool body_reached;
804 
805 	if (!reached) {
806 		/* loop not entered at top */
807 		warning(207);
808 		/* FIXME: that's plain wrong. */
809 		set_reached(true);
810 	}
811 
812 	if (tn != NULL)
813 		tn = check_controlling_expression(tn);
814 
815 	begin_control_statement(CS_WHILE);
816 	cstmt->c_loop = true;
817 	cstmt->c_maybe_endless = is_nonzero(tn);
818 	body_reached = !is_zero(tn);
819 
820 	check_getopt_begin_while(tn);
821 	expr(tn, false, true, true, false);
822 
823 	set_reached(body_reached);
824 }
825 
826 /*
827  * while_expr statement
828  * while_expr error
829  */
830 void
831 while2(void)
832 {
833 
834 	/*
835 	 * The end of the loop can be reached if it is no endless loop
836 	 * or there was a break statement which was reached.
837 	 */
838 	set_reached(!cstmt->c_maybe_endless || cstmt->c_break);
839 
840 	check_getopt_end_while();
841 	end_control_statement(CS_WHILE);
842 }
843 
844 /*
845  * T_DO
846  */
847 void
848 do1(void)
849 {
850 
851 	if (!reached) {
852 		/* loop not entered at top */
853 		warning(207);
854 		set_reached(true);
855 	}
856 
857 	begin_control_statement(CS_DO_WHILE);
858 	cstmt->c_loop = true;
859 }
860 
861 /*
862  * do statement do_while_expr
863  * do error
864  */
865 void
866 do2(tnode_t *tn)
867 {
868 
869 	/*
870 	 * If there was a continue statement, the expression controlling the
871 	 * loop is reached.
872 	 */
873 	if (cstmt->c_continue)
874 		set_reached(true);
875 
876 	if (tn != NULL)
877 		tn = check_controlling_expression(tn);
878 
879 	if (tn != NULL && tn->tn_op == CON) {
880 		cstmt->c_maybe_endless = constant_is_nonzero(tn);
881 		if (!cstmt->c_maybe_endless && cstmt->c_continue)
882 			/* continue in 'do ... while (0)' loop */
883 			error(323);
884 	}
885 
886 	expr(tn, false, true, true, true);
887 
888 	if (cstmt->c_maybe_endless)
889 		set_reached(false);
890 	if (cstmt->c_break)
891 		set_reached(true);
892 
893 	end_control_statement(CS_DO_WHILE);
894 }
895 
896 /*
897  * T_FOR T_LPAREN opt_expr T_SEMI opt_expr T_SEMI opt_expr T_RPAREN
898  */
899 void
900 for1(tnode_t *tn1, tnode_t *tn2, tnode_t *tn3)
901 {
902 
903 	/*
904 	 * If there is no initialization expression it is possible that
905 	 * it is intended not to enter the loop at top.
906 	 */
907 	if (tn1 != NULL && !reached) {
908 		/* loop not entered at top */
909 		warning(207);
910 		set_reached(true);
911 	}
912 
913 	begin_control_statement(CS_FOR);
914 	cstmt->c_loop = true;
915 
916 	/*
917 	 * Store the tree memory for the reinitialization expression.
918 	 * Also remember this expression itself. We must check it at
919 	 * the end of the loop to get "used but not set" warnings correct.
920 	 */
921 	cstmt->c_for_expr3_mem = expr_save_memory();
922 	cstmt->c_for_expr3 = tn3;
923 	cstmt->c_for_expr3_pos = curr_pos;
924 	cstmt->c_for_expr3_csrc_pos = csrc_pos;
925 
926 	if (tn1 != NULL)
927 		expr(tn1, false, false, true, false);
928 
929 	if (tn2 != NULL)
930 		tn2 = check_controlling_expression(tn2);
931 	if (tn2 != NULL)
932 		expr(tn2, false, true, true, false);
933 
934 	cstmt->c_maybe_endless = tn2 == NULL || is_nonzero(tn2);
935 
936 	/* Checking the reinitialization expression is done in for2() */
937 
938 	set_reached(!is_zero(tn2));
939 }
940 
941 /*
942  * for_exprs statement
943  * for_exprs error
944  */
945 void
946 for2(void)
947 {
948 	pos_t	cpos, cspos;
949 	tnode_t	*tn3;
950 
951 	if (cstmt->c_continue)
952 		set_reached(true);
953 
954 	cpos = curr_pos;
955 	cspos = csrc_pos;
956 
957 	/* Restore the tree memory for the reinitialization expression */
958 	expr_restore_memory(cstmt->c_for_expr3_mem);
959 	tn3 = cstmt->c_for_expr3;
960 	curr_pos = cstmt->c_for_expr3_pos;
961 	csrc_pos = cstmt->c_for_expr3_csrc_pos;
962 
963 	/* simply "statement not reached" would be confusing */
964 	if (!reached && warn_about_unreachable) {
965 		/* end-of-loop code not reached */
966 		warning(223);
967 		set_reached(true);
968 	}
969 
970 	if (tn3 != NULL) {
971 		expr(tn3, false, false, true, false);
972 	} else {
973 		expr_free_all();
974 	}
975 
976 	curr_pos = cpos;
977 	csrc_pos = cspos;
978 
979 	/* An endless loop without break will never terminate */
980 	/* TODO: What if the loop contains a 'return'? */
981 	set_reached(cstmt->c_break || !cstmt->c_maybe_endless);
982 
983 	end_control_statement(CS_FOR);
984 }
985 
986 /*
987  * T_GOTO identifier T_SEMI
988  */
989 void
990 do_goto(sym_t *lab)
991 {
992 
993 	mark_as_used(lab, false, false);
994 
995 	check_statement_reachable();
996 
997 	set_reached(false);
998 }
999 
1000 /*
1001  * T_BREAK T_SEMI
1002  */
1003 void
1004 do_break(void)
1005 {
1006 	control_statement *cs;
1007 
1008 	cs = cstmt;
1009 	while (cs != NULL && !cs->c_loop && !cs->c_switch)
1010 		cs = cs->c_surrounding;
1011 
1012 	if (cs == NULL) {
1013 		/* break outside loop or switch */
1014 		error(208);
1015 	} else {
1016 		if (reached)
1017 			cs->c_break = true;
1018 	}
1019 
1020 	if (bflag)
1021 		check_statement_reachable();
1022 
1023 	set_reached(false);
1024 }
1025 
1026 /*
1027  * T_CONTINUE T_SEMI
1028  */
1029 void
1030 do_continue(void)
1031 {
1032 	control_statement *cs;
1033 
1034 	for (cs = cstmt; cs != NULL && !cs->c_loop; cs = cs->c_surrounding)
1035 		continue;
1036 
1037 	if (cs == NULL) {
1038 		/* continue outside loop */
1039 		error(209);
1040 	} else {
1041 		/* TODO: only if reachable, for symmetry with c_break */
1042 		cs->c_continue = true;
1043 	}
1044 
1045 	check_statement_reachable();
1046 
1047 	set_reached(false);
1048 }
1049 
1050 /*
1051  * T_RETURN T_SEMI
1052  * T_RETURN expr T_SEMI
1053  */
1054 void
1055 do_return(bool sys, tnode_t *tn)
1056 {
1057 	tnode_t	*ln, *rn;
1058 	control_statement *cs;
1059 	op_t	op;
1060 
1061 	cs = cstmt;
1062 	if (cs == NULL) {
1063 		/* syntax error '%s' */
1064 		error(249, "return outside function");
1065 		return;
1066 	}
1067 
1068 	for (; cs->c_surrounding != NULL; cs = cs->c_surrounding)
1069 		continue;
1070 
1071 	if (tn != NULL)
1072 		cs->c_had_return_value = true;
1073 	else
1074 		cs->c_had_return_noval = true;
1075 
1076 	if (tn != NULL && funcsym->s_type->t_subt->t_tspec == VOID) {
1077 		/* void function '%s' cannot return value */
1078 		error(213, funcsym->s_name);
1079 		expr_free_all();
1080 		tn = NULL;
1081 	} else if (tn == NULL && funcsym->s_type->t_subt->t_tspec != VOID) {
1082 		/*
1083 		 * Assume that the function has a return value only if it
1084 		 * is explicitly declared.
1085 		 */
1086 		if (!funcsym->s_return_type_implicit_int)
1087 			/* function '%s' expects to return value */
1088 			warning(214, funcsym->s_name);
1089 	}
1090 
1091 	if (tn != NULL) {
1092 
1093 		/* Create a temporary node for the left side */
1094 		ln = expr_zero_alloc(sizeof(*ln));
1095 		ln->tn_op = NAME;
1096 		ln->tn_type = expr_unqualified_type(funcsym->s_type->t_subt);
1097 		ln->tn_lvalue = true;
1098 		ln->tn_sym = funcsym;		/* better than nothing */
1099 
1100 		tn = build_binary(ln, RETURN, sys, tn);
1101 
1102 		if (tn != NULL) {
1103 			rn = tn->tn_right;
1104 			while ((op = rn->tn_op) == CVT || op == PLUS)
1105 				rn = rn->tn_left;
1106 			if (rn->tn_op == ADDR && rn->tn_left->tn_op == NAME &&
1107 			    rn->tn_left->tn_sym->s_scl == AUTO) {
1108 				/* '%s' returns pointer to automatic object */
1109 				warning(302, funcsym->s_name);
1110 			}
1111 		}
1112 
1113 		expr(tn, true, false, true, false);
1114 
1115 	} else {
1116 
1117 		check_statement_reachable();
1118 
1119 	}
1120 
1121 	set_reached(false);
1122 }
1123 
1124 /*
1125  * Do some cleanup after a global declaration or definition.
1126  * Especially remove information about unused lint comments.
1127  */
1128 void
1129 global_clean_up_decl(bool silent)
1130 {
1131 
1132 	if (nargusg != -1) {
1133 		if (!silent) {
1134 			/* comment ** %s ** must precede function definition */
1135 			warning_at(282, &argsused_pos, "ARGSUSED");
1136 		}
1137 		nargusg = -1;
1138 	}
1139 	if (nvararg != -1) {
1140 		if (!silent) {
1141 			/* comment ** %s ** must precede function definition */
1142 			warning_at(282, &vapos, "VARARGS");
1143 		}
1144 		nvararg = -1;
1145 	}
1146 	if (printflike_argnum != -1) {
1147 		if (!silent) {
1148 			/* comment ** %s ** must precede function definition */
1149 			warning_at(282, &printflike_pos, "PRINTFLIKE");
1150 		}
1151 		printflike_argnum = -1;
1152 	}
1153 	if (scanflike_argnum != -1) {
1154 		if (!silent) {
1155 			/* comment ** %s ** must precede function definition */
1156 			warning_at(282, &scanflike_pos, "SCANFLIKE");
1157 		}
1158 		scanflike_argnum = -1;
1159 	}
1160 
1161 	dcs->d_asm = false;
1162 
1163 	/*
1164 	 * Needed for BSD yacc in case of parse errors; GNU Bison 3.0.4 is
1165 	 * fine.  See test gcc_attribute.c, function_with_unknown_attribute.
1166 	 */
1167 	in_gcc_attribute = false;
1168 	while (dcs->d_enclosing != NULL)
1169 		end_declaration_level();
1170 }
1171 
1172 /*
1173  * ARGSUSED comment
1174  *
1175  * Only the first n arguments of the following function are checked
1176  * for usage. A missing argument is taken to be 0.
1177  */
1178 void
1179 argsused(int n)
1180 {
1181 
1182 	if (n == -1)
1183 		n = 0;
1184 
1185 	if (dcs->d_kind != DK_EXTERN) {
1186 		/* comment ** %s ** must be outside function */
1187 		warning(280, "ARGSUSED");
1188 		return;
1189 	}
1190 	if (nargusg != -1) {
1191 		/* duplicate comment ** %s ** */
1192 		warning(281, "ARGSUSED");
1193 	}
1194 	nargusg = n;
1195 	argsused_pos = curr_pos;
1196 }
1197 
1198 /*
1199  * VARARGS comment
1200  *
1201  * Causes lint2 to check only the first n arguments for compatibility
1202  * with the function definition. A missing argument is taken to be 0.
1203  */
1204 void
1205 varargs(int n)
1206 {
1207 
1208 	if (n == -1)
1209 		n = 0;
1210 
1211 	if (dcs->d_kind != DK_EXTERN) {
1212 		/* comment ** %s ** must be outside function */
1213 		warning(280, "VARARGS");
1214 		return;
1215 	}
1216 	if (nvararg != -1) {
1217 		/* duplicate comment ** %s ** */
1218 		warning(281, "VARARGS");
1219 	}
1220 	nvararg = n;
1221 	vapos = curr_pos;
1222 }
1223 
1224 /*
1225  * PRINTFLIKE comment
1226  *
1227  * Check all arguments until the (n-1)-th as usual. The n-th argument is
1228  * used the check the types of remaining arguments.
1229  */
1230 void
1231 printflike(int n)
1232 {
1233 
1234 	if (n == -1)
1235 		n = 0;
1236 
1237 	if (dcs->d_kind != DK_EXTERN) {
1238 		/* comment ** %s ** must be outside function */
1239 		warning(280, "PRINTFLIKE");
1240 		return;
1241 	}
1242 	if (printflike_argnum != -1) {
1243 		/* duplicate comment ** %s ** */
1244 		warning(281, "PRINTFLIKE");
1245 	}
1246 	printflike_argnum = n;
1247 	printflike_pos = curr_pos;
1248 }
1249 
1250 /*
1251  * SCANFLIKE comment
1252  *
1253  * Check all arguments until the (n-1)-th as usual. The n-th argument is
1254  * used the check the types of remaining arguments.
1255  */
1256 void
1257 scanflike(int n)
1258 {
1259 
1260 	if (n == -1)
1261 		n = 0;
1262 
1263 	if (dcs->d_kind != DK_EXTERN) {
1264 		/* comment ** %s ** must be outside function */
1265 		warning(280, "SCANFLIKE");
1266 		return;
1267 	}
1268 	if (scanflike_argnum != -1) {
1269 		/* duplicate comment ** %s ** */
1270 		warning(281, "SCANFLIKE");
1271 	}
1272 	scanflike_argnum = n;
1273 	scanflike_pos = curr_pos;
1274 }
1275 
1276 /*
1277  * Set the line number for a CONSTCOND comment. At this and the following
1278  * line no warnings about constants in conditional contexts are printed.
1279  */
1280 /* ARGSUSED */
1281 void
1282 constcond(int n)
1283 {
1284 
1285 	constcond_flag = true;
1286 }
1287 
1288 /*
1289  * Suppress printing of "fallthrough on ..." warnings until next
1290  * statement.
1291  */
1292 /* ARGSUSED */
1293 void
1294 fallthru(int n)
1295 {
1296 
1297 	seen_fallthrough = true;
1298 }
1299 
1300 /*
1301  * Stop warnings about statements which cannot be reached. Also tells lint
1302  * that the following statements cannot be reached (e.g. after exit()).
1303  */
1304 /* ARGSUSED */
1305 void
1306 not_reached(int n)
1307 {
1308 
1309 	set_reached(false);
1310 	warn_about_unreachable = false;
1311 }
1312 
1313 /* ARGSUSED */
1314 void
1315 lintlib(int n)
1316 {
1317 
1318 	if (dcs->d_kind != DK_EXTERN) {
1319 		/* comment ** %s ** must be outside function */
1320 		warning(280, "LINTLIBRARY");
1321 		return;
1322 	}
1323 	llibflg = true;
1324 	vflag = false;
1325 }
1326 
1327 /*
1328  * Suppress most warnings at the current and the following line.
1329  */
1330 /* ARGSUSED */
1331 void
1332 linted(int n)
1333 {
1334 
1335 	debug_step("set lwarn %d", n);
1336 	lwarn = n;
1337 }
1338 
1339 /*
1340  * Suppress bitfield type errors on the current line.
1341  */
1342 /* ARGSUSED */
1343 void
1344 bitfieldtype(int n)
1345 {
1346 
1347 	debug_step("%s, %d: bitfieldtype_ok = true",
1348 	    curr_pos.p_file, curr_pos.p_line);
1349 	bitfieldtype_ok = true;
1350 }
1351 
1352 /*
1353  * PROTOLIB in conjunction with LINTLIBRARY can be used to handle
1354  * prototypes like function definitions. This is done if the argument
1355  * to PROTOLIB is nonzero. Otherwise prototypes are handled normally.
1356  */
1357 void
1358 protolib(int n)
1359 {
1360 
1361 	if (dcs->d_kind != DK_EXTERN) {
1362 		/* comment ** %s ** must be outside function */
1363 		warning(280, "PROTOLIB");
1364 		return;
1365 	}
1366 	plibflg = n != 0;
1367 }
1368 
1369 /* The next statement/declaration may use "long long" without a diagnostic. */
1370 /* ARGSUSED */
1371 void
1372 longlong(int n)
1373 {
1374 
1375 	quadflg = true;
1376 }
1377