msg_132.c revision 1.44 1 /* $NetBSD: msg_132.c,v 1.44 2024/10/08 19:50:49 rillig Exp $ */
2 # 3 "msg_132.c"
3
4 // Test for message: conversion from '%s' to '%s' may lose accuracy [132]
5
6 /* lint1-extra-flags: -X 351 */
7
8 /*
9 * NetBSD's default lint flags only include a single -a, which only flags
10 * narrowing conversions from long. To get warnings for all narrowing
11 * conversions, -a needs to be given more than once.
12 *
13 * https://gnats.netbsd.org/14531
14 */
15
16 /* lint1-extra-flags: -aa */
17
18 typedef unsigned char u8_t;
19 typedef unsigned short u16_t;
20 typedef unsigned int u32_t;
21 typedef unsigned long long u64_t;
22 typedef signed char s8_t;
23 typedef signed short s16_t;
24 typedef signed int s32_t;
25 typedef signed long long s64_t;
26
27 _Bool cond;
28 char ch;
29
30 u8_t u8;
31 u16_t u16;
32 u32_t u32;
33 u64_t u64;
34
35 s8_t s8;
36 s16_t s16;
37 s32_t s32;
38 s64_t s64;
39
40 struct bit_fields {
41 unsigned u1:1;
42 unsigned u2:2;
43 unsigned u3:3;
44 unsigned u4:4;
45 unsigned u5:5;
46 unsigned u6:6;
47 unsigned u7:7;
48 unsigned u8:8;
49 unsigned u9:9;
50 unsigned u10:10;
51 unsigned u11:11;
52 unsigned u12:12;
53 unsigned u32:32;
54 } bits;
55
56
57 void
58 unsigned_to_unsigned(void)
59 {
60 /* expect+1: warning: conversion from 'unsigned short' to 'unsigned char' may lose accuracy [132] */
61 u8 = u16;
62 /* expect+1: warning: conversion from 'unsigned int' to 'unsigned char' may lose accuracy [132] */
63 u8 = u32;
64 /* expect+1: warning: conversion from 'unsigned long long' to 'unsigned char' may lose accuracy [132] */
65 u8 = u64;
66
67 u16 = u8;
68 /* expect+1: warning: conversion from 'unsigned int' to 'unsigned short' may lose accuracy [132] */
69 u16 = u32;
70 /* expect+1: warning: conversion from 'unsigned long long' to 'unsigned short' may lose accuracy [132] */
71 u16 = u64;
72
73 u32 = u8;
74 u32 = u16;
75 /* expect+1: warning: conversion from 'unsigned long long' to 'unsigned int' may lose accuracy [132] */
76 u32 = u64;
77
78 u64 = u8;
79 u64 = u16;
80 u64 = u32;
81 }
82
83 void
84 unsigned_to_signed(void)
85 {
86 /* expect+1: warning: conversion from 'unsigned short' to 'signed char' may lose accuracy [132] */
87 s8 = u16;
88 /* expect+1: warning: conversion from 'unsigned int' to 'signed char' may lose accuracy [132] */
89 s8 = u32;
90 /* expect+1: warning: conversion from 'unsigned long long' to 'signed char' may lose accuracy [132] */
91 s8 = u64;
92
93 s16 = u8;
94 /* expect+1: warning: conversion from 'unsigned int' to 'short' may lose accuracy [132] */
95 s16 = u32;
96 /* expect+1: warning: conversion from 'unsigned long long' to 'short' may lose accuracy [132] */
97 s16 = u64;
98
99 s32 = u8;
100 s32 = u16;
101 /* expect+1: warning: conversion from 'unsigned long long' to 'int' may lose accuracy [132] */
102 s32 = u64;
103
104 s64 = u8;
105 s64 = u16;
106 s64 = u32;
107 }
108
109 void
110 signed_to_unsigned(void)
111 {
112 /* expect+1: warning: conversion from 'short' to 'unsigned char' may lose accuracy [132] */
113 u8 = s16;
114 /* expect+1: warning: conversion from 'int' to 'unsigned char' may lose accuracy [132] */
115 u8 = s32;
116 /* expect+1: warning: conversion from 'long long' to 'unsigned char' may lose accuracy [132] */
117 u8 = s64;
118
119 u16 = s8;
120 /* expect+1: warning: conversion from 'int' to 'unsigned short' may lose accuracy [132] */
121 u16 = s32;
122 /* expect+1: warning: conversion from 'long long' to 'unsigned short' may lose accuracy [132] */
123 u16 = s64;
124
125 u32 = s8;
126 u32 = s16;
127 /* expect+1: warning: conversion from 'long long' to 'unsigned int' may lose accuracy [132] */
128 u32 = s64;
129
130 u64 = s8;
131 u64 = s16;
132 u64 = s32;
133 }
134
135 void
136 signed_to_signed(void)
137 {
138 /* expect+1: warning: conversion from 'short' to 'signed char' may lose accuracy [132] */
139 s8 = s16;
140 /* expect+1: warning: conversion from 'int' to 'signed char' may lose accuracy [132] */
141 s8 = s32;
142 /* expect+1: warning: conversion from 'long long' to 'signed char' may lose accuracy [132] */
143 s8 = s64;
144
145 s16 = s8;
146 /* expect+1: warning: conversion from 'int' to 'short' may lose accuracy [132] */
147 s16 = s32;
148 /* expect+1: warning: conversion from 'long long' to 'short' may lose accuracy [132] */
149 s16 = s64;
150
151 s32 = s8;
152 s32 = s16;
153 /* expect+1: warning: conversion from 'long long' to 'int' may lose accuracy [132] */
154 s32 = s64;
155
156 s64 = s8;
157 s64 = s16;
158 s64 = s32;
159 }
160
161 /*
162 * Before tree.c 1.268 from 2021-04-06, lint wrongly warned that conversion
163 * to _Bool might lose accuracy. C99 6.3.1.2 defines a special conversion
164 * rule from scalar to _Bool though by comparing the value to 0.
165 */
166 _Bool
167 to_bool(long a, long b)
168 {
169 /* seen in fp_lib.h, function wideRightShiftWithSticky */
170 return a | b;
171 }
172
173 /* ARGSUSED */
174 const char *
175 cover_build_plus_minus(const char *arr, double idx)
176 {
177 if (idx > 0.0)
178 /* expect+2: error: operands of '+' have incompatible types 'pointer to const char' and 'double' [107] */
179 /* expect+1: error: function 'cover_build_plus_minus' expects to return value [214] */
180 return arr + idx;
181 return arr + (unsigned int)idx;
182 }
183
184 int
185 non_constant_expression(void)
186 {
187 /*
188 * Even though this variable definition looks like a constant, it
189 * does not fall within C's definition of an integer constant
190 * expression. Due to that, lint does not perform constant folding
191 * on the expression built from this variable and thus doesn't know
192 * that the conversion will always succeed.
193 */
194 const int not_a_constant = 8;
195 /* expect+1: warning: conversion from 'unsigned long long' to 'int' may lose accuracy [132] */
196 return not_a_constant * 8ULL;
197 }
198
199 /*
200 * PR 36668 notices that lint wrongly complains about the possible loss.
201 *
202 * The expression 'u8_t << 8' is guaranteed to fit into an 'u16_t', and its
203 * lower 8 bits are guaranteed to be clear. 'u16_t | u8_t' is guaranteed to
204 * fit into 'u16_t'.
205 *
206 * Since tree.c 1.444 from 2022-05-26, lint tracks simple bitwise and
207 * arithmetic constraints across a single expression.
208 */
209 static inline u16_t
210 be16dec(const void *buf)
211 {
212 const u8_t *p = buf;
213
214 /*
215 * Before tree.c 1.444 from 2022-05-26, lint complained that the
216 * conversion from 'int' to 'unsigned short' may lose accuracy.
217 */
218 return ((u16_t)p[0]) << 8 | p[1];
219 }
220
221 /*
222 * Since tree.c 1.434 from 2022-04-19, lint infers the possible values of
223 * expressions of the form 'integer & constant', see can_represent.
224 */
225 static inline void
226 be32enc(void *buf, u32_t u)
227 {
228 u8_t *p = buf;
229
230 p[0] = u >> 24 & 0xff;
231 p[1] = u >> 16 & 0xff;
232 p[2] = u >> 8 & 0xff;
233 p[3] = u & 0xff;
234 }
235
236 void
237 test_ic_mult(void)
238 {
239 u32 = u16 * 65537ULL;
240 /* expect+1: warning: conversion from 'unsigned long long' to 'unsigned int' may lose accuracy [132] */
241 u32 = u16 * 65538ULL;
242
243 u16 = 0 * u16;
244 u16 = 1 * u16;
245 /* expect+1: warning: conversion from 'int' to 'unsigned short' may lose accuracy [132] */
246 u16 = 2 * u16;
247
248 u32 = (u16 & 1023ULL) / 1ULL * 1024ULL | (u16 & 1023ULL) / 1ULL * 1ULL;
249 }
250
251 u32_t
252 test_ic_shr(u64_t x)
253 {
254 if (x > 3)
255 return x >> 32;
256 if (x > 2)
257 /* expect+1: warning: conversion from 'unsigned long long' to 'unsigned int' may lose accuracy [132] */
258 return x >> 31;
259
260 /* expect+1: warning: conversion from 'unsigned long long' to 'unsigned int' may lose accuracy [132] */
261 u32 = u64 >> 31;
262 u32 = u64 >> 32;
263 u16 = u64 >> 48;
264 u8 = u64 >> 56;
265 u16 = u32 >> 16;
266 u8 = u32 >> 24;
267 u8 = u16 >> 8;
268
269 /*
270 * No matter whether the big integer is signed or unsigned, the
271 * result of '&' is guaranteed to be an unsigned value.
272 */
273 u8 = (s64 & 0xf0) >> 4;
274 u8 = (s8 & 0xf0) >> 4;
275
276 /* expect+1: warning: conversion from 'unsigned long long' to 'unsigned int' may lose accuracy [132] */
277 return x;
278 }
279
280 unsigned char
281 test_bit_fields(unsigned long long m)
282 {
283 /* expect+1: warning: conversion from 'unsigned long long' to 'unsigned int:3' may lose accuracy [132] */
284 bits.u3 = bits.u32 & m;
285
286 bits.u5 = bits.u3 & m;
287 bits.u32 = bits.u5 & m;
288
289 /* expect+1: warning: conversion from 'unsigned long long' to 'unsigned char' may lose accuracy [132] */
290 return bits.u32 & m;
291 }
292
293 /*
294 * Traditional C has an extra rule that the right-hand operand of a bit shift
295 * operator is converted to 'int'. Before tree.c 1.467 from 2022-07-02, this
296 * conversion was implemented as a CVT node, which means a cast, not an
297 * implicit conversion. Changing the CVT to NOOP would have caused a wrong
298 * warning 'may lose accuracy' in language levels other than traditional C.
299 */
300
301 u64_t
302 u64_shl(u64_t lhs, u64_t rhs)
303 {
304 return lhs << rhs;
305 }
306
307 u64_t
308 u64_shr(u64_t lhs, u64_t rhs)
309 {
310 return lhs >> rhs;
311 }
312
313 s64_t
314 s64_shl(s64_t lhs, s64_t rhs)
315 {
316 return lhs << rhs;
317 }
318
319 s64_t
320 s64_shr(s64_t lhs, s64_t rhs)
321 {
322 return lhs >> rhs;
323 }
324
325 void
326 test_ic_mod(void)
327 {
328 /* The result is between 0 and 254. */
329 u8 = u64 % u8;
330
331 /* The result is between 0 and 255. */
332 u8 = u64 % 256;
333
334 /* The result is between 0 and 256. */
335 /* expect+1: warning: conversion from 'unsigned long long' to 'unsigned char' may lose accuracy [132] */
336 u8 = u64 % 257;
337
338 /* The result is between 0 and 1000. */
339 /* expect+1: warning: conversion from 'unsigned long long' to 'unsigned char' may lose accuracy [132] */
340 u8 = u64 % 1000;
341 /* expect+1: warning: conversion from 'unsigned long long' to 'unsigned int:9' may lose accuracy [132] */
342 bits.u9 = u64 % 1000;
343 bits.u10 = u64 % 1000;
344 u16 = u64 % 1000;
345
346 /*
347 * For signed division, if the result of 'a / b' is not representable
348 * exactly, the result of 'a % b' is defined such that
349 * '(a / b) * a + a % b == a'.
350 *
351 * If the result of 'a / b' is not representable exactly, the result
352 * of 'a % b' is not defined. Due to this uncertainty, lint does not
353 * narrow down the range for signed modulo expressions.
354 *
355 * C90 6.3.5, C99 6.5.5.
356 */
357
358 /* expect+1: warning: conversion from 'int' to 'signed char' may lose accuracy [132] */
359 s8 = s16 % s8;
360
361 /*
362 * The result is always 0, it's a theoretical edge case though, so
363 * lint doesn't care to implement this.
364 */
365 /* expect+1: warning: conversion from 'long long' to 'signed char' may lose accuracy [132] */
366 s8 = s64 % 1;
367 }
368
369 void
370 test_ic_bitand(void)
371 {
372 /*
373 * ic_bitand assumes that integers are represented in 2's complement,
374 * and that the sign bit of signed integers behaves like a value bit.
375 * That way, the following expressions get their constraints computed
376 * correctly, regardless of whether ic_expr takes care of integer
377 * promotions or not. Compare ic_mod, which ignores signed types.
378 */
379
380 u8 = u8 & u16;
381
382 /* expect+1: warning: conversion from 'unsigned int' to 'unsigned char' may lose accuracy [132] */
383 u8 = u16 & u32;
384 }
385
386 void
387 test_ic_cvt(void)
388 {
389 u16 = (u32 & 0x0000ff00);
390 u16 = (u32_t)(u32 & 0x0000ff00);
391 }
392
393 void
394 test_ic_conditional(char c1, char c2)
395 {
396 /* Both operands are representable as char. */
397 ch = cond ? '?' : ':';
398
399 /*
400 * Both operands are representable as char. Clang-Tidy 17 wrongly
401 * warns about a narrowing conversion from 'int' to signed type
402 * 'char'.
403 */
404 ch = cond ? c1 : c2;
405
406 /*
407 * Mixing s8 and u8 results in a number from -128 to 255, which does
408 * not necessarily fit into s8.
409 */
410 /* expect+1: warning: conversion from 'int' to 'signed char' may lose accuracy [132] */
411 s8 = cond ? s8 : u8;
412
413 /*
414 * Mixing s8 and u8 results in a number from -128 to 255, which does
415 * not necessarily fit into u8.
416 */
417 /* expect+1: warning: conversion from 'int' to 'unsigned char' may lose accuracy [132] */
418 u8 = cond ? s8 : u8;
419 }
420
421 void
422 compare_bit_field_to_integer_constant(void)
423 {
424 static _Bool b;
425 static struct {
426 short s16:15;
427 unsigned short u16:15;
428 int s32:15;
429 unsigned u32:15;
430 long long s64:15;
431 unsigned long long u64:15;
432 } s;
433
434 // Since decl.c 1.180 from 2021-05-02 and before tree.c 1.624 from
435 // 2024-03-12, lint warned about a possible loss of accuracy [132]
436 // when promoting an 'unsigned long long' bit-field to 'int'.
437 b = s.s16 == 0;
438 b = s.u16 == 0;
439 b = s.s32 == 0;
440 b = s.u32 == 0;
441 b = s.s64 == 0;
442 b = s.u64 == 0;
443 b = !b;
444 }
445
446 /*
447 * Before tree.c 1.626 from 2024-03-26, the usual arithmetic conversions for
448 * bit-field types with the same base type but different widths simply took
449 * the type of the left operand, leading to wrong warnings about loss of
450 * accuracy when the right operand was wider than the left operand.
451 */
452 void
453 binary_operators_on_bit_fields(void)
454 {
455 struct {
456 u64_t u15:15;
457 u64_t u48:48;
458 u64_t u64;
459 } s = { 0, 0, 0 };
460
461 u64 = s.u15 | s.u48;
462 u64 = s.u48 | s.u15;
463 u64 = s.u15 | s.u48 | s.u64;
464 u64 = s.u64 | s.u48 | s.u15;
465 cond = (s.u15 | s.u48 | s.u64) != 0;
466 cond = (s.u64 | s.u48 | s.u15) != 0;
467
468 // Before tree.c from 1.638 from 2024-05-01, lint wrongly warned:
469 // warning: conversion of 'int' to 'int:4' is out of range [119]
470 s32 = 8 - bits.u3;
471 }
472
473 unsigned char
474 combine_arithmetic_and_bit_operations(void)
475 {
476 return 0xc0 | (u32 & 0x07c0) / 64;
477 }
478