xref: /netbsd-src/usr.bin/xlint/lint1/func.c (revision f56b29a750628a7095c5912a389a6083a9f727f9)
1 /*	$NetBSD: func.c,v 1.135 2022/04/30 22:31:23 rillig Exp $	*/
2 
3 /*
4  * Copyright (c) 1994, 1995 Jochen Pohl
5  * All Rights Reserved.
6  *
7  * Redistribution and use in source and binary forms, with or without
8  * modification, are permitted provided that the following conditions
9  * are met:
10  * 1. Redistributions of source code must retain the above copyright
11  *    notice, this list of conditions and the following disclaimer.
12  * 2. Redistributions in binary form must reproduce the above copyright
13  *    notice, this list of conditions and the following disclaimer in the
14  *    documentation and/or other materials provided with the distribution.
15  * 3. All advertising materials mentioning features or use of this software
16  *    must display the following acknowledgement:
17  *      This product includes software developed by Jochen Pohl for
18  *	The NetBSD Project.
19  * 4. The name of the author may not be used to endorse or promote products
20  *    derived from this software without specific prior written permission.
21  *
22  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
23  * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
24  * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
25  * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
26  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
27  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
28  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
29  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
30  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
31  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
32  */
33 
34 #if HAVE_NBTOOL_CONFIG_H
35 #include "nbtool_config.h"
36 #endif
37 
38 #include <sys/cdefs.h>
39 #if defined(__RCSID) && !defined(lint)
40 __RCSID("$NetBSD: func.c,v 1.135 2022/04/30 22:31:23 rillig Exp $");
41 #endif
42 
43 #include <stdlib.h>
44 #include <string.h>
45 
46 #include "lint1.h"
47 #include "cgram.h"
48 
49 /*
50  * Contains a pointer to the symbol table entry of the current function
51  * definition.
52  */
53 sym_t	*funcsym;
54 
55 /* Is set as long as a statement can be reached. Must be set at level 0. */
56 bool	reached = true;
57 
58 /*
59  * Is true by default, can be cleared by NOTREACHED.
60  * Is reset to true whenever 'reached' changes.
61  */
62 bool	warn_about_unreachable;
63 
64 /*
65  * In conjunction with 'reached', controls printing of "fallthrough on ..."
66  * warnings.
67  * Reset by each statement and set by FALLTHROUGH, switch (switch1())
68  * and case (label()).
69  *
70  * Control statements if, for, while and switch do not reset seen_fallthrough
71  * because this must be done by the controlled statement. At least for if this
72  * is important because ** FALLTHROUGH ** after "if (expr) statement" is
73  * evaluated before the following token, which causes reduction of above.
74  * This means that ** FALLTHROUGH ** after "if ..." would always be ignored.
75  */
76 bool	seen_fallthrough;
77 
78 /* The innermost control statement */
79 control_statement *cstmt;
80 
81 /*
82  * Number of arguments which will be checked for usage in following
83  * function definition. -1 stands for all arguments.
84  *
85  * The position of the last ARGSUSED comment is stored in argsused_pos.
86  */
87 int	nargusg = -1;
88 pos_t	argsused_pos;
89 
90 /*
91  * Number of arguments of the following function definition whose types
92  * shall be checked by lint2. -1 stands for all arguments.
93  *
94  * The position of the last VARARGS comment is stored in vapos.
95  */
96 int	nvararg = -1;
97 pos_t	vapos;
98 
99 /*
100  * Both printflike_argnum and scanflike_argnum contain the 1-based number
101  * of the string argument which shall be used to check the types of remaining
102  * arguments (for PRINTFLIKE and SCANFLIKE).
103  *
104  * printflike_pos and scanflike_pos are the positions of the last PRINTFLIKE
105  * or SCANFLIKE comment.
106  */
107 int	printflike_argnum = -1;
108 int	scanflike_argnum = -1;
109 pos_t	printflike_pos;
110 pos_t	scanflike_pos;
111 
112 /*
113  * If both plibflg and llibflg are set, prototypes are written as function
114  * definitions to the output file.
115  */
116 bool	plibflg;
117 
118 /*
119  * True means that no warnings about constants in conditional
120  * context are printed.
121  */
122 bool	constcond_flag;
123 
124 /*
125  * llibflg is set if a lint library shall be created. The effect of
126  * llibflg is that all defined symbols are treated as used.
127  * (The LINTLIBRARY comment also resets vflag.)
128  */
129 bool	llibflg;
130 
131 /*
132  * Nonzero if warnings are suppressed by a LINTED directive
133  * LWARN_BAD:	error
134  * LWARN_ALL:	warnings on
135  * LWARN_NONE:	all warnings ignored
136  * 0..n: warning n ignored
137  */
138 int	lwarn = LWARN_ALL;
139 
140 /*
141  * Whether bitfield type errors are suppressed by a BITFIELDTYPE
142  * directive.
143  */
144 bool	bitfieldtype_ok;
145 
146 /*
147  * Whether complaints about use of "long long" are suppressed in
148  * the next statement or declaration.
149  */
150 bool	quadflg;
151 
152 /*
153  * Puts a new element at the top of the stack used for control statements.
154  */
155 void
156 begin_control_statement(control_statement_kind kind)
157 {
158 	control_statement *cs;
159 
160 	cs = xcalloc(1, sizeof(*cs));
161 	cs->c_kind = kind;
162 	cs->c_surrounding = cstmt;
163 	cstmt = cs;
164 }
165 
166 /*
167  * Removes the top element of the stack used for control statements.
168  */
169 void
170 end_control_statement(control_statement_kind kind)
171 {
172 	control_statement *cs;
173 	case_label_t *cl, *next;
174 
175 	lint_assert(cstmt != NULL);
176 
177 	while (cstmt->c_kind != kind)
178 		cstmt = cstmt->c_surrounding;
179 
180 	cs = cstmt;
181 	cstmt = cs->c_surrounding;
182 
183 	for (cl = cs->c_case_labels; cl != NULL; cl = next) {
184 		next = cl->cl_next;
185 		free(cl);
186 	}
187 
188 	free(cs->c_switch_type);
189 	free(cs);
190 }
191 
192 static void
193 set_reached(bool new_reached)
194 {
195 	debug_step("%s -> %s",
196 	    reached ? "reachable" : "unreachable",
197 	    new_reached ? "reachable" : "unreachable");
198 	reached = new_reached;
199 	warn_about_unreachable = true;
200 }
201 
202 /*
203  * Prints a warning if a statement cannot be reached.
204  */
205 void
206 check_statement_reachable(void)
207 {
208 	if (!reached && warn_about_unreachable) {
209 		/* statement not reached */
210 		warning(193);
211 		warn_about_unreachable = false;
212 	}
213 }
214 
215 /*
216  * Called after a function declaration which introduces a function definition
217  * and before an (optional) old style argument declaration list.
218  *
219  * Puts all symbols declared in the prototype or in an old style argument
220  * list back to the symbol table.
221  *
222  * Does the usual checking of storage class, type (return value),
223  * redeclaration, etc.
224  */
225 void
226 funcdef(sym_t *fsym)
227 {
228 	int	n;
229 	bool	dowarn;
230 	sym_t	*arg, *sym, *rdsym;
231 
232 	funcsym = fsym;
233 
234 	/*
235 	 * Put all symbols declared in the argument list back to the
236 	 * symbol table.
237 	 */
238 	for (sym = dcs->d_func_proto_syms; sym != NULL;
239 	    sym = sym->s_level_next) {
240 		if (sym->s_block_level != -1) {
241 			lint_assert(sym->s_block_level == 1);
242 			inssym(1, sym);
243 		}
244 	}
245 
246 	/*
247 	 * In old_style_function() we did not know whether it is an old
248 	 * style function definition or only an old style declaration,
249 	 * if there are no arguments inside the argument list ("f()").
250 	 */
251 	if (!fsym->s_type->t_proto && fsym->u.s_old_style_args == NULL)
252 		fsym->s_osdef = true;
253 
254 	check_type(fsym);
255 
256 	/*
257 	 * check_type() checks for almost all possible errors, but not for
258 	 * incomplete return values (these are allowed in declarations)
259 	 */
260 	if (fsym->s_type->t_subt->t_tspec != VOID &&
261 	    is_incomplete(fsym->s_type->t_subt)) {
262 		/* cannot return incomplete type */
263 		error(67);
264 	}
265 
266 	fsym->s_def = DEF;
267 
268 	if (fsym->s_scl == TYPEDEF) {
269 		fsym->s_scl = EXTERN;
270 		/* illegal storage class */
271 		error(8);
272 	}
273 
274 	if (dcs->d_inline)
275 		fsym->s_inline = true;
276 
277 	/*
278 	 * Arguments in new style function declarations need a name.
279 	 * (void is already removed from the list of arguments)
280 	 */
281 	n = 1;
282 	for (arg = fsym->s_type->t_args; arg != NULL; arg = arg->s_next) {
283 		if (arg->s_scl == ABSTRACT) {
284 			lint_assert(arg->s_name == unnamed);
285 			/* formal parameter lacks name: param #%d */
286 			error(59, n);
287 		} else {
288 			lint_assert(arg->s_name != unnamed);
289 		}
290 		n++;
291 	}
292 
293 	/*
294 	 * We must also remember the position. s_def_pos is overwritten
295 	 * if this is an old style definition and we had already a
296 	 * prototype.
297 	 */
298 	dcs->d_func_def_pos = fsym->s_def_pos;
299 
300 	if ((rdsym = dcs->d_redeclared_symbol) != NULL) {
301 
302 		if (!check_redeclaration(fsym, (dowarn = false, &dowarn))) {
303 
304 			/*
305 			 * Print nothing if the newly defined function
306 			 * is defined in old style. A better warning will
307 			 * be printed in check_func_lint_directives().
308 			 */
309 			if (dowarn && !fsym->s_osdef) {
310 				/* TODO: error in C99 mode as well? */
311 				if (!allow_trad && !allow_c99)
312 					/* redeclaration of %s */
313 					error(27, fsym->s_name);
314 				else
315 					/* redeclaration of %s */
316 					warning(27, fsym->s_name);
317 				print_previous_declaration(-1, rdsym);
318 			}
319 
320 			copy_usage_info(fsym, rdsym);
321 
322 			/*
323 			 * If the old symbol was a prototype and the new
324 			 * one is none, overtake the position of the
325 			 * declaration of the prototype.
326 			 */
327 			if (fsym->s_osdef && rdsym->s_type->t_proto)
328 				fsym->s_def_pos = rdsym->s_def_pos;
329 
330 			complete_type(fsym, rdsym);
331 
332 			if (rdsym->s_inline)
333 				fsym->s_inline = true;
334 
335 		}
336 
337 		/* remove the old symbol from the symbol table */
338 		rmsym(rdsym);
339 
340 	}
341 
342 	if (fsym->s_osdef && !fsym->s_type->t_proto) {
343 		/* TODO: Make this an error in C99 mode as well. */
344 		if ((!allow_trad && !allow_c99) && hflag &&
345 		    strcmp(fsym->s_name, "main") != 0)
346 			/* function definition is not a prototype */
347 			warning(286);
348 	}
349 
350 	if (dcs->d_notyp)
351 		fsym->s_return_type_implicit_int = true;
352 
353 	set_reached(true);
354 }
355 
356 static void
357 check_missing_return_value(void)
358 {
359 	if (funcsym->s_type->t_subt->t_tspec == VOID)
360 		return;
361 	if (funcsym->s_return_type_implicit_int)
362 		return;
363 
364 	/* C99 5.1.2.2.3 "Program termination" p1 */
365 	if (allow_c99 && strcmp(funcsym->s_name, "main") == 0)
366 		return;
367 
368 	/* function %s falls off bottom without returning value */
369 	warning(217, funcsym->s_name);
370 }
371 
372 /*
373  * Called at the end of a function definition.
374  */
375 void
376 funcend(void)
377 {
378 	sym_t	*arg;
379 	int	n;
380 
381 	if (reached) {
382 		cstmt->c_had_return_noval = true;
383 		check_missing_return_value();
384 	}
385 
386 	/*
387 	 * This warning is printed only if the return value was implicitly
388 	 * declared to be int. Otherwise the wrong return statement
389 	 * has already printed a warning.
390 	 */
391 	if (cstmt->c_had_return_noval && cstmt->c_had_return_value &&
392 	    funcsym->s_return_type_implicit_int)
393 		/* function %s has return (e); and return; */
394 		warning(216, funcsym->s_name);
395 
396 	/* Print warnings for unused arguments */
397 	arg = dcs->d_func_args;
398 	n = 0;
399 	while (arg != NULL && (nargusg == -1 || n < nargusg)) {
400 		check_usage_sym(dcs->d_asm, arg);
401 		arg = arg->s_next;
402 		n++;
403 	}
404 	nargusg = -1;
405 
406 	/*
407 	 * write the information about the function definition to the
408 	 * output file
409 	 * inline functions explicitly declared extern are written as
410 	 * declarations only.
411 	 */
412 	if (dcs->d_scl == EXTERN && funcsym->s_inline) {
413 		outsym(funcsym, funcsym->s_scl, DECL);
414 	} else {
415 		outfdef(funcsym, &dcs->d_func_def_pos,
416 		    cstmt->c_had_return_value, funcsym->s_osdef,
417 		    dcs->d_func_args);
418 	}
419 
420 	/* clean up after syntax errors, see test stmt_for.c. */
421 	while (dcs->d_enclosing != NULL)
422 		dcs = dcs->d_enclosing;
423 
424 	/*
425 	 * remove all symbols declared during argument declaration from
426 	 * the symbol table
427 	 */
428 	lint_assert(dcs->d_enclosing == NULL);
429 	lint_assert(dcs->d_kind == DK_EXTERN);
430 	rmsyms(dcs->d_func_proto_syms);
431 
432 	/* must be set on level 0 */
433 	set_reached(true);
434 }
435 
436 void
437 named_label(sym_t *sym)
438 {
439 
440 	if (sym->s_set) {
441 		/* label %s redefined */
442 		error(194, sym->s_name);
443 	} else {
444 		mark_as_set(sym);
445 	}
446 
447 	set_reached(true);
448 }
449 
450 static void
451 check_case_label_bitand(const tnode_t *case_expr, const tnode_t *switch_expr)
452 {
453 	uint64_t case_value, mask;
454 
455 	if (switch_expr->tn_op != BITAND ||
456 	    switch_expr->tn_right->tn_op != CON)
457 		return;
458 
459 	lint_assert(case_expr->tn_op == CON);
460 	case_value = case_expr->tn_val->v_quad;
461 	mask = switch_expr->tn_right->tn_val->v_quad;
462 
463 	if ((case_value & ~mask) != 0) {
464 		/* statement not reached */
465 		warning(193);
466 	}
467 }
468 
469 static void
470 check_case_label_enum(const tnode_t *tn, const control_statement *cs)
471 {
472 	/* similar to typeok_enum in tree.c */
473 
474 	if (!(tn->tn_type->t_is_enum || cs->c_switch_type->t_is_enum))
475 		return;
476 	if (tn->tn_type->t_is_enum && cs->c_switch_type->t_is_enum &&
477 	    tn->tn_type->t_enum == cs->c_switch_type->t_enum)
478 		return;
479 
480 #if 0 /* not yet ready, see msg_130.c */
481 	/* enum type mismatch: '%s' '%s' '%s' */
482 	warning(130, type_name(cs->c_switch_type), op_name(EQ),
483 	    type_name(tn->tn_type));
484 #endif
485 }
486 
487 static void
488 check_case_label(tnode_t *tn, control_statement *cs)
489 {
490 	case_label_t *cl;
491 	val_t	*v;
492 	val_t	nv;
493 	tspec_t	t;
494 
495 	if (cs == NULL) {
496 		/* case not in switch */
497 		error(195);
498 		return;
499 	}
500 
501 	if (tn != NULL && tn->tn_op != CON) {
502 		/* non-constant case expression */
503 		error(197);
504 		return;
505 	}
506 
507 	if (tn != NULL && !is_integer(tn->tn_type->t_tspec)) {
508 		/* non-integral case expression */
509 		error(198);
510 		return;
511 	}
512 
513 	check_case_label_bitand(tn, cs->c_switch_expr);
514 	check_case_label_enum(tn, cs);
515 
516 	lint_assert(cs->c_switch_type != NULL);
517 
518 	if (reached && !seen_fallthrough) {
519 		if (hflag)
520 			/* fallthrough on case statement */
521 			warning(220);
522 	}
523 
524 	t = tn->tn_type->t_tspec;
525 	if (t == LONG || t == ULONG ||
526 	    t == QUAD || t == UQUAD) {
527 		if (!allow_c90)
528 			/* case label must be of type 'int' in traditional C */
529 			warning(203);
530 	}
531 
532 	/*
533 	 * get the value of the expression and convert it
534 	 * to the type of the switch expression
535 	 */
536 	v = constant(tn, true);
537 	(void)memset(&nv, 0, sizeof(nv));
538 	convert_constant(CASE, 0, cs->c_switch_type, &nv, v);
539 	free(v);
540 
541 	/* look if we had this value already */
542 	for (cl = cs->c_case_labels; cl != NULL; cl = cl->cl_next) {
543 		if (cl->cl_val.v_quad == nv.v_quad)
544 			break;
545 	}
546 	if (cl != NULL && is_uinteger(nv.v_tspec)) {
547 		/* duplicate case in switch: %lu */
548 		error(200, (unsigned long)nv.v_quad);
549 	} else if (cl != NULL) {
550 		/* duplicate case in switch: %ld */
551 		error(199, (long)nv.v_quad);
552 	} else {
553 		check_getopt_case_label(nv.v_quad);
554 
555 		/* append the value to the list of case values */
556 		cl = xcalloc(1, sizeof(*cl));
557 		cl->cl_val = nv;
558 		cl->cl_next = cs->c_case_labels;
559 		cs->c_case_labels = cl;
560 	}
561 }
562 
563 void
564 case_label(tnode_t *tn)
565 {
566 	control_statement *cs;
567 
568 	/* find the innermost switch statement */
569 	for (cs = cstmt; cs != NULL && !cs->c_switch; cs = cs->c_surrounding)
570 		continue;
571 
572 	check_case_label(tn, cs);
573 
574 	expr_free_all();
575 
576 	set_reached(true);
577 }
578 
579 void
580 default_label(void)
581 {
582 	control_statement *cs;
583 
584 	/* find the innermost switch statement */
585 	for (cs = cstmt; cs != NULL && !cs->c_switch; cs = cs->c_surrounding)
586 		continue;
587 
588 	if (cs == NULL) {
589 		/* default outside switch */
590 		error(201);
591 	} else if (cs->c_default) {
592 		/* duplicate default in switch */
593 		error(202);
594 	} else {
595 		if (reached && !seen_fallthrough) {
596 			if (hflag)
597 				/* fallthrough on default statement */
598 				warning(284);
599 		}
600 		cs->c_default = true;
601 	}
602 
603 	set_reached(true);
604 }
605 
606 static tnode_t *
607 check_controlling_expression(tnode_t *tn)
608 {
609 
610 	tn = cconv(tn);
611 	if (tn != NULL)
612 		tn = promote(NOOP, false, tn);
613 
614 	if (tn != NULL && !is_scalar(tn->tn_type->t_tspec)) {
615 		/* C99 6.5.15p4 for the ?: operator; see typeok:QUEST */
616 		/* C99 6.8.4.1p1 for if statements */
617 		/* C99 6.8.5p2 for while, do and for loops */
618 		/* controlling expressions must have scalar type */
619 		error(204);
620 		return NULL;
621 	}
622 
623 	if (tn != NULL && Tflag && !is_typeok_bool_operand(tn)) {
624 		/* controlling expression must be bool, not '%s' */
625 		error(333, tspec_name(tn->tn_type->t_tspec));
626 	}
627 
628 	return tn;
629 }
630 
631 /*
632  * T_IF T_LPAREN expr T_RPAREN
633  */
634 void
635 if1(tnode_t *tn)
636 {
637 
638 	if (tn != NULL)
639 		tn = check_controlling_expression(tn);
640 	if (tn != NULL)
641 		expr(tn, false, true, false, false);
642 	begin_control_statement(CS_IF);
643 
644 	if (tn != NULL && tn->tn_op == CON && !tn->tn_system_dependent) {
645 		/* XXX: what if inside 'if (0)'? */
646 		set_reached(constant_is_nonzero(tn));
647 		/* XXX: what about always_else? */
648 		cstmt->c_always_then = reached;
649 	}
650 }
651 
652 /*
653  * if_without_else
654  * if_without_else T_ELSE
655  */
656 void
657 if2(void)
658 {
659 
660 	cstmt->c_reached_end_of_then = reached;
661 	/* XXX: what if inside 'if (0)'? */
662 	set_reached(!cstmt->c_always_then);
663 }
664 
665 /*
666  * if_without_else
667  * if_without_else T_ELSE statement
668  */
669 void
670 if3(bool els)
671 {
672 	if (cstmt->c_reached_end_of_then)
673 		set_reached(true);
674 	else if (cstmt->c_always_then)
675 		set_reached(false);
676 	else if (!els)
677 		set_reached(true);
678 
679 	end_control_statement(CS_IF);
680 }
681 
682 /*
683  * T_SWITCH T_LPAREN expr T_RPAREN
684  */
685 void
686 switch1(tnode_t *tn)
687 {
688 	tspec_t	t;
689 	type_t	*tp;
690 
691 	if (tn != NULL)
692 		tn = cconv(tn);
693 	if (tn != NULL)
694 		tn = promote(NOOP, false, tn);
695 	if (tn != NULL && !is_integer(tn->tn_type->t_tspec)) {
696 		/* switch expression must have integral type */
697 		error(205);
698 		tn = NULL;
699 	}
700 	if (tn != NULL && !allow_c90) {
701 		t = tn->tn_type->t_tspec;
702 		if (t == LONG || t == ULONG || t == QUAD || t == UQUAD) {
703 			/* switch expression must be of type 'int' in ... */
704 			warning(271);
705 		}
706 	}
707 
708 	/*
709 	 * Remember the type of the expression. Because it's possible
710 	 * that (*tp) is allocated on tree memory, the type must be
711 	 * duplicated. This is not too complicated because it is
712 	 * only an integer type.
713 	 */
714 	tp = xcalloc(1, sizeof(*tp));
715 	if (tn != NULL) {
716 		tp->t_tspec = tn->tn_type->t_tspec;
717 		if ((tp->t_is_enum = tn->tn_type->t_is_enum) != false)
718 			tp->t_enum = tn->tn_type->t_enum;
719 	} else {
720 		tp->t_tspec = INT;
721 	}
722 
723 	/* leak the memory, for check_case_label_bitand */
724 	(void)expr_save_memory();
725 
726 	check_getopt_begin_switch();
727 	expr(tn, true, false, false, false);
728 
729 	begin_control_statement(CS_SWITCH);
730 	cstmt->c_switch = true;
731 	cstmt->c_switch_type = tp;
732 	cstmt->c_switch_expr = tn;
733 
734 	set_reached(false);
735 	seen_fallthrough = true;
736 }
737 
738 /*
739  * switch_expr statement
740  */
741 void
742 switch2(void)
743 {
744 	int	nenum = 0, nclab = 0;
745 	sym_t	*esym;
746 	case_label_t *cl;
747 
748 	lint_assert(cstmt->c_switch_type != NULL);
749 
750 	if (cstmt->c_switch_type->t_is_enum) {
751 		/*
752 		 * Warn if the number of case labels is different from the
753 		 * number of enumerators.
754 		 */
755 		nenum = nclab = 0;
756 		lint_assert(cstmt->c_switch_type->t_enum != NULL);
757 		for (esym = cstmt->c_switch_type->t_enum->en_first_enumerator;
758 		     esym != NULL; esym = esym->s_next) {
759 			nenum++;
760 		}
761 		for (cl = cstmt->c_case_labels; cl != NULL; cl = cl->cl_next)
762 			nclab++;
763 		if (hflag && eflag && nenum != nclab && !cstmt->c_default) {
764 			/* enumeration value(s) not handled in switch */
765 			warning(206);
766 		}
767 	}
768 
769 	check_getopt_end_switch();
770 
771 	if (cstmt->c_break) {
772 		/*
773 		 * The end of the switch statement is always reached since
774 		 * c_break is only set if a break statement can actually
775 		 * be reached.
776 		 */
777 		set_reached(true);
778 	} else if (cstmt->c_default ||
779 		   (hflag && cstmt->c_switch_type->t_is_enum &&
780 		    nenum == nclab)) {
781 		/*
782 		 * The end of the switch statement is reached if the end
783 		 * of the last statement inside it is reached.
784 		 */
785 	} else {
786 		/*
787 		 * There are possible values that are not handled in the
788 		 * switch statement.
789 		 */
790 		set_reached(true);
791 	}
792 
793 	end_control_statement(CS_SWITCH);
794 }
795 
796 /*
797  * T_WHILE T_LPAREN expr T_RPAREN
798  */
799 void
800 while1(tnode_t *tn)
801 {
802 	bool body_reached;
803 
804 	if (!reached) {
805 		/* loop not entered at top */
806 		warning(207);
807 		/* FIXME: that's plain wrong. */
808 		set_reached(true);
809 	}
810 
811 	if (tn != NULL)
812 		tn = check_controlling_expression(tn);
813 
814 	begin_control_statement(CS_WHILE);
815 	cstmt->c_loop = true;
816 	cstmt->c_maybe_endless = is_nonzero(tn);
817 	body_reached = !is_zero(tn);
818 
819 	check_getopt_begin_while(tn);
820 	expr(tn, false, true, true, false);
821 
822 	set_reached(body_reached);
823 }
824 
825 /*
826  * while_expr statement
827  * while_expr error
828  */
829 void
830 while2(void)
831 {
832 
833 	/*
834 	 * The end of the loop can be reached if it is no endless loop
835 	 * or there was a break statement which was reached.
836 	 */
837 	set_reached(!cstmt->c_maybe_endless || cstmt->c_break);
838 
839 	check_getopt_end_while();
840 	end_control_statement(CS_WHILE);
841 }
842 
843 /*
844  * T_DO
845  */
846 void
847 do1(void)
848 {
849 
850 	if (!reached) {
851 		/* loop not entered at top */
852 		warning(207);
853 		set_reached(true);
854 	}
855 
856 	begin_control_statement(CS_DO_WHILE);
857 	cstmt->c_loop = true;
858 }
859 
860 /*
861  * do statement do_while_expr
862  * do error
863  */
864 void
865 do2(tnode_t *tn)
866 {
867 
868 	/*
869 	 * If there was a continue statement, the expression controlling the
870 	 * loop is reached.
871 	 */
872 	if (cstmt->c_continue)
873 		set_reached(true);
874 
875 	if (tn != NULL)
876 		tn = check_controlling_expression(tn);
877 
878 	if (tn != NULL && tn->tn_op == CON) {
879 		cstmt->c_maybe_endless = constant_is_nonzero(tn);
880 		if (!cstmt->c_maybe_endless && cstmt->c_continue)
881 			/* continue in 'do ... while (0)' loop */
882 			error(323);
883 	}
884 
885 	expr(tn, false, true, true, true);
886 
887 	if (cstmt->c_maybe_endless)
888 		set_reached(false);
889 	if (cstmt->c_break)
890 		set_reached(true);
891 
892 	end_control_statement(CS_DO_WHILE);
893 }
894 
895 /*
896  * T_FOR T_LPAREN opt_expr T_SEMI opt_expr T_SEMI opt_expr T_RPAREN
897  */
898 void
899 for1(tnode_t *tn1, tnode_t *tn2, tnode_t *tn3)
900 {
901 
902 	/*
903 	 * If there is no initialization expression it is possible that
904 	 * it is intended not to enter the loop at top.
905 	 */
906 	if (tn1 != NULL && !reached) {
907 		/* loop not entered at top */
908 		warning(207);
909 		set_reached(true);
910 	}
911 
912 	begin_control_statement(CS_FOR);
913 	cstmt->c_loop = true;
914 
915 	/*
916 	 * Store the tree memory for the reinitialization expression.
917 	 * Also remember this expression itself. We must check it at
918 	 * the end of the loop to get "used but not set" warnings correct.
919 	 */
920 	cstmt->c_for_expr3_mem = expr_save_memory();
921 	cstmt->c_for_expr3 = tn3;
922 	cstmt->c_for_expr3_pos = curr_pos;
923 	cstmt->c_for_expr3_csrc_pos = csrc_pos;
924 
925 	if (tn1 != NULL)
926 		expr(tn1, false, false, true, false);
927 
928 	if (tn2 != NULL)
929 		tn2 = check_controlling_expression(tn2);
930 	if (tn2 != NULL)
931 		expr(tn2, false, true, true, false);
932 
933 	cstmt->c_maybe_endless = tn2 == NULL || is_nonzero(tn2);
934 
935 	/* Checking the reinitialization expression is done in for2() */
936 
937 	set_reached(!is_zero(tn2));
938 }
939 
940 /*
941  * for_exprs statement
942  * for_exprs error
943  */
944 void
945 for2(void)
946 {
947 	pos_t	cpos, cspos;
948 	tnode_t	*tn3;
949 
950 	if (cstmt->c_continue)
951 		set_reached(true);
952 
953 	cpos = curr_pos;
954 	cspos = csrc_pos;
955 
956 	/* Restore the tree memory for the reinitialization expression */
957 	expr_restore_memory(cstmt->c_for_expr3_mem);
958 	tn3 = cstmt->c_for_expr3;
959 	curr_pos = cstmt->c_for_expr3_pos;
960 	csrc_pos = cstmt->c_for_expr3_csrc_pos;
961 
962 	/* simply "statement not reached" would be confusing */
963 	if (!reached && warn_about_unreachable) {
964 		/* end-of-loop code not reached */
965 		warning(223);
966 		set_reached(true);
967 	}
968 
969 	if (tn3 != NULL) {
970 		expr(tn3, false, false, true, false);
971 	} else {
972 		expr_free_all();
973 	}
974 
975 	curr_pos = cpos;
976 	csrc_pos = cspos;
977 
978 	/* An endless loop without break will never terminate */
979 	/* TODO: What if the loop contains a 'return'? */
980 	set_reached(cstmt->c_break || !cstmt->c_maybe_endless);
981 
982 	end_control_statement(CS_FOR);
983 }
984 
985 /*
986  * T_GOTO identifier T_SEMI
987  */
988 void
989 do_goto(sym_t *lab)
990 {
991 
992 	mark_as_used(lab, false, false);
993 
994 	check_statement_reachable();
995 
996 	set_reached(false);
997 }
998 
999 /*
1000  * T_BREAK T_SEMI
1001  */
1002 void
1003 do_break(void)
1004 {
1005 	control_statement *cs;
1006 
1007 	cs = cstmt;
1008 	while (cs != NULL && !cs->c_loop && !cs->c_switch)
1009 		cs = cs->c_surrounding;
1010 
1011 	if (cs == NULL) {
1012 		/* break outside loop or switch */
1013 		error(208);
1014 	} else {
1015 		if (reached)
1016 			cs->c_break = true;
1017 	}
1018 
1019 	if (bflag)
1020 		check_statement_reachable();
1021 
1022 	set_reached(false);
1023 }
1024 
1025 /*
1026  * T_CONTINUE T_SEMI
1027  */
1028 void
1029 do_continue(void)
1030 {
1031 	control_statement *cs;
1032 
1033 	for (cs = cstmt; cs != NULL && !cs->c_loop; cs = cs->c_surrounding)
1034 		continue;
1035 
1036 	if (cs == NULL) {
1037 		/* continue outside loop */
1038 		error(209);
1039 	} else {
1040 		/* TODO: only if reachable, for symmetry with c_break */
1041 		cs->c_continue = true;
1042 	}
1043 
1044 	check_statement_reachable();
1045 
1046 	set_reached(false);
1047 }
1048 
1049 /*
1050  * T_RETURN T_SEMI
1051  * T_RETURN expr T_SEMI
1052  */
1053 void
1054 do_return(bool sys, tnode_t *tn)
1055 {
1056 	tnode_t	*ln, *rn;
1057 	control_statement *cs;
1058 	op_t	op;
1059 
1060 	cs = cstmt;
1061 	if (cs == NULL) {
1062 		/* syntax error '%s' */
1063 		error(249, "return outside function");
1064 		return;
1065 	}
1066 
1067 	for (; cs->c_surrounding != NULL; cs = cs->c_surrounding)
1068 		continue;
1069 
1070 	if (tn != NULL)
1071 		cs->c_had_return_value = true;
1072 	else
1073 		cs->c_had_return_noval = true;
1074 
1075 	if (tn != NULL && funcsym->s_type->t_subt->t_tspec == VOID) {
1076 		/* void function %s cannot return value */
1077 		error(213, funcsym->s_name);
1078 		expr_free_all();
1079 		tn = NULL;
1080 	} else if (tn == NULL && funcsym->s_type->t_subt->t_tspec != VOID) {
1081 		/*
1082 		 * Assume that the function has a return value only if it
1083 		 * is explicitly declared.
1084 		 */
1085 		if (!funcsym->s_return_type_implicit_int)
1086 			/* function '%s' expects to return value */
1087 			warning(214, funcsym->s_name);
1088 	}
1089 
1090 	if (tn != NULL) {
1091 
1092 		/* Create a temporary node for the left side */
1093 		ln = expr_zero_alloc(sizeof(*ln));
1094 		ln->tn_op = NAME;
1095 		ln->tn_type = expr_unqualified_type(funcsym->s_type->t_subt);
1096 		ln->tn_lvalue = true;
1097 		ln->tn_sym = funcsym;		/* better than nothing */
1098 
1099 		tn = build_binary(ln, RETURN, sys, tn);
1100 
1101 		if (tn != NULL) {
1102 			rn = tn->tn_right;
1103 			while ((op = rn->tn_op) == CVT || op == PLUS)
1104 				rn = rn->tn_left;
1105 			if (rn->tn_op == ADDR && rn->tn_left->tn_op == NAME &&
1106 			    rn->tn_left->tn_sym->s_scl == AUTO) {
1107 				/* %s returns pointer to automatic object */
1108 				warning(302, funcsym->s_name);
1109 			}
1110 		}
1111 
1112 		expr(tn, true, false, true, false);
1113 
1114 	} else {
1115 
1116 		check_statement_reachable();
1117 
1118 	}
1119 
1120 	set_reached(false);
1121 }
1122 
1123 /*
1124  * Do some cleanup after a global declaration or definition.
1125  * Especially remove information about unused lint comments.
1126  */
1127 void
1128 global_clean_up_decl(bool silent)
1129 {
1130 
1131 	if (nargusg != -1) {
1132 		if (!silent) {
1133 			/* must precede function definition: ** %s ** */
1134 			warning_at(282, &argsused_pos, "ARGSUSED");
1135 		}
1136 		nargusg = -1;
1137 	}
1138 	if (nvararg != -1) {
1139 		if (!silent) {
1140 			/* must precede function definition: ** %s ** */
1141 			warning_at(282, &vapos, "VARARGS");
1142 		}
1143 		nvararg = -1;
1144 	}
1145 	if (printflike_argnum != -1) {
1146 		if (!silent) {
1147 			/* must precede function definition: ** %s ** */
1148 			warning_at(282, &printflike_pos, "PRINTFLIKE");
1149 		}
1150 		printflike_argnum = -1;
1151 	}
1152 	if (scanflike_argnum != -1) {
1153 		if (!silent) {
1154 			/* must precede function definition: ** %s ** */
1155 			warning_at(282, &scanflike_pos, "SCANFLIKE");
1156 		}
1157 		scanflike_argnum = -1;
1158 	}
1159 
1160 	dcs->d_asm = false;
1161 
1162 	/*
1163 	 * Needed for BSD yacc in case of parse errors; GNU Bison 3.0.4 is
1164 	 * fine.  See test gcc_attribute.c, function_with_unknown_attribute.
1165 	 */
1166 	in_gcc_attribute = false;
1167 	while (dcs->d_enclosing != NULL)
1168 		end_declaration_level();
1169 }
1170 
1171 /*
1172  * ARGSUSED comment
1173  *
1174  * Only the first n arguments of the following function are checked
1175  * for usage. A missing argument is taken to be 0.
1176  */
1177 void
1178 argsused(int n)
1179 {
1180 
1181 	if (n == -1)
1182 		n = 0;
1183 
1184 	if (dcs->d_kind != DK_EXTERN) {
1185 		/* must be outside function: ** %s ** */
1186 		warning(280, "ARGSUSED");
1187 		return;
1188 	}
1189 	if (nargusg != -1) {
1190 		/* duplicate use of ** %s ** */
1191 		warning(281, "ARGSUSED");
1192 	}
1193 	nargusg = n;
1194 	argsused_pos = curr_pos;
1195 }
1196 
1197 /*
1198  * VARARGS comment
1199  *
1200  * Causes lint2 to check only the first n arguments for compatibility
1201  * with the function definition. A missing argument is taken to be 0.
1202  */
1203 void
1204 varargs(int n)
1205 {
1206 
1207 	if (n == -1)
1208 		n = 0;
1209 
1210 	if (dcs->d_kind != DK_EXTERN) {
1211 		/* must be outside function: ** %s ** */
1212 		warning(280, "VARARGS");
1213 		return;
1214 	}
1215 	if (nvararg != -1) {
1216 		/* duplicate use of ** %s ** */
1217 		warning(281, "VARARGS");
1218 	}
1219 	nvararg = n;
1220 	vapos = curr_pos;
1221 }
1222 
1223 /*
1224  * PRINTFLIKE comment
1225  *
1226  * Check all arguments until the (n-1)-th as usual. The n-th argument is
1227  * used the check the types of remaining arguments.
1228  */
1229 void
1230 printflike(int n)
1231 {
1232 
1233 	if (n == -1)
1234 		n = 0;
1235 
1236 	if (dcs->d_kind != DK_EXTERN) {
1237 		/* must be outside function: ** %s ** */
1238 		warning(280, "PRINTFLIKE");
1239 		return;
1240 	}
1241 	if (printflike_argnum != -1) {
1242 		/* duplicate use of ** %s ** */
1243 		warning(281, "PRINTFLIKE");
1244 	}
1245 	printflike_argnum = n;
1246 	printflike_pos = curr_pos;
1247 }
1248 
1249 /*
1250  * SCANFLIKE comment
1251  *
1252  * Check all arguments until the (n-1)-th as usual. The n-th argument is
1253  * used the check the types of remaining arguments.
1254  */
1255 void
1256 scanflike(int n)
1257 {
1258 
1259 	if (n == -1)
1260 		n = 0;
1261 
1262 	if (dcs->d_kind != DK_EXTERN) {
1263 		/* must be outside function: ** %s ** */
1264 		warning(280, "SCANFLIKE");
1265 		return;
1266 	}
1267 	if (scanflike_argnum != -1) {
1268 		/* duplicate use of ** %s ** */
1269 		warning(281, "SCANFLIKE");
1270 	}
1271 	scanflike_argnum = n;
1272 	scanflike_pos = curr_pos;
1273 }
1274 
1275 /*
1276  * Set the line number for a CONSTCOND comment. At this and the following
1277  * line no warnings about constants in conditional contexts are printed.
1278  */
1279 /* ARGSUSED */
1280 void
1281 constcond(int n)
1282 {
1283 
1284 	constcond_flag = true;
1285 }
1286 
1287 /*
1288  * Suppress printing of "fallthrough on ..." warnings until next
1289  * statement.
1290  */
1291 /* ARGSUSED */
1292 void
1293 fallthru(int n)
1294 {
1295 
1296 	seen_fallthrough = true;
1297 }
1298 
1299 /*
1300  * Stop warnings about statements which cannot be reached. Also tells lint
1301  * that the following statements cannot be reached (e.g. after exit()).
1302  */
1303 /* ARGSUSED */
1304 void
1305 not_reached(int n)
1306 {
1307 
1308 	set_reached(false);
1309 	warn_about_unreachable = false;
1310 }
1311 
1312 /* ARGSUSED */
1313 void
1314 lintlib(int n)
1315 {
1316 
1317 	if (dcs->d_kind != DK_EXTERN) {
1318 		/* must be outside function: ** %s ** */
1319 		warning(280, "LINTLIBRARY");
1320 		return;
1321 	}
1322 	llibflg = true;
1323 	vflag = false;
1324 }
1325 
1326 /*
1327  * Suppress most warnings at the current and the following line.
1328  */
1329 /* ARGSUSED */
1330 void
1331 linted(int n)
1332 {
1333 
1334 	debug_step("set lwarn %d", n);
1335 	lwarn = n;
1336 }
1337 
1338 /*
1339  * Suppress bitfield type errors on the current line.
1340  */
1341 /* ARGSUSED */
1342 void
1343 bitfieldtype(int n)
1344 {
1345 
1346 	debug_step("%s, %d: bitfieldtype_ok = true",
1347 	    curr_pos.p_file, curr_pos.p_line);
1348 	bitfieldtype_ok = true;
1349 }
1350 
1351 /*
1352  * PROTOLIB in conjunction with LINTLIBRARY can be used to handle
1353  * prototypes like function definitions. This is done if the argument
1354  * to PROTOLIB is nonzero. Otherwise prototypes are handled normally.
1355  */
1356 void
1357 protolib(int n)
1358 {
1359 
1360 	if (dcs->d_kind != DK_EXTERN) {
1361 		/* must be outside function: ** %s ** */
1362 		warning(280, "PROTOLIB");
1363 		return;
1364 	}
1365 	plibflg = n != 0;
1366 }
1367 
1368 /* The next statement/declaration may use "long long" without a diagnostic. */
1369 /* ARGSUSED */
1370 void
1371 longlong(int n)
1372 {
1373 
1374 	quadflg = true;
1375 }
1376