From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from NAM02-BN1-obe.outbound.protection.outlook.com (mail-bn1nam07olkn2070.outbound.protection.outlook.com [40.92.15.70]) by sourceware.org (Postfix) with ESMTPS id E9D933858281 for ; Tue, 19 Jul 2022 16:06:53 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.1 sourceware.org E9D933858281 ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=RMpBPhA8+p9vja/CGa+px5W6nR4Yt17A6LKkgbG2bLwhzCHX5Q6XHUY65JQ+TgAa6ATl8+Z8YAzELlhT4bXuyCOIMV1O/tO6oTzfkknePqLhbrmXqe6XUa7jkWJn1WqEQt2Py486EV4/gK8lGTWLlMjqNCqSjTev3NqtyHQy7qYnDzIHzrjhNJXZcyG7Sjhx+Zu7Z//JKVI/oKJqhk+hkwOxo0daKD7IcLAHFttfZ4wj3Gm+kM1xwxD7WAy/X6zA4i/dOP6IrN7dNV8qTkTsHvw+JqASQPHCEQR/7Wq/HmU0zTE7ljTMipAIKpy2mstVu6dGWx6rVFyHpIXSjY2n1g== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=nsPEZsnXhDRTfBPY4kMV7ma1t4w06YNPuAi3+JuLEW8=; b=F65L1WXPES9f4VOSRdR/14Wtut3kedbNJ9nkSe1cLyYf5skSwwF4KuqZji4W71sF+H08BCxbngalBaUdzjm/R5rSzxLWIroS10HoNaKLoALTljy4dVh2eBocOcv7aiK1N/QKNOOjxH51CEh826NxFDGBUCBtGC2FC/LGMBuD9LUGHizFli3aEV464tiaA1V3pyVOdsNoOW6HkHoSbPnZS4uZqM2hfmA+ZTucvkgUI1kPAm10tYFO/QD5zOd80Mz8v7AIDoJlNnIpHn3gaoc5HymDHlHWDhMxxK+O15QpmCIWHZz8BHRypr4Wdy7r7mWy+KqD843nAtebGr7H3WcQ6w== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none; dkim=none; arc=none Received: from CY4PR1801MB1910.namprd18.prod.outlook.com (2603:10b6:910:79::14) by MN2PR18MB2767.namprd18.prod.outlook.com (2603:10b6:208:39::31) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5438.23; Tue, 19 Jul 2022 16:06:51 +0000 Received: from CY4PR1801MB1910.namprd18.prod.outlook.com ([fe80::4d74:63e5:d5ee:3647]) by CY4PR1801MB1910.namprd18.prod.outlook.com ([fe80::4d74:63e5:d5ee:3647%2]) with mapi id 15.20.5438.021; Tue, 19 Jul 2022 16:06:51 +0000 From: Immad Mir To: gcc-patches@gcc.gnu.org Cc: dmalcolm@redhat.com, mirimnan017@gmail.com, Immad Mir Subject: [PATCH] Adding three new function attributes for static analysis of file descriptors Date: Tue, 19 Jul 2022 21:36:25 +0530 Message-ID: X-Mailer: git-send-email 2.25.1 Reply-To: mirimnan017@gmail.com Content-Transfer-Encoding: quoted-printable Content-Type: text/plain X-TMN: [tKxzrM9jg/dSo9gzmHRWkEXQEYoDVuoDnwquLg67pRO6hBJHVBfjJSYFNGVd3tdX] X-ClientProxiedBy: PN0PR01CA0035.INDPRD01.PROD.OUTLOOK.COM (2603:1096:c01:4e::10) To CY4PR1801MB1910.namprd18.prod.outlook.com (2603:10b6:910:79::14) X-Microsoft-Original-Message-ID: <20220719160625.4892-1-mirimmad@outlook.com> MIME-Version: 1.0 X-MS-Exchange-MessageSentRepresentingType: 1 X-MS-PublicTrafficType: Email X-MS-Office365-Filtering-Correlation-Id: 4cf08835-c773-48cc-f4e8-08da69a0b0ad X-MS-Exchange-SLBlob-MailProps: LzDHi3doVoJyICjK/lhaG5LAoOU+C89dhlrgGX533YhMPcLCC0P0QsfpDEoCGlgu02kKDr4I9JYHIRpgtV0mTMzgmMW0p6PGd7RwoNUK+VNc1OSUGEcnDfAjPwvHN4qwpl9NycQZ6W7naudGhSFTSlJlmtfmS3W1IR/uWrzIhqJJP7Ixgq16D91oYvEyCVWeMNxVOAXVrmA+h75gUillTqoH7Q34uvv+VdBvT4/5HWITCf4B13cS3bZ1//aUqZG0isMX/ew+guvh+SNCaHrmphH++NkqbyVFvV9Xff17O5eGcTWgxjlwForse/m4vqavV/FngJogUIi6VcWJsgLUZbt+SekUEK4XDRv9BN44ApyhlCxThAkAipkctV++6k9E4WFnvnjMN0tRtwFzUr+1vmjkLXBlkSC322jnOKilxgcKmJkr/QgW8k9Nh0ijpAUu8jgLb3dRjlToNQ62LhSi/HUSqiLnSzlElXnwjXII9Y/zexrue67D4usKuaU7utvA9SDB+xDhlPZshPpuND2B8PEnKdCcwXj2UwyZn1AUWc58CLs+f2wDpYoR7QeB1o+2LgsDdaE4Y2t3tJ4qEVQsko4WXIrgCZzhviu1NrHQQarZ57hYM8s0C/YdJF4gWw1gofKnlxA6JYeFRgKhvQMXJpddawOy7CQfGxrid2TAjAmtgqlcVi9SQ64Qi6sXnYfkKsncDZh9cvNfxG9N7y6Sc2hstazYpBL8M62Q0zG4LyI= X-MS-TrafficTypeDiagnostic: MN2PR18MB2767:EE_ X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: nbirBmT2ntClVGq81ahpZsssAY6XGpB+g0oFaMr1O13KphQv7OX2ZUQ8T8fPNeUFkYNpdXTFwA1veea+l/T+YuWg1Fi1VCUe4y0VJh2lbVx8qAFKukV1y9+aVnhLvzYiux8SI/BKl6t8gEohz6OfYsg8QqImo8oqe4FoiJd7InrseT6jN6oJI14fG/rm+0AQ+43MMYpvL/pqNxyR9YEowJdZC1OToas7W1Ry6EUsf5Nbmo7+YZTTvsAvz5iAKAYTwfJtwo33scPKx+r3X0fPBc7Il9u/R6nPMP9Ku4puTdKR2jiyGWIbTowBxiETK2n0GAc4GZuqZHOUoIjKO/IKiJtmgA+/P8NFfv1eHrXTHCacv0HdzZM1xd/H8f1yX2m0RzZlv5ddWEuc5q+sbTM503ZOU/oNoobDdSc919Aj2elrrYy7GleNPZU6i01zVm1uDKv3TH09/MNIgN2JQo2zyITsN51JxCF4zFsKZ+hAwBylK81UKDDk1Re82IRv4azVn7LL2Nfo58iwjkBcDLddK9gE85pGNhWBnTHOV7Gs+EaXaJjtGlb6+Isos7UdEPyvJfbdgOh7gRxCpCp2R7ApBOCtsPhKfuwl1egDLUdDe+8sWW5KYYRfc2ZNxHAcYRhc X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?us-ascii?Q?r2SgJV+xQqAk70rr2ua5EpftboSwiJMMDS/xg1vySu6x254VfFdakaturVMo?= =?us-ascii?Q?pJ98ZetJx2MywHwNtP/1KwEfhhbYlFvoVKYrL6VmSXAFiNE+tixbl0xo/VOP?= =?us-ascii?Q?YZ5hknQkY5l1xJfKFXzCfdMmIC7ndNApMzzUtL03gg+53bZlwpNIB5B7O5bU?= =?us-ascii?Q?e0BJzz15vN4MKPZI4UvOVK1mMHQ2tEO5bw+5OqMso9qZ12utGEGcXCVkiw34?= =?us-ascii?Q?j5yUwzr2+mfsdr6zpk1w0zybnHCyDYqbqj6hxPWr4e9IyszErrUxQ3iKP2cM?= =?us-ascii?Q?zpM6ZmSrHYlP9ctBUCV4SRQFtdUnd+JW3wM3SnjDuXdovXRQvfkpuRuNv5kk?= =?us-ascii?Q?4GLJIga4gozOImboOj1ttecG7uM2iEX1LYEPZm38uFWhDuOH6Hjvnlwhlaaa?= =?us-ascii?Q?2lkthwK8/2PgrcNy+A8w62ExXvxPQOa7VxiWqaZiPYBus2mIoIeEsh3gRMIv?= =?us-ascii?Q?k8a8Cxi89lxKr+LqzitJs0JrKfedBgVHLKAOxDRFbXGg9KQKFxMx80v1D5Hd?= =?us-ascii?Q?gtutkUWigmJpXJIONfAc047u41xKgfNjOczm1NofdnwSodZwGPtzsAZIK5/1?= =?us-ascii?Q?4+QORCpej/Gp3owWbVk7ehCsYfnFCDT6hMT/NV2jUZWyKvsRdFbLxPBIIoAr?= =?us-ascii?Q?YSjisIYSviEChcLQ5Q1l/4T8DQ4SKBjdcsbN08Y5eFEXYbQ1Byu2xs8iWUaZ?= =?us-ascii?Q?Zbr49rPWf78iq7L0rhJRaarEvtrhiGSjmzQNL541STgQmuXwiE+b5UXvhfn9?= =?us-ascii?Q?FPdYlbFvuApAulj0KJDcpIvdeQgECvlHfdhM+Zj5OPmdFnH6GmlFKG2rAyCW?= =?us-ascii?Q?UCV98Lwql6b4MwntTFhtsbvriWkiWSRewuCU9K0A+exKj22ket1/FfvUWKji?= =?us-ascii?Q?s81rW4EdgN9Wo/ktrt+jUZ62rOmdW5dP7mUg1ea9O8EwFHAO8DpWJfuRW9Ly?= =?us-ascii?Q?TetMihhrVEo/4vL3rrPYnqtA7A2HBZiT9UyumbIa/7NH+70eXBZ59t02U3P/?= =?us-ascii?Q?T1Hbu1rIn4pQc7Myw8vtKml5Da1OZNJLzTIuJCJkdGu1EPPe7CwII9z65AcW?= =?us-ascii?Q?ohGcz20utKOQdtAH+tCuRAqd/0htLnouG3q1EaRj+SD2ncecpBINSUcSd3Z2?= =?us-ascii?Q?VLQaz+33jK8XjLkF/SMEOkfczbRrkEeTLRjvsec9CcAjvlc8M4KsiV3VLLCg?= =?us-ascii?Q?5GExDG7Ncm4ohsdRFyXdbJEQuVJpIvhWNbdzOZxWu/Upb5VuIOKxxMXhVlBr?= =?us-ascii?Q?lvzWETzAdqEvrql6bIWaBXnzLLAXc0+VuyrSbTXAHTU2eseJFvuA7TJBbdVJ?= =?us-ascii?Q?u4QLLNhGpsIa6typYbcqo9N0WX3H79TDEt6swUSaIbYdfg=3D=3D?= X-OriginatorOrg: outlook.com X-MS-Exchange-CrossTenant-Network-Message-Id: 4cf08835-c773-48cc-f4e8-08da69a0b0ad X-MS-Exchange-CrossTenant-AuthSource: CY4PR1801MB1910.namprd18.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 19 Jul 2022 16:06:51.2939 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: 00000000-0000-0000-0000-000000000000 X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN2PR18MB2767 X-Spam-Status: No, score=-12.0 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, FREEMAIL_FROM, FREEMAIL_REPLYTO, FREEMAIL_REPLYTO_END_DIGIT, GIT_PATCH_0, RCVD_IN_DNSWL_NONE, SPF_HELO_PASS, SPF_PASS, TXREP, T_FILL_THIS_FORM_SHORT autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on server2.sourceware.org X-BeenThere: gcc-patches@gcc.gnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Gcc-patches mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 19 Jul 2022 16:06:57 -0000 This patch adds three new function attributes to GCC that are used for static analysis of usage of file descriptors: 1) __attribute__ ((fd_arg(N))): The attributes may be applied to a function= that takes on open file descriptor at refrenced argument N. It indicates that the passed filedescriptor must not have been closed. Therefore, when the analyzer is enabled with -fanalyzer, the analyzer may emit a -Wanalyzer-fd-use-after-close diagnostic if it detects a code path in which a function with this attribute is called with a closed file descriptor. The attribute also indicates that the file descriptor must have been checke= d for validity before usage. Therefore, analyzer may emit -Wanalyzer-fd-use-without-check diagnostic if it detects a code path in which a function with this attribute is called with a file descriptor that = has not been checked for validity. 2) __attribute__((fd_arg_read(N))): The attribute is identical to fd_arg, but with the additional requirement that it might read from the file descriptor, and thus, the file descriptor must not have been opened as write-only. The analyzer may emit a -Wanalyzer-access-mode-mismatch diagnostic if it detects a code path in which a function with this attribute is called on a file descriptor opened with O_WRONLY. 3) __attribute__((fd_arg_write(N))): The attribute is identical to fd_arg_r= ead except that the analyzer may emit a -Wanalyzer-access-mode-mismatch diagnos= tic if it detects a code path in which a function with this attribute is called on= a file descriptor opened with O_RDONLY. gcc/analyzer/ChangeLog: * sm-fd.cc (fd_param_diagnostic): New diagnostic class. (fd_access_mode_mismatch): Change inheritance from fd_diagnostic to fd_param_diagnostic. Add new overloaded constructor. (fd_use_after_close): Likewise. (unchecked_use_of_fd): Likewise and also change name to fd_use_without_che= ck. (double_close): Change name to fd_double_close. (enum access_directions): New. (fd_state_machine::on_stmt): Handle calls to function with the new three function attributes. (fd_state_machine::check_for_fd_attrs): New. (fd_state_machine::on_open): Use the new overloaded constructors of diagnostic classes. gcc/c-family/ChangeLog: * c-attribs.cc: (c_common_attribute_table): add three new attributes namely: fd_arg, fd_arg_read and fd_arg_write. (handle_fd_arg_attribute): New. gcc/ChangeLog: * doc/extend.texi: Add fd_arg, fd_arg_read and fd_arg_write under "Common Function Attributes" section. gcc/testsuite/ChangeLog: * gcc.dg/analyzer/fd-5.c: New test. * c-c++-common/attr-fd.c: New test. Signed-off-by: Immad Mir --- gcc/analyzer/sm-fd.cc | 323 +++++++++++++++++++++------ gcc/c-family/c-attribs.cc | 36 ++- gcc/doc/extend.texi | 34 +++ gcc/testsuite/c-c++-common/attr-fd.c | 18 ++ gcc/testsuite/gcc.dg/analyzer/fd-5.c | 53 +++++ 5 files changed, 398 insertions(+), 66 deletions(-) create mode 100644 gcc/testsuite/c-c++-common/attr-fd.c create mode 100644 gcc/testsuite/gcc.dg/analyzer/fd-5.c diff --git a/gcc/analyzer/sm-fd.cc b/gcc/analyzer/sm-fd.cc index 8e4300b06e2..c577a7db7ea 100644 --- a/gcc/analyzer/sm-fd.cc +++ b/gcc/analyzer/sm-fd.cc @@ -39,10 +39,13 @@ along with GCC; see the file COPYING3. If not see #include "analyzer/analyzer-selftests.h"=0D #include "tristate.h"=0D #include "selftest.h"=0D +#include "stringpool.h"=0D +#include "attribs.h"=0D #include "analyzer/call-string.h"=0D #include "analyzer/program-point.h"=0D #include "analyzer/store.h"=0D #include "analyzer/region-model.h"=0D +#include "bitmap.h"=0D =0D #if ENABLE_ANALYZER=0D =0D @@ -59,6 +62,13 @@ enum access_mode WRITE_ONLY=0D };=0D =0D +enum access_directions=0D +{=0D + DIRS_READ_WRITE,=0D + DIRS_READ,=0D + DIRS_WRITE=0D +};=0D +=0D class fd_state_machine : public state_machine=0D {=0D public:=0D @@ -146,7 +156,7 @@ private: void check_for_open_fd (sm_context *sm_ctxt, const supernode *node,=0D const gimple *stmt, const gcall *call,=0D const tree callee_fndecl,=0D - enum access_direction access_fn) const;=0D + enum access_directions access_fn) const;=0D =0D void make_valid_transitions_on_condition (sm_context *sm_ctxt,=0D const supernode *node,=0D @@ -156,12 +166,17 @@ private: const supernode *node,=0D const gimple *stmt,=0D const svalue *lhs) const;=0D + void check_for_fd_attrs (sm_context *sm_ctxt, const supernode *node,=0D + const gimple *stmt, const tree callee_fndecl,=0D + const char *attr_name,=0D + access_directions fd_attr_access_dir) const;=0D +=0D };=0D =0D /* Base diagnostic class relative to fd_state_machine. */=0D class fd_diagnostic : public pending_diagnostic=0D {=0D -public:=0D +public: =0D fd_diagnostic (const fd_state_machine &sm, tree arg) : m_sm (sm), m_arg = (arg)=0D {=0D }=0D @@ -220,6 +235,65 @@ protected: tree m_arg;=0D };=0D =0D +class fd_param_diagnostic : public fd_diagnostic=0D +{=0D +public:=0D + fd_param_diagnostic (const fd_state_machine &sm, tree arg, tree callee_f= ndecl,=0D + bool attr, int arg_idx)=0D + : fd_diagnostic (sm, arg), m_callee_fndecl (callee_fndecl), m_attr (= attr),=0D + m_arg_idx (arg_idx)=0D + {=0D + }=0D +=0D + fd_param_diagnostic (const fd_state_machine &sm, tree arg, tree callee_f= ndecl)=0D + : fd_diagnostic (sm, arg), m_callee_fndecl (callee_fndecl),=0D + m_attr (false), m_arg_idx (-1)=0D + {=0D + }=0D + =0D + bool=0D + subclass_equal_p (const pending_diagnostic &base_other) const override=0D + {=0D + const fd_param_diagnostic &sub_other=0D + =3D (const fd_param_diagnostic &)base_other;=0D + return (same_tree_p (m_arg, sub_other.m_arg)=0D + && m_callee_fndecl =3D=3D sub_other.m_callee_fndecl=0D + && m_attr =3D=3D sub_other.m_attr=0D + && m_arg_idx =3D=3D sub_other.m_arg_idx);=0D + }=0D +=0D + void=0D + inform_filedescriptor_attribute (access_directions fd_dir)=0D + {=0D +=0D + if (m_attr)=0D + switch (fd_dir)=0D + {=0D + case DIRS_READ_WRITE:=0D + inform (DECL_SOURCE_LOCATION (m_callee_fndecl),=0D + "argument %d of %qD must be an open file descriptor",=0D + m_arg_idx + 1, m_callee_fndecl);=0D + break;=0D + case DIRS_WRITE:=0D + inform (DECL_SOURCE_LOCATION (m_callee_fndecl),=0D + "argument %d of %qD must be a read-only file descriptor"= ,=0D + m_arg_idx + 1, m_callee_fndecl);=0D + break;=0D + case DIRS_READ:=0D + inform (DECL_SOURCE_LOCATION (m_callee_fndecl),=0D + "argument %d of %qD must be a write-only file descriptor= ",=0D + m_arg_idx + 1, m_callee_fndecl);=0D + break;=0D + }=0D + }=0D +=0D +protected:=0D + tree m_callee_fndecl;=0D + bool m_attr;=0D + /* ARG_IDX is 0-based. */=0D + int m_arg_idx;=0D +};=0D +=0D class fd_leak : public fd_diagnostic=0D {=0D public:=0D @@ -290,18 +364,25 @@ private: diagnostic_event_id_t m_open_event;=0D };=0D =0D -class fd_access_mode_mismatch : public fd_diagnostic=0D +class fd_access_mode_mismatch : public fd_param_diagnostic=0D {=0D public:=0D fd_access_mode_mismatch (const fd_state_machine &sm, tree arg,=0D - enum access_direction fd_dir,=0D - const tree callee_fndecl)=0D - : fd_diagnostic (sm, arg), m_fd_dir (fd_dir),=0D - m_callee_fndecl (callee_fndecl)=0D + enum access_directions fd_dir,=0D + const tree callee_fndecl, bool attr, int arg_id= x)=0D + : fd_param_diagnostic (sm, arg, callee_fndecl, attr, arg_idx),=0D + m_fd_dir (fd_dir)=0D =0D {=0D }=0D =0D + fd_access_mode_mismatch (const fd_state_machine &sm, tree arg,=0D + enum access_directions fd_dir,=0D + const tree callee_fndecl)=0D + : fd_param_diagnostic (sm, arg, callee_fndecl), m_fd_dir (fd_dir)=0D + {=0D + }=0D + =0D const char *=0D get_kind () const final override=0D {=0D @@ -317,29 +398,25 @@ public: bool=0D emit (rich_location *rich_loc) final override=0D {=0D + bool warned;=0D switch (m_fd_dir)=0D {=0D - case DIR_READ:=0D - return warning_at (rich_loc, get_controlling_option (),=0D + case DIRS_READ:=0D + warned =3D warning_at (rich_loc, get_controlling_option (),=0D "%qE on % file descriptor %qE",=0D m_callee_fndecl, m_arg);=0D - case DIR_WRITE:=0D - return warning_at (rich_loc, get_controlling_option (),=0D + break;=0D + case DIRS_WRITE:=0D + warned =3D warning_at (rich_loc, get_controlling_option (),=0D "%qE on % file descriptor %qE",=0D m_callee_fndecl, m_arg);=0D + break;=0D default:=0D gcc_unreachable ();=0D }=0D - }=0D -=0D - bool=0D - subclass_equal_p (const pending_diagnostic &base_other) const override=0D - {=0D - const fd_access_mode_mismatch &sub_other=0D - =3D (const fd_access_mode_mismatch &)base_other;=0D - return (same_tree_p (m_arg, sub_other.m_arg)=0D - && m_callee_fndecl =3D=3D sub_other.m_callee_fndecl=0D - && m_fd_dir =3D=3D sub_other.m_fd_dir);=0D + if (warned)=0D + inform_filedescriptor_attribute (m_fd_dir);=0D + return warned;=0D }=0D =0D label_text=0D @@ -347,10 +424,10 @@ public: {=0D switch (m_fd_dir)=0D {=0D - case DIR_READ:=0D + case DIRS_READ:=0D return ev.formatted_print ("%qE on % file descriptor %= qE",=0D m_callee_fndecl, m_arg);=0D - case DIR_WRITE:=0D + case DIRS_WRITE:=0D return ev.formatted_print ("%qE on % file descriptor = %qE",=0D m_callee_fndecl, m_arg);=0D default:=0D @@ -359,21 +436,20 @@ public: }=0D =0D private:=0D - enum access_direction m_fd_dir;=0D - const tree m_callee_fndecl;=0D + enum access_directions m_fd_dir;=0D };=0D =0D -class double_close : public fd_diagnostic=0D +class fd_double_close : public fd_diagnostic=0D {=0D public:=0D - double_close (const fd_state_machine &sm, tree arg) : fd_diagnostic (sm,= arg)=0D + fd_double_close (const fd_state_machine &sm, tree arg) : fd_diagnostic (= sm, arg)=0D {=0D }=0D =0D const char *=0D get_kind () const final override=0D {=0D - return "double_close";=0D + return "fd_double_close";=0D }=0D =0D int=0D @@ -418,12 +494,18 @@ private: diagnostic_event_id_t m_first_close_event;=0D };=0D =0D -class fd_use_after_close : public fd_diagnostic=0D +class fd_use_after_close : public fd_param_diagnostic=0D {=0D public:=0D + fd_use_after_close (const fd_state_machine &sm, tree arg,=0D + const tree callee_fndecl, bool attr, int arg_idx)=0D + : fd_param_diagnostic(sm, arg, callee_fndecl, attr, arg_idx)=0D + {=0D + }=0D +=0D fd_use_after_close (const fd_state_machine &sm, tree arg,=0D const tree callee_fndecl)=0D - : fd_diagnostic (sm, arg), m_callee_fndecl (callee_fndecl)=0D + : fd_param_diagnostic(sm, arg, callee_fndecl)=0D {=0D }=0D =0D @@ -442,9 +524,13 @@ public: bool=0D emit (rich_location *rich_loc) final override=0D {=0D - return warning_at (rich_loc, get_controlling_option (),=0D + bool warned;=0D + warned =3D warning_at (rich_loc, get_controlling_option (),=0D "%qE on closed file descriptor %qE", m_callee_fndec= l,=0D m_arg);=0D + if (warned)=0D + inform_filedescriptor_attribute (DIRS_READ_WRITE);=0D + return warned;=0D }=0D =0D label_text=0D @@ -466,32 +552,37 @@ public: describe_final_event (const evdesc::final_event &ev) final override=0D {=0D if (m_first_close_event.known_p ())=0D - return ev.formatted_print (=0D - "%qE on closed file descriptor %qE; %qs was at %@", m_callee_fnd= ecl,=0D - m_arg, "close", &m_first_close_event);=0D - else=0D - return ev.formatted_print ("%qE on closed file descriptor %qE",=0D - m_callee_fndecl, m_arg);=0D + return ev.formatted_print (=0D + "%qE on closed file descriptor %qE; %qs was at %@", m_callee_f= ndecl,=0D + m_arg, "close", &m_first_close_event);=0D + else=0D + return ev.formatted_print ("%qE on closed file descriptor %qE",=0D + m_callee_fndecl, m_arg);=0D }=0D =0D private:=0D diagnostic_event_id_t m_first_close_event;=0D - const tree m_callee_fndecl;=0D };=0D =0D -class unchecked_use_of_fd : public fd_diagnostic=0D +class fd_use_without_check : public fd_param_diagnostic=0D {=0D public:=0D - unchecked_use_of_fd (const fd_state_machine &sm, tree arg,=0D + fd_use_without_check (const fd_state_machine &sm, tree arg,=0D + const tree callee_fndecl, bool attr, int arg_idx)=0D + : fd_param_diagnostic(sm, arg, callee_fndecl, attr, arg_idx)=0D + {=0D + }=0D +=0D + fd_use_without_check (const fd_state_machine &sm, tree arg,=0D const tree callee_fndecl)=0D - : fd_diagnostic (sm, arg), m_callee_fndecl (callee_fndecl)=0D + : fd_param_diagnostic(sm, arg, callee_fndecl)=0D {=0D }=0D =0D const char *=0D get_kind () const final override=0D {=0D - return "unchecked_use_of_fd";=0D + return "fd_use_without_check";=0D }=0D =0D int=0D @@ -503,18 +594,12 @@ public: bool=0D emit (rich_location *rich_loc) final override=0D {=0D - return warning_at (rich_loc, get_controlling_option (),=0D - "%qE on possibly invalid file descriptor %qE",=0D - m_callee_fndecl, m_arg);=0D - }=0D -=0D - bool=0D - subclass_equal_p (const pending_diagnostic &base_other) const override=0D - {=0D - const unchecked_use_of_fd &sub_other=0D - =3D (const unchecked_use_of_fd &)base_other;=0D - return (same_tree_p (m_arg, sub_other.m_arg)=0D - && m_callee_fndecl =3D=3D sub_other.m_callee_fndecl);=0D + bool warned;=0D + warned =3D warning_at (rich_loc, get_controlling_option (),=0D + "%qE on possibly invalid file descriptor %qE",=0D + m_callee_fndecl, m_arg);=0D + if (warned)=0D + inform_filedescriptor_attribute (DIRS_READ_WRITE);=0D }=0D =0D label_text=0D @@ -542,7 +627,7 @@ public: =0D private:=0D diagnostic_event_id_t m_first_open_event;=0D - const tree m_callee_fndecl;=0D + =0D };=0D =0D fd_state_machine::fd_state_machine (logger *logger)=0D @@ -647,11 +732,119 @@ fd_state_machine::on_stmt (sm_context *sm_ctxt, cons= t supernode *node, on_read (sm_ctxt, node, stmt, call, callee_fndecl);=0D return true;=0D } // "read"=0D +=0D + =0D + {=0D + // Handle __attribute__((fd_arg))=0D + =0D + check_for_fd_attrs (sm_ctxt, node, stmt, callee_fndecl, "fd_ar= g", DIRS_READ_WRITE);=0D + =0D + // Handle __attribute__((fd_arg_read))=0D + =0D + check_for_fd_attrs (sm_ctxt, node, stmt, callee_fndecl, "fd_ar= g_read", DIRS_READ);=0D + =0D + // Handle __attribute__((fd_arg_write))=0D + =0D + check_for_fd_attrs (sm_ctxt, node, stmt, callee_fndecl, "fd_ar= g_write", DIRS_WRITE);=0D + =0D + return true;=0D + }=0D + =0D }=0D =0D return false;=0D }=0D =0D +void=0D +fd_state_machine::check_for_fd_attrs (=0D + sm_context *sm_ctxt, const supernode *node, const gimple *stmt,=0D + const tree callee_fndecl, const char *attr_name,=0D + access_directions fd_attr_access_dir) const=0D +{=0D +=0D + tree attrs =3D TYPE_ATTRIBUTES (TREE_TYPE (callee_fndecl));=0D + attrs =3D lookup_attribute (attr_name, attrs);=0D + if (!attrs)=0D + return;=0D +=0D + if (!TREE_VALUE (attrs))=0D + return;=0D +=0D + auto_bitmap argmap;=0D +=0D + for (tree idx =3D TREE_VALUE (attrs); idx; idx =3D TREE_CHAIN (idx))=0D + {=0D + unsigned int val =3D TREE_INT_CST_LOW (TREE_VALUE (idx)) - 1;=0D + bitmap_set_bit (argmap, val);=0D + }=0D + if (bitmap_empty_p (argmap))=0D + return;=0D +=0D + for (unsigned i =3D 0; i < gimple_call_num_args (stmt); i++)=0D + {=0D +=0D + unsigned int arg_idx =3D i;=0D + tree arg =3D gimple_call_arg (stmt, arg_idx);=0D + tree diag_arg =3D sm_ctxt->get_diagnostic_tree (arg);=0D + state_t state =3D sm_ctxt->get_state (stmt, arg);=0D + bool bit_set =3D bitmap_bit_p (argmap, arg_idx);=0D + if (TREE_CODE (TREE_TYPE (arg)) !=3D INTEGER_TYPE)=0D + continue;=0D + if (bit_set) // Check if arg_idx is marked by any of the file descri= ptor=0D + // attributes=0D + {=0D +=0D + if (is_closed_fd_p (state))=0D + {=0D +=0D + sm_ctxt->warn (node, stmt, arg,=0D + new fd_use_after_close (*this, diag_arg,=0D + callee_fndecl, true,= =0D + arg_idx));=0D + continue;=0D + }=0D +=0D + if (!(is_valid_fd_p (state) || (state =3D=3D m_stop)))=0D + {=0D + if (!is_constant_fd_p (state))=0D + sm_ctxt->warn (node, stmt, arg,=0D + new fd_use_without_check (*this, diag_arg,= =0D + callee_fndecl, tru= e,=0D + arg_idx));=0D + }=0D +=0D + switch (fd_attr_access_dir)=0D + {=0D + case DIRS_READ_WRITE:=0D + break;=0D + case DIRS_READ:=0D +=0D + if (is_writeonly_fd_p (state))=0D + {=0D + sm_ctxt->warn (=0D + node, stmt, arg,=0D + new fd_access_mode_mismatch (*this, diag_arg, DIRS_W= RITE,=0D + callee_fndecl, true, i)= );=0D + }=0D +=0D + break;=0D + case DIRS_WRITE:=0D +=0D + if (is_readonly_fd_p (state))=0D + {=0D + sm_ctxt->warn (=0D + node, stmt, arg,=0D + new fd_access_mode_mismatch (*this, diag_arg, DIRS_R= EAD,=0D + callee_fndecl, true, i)= );=0D + }=0D +=0D + break;=0D + }=0D + }=0D + }=0D +}=0D +=0D +=0D void=0D fd_state_machine::on_open (sm_context *sm_ctxt, const supernode *node,=0D const gimple *stmt, const gcall *call) const=0D @@ -706,7 +899,7 @@ fd_state_machine::on_close (sm_context *sm_ctxt, const = supernode *node, =0D if (is_closed_fd_p (state))=0D {=0D - sm_ctxt->warn (node, stmt, arg, new double_close (*this, diag_arg));= =0D + sm_ctxt->warn (node, stmt, arg, new fd_double_close (*this, diag_arg= ));=0D sm_ctxt->set_next_state (stmt, arg, m_stop);=0D }=0D }=0D @@ -715,21 +908,21 @@ fd_state_machine::on_read (sm_context *sm_ctxt, const= supernode *node, const gimple *stmt, const gcall *call,=0D const tree callee_fndecl) const=0D {=0D - check_for_open_fd (sm_ctxt, node, stmt, call, callee_fndecl, DIR_READ);= =0D + check_for_open_fd (sm_ctxt, node, stmt, call, callee_fndecl, DIRS_READ);= =0D }=0D void=0D fd_state_machine::on_write (sm_context *sm_ctxt, const supernode *node,=0D const gimple *stmt, const gcall *call,=0D const tree callee_fndecl) const=0D {=0D - check_for_open_fd (sm_ctxt, node, stmt, call, callee_fndecl, DIR_WRITE);= =0D + check_for_open_fd (sm_ctxt, node, stmt, call, callee_fndecl, DIRS_WRITE)= ;=0D }=0D =0D void=0D fd_state_machine::check_for_open_fd (=0D sm_context *sm_ctxt, const supernode *node, const gimple *stmt,=0D const gcall *call, const tree callee_fndecl,=0D - enum access_direction callee_fndecl_dir) const=0D + enum access_directions callee_fndecl_dir) const=0D {=0D tree arg =3D gimple_call_arg (call, 0);=0D tree diag_arg =3D sm_ctxt->get_diagnostic_tree (arg);=0D @@ -748,30 +941,32 @@ fd_state_machine::check_for_open_fd ( if (!is_constant_fd_p (state))=0D sm_ctxt->warn (=0D node, stmt, arg,=0D - new unchecked_use_of_fd (*this, diag_arg, callee_fndecl));= =0D + new fd_use_without_check (*this, diag_arg, callee_fndecl))= ;=0D }=0D switch (callee_fndecl_dir)=0D {=0D - case DIR_READ:=0D + case DIRS_READ:=0D if (is_writeonly_fd_p (state))=0D {=0D tree diag_arg =3D sm_ctxt->get_diagnostic_tree (arg);=0D sm_ctxt->warn (node, stmt, arg,=0D new fd_access_mode_mismatch (=0D - *this, diag_arg, DIR_WRITE, callee_fndecl= ));=0D + *this, diag_arg, DIRS_WRITE, callee_fndec= l));=0D }=0D =0D break;=0D - case DIR_WRITE:=0D + case DIRS_WRITE:=0D =0D if (is_readonly_fd_p (state))=0D {=0D tree diag_arg =3D sm_ctxt->get_diagnostic_tree (arg);=0D sm_ctxt->warn (node, stmt, arg,=0D new fd_access_mode_mismatch (=0D - *this, diag_arg, DIR_READ, callee_fndecl)= );=0D + *this, diag_arg, DIRS_READ, callee_fndecl= ));=0D }=0D break;=0D + default:=0D + gcc_unreachable ();=0D }=0D }=0D }=0D diff --git a/gcc/c-family/c-attribs.cc b/gcc/c-family/c-attribs.cc index c8d96723f4c..a04cc541f95 100644 --- a/gcc/c-family/c-attribs.cc +++ b/gcc/c-family/c-attribs.cc @@ -173,6 +173,7 @@ static tree handle_objc_nullability_attribute (tree *, = tree, tree, int, bool *); static tree handle_signed_bool_precision_attribute (tree *, tree, tree, in= t, bool *); static tree handle_retain_attribute (tree *, tree, tree, int, bool *); +static tree handle_fd_arg_attribute (tree *, tree, tree, int, bool *); =20 /* Helper to define attribute exclusions. */ #define ATTR_EXCL(name, function, type, variable) \ @@ -426,7 +427,7 @@ const struct attribute_spec c_common_attribute_table[] = =3D { "tls_model", 1, 1, true, false, false, false, handle_tls_model_attribute, NULL }, { "nonnull", 0, -1, false, true, true, false, - handle_nonnull_attribute, NULL }, + handle_nonnull_attribute, NULL },=20=20=20=20=20=20=20=20=20 { "nonstring", 0, 0, true, false, false, false, handle_nonstring_attribute, NULL }, { "nothrow", 0, 0, true, false, false, false, @@ -555,7 +556,13 @@ const struct attribute_spec c_common_attribute_table[]= =3D handle_dealloc_attribute, NULL }, { "tainted_args", 0, 0, true, false, false, false, handle_tainted_args_attribute, NULL }, - { NULL, 0, 0, false, false, false, false, NULL, NULL= } + { NULL, 0, 0, false, false, false, false, NULL, NULL= }, + { "fd_arg", 1, 1, false, true, true, false, + handle_fd_arg_attribute, NULL},=20=20=20=20=20=20 + { "fd_arg_read", 1, 1, false, true, true, false, + handle_fd_arg_attribute, NULL}, + { "fd_arg_write", 1, 1, false, true, true, false, + handle_fd_arg_attribute, NULL}, }; =20 /* Give the specifications for the format attributes, used by C and all @@ -4521,6 +4528,31 @@ handle_nonnull_attribute (tree *node, tree name, return NULL_TREE; } =20 +/* Handle the "fd_arg", "fd_arg_read" and "fd_arg_write" attributes */ + +static tree +handle_fd_arg_attribute (tree *node, tree name, tree args, + int ARG_UNUSED (flags), bool *no_add_attrs) +{ + tree type =3D *node; + if (!args) + { + if (!prototype_p (type)) + { + error ("%qE attribute without arguments on a non-prototype", nam= e); + *no_add_attrs =3D true; + } + return NULL_TREE; + } + + if (tree val =3D positional_argument (*node, name, TREE_VALUE (args), + INTEGER_TYPE)) + return NULL_TREE; + + *no_add_attrs =3D true;=20=20 + return NULL_TREE; +} + /* Handle the "nonstring" variable attribute. */ =20 static tree diff --git a/gcc/doc/extend.texi b/gcc/doc/extend.texi index dfbe33ac652..7945d769e23 100644 --- a/gcc/doc/extend.texi +++ b/gcc/doc/extend.texi @@ -3007,6 +3007,40 @@ produced by @command{gold}. For other linkers that cannot generate resolution file, explicit @code{externally_visible} attributes are still necessary. =20 +@item fd_arg +@cindex @code{fd_arg} function attribute +The @code{fd_arg} attribute may be applied to a function that takes an ope= n=20 +file descriptor at referenced argument @var{N}. + +It indicates that the passed filedescriptor must not have been closed. +Therefore, when the analyzer is enabled with @option{-fanalyzer}, the=20 +analyzer may emit a @option{-Wanalyzer-fd-use-after-close} diagnostic=20 +if it detects a code path in which a function with this attribute is +called with a closed file descriptor. + +The attribute also indicates that the file descriptor must have been check= ed for +validity before usage. Therefore, analyzer may emit +@option{-Wanalyzer-fd-use-without-check} diagnostic if it detects a code p= ath in +which a function with this attribute is called with a file descriptor that= has +not been checked for validity. + +@item fd_arg_read +@cindex @code{fd_arg_read} function attribute +The @code{fd_arg_read} is identical to @code{fd_arg}, but with the additio= nal +requirement that it might read from the file descriptor, and thus, the file +descriptor must not have been opened as write-only. + +The analyzer may emit a @option{-Wanalyzer-access-mode-mismatch} +diagnostic if it detects a code path in which a function with this +attribute is called on a file descriptor opened with @code{O_WRONLY}. + +@item fd_arg_write +@cindex @code{fd_arg_write} function attribute +The @code{fd_arg_write} is identical to @code{fd_arg_read} except that the +analyzer may emit a @option{-Wanalyzer-access-mode-mismatch} diagnostic if= =20 +it detects a code path in which a function with this attribute is called o= n a=20 +file descriptor opened with @code{O_RDONLY}. + @item flatten @cindex @code{flatten} function attribute Generally, inlining into a function is limited. For a function marked with diff --git a/gcc/testsuite/c-c++-common/attr-fd.c b/gcc/testsuite/c-c++-com= mon/attr-fd.c new file mode 100644 index 00000000000..292c329856e --- /dev/null +++ b/gcc/testsuite/c-c++-common/attr-fd.c @@ -0,0 +1,18 @@ +=0D +int not_a_fn __attribute__ ((fd_arg(1))); /* { dg-warning "'fd_arg' attrib= ute only applies to function types" } */=0D +=0D +void f (char *p) __attribute__ ((fd_arg(1))); /* { dg-warning "'fd_arg' at= tribute argument value '1' refers to parameter type 'char \\\*'" } */=0D +=0D +=0D +int not_a_fn_b __attribute__ ((fd_arg_read(1))); /* { dg-warning "'fd_arg_= read' attribute only applies to function types" } */=0D +=0D +void g (char *p) __attribute__ ((fd_arg_read(1))); /* { dg-warning "'fd_ar= g_read' attribute argument value '1' refers to parameter type 'char \\\*'" = } */=0D +=0D +=0D +int not_a_fn_c __attribute__ ((fd_arg_write(1))); /* { dg-warning "'fd_arg= _write' attribute only applies to function types" } */=0D +=0D +void f (char *p) __attribute__ ((fd_arg_write(1))); /* { dg-warning "'fd_a= rg_write' attribute argument value '1' refers to parameter type 'char \\\*'= " } */=0D +=0D +=0D +void fn_a (int fd) __attribute__ ((fd_arg(0))); /* { dg-warning "'fd_arg' = attribute argument value '0' does not refer to a function parameter" } */=0D +void fd_a_1 (int fd) __attribute__ ((fd_arg("notint"))); /* { dg-warning "= 'fd_arg' attribute argument has type 'char\\\[7\\\]'" } */=0D diff --git a/gcc/testsuite/gcc.dg/analyzer/fd-5.c b/gcc/testsuite/gcc.dg/an= alyzer/fd-5.c new file mode 100644 index 00000000000..6287ddd38fc --- /dev/null +++ b/gcc/testsuite/gcc.dg/analyzer/fd-5.c @@ -0,0 +1,53 @@ +int open(const char *, int mode);=0D +void close(int fd);=0D +int write (int fd, void *buf, int nbytes);=0D +int read (int fd, void *buf, int nbytes);=0D +=0D +#define O_RDONLY 0=0D +#define O_WRONLY 1=0D +#define O_RDWR 2=0D +=0D +void f (int fd) __attribute__((fd_arg(1))); /* { dg-message "argument 1 of= 'f' must be an open file descriptor" } */=0D +=0D +void=0D +test_1 (const char *path)=0D +{=0D + int fd =3D open (path, O_RDWR);=0D + close(fd);=0D + f(fd); /* { dg-warning "'f' on closed file descriptor 'fd'" } */=0D + /* { dg-message "\\(3\\) 'f' on closed file descriptor 'fd'; 'close'= was at \\(2\\)" "" { target *-*-* } .-1 } */=0D +}=0D +=0D +void g (int fd) __attribute__((fd_arg_read(1))); /* { dg-message "argument= 1 of 'g' must be a read-only file descriptor" } */=0D +=0D +void=0D +test_2 (const char *path)=0D +{=0D + int fd =3D open (path, O_WRONLY);=0D + if (fd !=3D -1)=0D + {=0D + g (fd); /* { dg-warning "'g' on 'write-only' file descriptor 'fd'" } *= /=0D + }=0D + close (fd);=0D +}=0D +=0D +void h (int fd) __attribute__((fd_arg_write(1))); /* { dg-message "argumen= t 1 of 'h' must be a write-only file descriptor" } */=0D +void=0D +test_3 (const char *path)=0D +{=0D + int fd =3D open (path, O_RDONLY);=0D + if (fd !=3D -1)=0D + {=0D + h (fd); /* { dg-warning "'h' on 'read-only' file descriptor 'fd'" } */= =0D + }=0D + close(fd);=0D +}=0D +=0D +void ff (int fd) __attribute__((fd_arg(1))); /* { dg-message "argument 1 o= f 'ff' must be an open file descriptor" } */=0D +=0D +void test_4 (const char *path)=0D +{=0D + int fd =3D open (path, O_RDWR);=0D + ff (fd); /* { dg-warning "'ff' on possibly invalid file descriptor 'fd'"= } */=0D + close(fd);=0D +} \ No newline at end of file --=20 2.25.1