Blame lib/checknullpointer.cpp

Packit 2035a7
/*
Packit 2035a7
 * Cppcheck - A tool for static C/C++ code analysis
Packit 2035a7
 * Copyright (C) 2007-2018 Cppcheck team.
Packit 2035a7
 *
Packit 2035a7
 * This program is free software: you can redistribute it and/or modify
Packit 2035a7
 * it under the terms of the GNU General Public License as published by
Packit 2035a7
 * the Free Software Foundation, either version 3 of the License, or
Packit 2035a7
 * (at your option) any later version.
Packit 2035a7
 *
Packit 2035a7
 * This program is distributed in the hope that it will be useful,
Packit 2035a7
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
Packit 2035a7
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
Packit 2035a7
 * GNU General Public License for more details.
Packit 2035a7
 *
Packit 2035a7
 * You should have received a copy of the GNU General Public License
Packit 2035a7
 * along with this program.  If not, see <http://www.gnu.org/licenses/>.
Packit 2035a7
 */
Packit 2035a7
Packit 2035a7
Packit 2035a7
//---------------------------------------------------------------------------
Packit 2035a7
#include "checknullpointer.h"
Packit 2035a7
Packit 2035a7
#include "errorlogger.h"
Packit 2035a7
#include "library.h"
Packit 2035a7
#include "settings.h"
Packit 2035a7
#include "symboldatabase.h"
Packit 2035a7
#include "token.h"
Packit 2035a7
#include "tokenize.h"
Packit 2035a7
#include "utils.h"
Packit 2035a7
#include "astutils.h"
Packit 2035a7
Packit 2035a7
#include <algorithm>
Packit 2035a7
#include <cctype>
Packit 2035a7
#include <cstddef>
Packit 2035a7
#include <set>
Packit 2035a7
//---------------------------------------------------------------------------
Packit 2035a7
Packit 2035a7
// Register this check class (by creating a static instance of it)
Packit 2035a7
namespace {
Packit 2035a7
    CheckNullPointer instance;
Packit 2035a7
}
Packit 2035a7
Packit 2035a7
static const CWE CWE476(476U);  // NULL Pointer Dereference
Packit 2035a7
static const CWE CWE682(682U);  // Incorrect Calculation
Packit 2035a7
Packit 2035a7
//---------------------------------------------------------------------------
Packit 2035a7
Packit 2035a7
static bool checkNullpointerFunctionCallPlausibility(const Function* func, unsigned int arg)
Packit 2035a7
{
Packit 2035a7
    return !func || (func->argCount() >= arg && func->getArgumentVar(arg - 1) && func->getArgumentVar(arg - 1)->isPointer());
Packit 2035a7
}
Packit 2035a7
Packit 2035a7
/**
Packit 2035a7
 * @brief parse a function call and extract information about variable usage
Packit 2035a7
 * @param tok first token
Packit 2035a7
 * @param var variables that the function read / write.
Packit 2035a7
 * @param library --library files data
Packit 2035a7
 */
Packit 2035a7
void CheckNullPointer::parseFunctionCall(const Token &tok, std::list<const Token *> &var, const Library *library)
Packit 2035a7
{
Packit 2035a7
    if (Token::Match(&tok, "%name% ( )") || !tok.tokAt(2))
Packit 2035a7
        return;
Packit 2035a7
Packit 2035a7
    const Token* firstParam = tok.tokAt(2);
Packit 2035a7
    const Token* secondParam = firstParam->nextArgument();
Packit 2035a7
Packit 2035a7
    // 1st parameter..
Packit 2035a7
    if (Token::Match(&tok, "snprintf|vsnprintf|fnprintf|vfnprintf") && secondParam && secondParam->str() != "0") // Only if length (second parameter) is not zero
Packit 2035a7
        var.push_back(firstParam);
Packit 2035a7
Packit 2035a7
    if (library || tok.function() != nullptr) {
Packit 2035a7
        const Token *param = firstParam;
Packit 2035a7
        int argnr = 1;
Packit 2035a7
        while (param) {
Packit 2035a7
            if (library && library->isnullargbad(&tok, argnr) && checkNullpointerFunctionCallPlausibility(tok.function(), argnr))
Packit 2035a7
                var.push_back(param);
Packit 2035a7
            else if (tok.function()) {
Packit 2035a7
                const Variable* argVar = tok.function()->getArgumentVar(argnr-1);
Packit 2035a7
                if (argVar && argVar->isStlStringType() && !argVar->isArrayOrPointer())
Packit 2035a7
                    var.push_back(param);
Packit 2035a7
            }
Packit 2035a7
            param = param->nextArgument();
Packit 2035a7
            argnr++;
Packit 2035a7
        }
Packit 2035a7
    }
Packit 2035a7
Packit 2035a7
    if (Token::Match(&tok, "printf|sprintf|snprintf|fprintf|fnprintf|scanf|sscanf|fscanf|wprintf|swprintf|fwprintf|wscanf|swscanf|fwscanf")) {
Packit 2035a7
        const Token* argListTok = nullptr; // Points to first va_list argument
Packit 2035a7
        std::string formatString;
Packit 2035a7
        bool scan = Token::Match(&tok, "scanf|sscanf|fscanf|wscanf|swscanf|fwscanf");
Packit 2035a7
Packit 2035a7
        if (Token::Match(&tok, "printf|scanf|wprintf|wscanf ( %str%")) {
Packit 2035a7
            formatString = firstParam->strValue();
Packit 2035a7
            argListTok = secondParam;
Packit 2035a7
        } else if (Token::Match(&tok, "sprintf|fprintf|sscanf|fscanf|fwprintf|fwscanf|swscanf")) {
Packit 2035a7
            const Token* formatStringTok = secondParam; // Find second parameter (format string)
Packit 2035a7
            if (formatStringTok && formatStringTok->tokType() == Token::eString) {
Packit 2035a7
                argListTok = formatStringTok->nextArgument(); // Find third parameter (first argument of va_args)
Packit 2035a7
                formatString = formatStringTok->strValue();
Packit 2035a7
            }
Packit 2035a7
        } else if (Token::Match(&tok, "snprintf|fnprintf|swprintf") && secondParam) {
Packit 2035a7
            const Token* formatStringTok = secondParam->nextArgument(); // Find third parameter (format string)
Packit 2035a7
            if (formatStringTok && formatStringTok->tokType() == Token::eString) {
Packit 2035a7
                argListTok = formatStringTok->nextArgument(); // Find fourth parameter (first argument of va_args)
Packit 2035a7
                formatString = formatStringTok->strValue();
Packit 2035a7
            }
Packit 2035a7
        }
Packit 2035a7
Packit 2035a7
        if (argListTok) {
Packit 2035a7
            bool percent = false;
Packit 2035a7
            for (std::string::iterator i = formatString.begin(); i != formatString.end(); ++i) {
Packit 2035a7
                if (*i == '%') {
Packit 2035a7
                    percent = !percent;
Packit 2035a7
                } else if (percent) {
Packit 2035a7
                    percent = false;
Packit 2035a7
Packit 2035a7
                    bool _continue = false;
Packit 2035a7
                    while (!std::isalpha((unsigned char)*i)) {
Packit 2035a7
                        if (*i == '*') {
Packit 2035a7
                            if (scan)
Packit 2035a7
                                _continue = true;
Packit 2035a7
                            else
Packit 2035a7
                                argListTok = argListTok->nextArgument();
Packit 2035a7
                        }
Packit 2035a7
                        ++i;
Packit 2035a7
                        if (!argListTok || i == formatString.end())
Packit 2035a7
                            return;
Packit 2035a7
                    }
Packit 2035a7
                    if (_continue)
Packit 2035a7
                        continue;
Packit 2035a7
Packit 2035a7
                    if ((*i == 'n' || *i == 's' || scan)) {
Packit 2035a7
                        var.push_back(argListTok);
Packit 2035a7
                    }
Packit 2035a7
Packit 2035a7
                    if (*i != 'm') // %m is a non-standard glibc extension that requires no parameter
Packit 2035a7
                        argListTok = argListTok->nextArgument(); // Find next argument
Packit 2035a7
                    if (!argListTok)
Packit 2035a7
                        break;
Packit 2035a7
                }
Packit 2035a7
            }
Packit 2035a7
        }
Packit 2035a7
    }
Packit 2035a7
}
Packit 2035a7
Packit 2035a7
namespace {
Packit 2035a7
    const std::set<std::string> stl_stream = make_container< std::set<std::string> >() <<
Packit 2035a7
            "fstream" << "ifstream" << "iostream" << "istream" <<
Packit 2035a7
            "istringstream" << "ofstream" << "ostream" << "ostringstream" <<
Packit 2035a7
            "stringstream" << "wistringstream" << "wostringstream" << "wstringstream";
Packit 2035a7
}
Packit 2035a7
Packit 2035a7
/**
Packit 2035a7
 * Is there a pointer dereference? Everything that should result in
Packit 2035a7
 * a nullpointer dereference error message will result in a true
Packit 2035a7
 * return value. If it's unknown if the pointer is dereferenced false
Packit 2035a7
 * is returned.
Packit 2035a7
 * @param tok token for the pointer
Packit 2035a7
 * @param unknown it is not known if there is a pointer dereference (could be reported as a debug message)
Packit 2035a7
 * @return true => there is a dereference
Packit 2035a7
 */
Packit 2035a7
bool CheckNullPointer::isPointerDeRef(const Token *tok, bool &unknown)
Packit 2035a7
{
Packit 2035a7
    unknown = false;
Packit 2035a7
Packit 2035a7
    const Token* parent = tok->astParent();
Packit 2035a7
    if (!parent)
Packit 2035a7
        return false;
Packit 2035a7
    if (parent->str() == "." && parent->astOperand2() == tok)
Packit 2035a7
        return isPointerDeRef(parent, unknown);
Packit 2035a7
    const bool firstOperand = parent->astOperand1() == tok;
Packit 2035a7
    while (parent->str() == "(" && (parent->astOperand2() == nullptr && parent->strAt(1) != ")")) { // Skip over casts
Packit 2035a7
        parent = parent->astParent();
Packit 2035a7
        if (!parent)
Packit 2035a7
            return false;
Packit 2035a7
    }
Packit 2035a7
Packit 2035a7
    // Dereferencing pointer..
Packit 2035a7
    if (parent->str() == "*" && !parent->astOperand2() && !Token::Match(parent->tokAt(-2), "sizeof|decltype|typeof"))
Packit 2035a7
        return true;
Packit 2035a7
Packit 2035a7
    // array access
Packit 2035a7
    if (firstOperand && parent->str() == "[" && (!parent->astParent() || parent->astParent()->str() != "&"))
Packit 2035a7
        return true;
Packit 2035a7
Packit 2035a7
    // address of member variable / array element
Packit 2035a7
    const Token *parent2 = parent;
Packit 2035a7
    while (Token::Match(parent2, "[|."))
Packit 2035a7
        parent2 = parent2->astParent();
Packit 2035a7
    if (parent2 != parent && parent2 && parent2->str() == "&" && !parent2->astOperand2())
Packit 2035a7
        return false;
Packit 2035a7
Packit 2035a7
    // read/write member variable
Packit 2035a7
    if (firstOperand && parent->str() == "." && (!parent->astParent() || parent->astParent()->str() != "&")) {
Packit 2035a7
        if (!parent->astParent() || parent->astParent()->str() != "(" || parent->astParent() == tok->previous())
Packit 2035a7
            return true;
Packit 2035a7
        unknown = true;
Packit 2035a7
        return false;
Packit 2035a7
    }
Packit 2035a7
Packit 2035a7
    if (Token::Match(tok, "%name% ("))
Packit 2035a7
        return true;
Packit 2035a7
Packit 2035a7
    if (Token::Match(tok, "%var% = %var% .") &&
Packit 2035a7
        tok->varId() == tok->tokAt(2)->varId())
Packit 2035a7
        return true;
Packit 2035a7
Packit 2035a7
    // std::string dereferences nullpointers
Packit 2035a7
    if (Token::Match(parent->tokAt(-3), "std :: string|wstring (") && tok->strAt(1) == ")")
Packit 2035a7
        return true;
Packit 2035a7
    if (Token::Match(parent->previous(), "%name% (") && tok->strAt(1) == ")") {
Packit 2035a7
        const Variable* var = tok->tokAt(-2)->variable();
Packit 2035a7
        if (var && !var->isPointer() && !var->isArray() && var->isStlStringType())
Packit 2035a7
            return true;
Packit 2035a7
    }
Packit 2035a7
Packit 2035a7
    // streams dereference nullpointers
Packit 2035a7
    if (Token::Match(parent, "<<|>>") && !firstOperand) {
Packit 2035a7
        const Variable* var = tok->variable();
Packit 2035a7
        if (var && var->isPointer() && Token::Match(var->typeStartToken(), "char|wchar_t")) { // Only outputting or reading to char* can cause problems
Packit 2035a7
            const Token* tok2 = parent; // Find start of statement
Packit 2035a7
            for (; tok2; tok2 = tok2->previous()) {
Packit 2035a7
                if (Token::Match(tok2->previous(), ";|{|}|:"))
Packit 2035a7
                    break;
Packit 2035a7
            }
Packit 2035a7
            if (Token::Match(tok2, "std :: cout|cin|cerr"))
Packit 2035a7
                return true;
Packit 2035a7
            if (tok2 && tok2->varId() != 0) {
Packit 2035a7
                const Variable* var2 = tok2->variable();
Packit 2035a7
                if (var2 && var2->isStlType(stl_stream))
Packit 2035a7
                    return true;
Packit 2035a7
            }
Packit 2035a7
        }
Packit 2035a7
    }
Packit 2035a7
Packit 2035a7
    const Variable *ovar = nullptr;
Packit 2035a7
    if (Token::Match(parent, "+|==|!=") || (parent->str() == "=" && !firstOperand)) {
Packit 2035a7
        if (parent->astOperand1() == tok && parent->astOperand2())
Packit 2035a7
            ovar = parent->astOperand2()->variable();
Packit 2035a7
        else if (parent->astOperand1() && parent->astOperand2() == tok)
Packit 2035a7
            ovar = parent->astOperand1()->variable();
Packit 2035a7
    }
Packit 2035a7
    if (ovar && !ovar->isPointer() && !ovar->isArray() && ovar->isStlStringType())
Packit 2035a7
        return true;
Packit 2035a7
Packit 2035a7
    // assume that it's not a dereference (no false positives)
Packit 2035a7
    return false;
Packit 2035a7
}
Packit 2035a7
Packit 2035a7
Packit 2035a7
void CheckNullPointer::nullPointerLinkedList()
Packit 2035a7
{
Packit 2035a7
Packit 2035a7
    if (!_settings->isEnabled(Settings::WARNING))
Packit 2035a7
        return;
Packit 2035a7
Packit 2035a7
    const SymbolDatabase* const symbolDatabase = _tokenizer->getSymbolDatabase();
Packit 2035a7
Packit 2035a7
    // looping through items in a linked list in a inner loop.
Packit 2035a7
    // Here is an example:
Packit 2035a7
    //    for (const Token *tok = tokens; tok; tok = tok->next) {
Packit 2035a7
    //        if (tok->str() == "hello")
Packit 2035a7
    //            tok = tok->next;   // <- tok might become a null pointer!
Packit 2035a7
    //    }
Packit 2035a7
    for (std::list<Scope>::const_iterator i = symbolDatabase->scopeList.begin(); i != symbolDatabase->scopeList.end(); ++i) {
Packit 2035a7
        const Token* const tok1 = i->classDef;
Packit 2035a7
        // search for a "for" scope..
Packit 2035a7
        if (i->type != Scope::eFor || !tok1)
Packit 2035a7
            continue;
Packit 2035a7
Packit 2035a7
        // is there any dereferencing occurring in the for statement
Packit 2035a7
        const Token* end2 = tok1->linkAt(1);
Packit 2035a7
        for (const Token *tok2 = tok1->tokAt(2); tok2 != end2; tok2 = tok2->next()) {
Packit 2035a7
            // Dereferencing a variable inside the "for" parentheses..
Packit 2035a7
            if (Token::Match(tok2, "%var% . %name%")) {
Packit 2035a7
                // Is this variable a pointer?
Packit 2035a7
                const Variable *var = tok2->variable();
Packit 2035a7
                if (!var || !var->isPointer())
Packit 2035a7
                    continue;
Packit 2035a7
Packit 2035a7
                // Variable id for dereferenced variable
Packit 2035a7
                const unsigned int varid(tok2->varId());
Packit 2035a7
Packit 2035a7
                if (Token::Match(tok2->tokAt(-2), "%varid% ?", varid))
Packit 2035a7
                    continue;
Packit 2035a7
Packit 2035a7
                // Check usage of dereferenced variable in the loop..
Packit 2035a7
                // TODO: Move this to ValueFlow
Packit 2035a7
                for (std::list<Scope*>::const_iterator j = i->nestedList.begin(); j != i->nestedList.end(); ++j) {
Packit 2035a7
                    const Scope* const scope = *j;
Packit 2035a7
                    if (scope->type != Scope::eWhile)
Packit 2035a7
                        continue;
Packit 2035a7
Packit 2035a7
                    // TODO: are there false negatives for "while ( %varid% ||"
Packit 2035a7
                    if (Token::Match(scope->classDef->next(), "( %varid% &&|)", varid)) {
Packit 2035a7
                        // Make sure there is a "break" or "return" inside the loop.
Packit 2035a7
                        // Without the "break" a null pointer could be dereferenced in the
Packit 2035a7
                        // for statement.
Packit 2035a7
                        for (const Token *tok4 = scope->classStart; tok4; tok4 = tok4->next()) {
Packit 2035a7
                            if (tok4 == i->classEnd) {
Packit 2035a7
                                const ValueFlow::Value v(scope->classDef, 0LL);
Packit 2035a7
                                nullPointerError(tok1, var->name(), &v, false);
Packit 2035a7
                                break;
Packit 2035a7
                            }
Packit 2035a7
Packit 2035a7
                            // There is a "break" or "return" inside the loop.
Packit 2035a7
                            // TODO: there can be false negatives. There could still be
Packit 2035a7
                            //       execution paths that are not properly terminated
Packit 2035a7
                            else if (tok4->str() == "break" || tok4->str() == "return")
Packit 2035a7
                                break;
Packit 2035a7
                        }
Packit 2035a7
                    }
Packit 2035a7
                }
Packit 2035a7
            }
Packit 2035a7
        }
Packit 2035a7
    }
Packit 2035a7
}
Packit 2035a7
Packit 2035a7
void CheckNullPointer::nullPointerByDeRefAndChec()
Packit 2035a7
{
Packit 2035a7
    const bool printInconclusive = (_settings->inconclusive);
Packit 2035a7
Packit 2035a7
    for (const Token *tok = _tokenizer->tokens(); tok; tok = tok->next()) {
Packit 2035a7
        if (Token::Match(tok, "sizeof|decltype|typeid|typeof (")) {
Packit 2035a7
            tok = tok->next()->link();
Packit 2035a7
            continue;
Packit 2035a7
        }
Packit 2035a7
Packit 2035a7
        const Variable *var = tok->variable();
Packit 2035a7
        if (!var || !var->isPointer() || tok == var->nameToken())
Packit 2035a7
            continue;
Packit 2035a7
Packit 2035a7
        // Can pointer be NULL?
Packit 2035a7
        const ValueFlow::Value *value = tok->getValue(0);
Packit 2035a7
        if (!value)
Packit 2035a7
            continue;
Packit 2035a7
Packit 2035a7
        if (!printInconclusive && value->isInconclusive())
Packit 2035a7
            continue;
Packit 2035a7
Packit 2035a7
        // Is pointer used as function parameter?
Packit 2035a7
        if (Token::Match(tok->previous(), "[(,] %name% [,)]")) {
Packit 2035a7
            const Token *ftok = tok->previous();
Packit 2035a7
            while (ftok && ftok->str() != "(") {
Packit 2035a7
                if (ftok->str() == ")")
Packit 2035a7
                    ftok = ftok->link();
Packit 2035a7
                ftok = ftok->previous();
Packit 2035a7
            }
Packit 2035a7
            if (!ftok || !ftok->previous())
Packit 2035a7
                continue;
Packit 2035a7
            std::list<const Token *> varlist;
Packit 2035a7
            parseFunctionCall(*ftok->previous(), varlist, &_settings->library);
Packit 2035a7
            if (std::find(varlist.begin(), varlist.end(), tok) != varlist.end()) {
Packit 2035a7
                nullPointerError(tok, tok->str(), value, value->isInconclusive());
Packit 2035a7
            }
Packit 2035a7
            continue;
Packit 2035a7
        }
Packit 2035a7
Packit 2035a7
        // Pointer dereference.
Packit 2035a7
        bool unknown = false;
Packit 2035a7
        if (!isPointerDeRef(tok,unknown)) {
Packit 2035a7
            if (unknown)
Packit 2035a7
                nullPointerError(tok, tok->str(), value, true);
Packit 2035a7
            continue;
Packit 2035a7
        }
Packit 2035a7
Packit 2035a7
        nullPointerError(tok, tok->str(), value, value->isInconclusive());
Packit 2035a7
    }
Packit 2035a7
}
Packit 2035a7
Packit 2035a7
void CheckNullPointer::nullPointer()
Packit 2035a7
{
Packit 2035a7
    nullPointerLinkedList();
Packit 2035a7
    nullPointerByDeRefAndChec();
Packit 2035a7
}
Packit 2035a7
Packit 2035a7
namespace {
Packit 2035a7
    const std::set<std::string> stl_istream = make_container< std::set<std::string> >() <<
Packit 2035a7
            "fstream" << "ifstream" << "iostream" << "istream" <<
Packit 2035a7
            "istringstream" << "stringstream" << "wistringstream" << "wstringstream";
Packit 2035a7
}
Packit 2035a7
Packit 2035a7
/** Dereferencing null constant (simplified token list) */
Packit 2035a7
void CheckNullPointer::nullConstantDereference()
Packit 2035a7
{
Packit 2035a7
    const SymbolDatabase *symbolDatabase = _tokenizer->getSymbolDatabase();
Packit 2035a7
Packit 2035a7
    const std::size_t functions = symbolDatabase->functionScopes.size();
Packit 2035a7
    for (std::size_t i = 0; i < functions; ++i) {
Packit 2035a7
        const Scope * scope = symbolDatabase->functionScopes[i];
Packit 2035a7
        if (scope->function == nullptr || !scope->function->hasBody()) // We only look for functions with a body
Packit 2035a7
            continue;
Packit 2035a7
Packit 2035a7
        const Token *tok = scope->classStart;
Packit 2035a7
Packit 2035a7
        if (scope->function->isConstructor())
Packit 2035a7
            tok = scope->function->token; // Check initialization list
Packit 2035a7
Packit 2035a7
        for (; tok != scope->classEnd; tok = tok->next()) {
Packit 2035a7
            if (Token::Match(tok, "sizeof|decltype|typeid|typeof ("))
Packit 2035a7
                tok = tok->next()->link();
Packit 2035a7
Packit 2035a7
            else if (Token::simpleMatch(tok, "* 0")) {
Packit 2035a7
                if (Token::Match(tok->previous(), "return|throw|;|{|}|:|[|(|,") || tok->previous()->isOp()) {
Packit 2035a7
                    nullPointerError(tok);
Packit 2035a7
                }
Packit 2035a7
            }
Packit 2035a7
Packit 2035a7
            else if (Token::Match(tok, "0 [") && (tok->previous()->str() != "&" || !Token::Match(tok->next()->link()->next(), "[.(]")))
Packit 2035a7
                nullPointerError(tok);
Packit 2035a7
Packit 2035a7
            else if (Token::Match(tok->previous(), "!!. %name% (") && (tok->previous()->str() != "::" || tok->strAt(-2) == "std")) {
Packit 2035a7
                if (Token::Match(tok->tokAt(2), "0|NULL|nullptr )") && tok->varId()) { // constructor call
Packit 2035a7
                    const Variable *var = tok->variable();
Packit 2035a7
                    if (var && !var->isPointer() && !var->isArray() && var->isStlStringType())
Packit 2035a7
                        nullPointerError(tok);
Packit 2035a7
                } else { // function call
Packit 2035a7
                    std::list<const Token *> var;
Packit 2035a7
                    parseFunctionCall(*tok, var, &_settings->library);
Packit 2035a7
Packit 2035a7
                    // is one of the var items a NULL pointer?
Packit 2035a7
                    for (std::list<const Token *>::const_iterator it = var.begin(); it != var.end(); ++it) {
Packit 2035a7
                        if (Token::Match(*it, "0|NULL|nullptr [,)]")) {
Packit 2035a7
                            nullPointerError(*it);
Packit 2035a7
                        }
Packit 2035a7
                    }
Packit 2035a7
                }
Packit 2035a7
            } else if (Token::Match(tok, "std :: string|wstring ( 0|NULL|nullptr )"))
Packit 2035a7
                nullPointerError(tok);
Packit 2035a7
Packit 2035a7
            else if (Token::Match(tok->previous(), "::|. %name% (")) {
Packit 2035a7
                const std::vector<const Token *> &args = getArguments(tok);
Packit 2035a7
                for (int argnr = 0; argnr < args.size(); ++argnr) {
Packit 2035a7
                    const Token *argtok = args[argnr];
Packit 2035a7
                    if (!argtok->hasKnownIntValue())
Packit 2035a7
                        continue;
Packit 2035a7
                    if (argtok->values().front().intvalue != 0)
Packit 2035a7
                        continue;
Packit 2035a7
                    if (_settings->library.isnullargbad(tok, argnr+1))
Packit 2035a7
                        nullPointerError(argtok);
Packit 2035a7
                }
Packit 2035a7
            }
Packit 2035a7
Packit 2035a7
            else if (Token::Match(tok->previous(), ">> 0|NULL|nullptr")) { // Only checking input stream operations is safe here, because otherwise 0 can be an integer as well
Packit 2035a7
                const Token* tok2 = tok->previous(); // Find start of statement
Packit 2035a7
                for (; tok2; tok2 = tok2->previous()) {
Packit 2035a7
                    if (Token::Match(tok2->previous(), ";|{|}|:|("))
Packit 2035a7
                        break;
Packit 2035a7
                }
Packit 2035a7
                if (tok2 && tok2->previous() && tok2->previous()->str()=="(")
Packit 2035a7
                    continue;
Packit 2035a7
                if (Token::simpleMatch(tok2, "std :: cin"))
Packit 2035a7
                    nullPointerError(tok);
Packit 2035a7
                if (tok2 && tok2->varId() != 0) {
Packit 2035a7
                    const Variable *var = tok2->variable();
Packit 2035a7
                    if (var && var->isStlType(stl_istream))
Packit 2035a7
                        nullPointerError(tok);
Packit 2035a7
                }
Packit 2035a7
            }
Packit 2035a7
Packit 2035a7
            const Variable *ovar = nullptr;
Packit 2035a7
            const Token *tokNull = nullptr;
Packit 2035a7
            if (Token::Match(tok, "0|NULL|nullptr ==|!=|>|>=|<|<= %var%")) {
Packit 2035a7
                if (!Token::Match(tok->tokAt(3),".|[")) {
Packit 2035a7
                    ovar = tok->tokAt(2)->variable();
Packit 2035a7
                    tokNull = tok;
Packit 2035a7
                }
Packit 2035a7
            } else if (Token::Match(tok, "%var% ==|!=|>|>=|<|<= 0|NULL|nullptr") ||
Packit 2035a7
                       Token::Match(tok, "%var% =|+ 0|NULL|nullptr )|]|,|;|+")) {
Packit 2035a7
                ovar = tok->variable();
Packit 2035a7
                tokNull = tok->tokAt(2);
Packit 2035a7
            }
Packit 2035a7
            if (ovar && !ovar->isPointer() && !ovar->isArray() && ovar->isStlStringType() && tokNull && tokNull->originalName() != "'\\0'")
Packit 2035a7
                nullPointerError(tokNull);
Packit 2035a7
        }
Packit 2035a7
    }
Packit 2035a7
}
Packit 2035a7
Packit 2035a7
void CheckNullPointer::nullPointerError(const Token *tok, const std::string &varname, const ValueFlow::Value *value, bool inconclusive)
Packit 2035a7
{
Packit 2035a7
    const std::string errmsgcond(ValueFlow::eitherTheConditionIsRedundant(value ? value->condition : nullptr) + " or there is possible null pointer dereference: " + varname + ".");
Packit 2035a7
    const std::string errmsgdefarg("Possible null pointer dereference if the default parameter value is used: " + varname);
Packit 2035a7
Packit 2035a7
    if (!tok) {
Packit 2035a7
        reportError(tok, Severity::error, "nullPointer", "Null pointer dereference", CWE476, false);
Packit 2035a7
        reportError(tok, Severity::warning, "nullPointerDefaultArg", errmsgdefarg, CWE476, false);
Packit 2035a7
        reportError(tok, Severity::warning, "nullPointerRedundantCheck", errmsgcond, CWE476, false);
Packit 2035a7
        return;
Packit 2035a7
    }
Packit 2035a7
Packit 2035a7
    if (!value) {
Packit 2035a7
        reportError(tok, Severity::error, "nullPointer", "Null pointer dereference", CWE476, inconclusive);
Packit 2035a7
        return;
Packit 2035a7
    }
Packit 2035a7
Packit 2035a7
    if (!_settings->isEnabled(value, inconclusive))
Packit 2035a7
        return;
Packit 2035a7
Packit 2035a7
    const ErrorPath errorPath = getErrorPath(tok, value, "Null pointer dereference");
Packit 2035a7
Packit 2035a7
    if (value->condition) {
Packit 2035a7
        reportError(errorPath, Severity::warning, "nullPointerRedundantCheck", errmsgcond, CWE476, inconclusive || value->isInconclusive());
Packit 2035a7
    } else if (value->defaultArg) {
Packit 2035a7
        reportError(errorPath, Severity::warning, "nullPointerDefaultArg", errmsgdefarg, CWE476, inconclusive || value->isInconclusive());
Packit 2035a7
    } else {
Packit 2035a7
        std::string errmsg;
Packit 2035a7
        errmsg = std::string(value->isKnown() ? "Null" : "Possible null") + " pointer dereference";
Packit 2035a7
        if (!varname.empty())
Packit 2035a7
            errmsg += ": " + varname;
Packit 2035a7
Packit 2035a7
        reportError(errorPath,
Packit 2035a7
                    value->isKnown() ? Severity::error : Severity::warning,
Packit 2035a7
                    "nullPointer",
Packit 2035a7
                    errmsg,
Packit 2035a7
                    CWE476, inconclusive || value->isInconclusive());
Packit 2035a7
    }
Packit 2035a7
}
Packit 2035a7
Packit 2035a7
void CheckNullPointer::arithmetic()
Packit 2035a7
{
Packit 2035a7
    const SymbolDatabase *symbolDatabase = _tokenizer->getSymbolDatabase();
Packit 2035a7
    const std::size_t functions = symbolDatabase->functionScopes.size();
Packit 2035a7
    for (std::size_t i = 0; i < functions; ++i) {
Packit 2035a7
        const Scope * scope = symbolDatabase->functionScopes[i];
Packit 2035a7
        for (const Token* tok = scope->classStart->next(); tok != scope->classEnd; tok = tok->next()) {
Packit 2035a7
            if (!tok->astOperand2() || tok->str() != "-")
Packit 2035a7
                continue;
Packit 2035a7
            // pointer subtraction
Packit 2035a7
            if (!tok->valueType() || !tok->valueType()->pointer)
Packit 2035a7
                continue;
Packit 2035a7
            // Can LHS be NULL?
Packit 2035a7
            const ValueFlow::Value *value = tok->astOperand1()->getValue(0);
Packit 2035a7
            if (!value)
Packit 2035a7
                continue;
Packit 2035a7
            if (!_settings->inconclusive && value->isInconclusive())
Packit 2035a7
                continue;
Packit 2035a7
            if (value->condition && !_settings->isEnabled(Settings::WARNING))
Packit 2035a7
                continue;
Packit 2035a7
            arithmeticError(tok,value);
Packit 2035a7
        }
Packit 2035a7
    }
Packit 2035a7
}
Packit 2035a7
Packit 2035a7
void CheckNullPointer::arithmeticError(const Token *tok, const ValueFlow::Value *value)
Packit 2035a7
{
Packit 2035a7
    std::string errmsg;
Packit 2035a7
    if (value && value->condition)
Packit 2035a7
        errmsg = ValueFlow::eitherTheConditionIsRedundant(value->condition) + " or there is overflow in pointer subtraction.";
Packit 2035a7
    else
Packit 2035a7
        errmsg = "Overflow in pointer arithmetic, NULL pointer is subtracted.";
Packit 2035a7
Packit 2035a7
    std::list<const Token*> callstack;
Packit 2035a7
    callstack.push_back(tok);
Packit 2035a7
    if (value && value->condition)
Packit 2035a7
        callstack.push_back(value->condition);
Packit 2035a7
Packit 2035a7
    reportError(callstack,
Packit 2035a7
                (value && value->condition) ? Severity::warning : Severity::error,
Packit 2035a7
                (value && value->condition) ? "nullPointerArithmeticRedundantCheck" : "nullPointerArithmetic",
Packit 2035a7
                errmsg,
Packit 2035a7
                CWE682, // unknown - pointer overflow
Packit 2035a7
                value && value->isInconclusive());
Packit 2035a7
}