msg_132.c revision 1.44 1 1.44 rillig /* $NetBSD: msg_132.c,v 1.44 2024/10/08 19:50:49 rillig Exp $ */
2 1.1 rillig # 3 "msg_132.c"
3 1.1 rillig
4 1.1 rillig // Test for message: conversion from '%s' to '%s' may lose accuracy [132]
5 1.1 rillig
6 1.26 rillig /* lint1-extra-flags: -X 351 */
7 1.26 rillig
8 1.3 rillig /*
9 1.3 rillig * NetBSD's default lint flags only include a single -a, which only flags
10 1.3 rillig * narrowing conversions from long. To get warnings for all narrowing
11 1.9 rillig * conversions, -a needs to be given more than once.
12 1.3 rillig *
13 1.3 rillig * https://gnats.netbsd.org/14531
14 1.3 rillig */
15 1.3 rillig
16 1.3 rillig /* lint1-extra-flags: -aa */
17 1.3 rillig
18 1.20 rillig typedef unsigned char u8_t;
19 1.20 rillig typedef unsigned short u16_t;
20 1.20 rillig typedef unsigned int u32_t;
21 1.20 rillig typedef unsigned long long u64_t;
22 1.20 rillig typedef signed char s8_t;
23 1.20 rillig typedef signed short s16_t;
24 1.20 rillig typedef signed int s32_t;
25 1.20 rillig typedef signed long long s64_t;
26 1.20 rillig
27 1.27 rillig _Bool cond;
28 1.27 rillig char ch;
29 1.22 rillig
30 1.20 rillig u8_t u8;
31 1.20 rillig u16_t u16;
32 1.20 rillig u32_t u32;
33 1.20 rillig u64_t u64;
34 1.20 rillig
35 1.20 rillig s8_t s8;
36 1.20 rillig s16_t s16;
37 1.20 rillig s32_t s32;
38 1.20 rillig s64_t s64;
39 1.3 rillig
40 1.22 rillig struct bit_fields {
41 1.22 rillig unsigned u1:1;
42 1.22 rillig unsigned u2:2;
43 1.22 rillig unsigned u3:3;
44 1.22 rillig unsigned u4:4;
45 1.22 rillig unsigned u5:5;
46 1.22 rillig unsigned u6:6;
47 1.22 rillig unsigned u7:7;
48 1.22 rillig unsigned u8:8;
49 1.22 rillig unsigned u9:9;
50 1.22 rillig unsigned u10:10;
51 1.22 rillig unsigned u11:11;
52 1.22 rillig unsigned u12:12;
53 1.22 rillig unsigned u32:32;
54 1.22 rillig } bits;
55 1.22 rillig
56 1.22 rillig
57 1.3 rillig void
58 1.9 rillig unsigned_to_unsigned(void)
59 1.3 rillig {
60 1.18 rillig /* expect+1: warning: conversion from 'unsigned short' to 'unsigned char' may lose accuracy [132] */
61 1.18 rillig u8 = u16;
62 1.18 rillig /* expect+1: warning: conversion from 'unsigned int' to 'unsigned char' may lose accuracy [132] */
63 1.18 rillig u8 = u32;
64 1.18 rillig /* expect+1: warning: conversion from 'unsigned long long' to 'unsigned char' may lose accuracy [132] */
65 1.18 rillig u8 = u64;
66 1.9 rillig
67 1.9 rillig u16 = u8;
68 1.18 rillig /* expect+1: warning: conversion from 'unsigned int' to 'unsigned short' may lose accuracy [132] */
69 1.18 rillig u16 = u32;
70 1.18 rillig /* expect+1: warning: conversion from 'unsigned long long' to 'unsigned short' may lose accuracy [132] */
71 1.18 rillig u16 = u64;
72 1.9 rillig
73 1.9 rillig u32 = u8;
74 1.9 rillig u32 = u16;
75 1.18 rillig /* expect+1: warning: conversion from 'unsigned long long' to 'unsigned int' may lose accuracy [132] */
76 1.18 rillig u32 = u64;
77 1.9 rillig
78 1.9 rillig u64 = u8;
79 1.9 rillig u64 = u16;
80 1.9 rillig u64 = u32;
81 1.3 rillig }
82 1.3 rillig
83 1.3 rillig void
84 1.9 rillig unsigned_to_signed(void)
85 1.3 rillig {
86 1.18 rillig /* expect+1: warning: conversion from 'unsigned short' to 'signed char' may lose accuracy [132] */
87 1.18 rillig s8 = u16;
88 1.18 rillig /* expect+1: warning: conversion from 'unsigned int' to 'signed char' may lose accuracy [132] */
89 1.18 rillig s8 = u32;
90 1.18 rillig /* expect+1: warning: conversion from 'unsigned long long' to 'signed char' may lose accuracy [132] */
91 1.18 rillig s8 = u64;
92 1.9 rillig
93 1.9 rillig s16 = u8;
94 1.18 rillig /* expect+1: warning: conversion from 'unsigned int' to 'short' may lose accuracy [132] */
95 1.18 rillig s16 = u32;
96 1.18 rillig /* expect+1: warning: conversion from 'unsigned long long' to 'short' may lose accuracy [132] */
97 1.18 rillig s16 = u64;
98 1.9 rillig
99 1.9 rillig s32 = u8;
100 1.9 rillig s32 = u16;
101 1.18 rillig /* expect+1: warning: conversion from 'unsigned long long' to 'int' may lose accuracy [132] */
102 1.18 rillig s32 = u64;
103 1.9 rillig
104 1.9 rillig s64 = u8;
105 1.9 rillig s64 = u16;
106 1.9 rillig s64 = u32;
107 1.9 rillig }
108 1.9 rillig
109 1.9 rillig void
110 1.9 rillig signed_to_unsigned(void)
111 1.9 rillig {
112 1.18 rillig /* expect+1: warning: conversion from 'short' to 'unsigned char' may lose accuracy [132] */
113 1.18 rillig u8 = s16;
114 1.18 rillig /* expect+1: warning: conversion from 'int' to 'unsigned char' may lose accuracy [132] */
115 1.18 rillig u8 = s32;
116 1.18 rillig /* expect+1: warning: conversion from 'long long' to 'unsigned char' may lose accuracy [132] */
117 1.18 rillig u8 = s64;
118 1.9 rillig
119 1.9 rillig u16 = s8;
120 1.18 rillig /* expect+1: warning: conversion from 'int' to 'unsigned short' may lose accuracy [132] */
121 1.18 rillig u16 = s32;
122 1.18 rillig /* expect+1: warning: conversion from 'long long' to 'unsigned short' may lose accuracy [132] */
123 1.18 rillig u16 = s64;
124 1.9 rillig
125 1.9 rillig u32 = s8;
126 1.9 rillig u32 = s16;
127 1.18 rillig /* expect+1: warning: conversion from 'long long' to 'unsigned int' may lose accuracy [132] */
128 1.18 rillig u32 = s64;
129 1.9 rillig
130 1.9 rillig u64 = s8;
131 1.9 rillig u64 = s16;
132 1.9 rillig u64 = s32;
133 1.9 rillig }
134 1.9 rillig
135 1.9 rillig void
136 1.9 rillig signed_to_signed(void)
137 1.9 rillig {
138 1.18 rillig /* expect+1: warning: conversion from 'short' to 'signed char' may lose accuracy [132] */
139 1.18 rillig s8 = s16;
140 1.18 rillig /* expect+1: warning: conversion from 'int' to 'signed char' may lose accuracy [132] */
141 1.18 rillig s8 = s32;
142 1.18 rillig /* expect+1: warning: conversion from 'long long' to 'signed char' may lose accuracy [132] */
143 1.18 rillig s8 = s64;
144 1.9 rillig
145 1.9 rillig s16 = s8;
146 1.18 rillig /* expect+1: warning: conversion from 'int' to 'short' may lose accuracy [132] */
147 1.18 rillig s16 = s32;
148 1.18 rillig /* expect+1: warning: conversion from 'long long' to 'short' may lose accuracy [132] */
149 1.18 rillig s16 = s64;
150 1.9 rillig
151 1.9 rillig s32 = s8;
152 1.9 rillig s32 = s16;
153 1.18 rillig /* expect+1: warning: conversion from 'long long' to 'int' may lose accuracy [132] */
154 1.18 rillig s32 = s64;
155 1.9 rillig
156 1.9 rillig s64 = s8;
157 1.9 rillig s64 = s16;
158 1.9 rillig s64 = s32;
159 1.3 rillig }
160 1.4 rillig
161 1.5 rillig /*
162 1.9 rillig * Before tree.c 1.268 from 2021-04-06, lint wrongly warned that conversion
163 1.9 rillig * to _Bool might lose accuracy. C99 6.3.1.2 defines a special conversion
164 1.9 rillig * rule from scalar to _Bool though by comparing the value to 0.
165 1.5 rillig */
166 1.4 rillig _Bool
167 1.4 rillig to_bool(long a, long b)
168 1.4 rillig {
169 1.4 rillig /* seen in fp_lib.h, function wideRightShiftWithSticky */
170 1.5 rillig return a | b;
171 1.4 rillig }
172 1.6 rillig
173 1.6 rillig /* ARGSUSED */
174 1.6 rillig const char *
175 1.6 rillig cover_build_plus_minus(const char *arr, double idx)
176 1.6 rillig {
177 1.6 rillig if (idx > 0.0)
178 1.33 rillig /* expect+2: error: operands of '+' have incompatible types 'pointer to const char' and 'double' [107] */
179 1.33 rillig /* expect+1: error: function 'cover_build_plus_minus' expects to return value [214] */
180 1.6 rillig return arr + idx;
181 1.6 rillig return arr + (unsigned int)idx;
182 1.6 rillig }
183 1.7 rillig
184 1.7 rillig int
185 1.7 rillig non_constant_expression(void)
186 1.7 rillig {
187 1.7 rillig /*
188 1.7 rillig * Even though this variable definition looks like a constant, it
189 1.7 rillig * does not fall within C's definition of an integer constant
190 1.7 rillig * expression. Due to that, lint does not perform constant folding
191 1.7 rillig * on the expression built from this variable and thus doesn't know
192 1.7 rillig * that the conversion will always succeed.
193 1.7 rillig */
194 1.7 rillig const int not_a_constant = 8;
195 1.8 rillig /* expect+1: warning: conversion from 'unsigned long long' to 'int' may lose accuracy [132] */
196 1.8 rillig return not_a_constant * 8ULL;
197 1.7 rillig }
198 1.10 rillig
199 1.10 rillig /*
200 1.10 rillig * PR 36668 notices that lint wrongly complains about the possible loss.
201 1.11 rillig *
202 1.11 rillig * The expression 'u8_t << 8' is guaranteed to fit into an 'u16_t', and its
203 1.11 rillig * lower 8 bits are guaranteed to be clear. 'u16_t | u8_t' is guaranteed to
204 1.11 rillig * fit into 'u16_t'.
205 1.11 rillig *
206 1.11 rillig * Since tree.c 1.444 from 2022-05-26, lint tracks simple bitwise and
207 1.11 rillig * arithmetic constraints across a single expression.
208 1.10 rillig */
209 1.10 rillig static inline u16_t
210 1.10 rillig be16dec(const void *buf)
211 1.10 rillig {
212 1.10 rillig const u8_t *p = buf;
213 1.10 rillig
214 1.11 rillig /*
215 1.11 rillig * Before tree.c 1.444 from 2022-05-26, lint complained that the
216 1.11 rillig * conversion from 'int' to 'unsigned short' may lose accuracy.
217 1.11 rillig */
218 1.10 rillig return ((u16_t)p[0]) << 8 | p[1];
219 1.10 rillig }
220 1.10 rillig
221 1.10 rillig /*
222 1.10 rillig * Since tree.c 1.434 from 2022-04-19, lint infers the possible values of
223 1.10 rillig * expressions of the form 'integer & constant', see can_represent.
224 1.10 rillig */
225 1.10 rillig static inline void
226 1.10 rillig be32enc(void *buf, u32_t u)
227 1.10 rillig {
228 1.10 rillig u8_t *p = buf;
229 1.10 rillig
230 1.10 rillig p[0] = u >> 24 & 0xff;
231 1.10 rillig p[1] = u >> 16 & 0xff;
232 1.10 rillig p[2] = u >> 8 & 0xff;
233 1.10 rillig p[3] = u & 0xff;
234 1.10 rillig }
235 1.12 rillig
236 1.43 rillig void
237 1.43 rillig test_ic_mult(void)
238 1.43 rillig {
239 1.44 rillig u32 = u16 * 65537ULL;
240 1.43 rillig /* expect+1: warning: conversion from 'unsigned long long' to 'unsigned int' may lose accuracy [132] */
241 1.44 rillig u32 = u16 * 65538ULL;
242 1.43 rillig
243 1.43 rillig u16 = 0 * u16;
244 1.43 rillig u16 = 1 * u16;
245 1.43 rillig /* expect+1: warning: conversion from 'int' to 'unsigned short' may lose accuracy [132] */
246 1.43 rillig u16 = 2 * u16;
247 1.43 rillig
248 1.43 rillig u32 = (u16 & 1023ULL) / 1ULL * 1024ULL | (u16 & 1023ULL) / 1ULL * 1ULL;
249 1.43 rillig }
250 1.43 rillig
251 1.12 rillig u32_t
252 1.12 rillig test_ic_shr(u64_t x)
253 1.12 rillig {
254 1.12 rillig if (x > 3)
255 1.12 rillig return x >> 32;
256 1.12 rillig if (x > 2)
257 1.12 rillig /* expect+1: warning: conversion from 'unsigned long long' to 'unsigned int' may lose accuracy [132] */
258 1.12 rillig return x >> 31;
259 1.25 rillig
260 1.25 rillig /* expect+1: warning: conversion from 'unsigned long long' to 'unsigned int' may lose accuracy [132] */
261 1.25 rillig u32 = u64 >> 31;
262 1.25 rillig u32 = u64 >> 32;
263 1.25 rillig u16 = u64 >> 48;
264 1.25 rillig u8 = u64 >> 56;
265 1.25 rillig u16 = u32 >> 16;
266 1.25 rillig u8 = u32 >> 24;
267 1.25 rillig u8 = u16 >> 8;
268 1.25 rillig
269 1.25 rillig /*
270 1.25 rillig * No matter whether the big integer is signed or unsigned, the
271 1.25 rillig * result of '&' is guaranteed to be an unsigned value.
272 1.25 rillig */
273 1.25 rillig u8 = (s64 & 0xf0) >> 4;
274 1.25 rillig u8 = (s8 & 0xf0) >> 4;
275 1.25 rillig
276 1.12 rillig /* expect+1: warning: conversion from 'unsigned long long' to 'unsigned int' may lose accuracy [132] */
277 1.12 rillig return x;
278 1.12 rillig }
279 1.14 rillig
280 1.14 rillig unsigned char
281 1.22 rillig test_bit_fields(unsigned long long m)
282 1.14 rillig {
283 1.40 rillig /* expect+1: warning: conversion from 'unsigned long long' to 'unsigned int:3' may lose accuracy [132] */
284 1.22 rillig bits.u3 = bits.u32 & m;
285 1.14 rillig
286 1.22 rillig bits.u5 = bits.u3 & m;
287 1.22 rillig bits.u32 = bits.u5 & m;
288 1.14 rillig
289 1.40 rillig /* expect+1: warning: conversion from 'unsigned long long' to 'unsigned char' may lose accuracy [132] */
290 1.22 rillig return bits.u32 & m;
291 1.14 rillig }
292 1.20 rillig
293 1.22 rillig /*
294 1.22 rillig * Traditional C has an extra rule that the right-hand operand of a bit shift
295 1.22 rillig * operator is converted to 'int'. Before tree.c 1.467 from 2022-07-02, this
296 1.22 rillig * conversion was implemented as a CVT node, which means a cast, not an
297 1.22 rillig * implicit conversion. Changing the CVT to NOOP would have caused a wrong
298 1.22 rillig * warning 'may lose accuracy' in language levels other than traditional C.
299 1.22 rillig */
300 1.22 rillig
301 1.20 rillig u64_t
302 1.20 rillig u64_shl(u64_t lhs, u64_t rhs)
303 1.20 rillig {
304 1.20 rillig return lhs << rhs;
305 1.20 rillig }
306 1.20 rillig
307 1.20 rillig u64_t
308 1.20 rillig u64_shr(u64_t lhs, u64_t rhs)
309 1.20 rillig {
310 1.20 rillig return lhs >> rhs;
311 1.20 rillig }
312 1.20 rillig
313 1.20 rillig s64_t
314 1.20 rillig s64_shl(s64_t lhs, s64_t rhs)
315 1.20 rillig {
316 1.20 rillig return lhs << rhs;
317 1.20 rillig }
318 1.20 rillig
319 1.20 rillig s64_t
320 1.20 rillig s64_shr(s64_t lhs, s64_t rhs)
321 1.20 rillig {
322 1.20 rillig return lhs >> rhs;
323 1.20 rillig }
324 1.22 rillig
325 1.22 rillig void
326 1.22 rillig test_ic_mod(void)
327 1.22 rillig {
328 1.22 rillig /* The result is between 0 and 254. */
329 1.23 rillig u8 = u64 % u8;
330 1.23 rillig
331 1.23 rillig /* The result is between 0 and 255. */
332 1.23 rillig u8 = u64 % 256;
333 1.23 rillig
334 1.23 rillig /* The result is between 0 and 256. */
335 1.22 rillig /* expect+1: warning: conversion from 'unsigned long long' to 'unsigned char' may lose accuracy [132] */
336 1.23 rillig u8 = u64 % 257;
337 1.22 rillig
338 1.22 rillig /* The result is between 0 and 1000. */
339 1.22 rillig /* expect+1: warning: conversion from 'unsigned long long' to 'unsigned char' may lose accuracy [132] */
340 1.22 rillig u8 = u64 % 1000;
341 1.22 rillig /* expect+1: warning: conversion from 'unsigned long long' to 'unsigned int:9' may lose accuracy [132] */
342 1.22 rillig bits.u9 = u64 % 1000;
343 1.22 rillig bits.u10 = u64 % 1000;
344 1.23 rillig u16 = u64 % 1000;
345 1.22 rillig
346 1.22 rillig /*
347 1.22 rillig * For signed division, if the result of 'a / b' is not representable
348 1.22 rillig * exactly, the result of 'a % b' is defined such that
349 1.22 rillig * '(a / b) * a + a % b == a'.
350 1.22 rillig *
351 1.22 rillig * If the result of 'a / b' is not representable exactly, the result
352 1.23 rillig * of 'a % b' is not defined. Due to this uncertainty, lint does not
353 1.23 rillig * narrow down the range for signed modulo expressions.
354 1.22 rillig *
355 1.22 rillig * C90 6.3.5, C99 6.5.5.
356 1.22 rillig */
357 1.23 rillig
358 1.23 rillig /* expect+1: warning: conversion from 'int' to 'signed char' may lose accuracy [132] */
359 1.23 rillig s8 = s16 % s8;
360 1.23 rillig
361 1.23 rillig /*
362 1.23 rillig * The result is always 0, it's a theoretical edge case though, so
363 1.23 rillig * lint doesn't care to implement this.
364 1.23 rillig */
365 1.23 rillig /* expect+1: warning: conversion from 'long long' to 'signed char' may lose accuracy [132] */
366 1.23 rillig s8 = s64 % 1;
367 1.22 rillig }
368 1.24 rillig
369 1.24 rillig void
370 1.24 rillig test_ic_bitand(void)
371 1.24 rillig {
372 1.24 rillig /*
373 1.24 rillig * ic_bitand assumes that integers are represented in 2's complement,
374 1.24 rillig * and that the sign bit of signed integers behaves like a value bit.
375 1.24 rillig * That way, the following expressions get their constraints computed
376 1.24 rillig * correctly, regardless of whether ic_expr takes care of integer
377 1.24 rillig * promotions or not. Compare ic_mod, which ignores signed types.
378 1.24 rillig */
379 1.24 rillig
380 1.24 rillig u8 = u8 & u16;
381 1.24 rillig
382 1.24 rillig /* expect+1: warning: conversion from 'unsigned int' to 'unsigned char' may lose accuracy [132] */
383 1.24 rillig u8 = u16 & u32;
384 1.24 rillig }
385 1.27 rillig
386 1.27 rillig void
387 1.28 rillig test_ic_cvt(void)
388 1.28 rillig {
389 1.28 rillig u16 = (u32 & 0x0000ff00);
390 1.28 rillig u16 = (u32_t)(u32 & 0x0000ff00);
391 1.28 rillig }
392 1.28 rillig
393 1.28 rillig void
394 1.27 rillig test_ic_conditional(char c1, char c2)
395 1.27 rillig {
396 1.27 rillig /* Both operands are representable as char. */
397 1.27 rillig ch = cond ? '?' : ':';
398 1.27 rillig
399 1.27 rillig /*
400 1.27 rillig * Both operands are representable as char. Clang-Tidy 17 wrongly
401 1.27 rillig * warns about a narrowing conversion from 'int' to signed type
402 1.27 rillig * 'char'.
403 1.27 rillig */
404 1.27 rillig ch = cond ? c1 : c2;
405 1.27 rillig
406 1.30 rillig /*
407 1.30 rillig * Mixing s8 and u8 results in a number from -128 to 255, which does
408 1.30 rillig * not necessarily fit into s8.
409 1.30 rillig */
410 1.27 rillig /* expect+1: warning: conversion from 'int' to 'signed char' may lose accuracy [132] */
411 1.27 rillig s8 = cond ? s8 : u8;
412 1.27 rillig
413 1.30 rillig /*
414 1.30 rillig * Mixing s8 and u8 results in a number from -128 to 255, which does
415 1.30 rillig * not necessarily fit into u8.
416 1.30 rillig */
417 1.27 rillig /* expect+1: warning: conversion from 'int' to 'unsigned char' may lose accuracy [132] */
418 1.27 rillig u8 = cond ? s8 : u8;
419 1.27 rillig }
420 1.34 rillig
421 1.34 rillig void
422 1.36 rillig compare_bit_field_to_integer_constant(void)
423 1.34 rillig {
424 1.36 rillig static _Bool b;
425 1.36 rillig static struct {
426 1.36 rillig short s16:15;
427 1.36 rillig unsigned short u16:15;
428 1.36 rillig int s32:15;
429 1.36 rillig unsigned u32:15;
430 1.36 rillig long long s64:15;
431 1.36 rillig unsigned long long u64:15;
432 1.36 rillig } s;
433 1.34 rillig
434 1.35 rillig // Since decl.c 1.180 from 2021-05-02 and before tree.c 1.624 from
435 1.35 rillig // 2024-03-12, lint warned about a possible loss of accuracy [132]
436 1.36 rillig // when promoting an 'unsigned long long' bit-field to 'int'.
437 1.36 rillig b = s.s16 == 0;
438 1.36 rillig b = s.u16 == 0;
439 1.36 rillig b = s.s32 == 0;
440 1.36 rillig b = s.u32 == 0;
441 1.36 rillig b = s.s64 == 0;
442 1.36 rillig b = s.u64 == 0;
443 1.36 rillig b = !b;
444 1.34 rillig }
445 1.37 rillig
446 1.38 rillig /*
447 1.38 rillig * Before tree.c 1.626 from 2024-03-26, the usual arithmetic conversions for
448 1.38 rillig * bit-field types with the same base type but different widths simply took
449 1.38 rillig * the type of the left operand, leading to wrong warnings about loss of
450 1.38 rillig * accuracy when the right operand was wider than the left operand.
451 1.38 rillig */
452 1.38 rillig void
453 1.37 rillig binary_operators_on_bit_fields(void)
454 1.37 rillig {
455 1.37 rillig struct {
456 1.38 rillig u64_t u15:15;
457 1.38 rillig u64_t u48:48;
458 1.38 rillig u64_t u64;
459 1.37 rillig } s = { 0, 0, 0 };
460 1.37 rillig
461 1.37 rillig u64 = s.u15 | s.u48;
462 1.38 rillig u64 = s.u48 | s.u15;
463 1.37 rillig u64 = s.u15 | s.u48 | s.u64;
464 1.38 rillig u64 = s.u64 | s.u48 | s.u15;
465 1.38 rillig cond = (s.u15 | s.u48 | s.u64) != 0;
466 1.38 rillig cond = (s.u64 | s.u48 | s.u15) != 0;
467 1.39 rillig
468 1.40 rillig // Before tree.c from 1.638 from 2024-05-01, lint wrongly warned:
469 1.40 rillig // warning: conversion of 'int' to 'int:4' is out of range [119]
470 1.39 rillig s32 = 8 - bits.u3;
471 1.37 rillig }
472 1.41 rillig
473 1.41 rillig unsigned char
474 1.43 rillig combine_arithmetic_and_bit_operations(void)
475 1.41 rillig {
476 1.43 rillig return 0xc0 | (u32 & 0x07c0) / 64;
477 1.41 rillig }
478