1 /* $NetBSD: chk.c,v 1.60 2023/07/13 08:40:38 rillig Exp $ */ 2 3 /* 4 * Copyright (c) 1996 Christopher G. Demetriou. All Rights Reserved. 5 * Copyright (c) 1994, 1995 Jochen Pohl 6 * All Rights Reserved. 7 * 8 * Redistribution and use in source and binary forms, with or without 9 * modification, are permitted provided that the following conditions 10 * are met: 11 * 1. Redistributions of source code must retain the above copyright 12 * notice, this list of conditions and the following disclaimer. 13 * 2. Redistributions in binary form must reproduce the above copyright 14 * notice, this list of conditions and the following disclaimer in the 15 * documentation and/or other materials provided with the distribution. 16 * 3. All advertising materials mentioning features or use of this software 17 * must display the following acknowledgement: 18 * This product includes software developed by Jochen Pohl for 19 * The NetBSD Project. 20 * 4. The name of the author may not be used to endorse or promote products 21 * derived from this software without specific prior written permission. 22 * 23 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR 24 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES 25 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. 26 * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, 27 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT 28 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, 29 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY 30 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT 31 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF 32 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 33 */ 34 35 #if HAVE_NBTOOL_CONFIG_H 36 #include "nbtool_config.h" 37 #endif 38 39 #include <sys/cdefs.h> 40 #if defined(__RCSID) 41 __RCSID("$NetBSD: chk.c,v 1.60 2023/07/13 08:40:38 rillig Exp $"); 42 #endif 43 44 #include <ctype.h> 45 #include <limits.h> 46 #include <stdlib.h> 47 #include <string.h> 48 49 #include "lint2.h" 50 51 static void check_used_not_defined(const hte_t *); 52 static void check_defined_not_used(const hte_t *); 53 static void check_declared_not_used_or_defined(const hte_t *); 54 static void check_multiple_definitions(const hte_t *); 55 static void chkvtui(const hte_t *, sym_t *, sym_t *); 56 static void chkvtdi(const hte_t *, sym_t *, sym_t *); 57 static void chkfaui(const hte_t *, sym_t *, sym_t *); 58 static void chkau(const hte_t *, int, sym_t *, sym_t *, pos_t *, 59 fcall_t *, fcall_t *, type_t *, type_t *); 60 static void check_return_values(const hte_t *, sym_t *); 61 static void check_argument_declarations(const hte_t *, sym_t *, sym_t *); 62 static void printflike(const hte_t *, fcall_t *, int, const char *, type_t **); 63 static void scanflike(const hte_t *, fcall_t *, int, const char *, type_t **); 64 static void bad_format_string(const hte_t *, fcall_t *); 65 static void inconsistent_arguments(const hte_t *, fcall_t *, int); 66 static void too_few_arguments(const hte_t *, fcall_t *); 67 static void too_many_arguments(const hte_t *, fcall_t *); 68 static bool types_compatible(type_t *, type_t *, bool, bool, bool, bool *); 69 static bool prototypes_compatible(type_t *, type_t *, bool *); 70 static bool matches_no_arg_function(type_t *, bool *); 71 72 73 /* 74 * If there is a symbol named "main", mark it as used. 75 */ 76 void 77 mark_main_as_used(void) 78 { 79 hte_t *hte; 80 81 if ((hte = htab_search("main", false)) != NULL) 82 hte->h_used = true; 83 } 84 85 /* 86 * Performs all tests for a single name 87 */ 88 void 89 check_name(const hte_t *hte) 90 { 91 sym_t *sym, *def, *pdecl, *decl; 92 93 if (!uflag) { 94 check_used_not_defined(hte); 95 check_defined_not_used(hte); 96 if (xflag) 97 check_declared_not_used_or_defined(hte); 98 } 99 check_multiple_definitions(hte); 100 101 /* Get definition, prototype declaration and declaration */ 102 def = pdecl = decl = NULL; 103 for (sym = hte->h_syms; sym != NULL; sym = sym->s_next) { 104 if (def == NULL && (sym->s_def == DEF || sym->s_def == TDEF)) 105 def = sym; 106 if (pdecl == NULL && sym->s_def == DECL && 107 TP(sym->s_type)->t_tspec == FUNC && 108 TP(sym->s_type)->t_proto) { 109 pdecl = sym; 110 } 111 if (decl == NULL && sym->s_def == DECL) 112 decl = sym; 113 } 114 115 /* A prototype is better than an old-style declaration. */ 116 if (pdecl != NULL) 117 decl = pdecl; 118 119 chkvtui(hte, def, decl); 120 121 chkvtdi(hte, def, decl); 122 123 chkfaui(hte, def, decl); 124 125 check_return_values(hte, def); 126 127 check_argument_declarations(hte, def, decl); 128 } 129 130 /* 131 * Print a warning if the name has been used, but not defined. 132 */ 133 static void 134 check_used_not_defined(const hte_t *hte) 135 { 136 fcall_t *fcall; 137 usym_t *usym; 138 139 if (!hte->h_used || hte->h_def) 140 return; 141 142 if ((fcall = hte->h_calls) != NULL) { 143 /* %s used( %s ), but not defined */ 144 msg(0, hte->h_name, mkpos(&fcall->f_pos)); 145 } else if ((usym = hte->h_usyms) != NULL) { 146 /* %s used( %s ), but not defined */ 147 msg(0, hte->h_name, mkpos(&usym->u_pos)); 148 } 149 } 150 151 /* 152 * Print a warning if the name has been defined, but never used. 153 */ 154 static void 155 check_defined_not_used(const hte_t *hte) 156 { 157 sym_t *sym; 158 159 if (!hte->h_def || hte->h_used) 160 return; 161 162 for (sym = hte->h_syms; sym != NULL; sym = sym->s_next) { 163 if (sym->s_def == DEF || sym->s_def == TDEF) { 164 /* %s defined( %s ), but never used */ 165 msg(1, hte->h_name, mkpos(&sym->s_pos)); 166 break; 167 } 168 } 169 } 170 171 /* 172 * Print a warning if the variable has been declared, but is not used 173 * or defined. 174 */ 175 static void 176 check_declared_not_used_or_defined(const hte_t *hte) 177 { 178 sym_t *sym; 179 180 if (hte->h_syms == NULL || hte->h_used || hte->h_def) 181 return; 182 183 sym = hte->h_syms; 184 if (TP(sym->s_type)->t_tspec == FUNC) 185 return; 186 187 if (sym->s_def != DECL) 188 errx(1, "internal error: check_declared_not_used_or_defined"); 189 /* %s declared( %s ), but never used or defined */ 190 msg(2, hte->h_name, mkpos(&sym->s_pos)); 191 } 192 193 /* 194 * Print a warning if there is more than one definition for 195 * this name. 196 */ 197 static void 198 check_multiple_definitions(const hte_t *hte) 199 { 200 sym_t *sym, *def1; 201 202 if (!hte->h_def) 203 return; 204 205 def1 = NULL; 206 for (sym = hte->h_syms; sym != NULL; sym = sym->s_next) { 207 /* 208 * ANSI C allows tentative definitions of the same name in 209 * only one compilation unit. 210 */ 211 if (sym->s_def != DEF && (!sflag || sym->s_def != TDEF)) 212 continue; 213 if (sym->s_inline) 214 continue; 215 if (def1 == NULL) { 216 def1 = sym; 217 continue; 218 } 219 /* %s multiply defined \t%s :: %s */ 220 msg(3, hte->h_name, mkpos(&def1->s_pos), mkpos(&sym->s_pos)); 221 } 222 } 223 224 /* 225 * Print a warning if the return value assumed for a function call 226 * differs from the return value of the function definition or 227 * function declaration. 228 * 229 * If no definition/declaration can be found, the assumed return values 230 * are always int. So there is no need to compare with another function 231 * call as it's done for function arguments. 232 */ 233 static void 234 chkvtui(const hte_t *hte, sym_t *def, sym_t *decl) 235 { 236 fcall_t *call; 237 type_t *tp1, *tp2; 238 bool dowarn, eq; 239 tspec_t t1; 240 241 if (hte->h_calls == NULL) 242 return; 243 244 if (def == NULL) 245 def = decl; 246 if (def == NULL) 247 return; 248 249 t1 = (tp1 = TP(def->s_type)->t_subt)->t_tspec; 250 for (call = hte->h_calls; call != NULL; call = call->f_next) { 251 tp2 = TP(call->f_type)->t_subt; 252 eq = types_compatible(tp1, tp2, 253 true, false, false, (dowarn = false, &dowarn)); 254 if (!call->f_rused) { 255 /* no return value used */ 256 if ((t1 == STRUCT || t1 == UNION) && !eq) { 257 /* 258 * If a function returns a struct or union it 259 * must be declared to return a struct or 260 * union, also if the return value is ignored. 261 * This is necessary because the caller must 262 * allocate stack space for the return value. 263 * If it does not, the return value would 264 * overwrite other data. 265 * 266 * XXX Following message may be confusing 267 * because it appears also if the return value 268 * was declared inconsistently. But this 269 * behavior matches pcc-based lint, so it is 270 * accepted for now. 271 */ 272 /* %s function value must be declared ... */ 273 msg(17, hte->h_name, 274 mkpos(&def->s_pos), mkpos(&call->f_pos)); 275 } 276 continue; 277 } 278 if (!eq || (sflag && dowarn)) { 279 /* %s value used inconsistently \t%s :: %s */ 280 msg(4, hte->h_name, 281 mkpos(&def->s_pos), mkpos(&call->f_pos)); 282 } 283 } 284 } 285 286 /* 287 * Print a warning if a definition/declaration does not match another 288 * definition/declaration of the same name. For functions, only the 289 * types of return values are tested. 290 */ 291 static void 292 chkvtdi(const hte_t *hte, sym_t *def, sym_t *decl) 293 { 294 sym_t *sym; 295 type_t *tp1, *tp2; 296 bool eq, dowarn; 297 298 if (def == NULL) 299 def = decl; 300 if (def == NULL) 301 return; 302 303 tp1 = TP(def->s_type); 304 for (sym = hte->h_syms; sym != NULL; sym = sym->s_next) { 305 type_t *xt1, *xt2; 306 if (sym == def) 307 continue; 308 tp2 = TP(sym->s_type); 309 dowarn = false; 310 if (tp1->t_tspec == FUNC && tp2->t_tspec == FUNC) { 311 eq = types_compatible(xt1 = tp1->t_subt, 312 xt2 = tp2->t_subt, true, false, false, &dowarn); 313 } else { 314 eq = types_compatible(xt1 = tp1, xt2 = tp2, 315 false, false, false, &dowarn); 316 } 317 if (!eq || (sflag && dowarn)) { 318 /* %s value declared inconsistently (%s != %s) \t... */ 319 msg(5, hte->h_name, type_name(xt1), type_name(xt2), 320 mkpos(&def->s_pos), mkpos(&sym->s_pos)); 321 } 322 } 323 } 324 325 /* 326 * Print a warning if a function is called with arguments which does 327 * not match the function definition, declaration or another call 328 * of the same function. 329 */ 330 static void 331 chkfaui(const hte_t *hte, sym_t *def, sym_t *decl) 332 { 333 type_t *tp1, *tp2, **ap1, **ap2; 334 pos_t *pos1p = NULL; 335 fcall_t *calls, *call, *call1; 336 int n, as; 337 arginf_t *ai; 338 339 if ((calls = hte->h_calls) == NULL) 340 return; 341 342 /* 343 * If we find a function definition, we use this for comparison, 344 * otherwise the first prototype we can find. If there is no 345 * definition or prototype declaration, the first function call 346 * is used. 347 */ 348 tp1 = NULL; 349 call1 = NULL; 350 if (def != NULL) { 351 if ((tp1 = TP(def->s_type))->t_tspec != FUNC) 352 return; 353 pos1p = &def->s_pos; 354 } else if (decl != NULL && TP(decl->s_type)->t_proto) { 355 if ((tp1 = TP(decl->s_type))->t_tspec != FUNC) 356 return; 357 pos1p = &decl->s_pos; 358 } 359 if (tp1 == NULL) { 360 call1 = calls; 361 calls = calls->f_next; 362 if ((tp1 = TP(call1->f_type))->t_tspec != FUNC) 363 return; 364 pos1p = &call1->f_pos; 365 } 366 367 n = 1; 368 for (call = calls; call != NULL; call = call->f_next) { 369 if ((tp2 = TP(call->f_type))->t_tspec != FUNC) 370 continue; 371 ap1 = tp1->t_args; 372 ap2 = tp2->t_args; 373 n = 0; 374 while (*ap1 != NULL && *ap2 != NULL) { 375 if (def != NULL && def->s_check_only_first_args && 376 n >= def->s_check_num_args) 377 break; 378 n++; 379 chkau(hte, n, def, decl, pos1p, call1, call, 380 *ap1, *ap2); 381 ap1++; 382 ap2++; 383 } 384 if (*ap1 == *ap2) { 385 /* equal # of arguments */ 386 } else if (def != NULL && def->s_check_only_first_args && 387 n >= def->s_check_num_args) { 388 /* 389 * function definition with VARARGS; The # of 390 * arguments of the call must be at least as large 391 * as the parameter of VARARGS. 392 */ 393 } else if (*ap2 != NULL && tp1->t_proto && tp1->t_vararg) { 394 /* 395 * prototype with ... and function call with 396 * at least the same # of arguments as declared 397 * in the prototype. 398 */ 399 } else { 400 /* %s: variable # of args \t%s :: %s */ 401 msg(7, hte->h_name, mkpos(pos1p), mkpos(&call->f_pos)); 402 continue; 403 } 404 405 /* perform SCANFLIKE/PRINTFLIKE tests */ 406 if (def == NULL || (!def->s_printflike && !def->s_scanflike)) 407 continue; 408 as = def->s_printflike 409 ? def->s_printflike_arg 410 : def->s_scanflike_arg; 411 for (ai = call->f_args; ai != NULL; ai = ai->a_next) { 412 if (ai->a_num == as) 413 break; 414 } 415 if (ai == NULL || !ai->a_fmt) 416 continue; 417 if (def->s_printflike) { 418 printflike(hte, call, n, ai->a_fstrg, ap2); 419 } else { 420 scanflike(hte, call, n, ai->a_fstrg, ap2); 421 } 422 } 423 } 424 425 /* 426 * Check a single argument in a function call. 427 * 428 * hte a pointer to the hash table entry of the function 429 * n the number of the argument (1..) 430 * def the function definition or NULL 431 * decl prototype declaration, old-style declaration or NULL 432 * pos1p position of definition, declaration of first call 433 * call1 first call, if both def and decl are old-style def/decl 434 * call checked call 435 * arg1 currently checked argument of def/decl/call1 436 * arg2 currently checked argument of call 437 * 438 */ 439 static void 440 chkau(const hte_t *hte, int n, sym_t *def, sym_t *decl, pos_t *pos1p, 441 fcall_t *call1, fcall_t *call, type_t *arg1, type_t *arg2) 442 { 443 bool promote, asgn, dowarn; 444 tspec_t t1, t2; 445 arginf_t *ai, *ai1; 446 447 /* 448 * If a function definition is available (def != NULL), we compare the 449 * function call (call) with the definition. Otherwise, if a function 450 * definition is available and it is not an old-style definition 451 * (decl != NULL && TP(decl->s_type)->t_proto), we compare the call 452 * with this declaration. Otherwise we compare it with the first 453 * call we have found (call1). 454 */ 455 456 /* arg1 must be promoted if it stems from an old-style definition */ 457 promote = def != NULL && def->s_old_style_function; 458 459 /* 460 * If we compare with a definition or declaration, we must perform 461 * the same checks for qualifiers in indirected types as in 462 * assignments. 463 */ 464 asgn = def != NULL || (decl != NULL && TP(decl->s_type)->t_proto); 465 466 dowarn = false; 467 if (types_compatible(arg1, arg2, true, promote, asgn, &dowarn) && 468 (!sflag || !dowarn)) 469 return; 470 471 /* 472 * Other lint implementations print warnings as soon as the type 473 * of an argument does not match exactly the expected type. The 474 * result are lots of warnings which are really not necessary. 475 * We print a warning only if 476 * (0) at least one type is not an integer type and types differ 477 * (1) hflag is set and types differ 478 * (2) types differ, except in signedness 479 * If the argument is an integer constant whose msb is not set, 480 * signedness is ignored (e.g. 0 matches both signed and unsigned 481 * int). This is with and without hflag. 482 * If the argument is an integer constant with value 0 and the 483 * expected argument is of type pointer and the width of the 484 * integer constant is the same as the width of the pointer, 485 * no warning is printed. 486 */ 487 t1 = arg1->t_tspec; 488 t2 = arg2->t_tspec; 489 if (is_integer(t1) && is_integer(t2) && 490 !arg1->t_is_enum && !arg2->t_is_enum) { 491 if (promote) { 492 /* 493 * XXX Here is a problem: Although it is possible to 494 * pass an int where a char/short it expected, there 495 * may be loss in significant digits. We should first 496 * check for const arguments if they can be converted 497 * into the original parameter type. 498 */ 499 if (t1 == FLOAT) { 500 t1 = DOUBLE; 501 } else if (t1 == CHAR || t1 == SCHAR) { 502 t1 = INT; 503 } else if (t1 == UCHAR) { 504 t1 = tflag ? UINT : INT; 505 } else if (t1 == SHORT) { 506 t1 = INT; 507 } else if (t1 == USHORT) { 508 /* CONSTCOND */ 509 t1 = INT_MAX < USHRT_MAX || tflag ? UINT : INT; 510 } 511 } 512 513 if (signed_type(t1) == signed_type(t2)) { 514 515 /* 516 * types differ only in signedness; get information 517 * about arguments 518 */ 519 520 /* 521 * treat a definition like a call with variable 522 * arguments 523 */ 524 ai1 = call1 != NULL ? call1->f_args : NULL; 525 526 /* 527 * if two calls are compared, ai1 is set to the 528 * information for the n-th argument, if this was 529 * a constant, otherwise to NULL 530 */ 531 for ( ; ai1 != NULL; ai1 = ai1->a_next) { 532 if (ai1->a_num == n) 533 break; 534 } 535 /* 536 * ai is set to the information of the n-th arg 537 * of the (second) call, if this was a constant, 538 * otherwise to NULL 539 */ 540 for (ai = call->f_args; ai != NULL; ai = ai->a_next) { 541 if (ai->a_num == n) 542 break; 543 } 544 545 if (ai1 == NULL && ai == NULL) { 546 /* no constant at all */ 547 if (!hflag) 548 return; 549 } else if (ai1 == NULL || ai == NULL) { 550 /* one constant */ 551 if (ai == NULL) 552 ai = ai1; 553 if (ai->a_zero || ai->a_pcon) 554 /* same value in signed and unsigned */ 555 return; 556 /* value (not representation) differently */ 557 } else { 558 /* 559 * two constants, one signed, one unsigned; 560 * if the msb of one of the constants is set, 561 * the argument is used inconsistently. 562 */ 563 if (!ai1->a_ncon && !ai->a_ncon) 564 return; 565 } 566 } 567 568 } else if (t1 == PTR && is_integer(t2)) { 569 for (ai = call->f_args; ai != NULL; ai = ai->a_next) { 570 if (ai->a_num == n) 571 break; 572 } 573 /* 574 * Vendor implementations of lint (e.g. HP-UX, Digital UNIX) 575 * don't care about the size of the integer argument, 576 * only whether or not it is zero. We do the same. 577 */ 578 if (ai != NULL && ai->a_zero) 579 return; 580 } 581 582 /* %s, arg %d used inconsistently \t%s[%s] :: %s[%s] */ 583 msg(6, hte->h_name, n, mkpos(pos1p), type_name(arg1), 584 mkpos(&call->f_pos), type_name(arg2)); 585 } 586 587 /* 588 * Compare the types in the NULL-terminated array ap with the format 589 * string fmt. 590 */ 591 static void 592 printflike(const hte_t *hte, fcall_t *call, int n, const char *fmt, type_t **ap) 593 { 594 const char *fp; 595 char fc; 596 bool fwidth, prec, left, sign, space, alt, zero; 597 tspec_t sz, t1, t2 = NO_TSPEC; 598 type_t *tp; 599 600 fp = fmt; 601 fc = *fp++; 602 603 for (;;) { 604 if (fc == '\0') { 605 if (*ap != NULL) 606 too_many_arguments(hte, call); 607 break; 608 } 609 if (fc != '%') { 610 bad_format_string(hte, call); 611 break; 612 } 613 fc = *fp++; 614 fwidth = prec = left = sign = space = alt = zero = false; 615 sz = NO_TSPEC; 616 617 /* Flags */ 618 for (;;) { 619 if (fc == '-') { 620 if (left) 621 break; 622 left = true; 623 } else if (fc == '+') { 624 if (sign) 625 break; 626 sign = true; 627 } else if (fc == ' ') { 628 if (space) 629 break; 630 space = true; 631 } else if (fc == '#') { 632 if (alt) 633 break; 634 alt = true; 635 } else if (fc == '0') { 636 if (zero) 637 break; 638 zero = true; 639 } else { 640 break; 641 } 642 fc = *fp++; 643 } 644 645 /* field width */ 646 if (ch_isdigit(fc)) { 647 fwidth = true; 648 do { fc = *fp++; } while (ch_isdigit(fc)); 649 } else if (fc == '*') { 650 fwidth = true; 651 fc = *fp++; 652 if ((tp = *ap++) == NULL) { 653 too_few_arguments(hte, call); 654 break; 655 } 656 n++; 657 if ((t1 = tp->t_tspec) != INT && (hflag || t1 != UINT)) 658 inconsistent_arguments(hte, call, n); 659 } 660 661 /* precision */ 662 if (fc == '.') { 663 fc = *fp++; 664 prec = true; 665 if (ch_isdigit(fc)) { 666 do { fc = *fp++; } while (ch_isdigit(fc)); 667 } else if (fc == '*') { 668 fc = *fp++; 669 if ((tp = *ap++) == NULL) { 670 too_few_arguments(hte, call); 671 break; 672 } 673 n++; 674 if (tp->t_tspec != INT) 675 inconsistent_arguments(hte, call, n); 676 } else { 677 bad_format_string(hte, call); 678 break; 679 } 680 } 681 682 if (fc == 'h') { 683 sz = SHORT; 684 } else if (fc == 'l') { 685 sz = LONG; 686 } else if (fc == 'q') { 687 sz = LLONG; 688 } else if (fc == 'L') { 689 sz = LDOUBLE; 690 } 691 if (sz != NO_TSPEC) 692 fc = *fp++; 693 694 if (fc == '%') { 695 if (sz != NO_TSPEC || left || sign || space || 696 alt || zero || prec || fwidth) { 697 bad_format_string(hte, call); 698 } 699 fc = *fp++; 700 continue; 701 } 702 703 if (fc == '\0') { 704 bad_format_string(hte, call); 705 break; 706 } 707 708 if ((tp = *ap++) == NULL) { 709 too_few_arguments(hte, call); 710 break; 711 } 712 n++; 713 if ((t1 = tp->t_tspec) == PTR) 714 t2 = tp->t_subt->t_tspec; 715 716 if (fc == 'd' || fc == 'i') { 717 if (alt || sz == LDOUBLE) { 718 bad_format_string(hte, call); 719 break; 720 } 721 int_conv: 722 if (sz == LONG) { 723 if (t1 != LONG && (hflag || t1 != ULONG)) 724 inconsistent_arguments(hte, call, n); 725 } else if (sz == LLONG) { 726 if (t1 != LLONG && (hflag || t1 != ULLONG)) 727 inconsistent_arguments(hte, call, n); 728 } else { 729 /* 730 * SHORT is always promoted to INT, USHORT 731 * to INT or UINT. 732 */ 733 if (t1 != INT && (hflag || t1 != UINT)) 734 inconsistent_arguments(hte, call, n); 735 } 736 } else if (fc == 'o' || fc == 'u' || fc == 'x' || fc == 'X') { 737 if ((alt && fc == 'u') || sz == LDOUBLE) 738 bad_format_string(hte, call); 739 uint_conv: 740 if (sz == LONG) { 741 if (t1 != ULONG && (hflag || t1 != LONG)) 742 inconsistent_arguments(hte, call, n); 743 } else if (sz == LLONG) { 744 if (t1 != ULLONG && (hflag || t1 != LLONG)) 745 inconsistent_arguments(hte, call, n); 746 } else if (sz == SHORT) { 747 /* USHORT was promoted to INT or UINT */ 748 if (t1 != UINT && t1 != INT) 749 inconsistent_arguments(hte, call, n); 750 } else { 751 if (t1 != UINT && (hflag || t1 != INT)) 752 inconsistent_arguments(hte, call, n); 753 } 754 } else if (fc == 'D' || fc == 'O' || fc == 'U') { 755 if ((alt && fc != 'O') || sz != NO_TSPEC || !tflag) 756 bad_format_string(hte, call); 757 sz = LONG; 758 if (fc == 'D') { 759 goto int_conv; 760 } else { 761 goto uint_conv; 762 } 763 } else if (fc == 'f' || fc == 'e' || fc == 'E' || 764 fc == 'g' || fc == 'G') { 765 if (sz == NO_TSPEC) 766 sz = DOUBLE; 767 if (sz != DOUBLE && sz != LDOUBLE) 768 bad_format_string(hte, call); 769 if (t1 != sz) 770 inconsistent_arguments(hte, call, n); 771 } else if (fc == 'c') { 772 if (sz != NO_TSPEC || alt || zero) 773 bad_format_string(hte, call); 774 if (t1 != INT) 775 inconsistent_arguments(hte, call, n); 776 } else if (fc == 's') { 777 if (sz != NO_TSPEC || alt || zero) 778 bad_format_string(hte, call); 779 if (t1 != PTR || 780 (t2 != CHAR && t2 != UCHAR && t2 != SCHAR)) { 781 inconsistent_arguments(hte, call, n); 782 } 783 } else if (fc == 'p') { 784 if (fwidth || prec || sz != NO_TSPEC || alt || zero) 785 bad_format_string(hte, call); 786 if (t1 != PTR || (hflag && t2 != VOID)) 787 inconsistent_arguments(hte, call, n); 788 } else if (fc == 'n') { 789 if (fwidth || prec || alt || zero || sz == LDOUBLE) 790 bad_format_string(hte, call); 791 if (t1 != PTR) { 792 inconsistent_arguments(hte, call, n); 793 } else if (sz == LONG) { 794 if (t2 != LONG && t2 != ULONG) 795 inconsistent_arguments(hte, call, n); 796 } else if (sz == SHORT) { 797 if (t2 != SHORT && t2 != USHORT) 798 inconsistent_arguments(hte, call, n); 799 } else { 800 if (t2 != INT && t2 != UINT) 801 inconsistent_arguments(hte, call, n); 802 } 803 } else { 804 bad_format_string(hte, call); 805 break; 806 } 807 808 fc = *fp++; 809 } 810 } 811 812 /* 813 * Compare the types in the NULL-terminated array ap with the format 814 * string fmt. 815 */ 816 static void 817 scanflike(const hte_t *hte, fcall_t *call, int n, const char *fmt, type_t **ap) 818 { 819 const char *fp; 820 char fc; 821 bool noasgn, fwidth; 822 tspec_t sz, t1 = NO_TSPEC, t2 = NO_TSPEC; 823 type_t *tp = NULL; 824 825 fp = fmt; 826 fc = *fp++; 827 828 for (;;) { 829 if (fc == '\0') { 830 if (*ap != NULL) 831 too_many_arguments(hte, call); 832 break; 833 } 834 if (fc != '%') { 835 bad_format_string(hte, call); 836 break; 837 } 838 fc = *fp++; 839 840 noasgn = fwidth = false; 841 sz = NO_TSPEC; 842 843 if (fc == '*') { 844 noasgn = true; 845 fc = *fp++; 846 } 847 848 if (ch_isdigit(fc)) { 849 fwidth = true; 850 do { fc = *fp++; } while (ch_isdigit(fc)); 851 } 852 853 if (fc == 'h') { 854 sz = SHORT; 855 } else if (fc == 'l') { 856 sz = LONG; 857 } else if (fc == 'q') { 858 sz = LLONG; 859 } else if (fc == 'L') { 860 sz = LDOUBLE; 861 } 862 if (sz != NO_TSPEC) 863 fc = *fp++; 864 865 if (fc == '%') { 866 if (sz != NO_TSPEC || noasgn || fwidth) 867 bad_format_string(hte, call); 868 fc = *fp++; 869 continue; 870 } 871 872 if (!noasgn) { 873 if ((tp = *ap++) == NULL) { 874 too_few_arguments(hte, call); 875 break; 876 } 877 n++; 878 if ((t1 = tp->t_tspec) == PTR) 879 t2 = tp->t_subt->t_tspec; 880 } 881 882 if (fc == 'd' || fc == 'i' || fc == 'n') { 883 if (sz == LDOUBLE) 884 bad_format_string(hte, call); 885 if (sz != SHORT && sz != LONG && sz != LLONG) 886 sz = INT; 887 conv: 888 if (!noasgn) { 889 if (t1 != PTR) { 890 inconsistent_arguments(hte, call, n); 891 } else if (t2 != signed_type(sz)) { 892 inconsistent_arguments(hte, call, n); 893 } else if (hflag && t2 != sz) { 894 inconsistent_arguments(hte, call, n); 895 } else if (tp->t_subt->t_const) { 896 inconsistent_arguments(hte, call, n); 897 } 898 } 899 } else if (fc == 'o' || fc == 'u' || fc == 'x') { 900 if (sz == LDOUBLE) 901 bad_format_string(hte, call); 902 if (sz == SHORT) { 903 sz = USHORT; 904 } else if (sz == LONG) { 905 sz = ULONG; 906 } else if (sz == LLONG) { 907 sz = ULLONG; 908 } else { 909 sz = UINT; 910 } 911 goto conv; 912 } else if (fc == 'D') { 913 if (sz != NO_TSPEC || !tflag) 914 bad_format_string(hte, call); 915 sz = LONG; 916 goto conv; 917 } else if (fc == 'O') { 918 if (sz != NO_TSPEC || !tflag) 919 bad_format_string(hte, call); 920 sz = ULONG; 921 goto conv; 922 } else if (fc == 'X') { 923 /* 924 * XXX valid in ANSI C, but in NetBSD's libc imple- 925 * mented as "lx". That's why it should be avoided. 926 */ 927 if (sz != NO_TSPEC || !tflag) 928 bad_format_string(hte, call); 929 sz = ULONG; 930 goto conv; 931 } else if (fc == 'E') { 932 /* 933 * XXX valid in ANSI C, but in NetBSD's libc imple- 934 * mented as "lf". That's why it should be avoided. 935 */ 936 if (sz != NO_TSPEC || !tflag) 937 bad_format_string(hte, call); 938 sz = DOUBLE; 939 goto conv; 940 } else if (fc == 'F') { 941 /* XXX only for backward compatibility */ 942 if (sz != NO_TSPEC || !tflag) 943 bad_format_string(hte, call); 944 sz = DOUBLE; 945 goto conv; 946 } else if (fc == 'G') { 947 /* 948 * XXX valid in ANSI C, but in NetBSD's libc not 949 * implemented 950 */ 951 if (sz != NO_TSPEC && sz != LONG && sz != LDOUBLE) 952 bad_format_string(hte, call); 953 goto fconv; 954 } else if (fc == 'e' || fc == 'f' || fc == 'g') { 955 fconv: 956 if (sz == NO_TSPEC) { 957 sz = FLOAT; 958 } else if (sz == LONG) { 959 sz = DOUBLE; 960 } else if (sz != LDOUBLE) { 961 bad_format_string(hte, call); 962 sz = FLOAT; 963 } 964 goto conv; 965 } else if (fc == 's' || fc == '[' || fc == 'c') { 966 if (sz != NO_TSPEC) 967 bad_format_string(hte, call); 968 if (fc == '[') { 969 if ((fc = *fp++) == '-') { 970 bad_format_string(hte, call); 971 fc = *fp++; 972 } 973 if (fc != ']') { 974 bad_format_string(hte, call); 975 if (fc == '\0') 976 break; 977 } 978 } 979 if (!noasgn) { 980 if (t1 != PTR) { 981 inconsistent_arguments(hte, call, n); 982 } else if (t2 != CHAR && t2 != UCHAR && 983 t2 != SCHAR) { 984 inconsistent_arguments(hte, call, n); 985 } 986 } 987 } else if (fc == 'p') { 988 if (sz != NO_TSPEC) 989 bad_format_string(hte, call); 990 if (!noasgn) { 991 if (t1 != PTR || t2 != PTR) { 992 inconsistent_arguments(hte, call, n); 993 } else if (tp->t_subt->t_subt->t_tspec!=VOID) { 994 if (hflag) 995 inconsistent_arguments(hte, call, n); 996 } 997 } 998 } else { 999 bad_format_string(hte, call); 1000 break; 1001 } 1002 1003 fc = *fp++; 1004 } 1005 } 1006 1007 static void 1008 bad_format_string(const hte_t *hte, fcall_t *call) 1009 { 1010 1011 /* %s: malformed format string \t%s */ 1012 msg(13, hte->h_name, mkpos(&call->f_pos)); 1013 } 1014 1015 static void 1016 inconsistent_arguments(const hte_t *hte, fcall_t *call, int n) 1017 { 1018 1019 /* %s, arg %d inconsistent with format \t%s */ 1020 msg(14, hte->h_name, n, mkpos(&call->f_pos)); 1021 } 1022 1023 static void 1024 too_few_arguments(const hte_t *hte, fcall_t *call) 1025 { 1026 1027 /* %s: too few args for format \t%s */ 1028 msg(15, hte->h_name, mkpos(&call->f_pos)); 1029 } 1030 1031 static void 1032 too_many_arguments(const hte_t *hte, fcall_t *call) 1033 { 1034 1035 /* %s: too many args for format \t%s */ 1036 msg(16, hte->h_name, mkpos(&call->f_pos)); 1037 } 1038 1039 /* 1040 * List of functions where we usually don't care about their result. 1041 * NB: Must be sorted. 1042 */ 1043 static const char ignorelist[][8] = { 1044 "memcpy", 1045 "memmove", 1046 "memset", 1047 "printf", 1048 "strcat", 1049 "strcpy", 1050 "vprintf", 1051 }; 1052 1053 /* 1054 * Print warnings for return values which are used but not returned, 1055 * or return values which are always or sometimes ignored. 1056 */ 1057 static void 1058 check_return_values(const hte_t *hte, sym_t *def) 1059 { 1060 fcall_t *call; 1061 bool used, ignored; 1062 1063 if (def == NULL) 1064 /* don't know whether or not the functions returns a value */ 1065 return; 1066 1067 if (hte->h_calls == NULL) 1068 return; 1069 1070 if (def->s_function_has_return_value) { 1071 /* 1072 * XXX as soon as we are able to disable single warnings, 1073 * the following dependencies from hflag should be removed. 1074 * But for now I don't want to be bothered by these warnings 1075 * which are almost always useless. 1076 */ 1077 if (!hflag) 1078 return; 1079 if (hflag && bsearch(hte->h_name, ignorelist, 1080 sizeof(ignorelist) / sizeof(ignorelist[0]), 1081 sizeof(ignorelist[0]), 1082 (int (*)(const void *, const void *))strcmp) != NULL) 1083 return; 1084 1085 /* function has return value */ 1086 used = ignored = false; 1087 for (call = hte->h_calls; call != NULL; call = call->f_next) { 1088 used |= call->f_rused || call->f_rdisc; 1089 ignored |= !call->f_rused && !call->f_rdisc; 1090 } 1091 if (!used && ignored) { 1092 /* %s returns value which is always ignored */ 1093 msg(8, hte->h_name); 1094 } else if (used && ignored) { 1095 /* %s returns value which is sometimes ignored */ 1096 msg(9, hte->h_name); 1097 } 1098 } else { 1099 /* function has no return value */ 1100 for (call = hte->h_calls; call != NULL; call = call->f_next) { 1101 if (call->f_rused) 1102 /* %s value is used( %s ), but none returned */ 1103 msg(10, hte->h_name, mkpos(&call->f_pos)); 1104 } 1105 } 1106 } 1107 1108 /* 1109 * Print warnings for inconsistent argument declarations. 1110 */ 1111 static void 1112 check_argument_declarations(const hte_t *hte, sym_t *def, sym_t *decl) 1113 { 1114 bool osdef, eq, dowarn; 1115 int n; 1116 sym_t *sym1, *sym; 1117 type_t **ap1, **ap2, *tp1, *tp2; 1118 1119 osdef = false; 1120 if (def != NULL) { 1121 osdef = def->s_old_style_function; 1122 sym1 = def; 1123 } else if (decl != NULL && TP(decl->s_type)->t_proto) { 1124 sym1 = decl; 1125 } else { 1126 return; 1127 } 1128 if (TP(sym1->s_type)->t_tspec != FUNC) 1129 return; 1130 1131 /* 1132 * XXX Prototypes should also be compared with old-style function 1133 * declarations. 1134 */ 1135 1136 for (sym = hte->h_syms; sym != NULL; sym = sym->s_next) { 1137 if (sym == sym1 || !TP(sym->s_type)->t_proto) 1138 continue; 1139 ap1 = TP(sym1->s_type)->t_args; 1140 ap2 = TP(sym->s_type)->t_args; 1141 n = 0; 1142 while (*ap1 != NULL && *ap2 != NULL) { 1143 type_t *xt1, *xt2; 1144 dowarn = false; 1145 eq = types_compatible(xt1 = *ap1, xt2 = *ap2, 1146 true, osdef, false, &dowarn); 1147 if (!eq || dowarn) { 1148 /* %s, arg %d declared inconsistently ... */ 1149 msg(11, hte->h_name, n + 1, 1150 type_name(xt1), type_name(xt2), 1151 mkpos(&sym1->s_pos), mkpos(&sym->s_pos)); 1152 } 1153 n++; 1154 ap1++; 1155 ap2++; 1156 } 1157 if (*ap1 == *ap2) { 1158 tp1 = TP(sym1->s_type); 1159 tp2 = TP(sym->s_type); 1160 if (tp1->t_vararg == tp2->t_vararg) 1161 continue; 1162 if (tp2->t_vararg && sym1->s_check_only_first_args && 1163 sym1->s_check_num_args == n && !sflag) { 1164 continue; 1165 } 1166 } 1167 /* %s: variable # of args declared \t%s :: %s */ 1168 msg(12, hte->h_name, mkpos(&sym1->s_pos), mkpos(&sym->s_pos)); 1169 } 1170 } 1171 1172 1173 /* 1174 * Check compatibility of two types. Returns whether types are compatible. 1175 * 1176 * ignqual if set, ignore qualifiers of outermost type; used for 1177 * function arguments 1178 * promote if set, promote left type before comparison; used for 1179 * comparisons of arguments with parameters of old-style 1180 * definitions 1181 * asgn left indirected type must have at least the same qualifiers 1182 * like right indirected type (for assignments and function 1183 * arguments) 1184 * *dowarn set to true if an old-style declaration was compared with 1185 * an incompatible prototype declaration 1186 */ 1187 static bool 1188 types_compatible(type_t *tp1, type_t *tp2, 1189 bool ignqual, bool promot, bool asgn, bool *dowarn) 1190 { 1191 tspec_t t, to; 1192 int indir; 1193 1194 to = NO_TSPEC; 1195 indir = 0; 1196 1197 while (tp1 != NULL && tp2 != NULL) { 1198 1199 t = tp1->t_tspec; 1200 if (promot) { 1201 if (t == FLOAT) { 1202 t = DOUBLE; 1203 } else if (t == CHAR || t == SCHAR) { 1204 t = INT; 1205 } else if (t == UCHAR) { 1206 t = tflag ? UINT : INT; 1207 } else if (t == SHORT) { 1208 t = INT; 1209 } else if (t == USHORT) { 1210 /* CONSTCOND */ 1211 t = INT_MAX < USHRT_MAX || tflag ? UINT : INT; 1212 } 1213 } 1214 1215 if (asgn && to == PTR) { 1216 if (indir == 1 && (t == VOID || tp2->t_tspec == VOID)) 1217 return true; 1218 } 1219 1220 if (t != tp2->t_tspec) { 1221 /* 1222 * Give pointer to types which differ only in 1223 * signedness a chance if not sflag and not hflag. 1224 */ 1225 if (sflag || hflag || to != PTR) 1226 return false; 1227 if (signed_type(t) != signed_type(tp2->t_tspec)) 1228 return false; 1229 } 1230 1231 if (tp1->t_is_enum && tp2->t_is_enum) { 1232 if (tp1->t_istag && tp2->t_istag) { 1233 return tp1->t_tag == tp2->t_tag; 1234 } else if (tp1->t_istynam && tp2->t_istynam) { 1235 return tp1->t_tynam == tp2->t_tynam; 1236 } else if (tp1->t_isuniqpos && tp2->t_isuniqpos) { 1237 return (tp1->t_uniqpos.p_line == 1238 tp2->t_uniqpos.p_line && 1239 tp1->t_uniqpos.p_file == 1240 tp2->t_uniqpos.p_file && 1241 tp1->t_uniqpos.p_uniq == 1242 tp2->t_uniqpos.p_uniq); 1243 } else { 1244 return false; 1245 } 1246 } 1247 1248 /* 1249 * XXX Handle combinations of enum and int if eflag is set. 1250 * But note: enum and 0 should be allowed. 1251 */ 1252 1253 if (asgn && indir == 1) { 1254 if (!tp1->t_const && tp2->t_const) 1255 return false; 1256 if (!tp1->t_volatile && tp2->t_volatile) 1257 return false; 1258 } else if (!ignqual && !tflag) { 1259 if (tp1->t_const != tp2->t_const) 1260 return false; 1261 if (tp1->t_const != tp2->t_const) 1262 return false; 1263 } 1264 1265 if (t == STRUCT || t == UNION) { 1266 if (tp1->t_istag && tp2->t_istag) { 1267 return tp1->t_tag == tp2->t_tag; 1268 } else if (tp1->t_istynam && tp2->t_istynam) { 1269 return tp1->t_tynam == tp2->t_tynam; 1270 } else if (tp1->t_isuniqpos && tp2->t_isuniqpos) { 1271 return (tp1->t_uniqpos.p_line == 1272 tp2->t_uniqpos.p_line && 1273 tp1->t_uniqpos.p_file == 1274 tp2->t_uniqpos.p_file && 1275 tp1->t_uniqpos.p_uniq == 1276 tp2->t_uniqpos.p_uniq); 1277 } else { 1278 return false; 1279 } 1280 } 1281 1282 if (t == ARRAY && tp1->t_dim != tp2->t_dim) { 1283 if (tp1->t_dim != 0 && tp2->t_dim != 0) 1284 return false; 1285 } 1286 1287 if (t == FUNC) { 1288 if (tp1->t_proto && tp2->t_proto) { 1289 if (!prototypes_compatible(tp1, tp2, dowarn)) 1290 return false; 1291 } else if (tp1->t_proto) { 1292 if (!matches_no_arg_function(tp1, dowarn)) 1293 return false; 1294 } else if (tp2->t_proto) { 1295 if (!matches_no_arg_function(tp2, dowarn)) 1296 return false; 1297 } 1298 } 1299 1300 tp1 = tp1->t_subt; 1301 tp2 = tp2->t_subt; 1302 ignqual = promot = false; 1303 to = t; 1304 indir++; 1305 1306 } 1307 1308 return tp1 == tp2; 1309 } 1310 1311 /* 1312 * Compares arguments of two prototypes 1313 */ 1314 static bool 1315 prototypes_compatible(type_t *tp1, type_t *tp2, bool *dowarn) 1316 { 1317 type_t **a1, **a2; 1318 1319 if (tp1->t_vararg != tp2->t_vararg) 1320 return false; 1321 1322 a1 = tp1->t_args; 1323 a2 = tp2->t_args; 1324 1325 while (*a1 != NULL && *a2 != NULL) { 1326 1327 if (!types_compatible(*a1, *a2, true, false, false, dowarn)) 1328 return false; 1329 1330 a1++; 1331 a2++; 1332 1333 } 1334 1335 return *a1 == *a2; 1336 } 1337 1338 /* 1339 * Returns whether all parameters of a prototype are compatible with an 1340 * old-style function declaration. 1341 * 1342 * This is the case if the following conditions are met: 1343 * 1. the prototype must have a fixed number of parameters 1344 * 2. no parameter is of type float 1345 * 3. no parameter is converted to another type if integer promotion 1346 * is applied on it 1347 */ 1348 static bool 1349 matches_no_arg_function(type_t *tp, bool *dowarn) 1350 { 1351 type_t **arg; 1352 tspec_t t; 1353 1354 if (tp->t_vararg && dowarn != NULL) 1355 *dowarn = true; 1356 for (arg = tp->t_args; *arg != NULL; arg++) { 1357 if ((t = (*arg)->t_tspec) == FLOAT) 1358 return false; 1359 if (t == CHAR || t == SCHAR || t == UCHAR) 1360 return false; 1361 if (t == SHORT || t == USHORT) 1362 return false; 1363 } 1364 return true; 1365 } 1366