Home | History | Annotate | Line # | Download | only in lint1
func.c revision 1.155
      1  1.155    rillig /*	$NetBSD: func.c,v 1.155 2023/06/09 13:03:49 rillig Exp $	*/
      2    1.2       cgd 
      3    1.1       cgd /*
      4    1.1       cgd  * Copyright (c) 1994, 1995 Jochen Pohl
      5    1.1       cgd  * All Rights Reserved.
      6    1.1       cgd  *
      7    1.1       cgd  * Redistribution and use in source and binary forms, with or without
      8    1.1       cgd  * modification, are permitted provided that the following conditions
      9    1.1       cgd  * are met:
     10    1.1       cgd  * 1. Redistributions of source code must retain the above copyright
     11    1.1       cgd  *    notice, this list of conditions and the following disclaimer.
     12    1.1       cgd  * 2. Redistributions in binary form must reproduce the above copyright
     13    1.1       cgd  *    notice, this list of conditions and the following disclaimer in the
     14    1.1       cgd  *    documentation and/or other materials provided with the distribution.
     15    1.1       cgd  * 3. All advertising materials mentioning features or use of this software
     16    1.1       cgd  *    must display the following acknowledgement:
     17    1.1       cgd  *      This product includes software developed by Jochen Pohl for
     18    1.1       cgd  *	The NetBSD Project.
     19    1.1       cgd  * 4. The name of the author may not be used to endorse or promote products
     20    1.1       cgd  *    derived from this software without specific prior written permission.
     21    1.1       cgd  *
     22    1.1       cgd  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
     23    1.1       cgd  * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
     24    1.1       cgd  * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
     25    1.1       cgd  * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
     26    1.1       cgd  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
     27    1.1       cgd  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
     28    1.1       cgd  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
     29    1.1       cgd  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
     30    1.1       cgd  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
     31    1.1       cgd  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
     32    1.1       cgd  */
     33    1.1       cgd 
     34   1.21       jmc #if HAVE_NBTOOL_CONFIG_H
     35   1.21       jmc #include "nbtool_config.h"
     36   1.21       jmc #endif
     37   1.21       jmc 
     38    1.8  christos #include <sys/cdefs.h>
     39  1.136    rillig #if defined(__RCSID)
     40  1.155    rillig __RCSID("$NetBSD: func.c,v 1.155 2023/06/09 13:03:49 rillig Exp $");
     41    1.1       cgd #endif
     42    1.1       cgd 
     43    1.1       cgd #include <stdlib.h>
     44    1.1       cgd #include <string.h>
     45    1.1       cgd 
     46    1.1       cgd #include "lint1.h"
     47   1.10        tv #include "cgram.h"
     48    1.1       cgd 
     49    1.1       cgd /*
     50    1.1       cgd  * Contains a pointer to the symbol table entry of the current function
     51    1.1       cgd  * definition.
     52    1.1       cgd  */
     53    1.1       cgd sym_t	*funcsym;
     54    1.1       cgd 
     55    1.1       cgd /* Is set as long as a statement can be reached. Must be set at level 0. */
     56   1.59    rillig bool	reached = true;
     57    1.1       cgd 
     58    1.1       cgd /*
     59   1.94    rillig  * Is true by default, can be cleared by NOTREACHED.
     60   1.94    rillig  * Is reset to true whenever 'reached' changes.
     61    1.1       cgd  */
     62   1.94    rillig bool	warn_about_unreachable;
     63    1.1       cgd 
     64    1.1       cgd /*
     65   1.63    rillig  * In conjunction with 'reached', controls printing of "fallthrough on ..."
     66    1.1       cgd  * warnings.
     67    1.1       cgd  * Reset by each statement and set by FALLTHROUGH, switch (switch1())
     68    1.1       cgd  * and case (label()).
     69    1.1       cgd  *
     70   1.78    rillig  * Control statements if, for, while and switch do not reset seen_fallthrough
     71   1.78    rillig  * because this must be done by the controlled statement. At least for if this
     72   1.78    rillig  * is important because ** FALLTHROUGH ** after "if (expr) statement" is
     73   1.54    rillig  * evaluated before the following token, which causes reduction of above.
     74    1.1       cgd  * This means that ** FALLTHROUGH ** after "if ..." would always be ignored.
     75    1.1       cgd  */
     76   1.78    rillig bool	seen_fallthrough;
     77    1.1       cgd 
     78   1.48    rillig /* The innermost control statement */
     79  1.150    rillig static control_statement *cstmt;
     80    1.1       cgd 
     81    1.1       cgd /*
     82    1.1       cgd  * Number of arguments which will be checked for usage in following
     83    1.1       cgd  * function definition. -1 stands for all arguments.
     84    1.1       cgd  *
     85   1.31    rillig  * The position of the last ARGSUSED comment is stored in argsused_pos.
     86    1.1       cgd  */
     87    1.1       cgd int	nargusg = -1;
     88   1.31    rillig pos_t	argsused_pos;
     89    1.1       cgd 
     90    1.1       cgd /*
     91    1.1       cgd  * Number of arguments of the following function definition whose types
     92    1.1       cgd  * shall be checked by lint2. -1 stands for all arguments.
     93    1.1       cgd  *
     94    1.1       cgd  * The position of the last VARARGS comment is stored in vapos.
     95    1.1       cgd  */
     96    1.1       cgd int	nvararg = -1;
     97    1.1       cgd pos_t	vapos;
     98    1.1       cgd 
     99    1.1       cgd /*
    100   1.49    rillig  * Both printflike_argnum and scanflike_argnum contain the 1-based number
    101   1.49    rillig  * of the string argument which shall be used to check the types of remaining
    102   1.49    rillig  * arguments (for PRINTFLIKE and SCANFLIKE).
    103    1.1       cgd  *
    104   1.31    rillig  * printflike_pos and scanflike_pos are the positions of the last PRINTFLIKE
    105   1.31    rillig  * or SCANFLIKE comment.
    106    1.1       cgd  */
    107   1.49    rillig int	printflike_argnum = -1;
    108   1.49    rillig int	scanflike_argnum = -1;
    109   1.31    rillig pos_t	printflike_pos;
    110   1.31    rillig pos_t	scanflike_pos;
    111    1.1       cgd 
    112    1.1       cgd /*
    113   1.28    rillig  * If both plibflg and llibflg are set, prototypes are written as function
    114    1.1       cgd  * definitions to the output file.
    115    1.1       cgd  */
    116   1.59    rillig bool	plibflg;
    117    1.1       cgd 
    118    1.1       cgd /*
    119   1.59    rillig  * True means that no warnings about constants in conditional
    120    1.6       jpo  * context are printed.
    121    1.1       cgd  */
    122   1.59    rillig bool	constcond_flag;
    123    1.1       cgd 
    124    1.1       cgd /*
    125  1.138    rillig  * Whether a lint library shall be created. The effect of this flag is that
    126  1.138    rillig  * all defined symbols are treated as used.
    127    1.1       cgd  * (The LINTLIBRARY comment also resets vflag.)
    128    1.1       cgd  */
    129   1.59    rillig bool	llibflg;
    130    1.1       cgd 
    131    1.1       cgd /*
    132  1.138    rillig  * Determines the warnings that are suppressed by a LINTED directive.  For
    133  1.138    rillig  * globally suppressed warnings, see 'msgset'.
    134  1.138    rillig  *
    135  1.138    rillig  * LWARN_ALL:	all warnings are enabled
    136  1.138    rillig  * LWARN_NONE:	all warnings are suppressed
    137  1.138    rillig  * n >= 0:	warning n is ignored, the others are active
    138    1.1       cgd  */
    139   1.25  christos int	lwarn = LWARN_ALL;
    140    1.6       jpo 
    141    1.6       jpo /*
    142   1.47    rillig  * Whether bitfield type errors are suppressed by a BITFIELDTYPE
    143   1.16   thorpej  * directive.
    144   1.16   thorpej  */
    145   1.47    rillig bool	bitfieldtype_ok;
    146   1.16   thorpej 
    147   1.16   thorpej /*
    148   1.59    rillig  * Whether complaints about use of "long long" are suppressed in
    149    1.6       jpo  * the next statement or declaration.
    150    1.6       jpo  */
    151   1.59    rillig bool	quadflg;
    152    1.1       cgd 
    153    1.1       cgd void
    154   1.96    rillig begin_control_statement(control_statement_kind kind)
    155    1.1       cgd {
    156  1.115    rillig 	control_statement *cs;
    157    1.1       cgd 
    158  1.115    rillig 	cs = xcalloc(1, sizeof(*cs));
    159  1.115    rillig 	cs->c_kind = kind;
    160  1.115    rillig 	cs->c_surrounding = cstmt;
    161  1.115    rillig 	cstmt = cs;
    162    1.1       cgd }
    163    1.1       cgd 
    164    1.1       cgd void
    165   1.96    rillig end_control_statement(control_statement_kind kind)
    166    1.1       cgd {
    167  1.115    rillig 	control_statement *cs;
    168   1.79    rillig 	case_label_t *cl, *next;
    169    1.1       cgd 
    170   1.48    rillig 	lint_assert(cstmt != NULL);
    171  1.110    rillig 
    172  1.110    rillig 	while (cstmt->c_kind != kind)
    173  1.110    rillig 		cstmt = cstmt->c_surrounding;
    174    1.1       cgd 
    175  1.115    rillig 	cs = cstmt;
    176  1.115    rillig 	cstmt = cs->c_surrounding;
    177    1.1       cgd 
    178  1.115    rillig 	for (cl = cs->c_case_labels; cl != NULL; cl = next) {
    179   1.63    rillig 		next = cl->cl_next;
    180    1.1       cgd 		free(cl);
    181    1.1       cgd 	}
    182    1.1       cgd 
    183  1.115    rillig 	free(cs->c_switch_type);
    184  1.115    rillig 	free(cs);
    185    1.1       cgd }
    186    1.1       cgd 
    187   1.93    rillig static void
    188   1.93    rillig set_reached(bool new_reached)
    189   1.93    rillig {
    190  1.118    rillig 	debug_step("%s -> %s",
    191  1.106    rillig 	    reached ? "reachable" : "unreachable",
    192  1.106    rillig 	    new_reached ? "reachable" : "unreachable");
    193   1.93    rillig 	reached = new_reached;
    194   1.94    rillig 	warn_about_unreachable = true;
    195   1.93    rillig }
    196   1.93    rillig 
    197    1.1       cgd /*
    198    1.1       cgd  * Prints a warning if a statement cannot be reached.
    199    1.1       cgd  */
    200    1.1       cgd void
    201   1.31    rillig check_statement_reachable(void)
    202    1.1       cgd {
    203   1.94    rillig 	if (!reached && warn_about_unreachable) {
    204    1.1       cgd 		/* statement not reached */
    205    1.1       cgd 		warning(193);
    206   1.95    rillig 		warn_about_unreachable = false;
    207    1.1       cgd 	}
    208    1.1       cgd }
    209    1.1       cgd 
    210    1.1       cgd /*
    211    1.1       cgd  * Called after a function declaration which introduces a function definition
    212  1.145    rillig  * and before an (optional) old-style argument declaration list.
    213    1.1       cgd  *
    214  1.145    rillig  * Puts all symbols declared in the prototype or in an old-style argument
    215    1.1       cgd  * list back to the symbol table.
    216    1.1       cgd  *
    217    1.1       cgd  * Does the usual checking of storage class, type (return value),
    218   1.28    rillig  * redeclaration, etc.
    219    1.1       cgd  */
    220    1.1       cgd void
    221  1.146    rillig begin_function(sym_t *fsym)
    222    1.1       cgd {
    223  1.155    rillig 	int n;
    224  1.155    rillig 	bool dowarn;
    225  1.155    rillig 	sym_t *arg, *sym, *rdsym;
    226    1.1       cgd 
    227    1.1       cgd 	funcsym = fsym;
    228    1.1       cgd 
    229    1.1       cgd 	/*
    230    1.1       cgd 	 * Put all symbols declared in the argument list back to the
    231    1.1       cgd 	 * symbol table.
    232    1.1       cgd 	 */
    233  1.128    rillig 	for (sym = dcs->d_func_proto_syms; sym != NULL;
    234  1.128    rillig 	    sym = sym->s_level_next) {
    235   1.77    rillig 		if (sym->s_block_level != -1) {
    236   1.77    rillig 			lint_assert(sym->s_block_level == 1);
    237    1.1       cgd 			inssym(1, sym);
    238    1.1       cgd 		}
    239    1.1       cgd 	}
    240    1.1       cgd 
    241    1.1       cgd 	/*
    242   1.29    rillig 	 * In old_style_function() we did not know whether it is an old
    243  1.145    rillig 	 * style function definition or only an old-style declaration,
    244   1.29    rillig 	 * if there are no arguments inside the argument list ("f()").
    245    1.1       cgd 	 */
    246  1.131    rillig 	if (!fsym->s_type->t_proto && fsym->u.s_old_style_args == NULL)
    247   1.59    rillig 		fsym->s_osdef = true;
    248    1.1       cgd 
    249   1.29    rillig 	check_type(fsym);
    250    1.1       cgd 
    251    1.1       cgd 	/*
    252   1.29    rillig 	 * check_type() checks for almost all possible errors, but not for
    253    1.1       cgd 	 * incomplete return values (these are allowed in declarations)
    254    1.1       cgd 	 */
    255    1.1       cgd 	if (fsym->s_type->t_subt->t_tspec != VOID &&
    256   1.66    rillig 	    is_incomplete(fsym->s_type->t_subt)) {
    257    1.1       cgd 		/* cannot return incomplete type */
    258    1.1       cgd 		error(67);
    259    1.1       cgd 	}
    260    1.1       cgd 
    261    1.4       jpo 	fsym->s_def = DEF;
    262    1.1       cgd 
    263    1.1       cgd 	if (fsym->s_scl == TYPEDEF) {
    264    1.1       cgd 		fsym->s_scl = EXTERN;
    265    1.1       cgd 		/* illegal storage class */
    266    1.1       cgd 		error(8);
    267    1.1       cgd 	}
    268    1.1       cgd 
    269    1.4       jpo 	if (dcs->d_inline)
    270   1.59    rillig 		fsym->s_inline = true;
    271    1.4       jpo 
    272    1.1       cgd 	/*
    273    1.1       cgd 	 * Arguments in new style function declarations need a name.
    274    1.1       cgd 	 * (void is already removed from the list of arguments)
    275    1.1       cgd 	 */
    276    1.1       cgd 	n = 1;
    277   1.32    rillig 	for (arg = fsym->s_type->t_args; arg != NULL; arg = arg->s_next) {
    278    1.1       cgd 		if (arg->s_scl == ABSTRACT) {
    279   1.41    rillig 			lint_assert(arg->s_name == unnamed);
    280  1.141    rillig 			/* formal parameter #%d lacks name */
    281    1.1       cgd 			error(59, n);
    282    1.1       cgd 		} else {
    283   1.41    rillig 			lint_assert(arg->s_name != unnamed);
    284    1.1       cgd 		}
    285    1.1       cgd 		n++;
    286    1.1       cgd 	}
    287    1.1       cgd 
    288    1.1       cgd 	/*
    289   1.35    rillig 	 * We must also remember the position. s_def_pos is overwritten
    290  1.145    rillig 	 * if this is an old-style definition and we had already a
    291    1.1       cgd 	 * prototype.
    292    1.1       cgd 	 */
    293   1.81    rillig 	dcs->d_func_def_pos = fsym->s_def_pos;
    294    1.1       cgd 
    295   1.80    rillig 	if ((rdsym = dcs->d_redeclared_symbol) != NULL) {
    296    1.1       cgd 
    297   1.59    rillig 		if (!check_redeclaration(fsym, (dowarn = false, &dowarn))) {
    298    1.1       cgd 
    299    1.1       cgd 			/*
    300    1.5       jpo 			 * Print nothing if the newly defined function
    301    1.1       cgd 			 * is defined in old style. A better warning will
    302   1.38    rillig 			 * be printed in check_func_lint_directives().
    303    1.1       cgd 			 */
    304   1.24  dholland 			if (dowarn && !fsym->s_osdef) {
    305  1.135    rillig 				/* TODO: error in C99 mode as well? */
    306  1.135    rillig 				if (!allow_trad && !allow_c99)
    307  1.139    rillig 					/* redeclaration of '%s' */
    308   1.50    rillig 					error(27, fsym->s_name);
    309   1.50    rillig 				else
    310  1.139    rillig 					/* redeclaration of '%s' */
    311   1.50    rillig 					warning(27, fsym->s_name);
    312  1.144    rillig 				print_previous_declaration(rdsym);
    313    1.1       cgd 			}
    314    1.1       cgd 
    315   1.29    rillig 			copy_usage_info(fsym, rdsym);
    316    1.1       cgd 
    317    1.1       cgd 			/*
    318    1.1       cgd 			 * If the old symbol was a prototype and the new
    319    1.1       cgd 			 * one is none, overtake the position of the
    320    1.1       cgd 			 * declaration of the prototype.
    321    1.1       cgd 			 */
    322    1.1       cgd 			if (fsym->s_osdef && rdsym->s_type->t_proto)
    323   1.36    rillig 				fsym->s_def_pos = rdsym->s_def_pos;
    324    1.1       cgd 
    325   1.29    rillig 			complete_type(fsym, rdsym);
    326    1.1       cgd 
    327    1.4       jpo 			if (rdsym->s_inline)
    328   1.59    rillig 				fsym->s_inline = true;
    329    1.4       jpo 
    330    1.1       cgd 		}
    331    1.1       cgd 
    332    1.1       cgd 		/* remove the old symbol from the symbol table */
    333    1.1       cgd 		rmsym(rdsym);
    334    1.1       cgd 
    335    1.1       cgd 	}
    336    1.1       cgd 
    337    1.1       cgd 	if (fsym->s_osdef && !fsym->s_type->t_proto) {
    338  1.135    rillig 		/* TODO: Make this an error in C99 mode as well. */
    339  1.135    rillig 		if ((!allow_trad && !allow_c99) && hflag &&
    340  1.135    rillig 		    strcmp(fsym->s_name, "main") != 0)
    341   1.28    rillig 			/* function definition is not a prototype */
    342    1.1       cgd 			warning(286);
    343    1.1       cgd 	}
    344    1.1       cgd 
    345    1.3       jpo 	if (dcs->d_notyp)
    346   1.69    rillig 		fsym->s_return_type_implicit_int = true;
    347    1.1       cgd 
    348   1.93    rillig 	set_reached(true);
    349    1.1       cgd }
    350    1.1       cgd 
    351   1.72    rillig static void
    352   1.72    rillig check_missing_return_value(void)
    353   1.72    rillig {
    354   1.72    rillig 	if (funcsym->s_type->t_subt->t_tspec == VOID)
    355   1.72    rillig 		return;
    356   1.72    rillig 	if (funcsym->s_return_type_implicit_int)
    357   1.72    rillig 		return;
    358   1.72    rillig 
    359   1.72    rillig 	/* C99 5.1.2.2.3 "Program termination" p1 */
    360  1.133    rillig 	if (allow_c99 && strcmp(funcsym->s_name, "main") == 0)
    361   1.72    rillig 		return;
    362   1.72    rillig 
    363  1.142    rillig 	/* function '%s' falls off bottom without returning value */
    364   1.72    rillig 	warning(217, funcsym->s_name);
    365   1.72    rillig }
    366   1.72    rillig 
    367    1.1       cgd /*
    368    1.1       cgd  * Called at the end of a function definition.
    369    1.1       cgd  */
    370    1.1       cgd void
    371  1.146    rillig end_function(void)
    372    1.1       cgd {
    373  1.155    rillig 	sym_t *arg;
    374  1.155    rillig 	int n;
    375    1.1       cgd 
    376    1.1       cgd 	if (reached) {
    377   1.63    rillig 		cstmt->c_had_return_noval = true;
    378   1.72    rillig 		check_missing_return_value();
    379    1.1       cgd 	}
    380    1.1       cgd 
    381    1.1       cgd 	/*
    382   1.22     perry 	 * This warning is printed only if the return value was implicitly
    383    1.1       cgd 	 * declared to be int. Otherwise the wrong return statement
    384    1.1       cgd 	 * has already printed a warning.
    385    1.1       cgd 	 */
    386   1.63    rillig 	if (cstmt->c_had_return_noval && cstmt->c_had_return_value &&
    387   1.69    rillig 	    funcsym->s_return_type_implicit_int)
    388  1.142    rillig 		/* function '%s' has 'return expr' and 'return' */
    389    1.1       cgd 		warning(216, funcsym->s_name);
    390    1.1       cgd 
    391    1.1       cgd 	/* Print warnings for unused arguments */
    392   1.81    rillig 	arg = dcs->d_func_args;
    393    1.1       cgd 	n = 0;
    394    1.1       cgd 	while (arg != NULL && (nargusg == -1 || n < nargusg)) {
    395   1.29    rillig 		check_usage_sym(dcs->d_asm, arg);
    396   1.32    rillig 		arg = arg->s_next;
    397    1.1       cgd 		n++;
    398    1.1       cgd 	}
    399    1.1       cgd 	nargusg = -1;
    400    1.1       cgd 
    401    1.1       cgd 	/*
    402    1.4       jpo 	 * write the information about the function definition to the
    403    1.1       cgd 	 * output file
    404   1.15       wiz 	 * inline functions explicitly declared extern are written as
    405    1.4       jpo 	 * declarations only.
    406    1.1       cgd 	 */
    407    1.4       jpo 	if (dcs->d_scl == EXTERN && funcsym->s_inline) {
    408    1.4       jpo 		outsym(funcsym, funcsym->s_scl, DECL);
    409    1.4       jpo 	} else {
    410   1.81    rillig 		outfdef(funcsym, &dcs->d_func_def_pos,
    411   1.81    rillig 		    cstmt->c_had_return_value, funcsym->s_osdef,
    412   1.81    rillig 		    dcs->d_func_args);
    413    1.1       cgd 	}
    414    1.1       cgd 
    415  1.111    rillig 	/* clean up after syntax errors, see test stmt_for.c. */
    416  1.129    rillig 	while (dcs->d_enclosing != NULL)
    417  1.129    rillig 		dcs = dcs->d_enclosing;
    418  1.111    rillig 
    419    1.1       cgd 	/*
    420    1.1       cgd 	 * remove all symbols declared during argument declaration from
    421    1.1       cgd 	 * the symbol table
    422    1.1       cgd 	 */
    423  1.129    rillig 	lint_assert(dcs->d_enclosing == NULL);
    424  1.132    rillig 	lint_assert(dcs->d_kind == DK_EXTERN);
    425   1.81    rillig 	rmsyms(dcs->d_func_proto_syms);
    426    1.1       cgd 
    427    1.1       cgd 	/* must be set on level 0 */
    428   1.93    rillig 	set_reached(true);
    429  1.147    rillig 
    430  1.147    rillig 	funcsym = NULL;
    431    1.1       cgd }
    432    1.1       cgd 
    433    1.1       cgd void
    434   1.42    rillig named_label(sym_t *sym)
    435   1.42    rillig {
    436   1.42    rillig 
    437   1.42    rillig 	if (sym->s_set) {
    438  1.142    rillig 		/* label '%s' redefined */
    439   1.42    rillig 		error(194, sym->s_name);
    440   1.42    rillig 	} else {
    441   1.42    rillig 		mark_as_set(sym);
    442   1.42    rillig 	}
    443   1.42    rillig 
    444  1.149    rillig 	/* XXX: Assuming that each label is reachable is wrong. */
    445   1.93    rillig 	set_reached(true);
    446   1.42    rillig }
    447   1.42    rillig 
    448   1.43    rillig static void
    449  1.108    rillig check_case_label_bitand(const tnode_t *case_expr, const tnode_t *switch_expr)
    450  1.108    rillig {
    451  1.108    rillig 	uint64_t case_value, mask;
    452  1.108    rillig 
    453  1.108    rillig 	if (switch_expr->tn_op != BITAND ||
    454  1.108    rillig 	    switch_expr->tn_right->tn_op != CON)
    455  1.108    rillig 		return;
    456  1.108    rillig 
    457  1.108    rillig 	lint_assert(case_expr->tn_op == CON);
    458  1.108    rillig 	case_value = case_expr->tn_val->v_quad;
    459  1.108    rillig 	mask = switch_expr->tn_right->tn_val->v_quad;
    460  1.108    rillig 
    461  1.108    rillig 	if ((case_value & ~mask) != 0) {
    462  1.108    rillig 		/* statement not reached */
    463  1.108    rillig 		warning(193);
    464  1.108    rillig 	}
    465  1.108    rillig }
    466  1.108    rillig 
    467  1.108    rillig static void
    468  1.115    rillig check_case_label_enum(const tnode_t *tn, const control_statement *cs)
    469   1.75    rillig {
    470   1.75    rillig 	/* similar to typeok_enum in tree.c */
    471   1.75    rillig 
    472  1.115    rillig 	if (!(tn->tn_type->t_is_enum || cs->c_switch_type->t_is_enum))
    473   1.75    rillig 		return;
    474  1.115    rillig 	if (tn->tn_type->t_is_enum && cs->c_switch_type->t_is_enum &&
    475  1.115    rillig 	    tn->tn_type->t_enum == cs->c_switch_type->t_enum)
    476   1.75    rillig 		return;
    477   1.75    rillig 
    478   1.76    rillig #if 0 /* not yet ready, see msg_130.c */
    479   1.75    rillig 	/* enum type mismatch: '%s' '%s' '%s' */
    480  1.115    rillig 	warning(130, type_name(cs->c_switch_type), op_name(EQ),
    481   1.75    rillig 	    type_name(tn->tn_type));
    482   1.76    rillig #endif
    483   1.75    rillig }
    484   1.75    rillig 
    485   1.75    rillig static void
    486  1.115    rillig check_case_label(tnode_t *tn, control_statement *cs)
    487    1.1       cgd {
    488   1.79    rillig 	case_label_t *cl;
    489  1.155    rillig 	val_t *v;
    490  1.155    rillig 	val_t nv;
    491  1.155    rillig 	tspec_t t;
    492    1.1       cgd 
    493  1.115    rillig 	if (cs == NULL) {
    494   1.42    rillig 		/* case not in switch */
    495   1.42    rillig 		error(195);
    496   1.43    rillig 		return;
    497   1.43    rillig 	}
    498   1.43    rillig 
    499  1.149    rillig 	if (tn == NULL)
    500  1.149    rillig 		return;
    501  1.149    rillig 
    502  1.149    rillig 	if (tn->tn_op != CON) {
    503   1.42    rillig 		/* non-constant case expression */
    504   1.42    rillig 		error(197);
    505   1.43    rillig 		return;
    506   1.43    rillig 	}
    507   1.43    rillig 
    508  1.149    rillig 	if (!is_integer(tn->tn_type->t_tspec)) {
    509   1.42    rillig 		/* non-integral case expression */
    510   1.42    rillig 		error(198);
    511   1.43    rillig 		return;
    512   1.42    rillig 	}
    513    1.1       cgd 
    514  1.115    rillig 	check_case_label_bitand(tn, cs->c_switch_expr);
    515  1.115    rillig 	check_case_label_enum(tn, cs);
    516   1.75    rillig 
    517  1.115    rillig 	lint_assert(cs->c_switch_type != NULL);
    518    1.1       cgd 
    519   1.78    rillig 	if (reached && !seen_fallthrough) {
    520   1.43    rillig 		if (hflag)
    521   1.43    rillig 			/* fallthrough on case statement */
    522   1.43    rillig 			warning(220);
    523   1.43    rillig 	}
    524    1.1       cgd 
    525   1.43    rillig 	t = tn->tn_type->t_tspec;
    526   1.43    rillig 	if (t == LONG || t == ULONG ||
    527   1.43    rillig 	    t == QUAD || t == UQUAD) {
    528  1.134    rillig 		if (!allow_c90)
    529  1.120    rillig 			/* case label must be of type 'int' in traditional C */
    530   1.43    rillig 			warning(203);
    531   1.43    rillig 	}
    532    1.1       cgd 
    533   1.43    rillig 	/*
    534   1.43    rillig 	 * get the value of the expression and convert it
    535   1.43    rillig 	 * to the type of the switch expression
    536   1.43    rillig 	 */
    537   1.60    rillig 	v = constant(tn, true);
    538  1.101    rillig 	(void)memset(&nv, 0, sizeof(nv));
    539  1.115    rillig 	convert_constant(CASE, 0, cs->c_switch_type, &nv, v);
    540   1.43    rillig 	free(v);
    541   1.43    rillig 
    542   1.43    rillig 	/* look if we had this value already */
    543  1.115    rillig 	for (cl = cs->c_case_labels; cl != NULL; cl = cl->cl_next) {
    544   1.43    rillig 		if (cl->cl_val.v_quad == nv.v_quad)
    545   1.43    rillig 			break;
    546   1.43    rillig 	}
    547   1.55    rillig 	if (cl != NULL && is_uinteger(nv.v_tspec)) {
    548   1.43    rillig 		/* duplicate case in switch: %lu */
    549  1.121    rillig 		error(200, (unsigned long)nv.v_quad);
    550   1.43    rillig 	} else if (cl != NULL) {
    551   1.43    rillig 		/* duplicate case in switch: %ld */
    552   1.43    rillig 		error(199, (long)nv.v_quad);
    553   1.43    rillig 	} else {
    554   1.68    rillig 		check_getopt_case_label(nv.v_quad);
    555   1.68    rillig 
    556  1.103    rillig 		/* append the value to the list of case values */
    557  1.101    rillig 		cl = xcalloc(1, sizeof(*cl));
    558   1.43    rillig 		cl->cl_val = nv;
    559  1.115    rillig 		cl->cl_next = cs->c_case_labels;
    560  1.115    rillig 		cs->c_case_labels = cl;
    561   1.42    rillig 	}
    562   1.43    rillig }
    563   1.43    rillig 
    564   1.43    rillig void
    565   1.43    rillig case_label(tnode_t *tn)
    566   1.43    rillig {
    567  1.115    rillig 	control_statement *cs;
    568   1.43    rillig 
    569   1.51    rillig 	/* find the innermost switch statement */
    570  1.115    rillig 	for (cs = cstmt; cs != NULL && !cs->c_switch; cs = cs->c_surrounding)
    571   1.43    rillig 		continue;
    572   1.43    rillig 
    573  1.115    rillig 	check_case_label(tn, cs);
    574   1.43    rillig 
    575   1.99    rillig 	expr_free_all();
    576   1.42    rillig 
    577   1.93    rillig 	set_reached(true);
    578   1.42    rillig }
    579   1.42    rillig 
    580   1.42    rillig void
    581   1.42    rillig default_label(void)
    582   1.42    rillig {
    583  1.115    rillig 	control_statement *cs;
    584    1.1       cgd 
    585   1.51    rillig 	/* find the innermost switch statement */
    586  1.115    rillig 	for (cs = cstmt; cs != NULL && !cs->c_switch; cs = cs->c_surrounding)
    587   1.42    rillig 		continue;
    588    1.1       cgd 
    589  1.115    rillig 	if (cs == NULL) {
    590   1.42    rillig 		/* default outside switch */
    591   1.42    rillig 		error(201);
    592  1.115    rillig 	} else if (cs->c_default) {
    593   1.42    rillig 		/* duplicate default in switch */
    594   1.42    rillig 		error(202);
    595   1.42    rillig 	} else {
    596   1.78    rillig 		if (reached && !seen_fallthrough) {
    597   1.42    rillig 			if (hflag)
    598   1.42    rillig 				/* fallthrough on default statement */
    599   1.42    rillig 				warning(284);
    600    1.1       cgd 		}
    601  1.115    rillig 		cs->c_default = true;
    602   1.42    rillig 	}
    603   1.42    rillig 
    604   1.93    rillig 	set_reached(true);
    605    1.1       cgd }
    606    1.1       cgd 
    607   1.39    rillig static tnode_t *
    608   1.39    rillig check_controlling_expression(tnode_t *tn)
    609   1.39    rillig {
    610   1.39    rillig 
    611  1.124    rillig 	tn = cconv(tn);
    612   1.39    rillig 	if (tn != NULL)
    613   1.60    rillig 		tn = promote(NOOP, false, tn);
    614   1.39    rillig 
    615   1.55    rillig 	if (tn != NULL && !is_scalar(tn->tn_type->t_tspec)) {
    616   1.39    rillig 		/* C99 6.5.15p4 for the ?: operator; see typeok:QUEST */
    617   1.39    rillig 		/* C99 6.8.4.1p1 for if statements */
    618   1.39    rillig 		/* C99 6.8.5p2 for while, do and for loops */
    619   1.39    rillig 		/* controlling expressions must have scalar type */
    620   1.39    rillig 		error(204);
    621   1.39    rillig 		return NULL;
    622   1.39    rillig 	}
    623   1.39    rillig 
    624  1.140    rillig 	if (tn != NULL && Tflag && !is_typeok_bool_compares_with_zero(tn)) {
    625   1.57    rillig 		/* controlling expression must be bool, not '%s' */
    626  1.154    rillig 		error(333, tn->tn_type->t_is_enum ? type_name(tn->tn_type)
    627  1.154    rillig 		    : tspec_name(tn->tn_type->t_tspec));
    628   1.57    rillig 	}
    629   1.57    rillig 
    630   1.39    rillig 	return tn;
    631   1.39    rillig }
    632   1.39    rillig 
    633    1.1       cgd /*
    634   1.44    rillig  * T_IF T_LPAREN expr T_RPAREN
    635    1.1       cgd  */
    636    1.1       cgd void
    637   1.14     lukem if1(tnode_t *tn)
    638    1.1       cgd {
    639   1.14     lukem 
    640    1.1       cgd 	if (tn != NULL)
    641   1.39    rillig 		tn = check_controlling_expression(tn);
    642    1.1       cgd 	if (tn != NULL)
    643   1.67    rillig 		expr(tn, false, true, false, false);
    644   1.96    rillig 	begin_control_statement(CS_IF);
    645   1.88    rillig 
    646   1.88    rillig 	if (tn != NULL && tn->tn_op == CON && !tn->tn_system_dependent) {
    647   1.93    rillig 		/* XXX: what if inside 'if (0)'? */
    648   1.93    rillig 		set_reached(constant_is_nonzero(tn));
    649   1.93    rillig 		/* XXX: what about always_else? */
    650   1.88    rillig 		cstmt->c_always_then = reached;
    651   1.88    rillig 	}
    652    1.1       cgd }
    653    1.1       cgd 
    654    1.1       cgd /*
    655    1.1       cgd  * if_without_else
    656    1.1       cgd  * if_without_else T_ELSE
    657    1.1       cgd  */
    658    1.1       cgd void
    659   1.14     lukem if2(void)
    660    1.1       cgd {
    661   1.14     lukem 
    662   1.87    rillig 	cstmt->c_reached_end_of_then = reached;
    663   1.93    rillig 	/* XXX: what if inside 'if (0)'? */
    664   1.93    rillig 	set_reached(!cstmt->c_always_then);
    665    1.1       cgd }
    666    1.1       cgd 
    667    1.1       cgd /*
    668    1.1       cgd  * if_without_else
    669   1.54    rillig  * if_without_else T_ELSE statement
    670    1.1       cgd  */
    671    1.1       cgd void
    672   1.59    rillig if3(bool els)
    673    1.1       cgd {
    674   1.90    rillig 	if (cstmt->c_reached_end_of_then)
    675   1.93    rillig 		set_reached(true);
    676   1.90    rillig 	else if (cstmt->c_always_then)
    677   1.93    rillig 		set_reached(false);
    678   1.90    rillig 	else if (!els)
    679   1.93    rillig 		set_reached(true);
    680   1.14     lukem 
    681   1.96    rillig 	end_control_statement(CS_IF);
    682    1.1       cgd }
    683    1.1       cgd 
    684    1.1       cgd /*
    685   1.44    rillig  * T_SWITCH T_LPAREN expr T_RPAREN
    686    1.1       cgd  */
    687    1.1       cgd void
    688   1.14     lukem switch1(tnode_t *tn)
    689    1.1       cgd {
    690  1.155    rillig 	tspec_t t;
    691  1.155    rillig 	type_t *tp;
    692    1.1       cgd 
    693    1.1       cgd 	if (tn != NULL)
    694    1.1       cgd 		tn = cconv(tn);
    695    1.1       cgd 	if (tn != NULL)
    696   1.60    rillig 		tn = promote(NOOP, false, tn);
    697   1.55    rillig 	if (tn != NULL && !is_integer(tn->tn_type->t_tspec)) {
    698    1.1       cgd 		/* switch expression must have integral type */
    699    1.1       cgd 		error(205);
    700    1.1       cgd 		tn = NULL;
    701    1.1       cgd 	}
    702  1.134    rillig 	if (tn != NULL && !allow_c90) {
    703    1.1       cgd 		t = tn->tn_type->t_tspec;
    704    1.1       cgd 		if (t == LONG || t == ULONG || t == QUAD || t == UQUAD) {
    705  1.123    rillig 			/* switch expression must be of type 'int' in ... */
    706    1.1       cgd 			warning(271);
    707    1.1       cgd 		}
    708    1.1       cgd 	}
    709    1.1       cgd 
    710    1.1       cgd 	/*
    711   1.37    rillig 	 * Remember the type of the expression. Because it's possible
    712   1.37    rillig 	 * that (*tp) is allocated on tree memory, the type must be
    713    1.1       cgd 	 * duplicated. This is not too complicated because it is
    714    1.1       cgd 	 * only an integer type.
    715    1.1       cgd 	 */
    716  1.101    rillig 	tp = xcalloc(1, sizeof(*tp));
    717    1.1       cgd 	if (tn != NULL) {
    718    1.1       cgd 		tp->t_tspec = tn->tn_type->t_tspec;
    719   1.71    rillig 		if ((tp->t_is_enum = tn->tn_type->t_is_enum) != false)
    720    1.1       cgd 			tp->t_enum = tn->tn_type->t_enum;
    721    1.1       cgd 	} else {
    722    1.1       cgd 		tp->t_tspec = INT;
    723    1.1       cgd 	}
    724    1.1       cgd 
    725  1.108    rillig 	/* leak the memory, for check_case_label_bitand */
    726  1.122    rillig 	(void)expr_save_memory();
    727  1.108    rillig 
    728   1.68    rillig 	check_getopt_begin_switch();
    729  1.108    rillig 	expr(tn, true, false, false, false);
    730    1.1       cgd 
    731   1.96    rillig 	begin_control_statement(CS_SWITCH);
    732   1.59    rillig 	cstmt->c_switch = true;
    733   1.97    rillig 	cstmt->c_switch_type = tp;
    734  1.108    rillig 	cstmt->c_switch_expr = tn;
    735    1.1       cgd 
    736   1.93    rillig 	set_reached(false);
    737   1.78    rillig 	seen_fallthrough = true;
    738    1.1       cgd }
    739    1.1       cgd 
    740    1.1       cgd /*
    741   1.54    rillig  * switch_expr statement
    742    1.1       cgd  */
    743    1.1       cgd void
    744   1.14     lukem switch2(void)
    745    1.1       cgd {
    746  1.155    rillig 	int nenum = 0, nclab = 0;
    747  1.155    rillig 	sym_t *esym;
    748   1.79    rillig 	case_label_t *cl;
    749    1.1       cgd 
    750   1.97    rillig 	lint_assert(cstmt->c_switch_type != NULL);
    751    1.1       cgd 
    752   1.97    rillig 	if (cstmt->c_switch_type->t_is_enum) {
    753  1.112    rillig 		/*
    754  1.112    rillig 		 * Warn if the number of case labels is different from the
    755  1.112    rillig 		 * number of enumerators.
    756  1.112    rillig 		 */
    757    1.1       cgd 		nenum = nclab = 0;
    758   1.97    rillig 		lint_assert(cstmt->c_switch_type->t_enum != NULL);
    759   1.97    rillig 		for (esym = cstmt->c_switch_type->t_enum->en_first_enumerator;
    760   1.32    rillig 		     esym != NULL; esym = esym->s_next) {
    761    1.1       cgd 			nenum++;
    762    1.1       cgd 		}
    763   1.79    rillig 		for (cl = cstmt->c_case_labels; cl != NULL; cl = cl->cl_next)
    764    1.1       cgd 			nclab++;
    765  1.137    rillig 		if (hflag && eflag && nclab < nenum && !cstmt->c_default) {
    766    1.1       cgd 			/* enumeration value(s) not handled in switch */
    767    1.1       cgd 			warning(206);
    768    1.1       cgd 		}
    769    1.1       cgd 	}
    770    1.1       cgd 
    771   1.68    rillig 	check_getopt_end_switch();
    772   1.68    rillig 
    773   1.48    rillig 	if (cstmt->c_break) {
    774    1.1       cgd 		/*
    775  1.112    rillig 		 * The end of the switch statement is always reached since
    776  1.112    rillig 		 * c_break is only set if a break statement can actually
    777  1.112    rillig 		 * be reached.
    778    1.1       cgd 		 */
    779   1.93    rillig 		set_reached(true);
    780  1.112    rillig 	} else if (cstmt->c_default ||
    781  1.112    rillig 		   (hflag && cstmt->c_switch_type->t_is_enum &&
    782  1.112    rillig 		    nenum == nclab)) {
    783    1.1       cgd 		/*
    784  1.112    rillig 		 * The end of the switch statement is reached if the end
    785  1.112    rillig 		 * of the last statement inside it is reached.
    786  1.112    rillig 		 */
    787  1.112    rillig 	} else {
    788  1.112    rillig 		/*
    789  1.112    rillig 		 * There are possible values that are not handled in the
    790  1.112    rillig 		 * switch statement.
    791    1.1       cgd 		 */
    792   1.93    rillig 		set_reached(true);
    793  1.112    rillig 	}
    794    1.1       cgd 
    795   1.96    rillig 	end_control_statement(CS_SWITCH);
    796    1.1       cgd }
    797    1.1       cgd 
    798    1.1       cgd /*
    799   1.44    rillig  * T_WHILE T_LPAREN expr T_RPAREN
    800    1.1       cgd  */
    801    1.1       cgd void
    802   1.14     lukem while1(tnode_t *tn)
    803    1.1       cgd {
    804   1.92    rillig 	bool body_reached;
    805   1.14     lukem 
    806    1.1       cgd 	if (!reached) {
    807    1.1       cgd 		/* loop not entered at top */
    808    1.1       cgd 		warning(207);
    809   1.93    rillig 		/* FIXME: that's plain wrong. */
    810   1.93    rillig 		set_reached(true);
    811    1.1       cgd 	}
    812    1.1       cgd 
    813    1.1       cgd 	if (tn != NULL)
    814   1.39    rillig 		tn = check_controlling_expression(tn);
    815    1.1       cgd 
    816   1.96    rillig 	begin_control_statement(CS_WHILE);
    817   1.59    rillig 	cstmt->c_loop = true;
    818   1.92    rillig 	cstmt->c_maybe_endless = is_nonzero(tn);
    819   1.92    rillig 	body_reached = !is_zero(tn);
    820    1.1       cgd 
    821   1.68    rillig 	check_getopt_begin_while(tn);
    822   1.67    rillig 	expr(tn, false, true, true, false);
    823   1.92    rillig 
    824   1.93    rillig 	set_reached(body_reached);
    825    1.1       cgd }
    826    1.1       cgd 
    827    1.1       cgd /*
    828   1.54    rillig  * while_expr statement
    829    1.1       cgd  * while_expr error
    830    1.1       cgd  */
    831    1.1       cgd void
    832   1.14     lukem while2(void)
    833    1.1       cgd {
    834   1.14     lukem 
    835    1.1       cgd 	/*
    836    1.1       cgd 	 * The end of the loop can be reached if it is no endless loop
    837    1.1       cgd 	 * or there was a break statement which was reached.
    838    1.1       cgd 	 */
    839   1.93    rillig 	set_reached(!cstmt->c_maybe_endless || cstmt->c_break);
    840    1.1       cgd 
    841   1.68    rillig 	check_getopt_end_while();
    842   1.96    rillig 	end_control_statement(CS_WHILE);
    843    1.1       cgd }
    844    1.1       cgd 
    845    1.1       cgd /*
    846    1.1       cgd  * T_DO
    847    1.1       cgd  */
    848    1.1       cgd void
    849   1.14     lukem do1(void)
    850    1.1       cgd {
    851   1.14     lukem 
    852    1.1       cgd 	if (!reached) {
    853    1.1       cgd 		/* loop not entered at top */
    854    1.1       cgd 		warning(207);
    855   1.93    rillig 		set_reached(true);
    856    1.1       cgd 	}
    857    1.1       cgd 
    858   1.96    rillig 	begin_control_statement(CS_DO_WHILE);
    859   1.59    rillig 	cstmt->c_loop = true;
    860    1.1       cgd }
    861    1.1       cgd 
    862    1.1       cgd /*
    863   1.54    rillig  * do statement do_while_expr
    864    1.1       cgd  * do error
    865    1.1       cgd  */
    866    1.1       cgd void
    867   1.14     lukem do2(tnode_t *tn)
    868    1.1       cgd {
    869   1.14     lukem 
    870    1.1       cgd 	/*
    871   1.28    rillig 	 * If there was a continue statement, the expression controlling the
    872    1.1       cgd 	 * loop is reached.
    873    1.1       cgd 	 */
    874   1.85    rillig 	if (cstmt->c_continue)
    875   1.93    rillig 		set_reached(true);
    876    1.1       cgd 
    877    1.1       cgd 	if (tn != NULL)
    878   1.39    rillig 		tn = check_controlling_expression(tn);
    879    1.1       cgd 
    880    1.1       cgd 	if (tn != NULL && tn->tn_op == CON) {
    881   1.84    rillig 		cstmt->c_maybe_endless = constant_is_nonzero(tn);
    882   1.85    rillig 		if (!cstmt->c_maybe_endless && cstmt->c_continue)
    883   1.46    rillig 			/* continue in 'do ... while (0)' loop */
    884   1.46    rillig 			error(323);
    885    1.1       cgd 	}
    886    1.1       cgd 
    887   1.67    rillig 	expr(tn, false, true, true, true);
    888    1.1       cgd 
    889   1.84    rillig 	if (cstmt->c_maybe_endless)
    890   1.93    rillig 		set_reached(false);
    891   1.83    rillig 	if (cstmt->c_break)
    892   1.93    rillig 		set_reached(true);
    893    1.1       cgd 
    894   1.96    rillig 	end_control_statement(CS_DO_WHILE);
    895    1.1       cgd }
    896    1.1       cgd 
    897    1.1       cgd /*
    898   1.44    rillig  * T_FOR T_LPAREN opt_expr T_SEMI opt_expr T_SEMI opt_expr T_RPAREN
    899    1.1       cgd  */
    900    1.1       cgd void
    901   1.14     lukem for1(tnode_t *tn1, tnode_t *tn2, tnode_t *tn3)
    902    1.1       cgd {
    903   1.14     lukem 
    904    1.1       cgd 	/*
    905   1.73    rillig 	 * If there is no initialization expression it is possible that
    906    1.1       cgd 	 * it is intended not to enter the loop at top.
    907    1.1       cgd 	 */
    908    1.1       cgd 	if (tn1 != NULL && !reached) {
    909    1.1       cgd 		/* loop not entered at top */
    910    1.1       cgd 		warning(207);
    911   1.93    rillig 		set_reached(true);
    912    1.1       cgd 	}
    913    1.1       cgd 
    914   1.96    rillig 	begin_control_statement(CS_FOR);
    915   1.59    rillig 	cstmt->c_loop = true;
    916    1.1       cgd 
    917    1.1       cgd 	/*
    918   1.73    rillig 	 * Store the tree memory for the reinitialization expression.
    919    1.1       cgd 	 * Also remember this expression itself. We must check it at
    920    1.1       cgd 	 * the end of the loop to get "used but not set" warnings correct.
    921    1.1       cgd 	 */
    922   1.99    rillig 	cstmt->c_for_expr3_mem = expr_save_memory();
    923   1.97    rillig 	cstmt->c_for_expr3 = tn3;
    924   1.97    rillig 	cstmt->c_for_expr3_pos = curr_pos;
    925   1.97    rillig 	cstmt->c_for_expr3_csrc_pos = csrc_pos;
    926    1.1       cgd 
    927    1.1       cgd 	if (tn1 != NULL)
    928   1.67    rillig 		expr(tn1, false, false, true, false);
    929    1.1       cgd 
    930    1.1       cgd 	if (tn2 != NULL)
    931   1.39    rillig 		tn2 = check_controlling_expression(tn2);
    932    1.1       cgd 	if (tn2 != NULL)
    933   1.67    rillig 		expr(tn2, false, true, true, false);
    934    1.1       cgd 
    935   1.91    rillig 	cstmt->c_maybe_endless = tn2 == NULL || is_nonzero(tn2);
    936    1.1       cgd 
    937   1.73    rillig 	/* Checking the reinitialization expression is done in for2() */
    938    1.1       cgd 
    939   1.93    rillig 	set_reached(!is_zero(tn2));
    940    1.1       cgd }
    941    1.1       cgd 
    942    1.1       cgd /*
    943   1.54    rillig  * for_exprs statement
    944    1.1       cgd  * for_exprs error
    945    1.1       cgd  */
    946    1.1       cgd void
    947   1.14     lukem for2(void)
    948    1.1       cgd {
    949  1.155    rillig 	pos_t cpos, cspos;
    950  1.155    rillig 	tnode_t *tn3;
    951    1.1       cgd 
    952   1.85    rillig 	if (cstmt->c_continue)
    953   1.93    rillig 		set_reached(true);
    954    1.1       cgd 
    955   1.36    rillig 	cpos = curr_pos;
    956   1.36    rillig 	cspos = csrc_pos;
    957    1.1       cgd 
    958   1.73    rillig 	/* Restore the tree memory for the reinitialization expression */
    959   1.99    rillig 	expr_restore_memory(cstmt->c_for_expr3_mem);
    960   1.97    rillig 	tn3 = cstmt->c_for_expr3;
    961   1.97    rillig 	curr_pos = cstmt->c_for_expr3_pos;
    962   1.97    rillig 	csrc_pos = cstmt->c_for_expr3_csrc_pos;
    963    1.1       cgd 
    964    1.1       cgd 	/* simply "statement not reached" would be confusing */
    965   1.94    rillig 	if (!reached && warn_about_unreachable) {
    966    1.1       cgd 		/* end-of-loop code not reached */
    967    1.1       cgd 		warning(223);
    968   1.93    rillig 		set_reached(true);
    969    1.1       cgd 	}
    970    1.1       cgd 
    971    1.1       cgd 	if (tn3 != NULL) {
    972   1.67    rillig 		expr(tn3, false, false, true, false);
    973    1.1       cgd 	} else {
    974   1.99    rillig 		expr_free_all();
    975    1.1       cgd 	}
    976    1.1       cgd 
    977   1.36    rillig 	curr_pos = cpos;
    978   1.36    rillig 	csrc_pos = cspos;
    979    1.1       cgd 
    980    1.1       cgd 	/* An endless loop without break will never terminate */
    981   1.84    rillig 	/* TODO: What if the loop contains a 'return'? */
    982   1.93    rillig 	set_reached(cstmt->c_break || !cstmt->c_maybe_endless);
    983    1.1       cgd 
    984   1.96    rillig 	end_control_statement(CS_FOR);
    985    1.1       cgd }
    986    1.1       cgd 
    987    1.1       cgd /*
    988    1.1       cgd  * T_GOTO identifier T_SEMI
    989    1.1       cgd  */
    990    1.1       cgd void
    991   1.89    rillig do_goto(sym_t *lab)
    992    1.1       cgd {
    993   1.14     lukem 
    994   1.60    rillig 	mark_as_used(lab, false, false);
    995    1.1       cgd 
    996   1.31    rillig 	check_statement_reachable();
    997    1.1       cgd 
    998   1.93    rillig 	set_reached(false);
    999    1.1       cgd }
   1000    1.1       cgd 
   1001    1.1       cgd /*
   1002    1.1       cgd  * T_BREAK T_SEMI
   1003    1.1       cgd  */
   1004    1.1       cgd void
   1005   1.89    rillig do_break(void)
   1006    1.1       cgd {
   1007  1.115    rillig 	control_statement *cs;
   1008    1.1       cgd 
   1009  1.115    rillig 	cs = cstmt;
   1010  1.115    rillig 	while (cs != NULL && !cs->c_loop && !cs->c_switch)
   1011  1.115    rillig 		cs = cs->c_surrounding;
   1012    1.1       cgd 
   1013  1.115    rillig 	if (cs == NULL) {
   1014    1.1       cgd 		/* break outside loop or switch */
   1015    1.1       cgd 		error(208);
   1016    1.1       cgd 	} else {
   1017    1.1       cgd 		if (reached)
   1018  1.115    rillig 			cs->c_break = true;
   1019    1.1       cgd 	}
   1020    1.1       cgd 
   1021    1.1       cgd 	if (bflag)
   1022   1.31    rillig 		check_statement_reachable();
   1023    1.1       cgd 
   1024   1.93    rillig 	set_reached(false);
   1025    1.1       cgd }
   1026    1.1       cgd 
   1027    1.1       cgd /*
   1028    1.1       cgd  * T_CONTINUE T_SEMI
   1029    1.1       cgd  */
   1030    1.1       cgd void
   1031   1.89    rillig do_continue(void)
   1032    1.1       cgd {
   1033  1.115    rillig 	control_statement *cs;
   1034    1.1       cgd 
   1035  1.115    rillig 	for (cs = cstmt; cs != NULL && !cs->c_loop; cs = cs->c_surrounding)
   1036   1.14     lukem 		continue;
   1037    1.1       cgd 
   1038  1.115    rillig 	if (cs == NULL) {
   1039    1.1       cgd 		/* continue outside loop */
   1040    1.1       cgd 		error(209);
   1041    1.1       cgd 	} else {
   1042   1.85    rillig 		/* TODO: only if reachable, for symmetry with c_break */
   1043  1.115    rillig 		cs->c_continue = true;
   1044    1.1       cgd 	}
   1045    1.1       cgd 
   1046   1.31    rillig 	check_statement_reachable();
   1047    1.1       cgd 
   1048   1.93    rillig 	set_reached(false);
   1049    1.1       cgd }
   1050    1.1       cgd 
   1051  1.153    rillig static bool
   1052  1.153    rillig is_parenthesized(const tnode_t *tn)
   1053  1.153    rillig {
   1054  1.153    rillig 
   1055  1.153    rillig 	while (!tn->tn_parenthesized && tn->tn_op == COMMA)
   1056  1.153    rillig 		tn = tn->tn_right;
   1057  1.153    rillig 	return tn->tn_parenthesized && !tn->tn_sys;
   1058  1.153    rillig }
   1059  1.153    rillig 
   1060  1.152    rillig static void
   1061  1.152    rillig check_return_value(bool sys, tnode_t *tn)
   1062  1.152    rillig {
   1063  1.153    rillig 
   1064  1.153    rillig 	if (any_query_enabled && is_parenthesized(tn)) {
   1065  1.153    rillig 		/* parenthesized return value */
   1066  1.153    rillig 		query_message(9);
   1067  1.153    rillig 	}
   1068  1.153    rillig 
   1069  1.152    rillig 	/* Create a temporary node for the left side */
   1070  1.152    rillig 	tnode_t *ln = expr_zero_alloc(sizeof(*ln));
   1071  1.152    rillig 	ln->tn_op = NAME;
   1072  1.152    rillig 	ln->tn_type = expr_unqualified_type(funcsym->s_type->t_subt);
   1073  1.152    rillig 	ln->tn_lvalue = true;
   1074  1.152    rillig 	ln->tn_sym = funcsym;	/* better than nothing */
   1075  1.152    rillig 
   1076  1.152    rillig 	tnode_t *retn = build_binary(ln, RETURN, sys, tn);
   1077  1.152    rillig 
   1078  1.152    rillig 	if (retn != NULL) {
   1079  1.152    rillig 		const tnode_t *rn = retn->tn_right;
   1080  1.152    rillig 		while (rn->tn_op == CVT || rn->tn_op == PLUS)
   1081  1.152    rillig 			rn = rn->tn_left;
   1082  1.152    rillig 		if (rn->tn_op == ADDR && rn->tn_left->tn_op == NAME &&
   1083  1.152    rillig 		    rn->tn_left->tn_sym->s_scl == AUTO) {
   1084  1.152    rillig 			/* '%s' returns pointer to automatic object */
   1085  1.152    rillig 			warning(302, funcsym->s_name);
   1086  1.152    rillig 		}
   1087  1.152    rillig 	}
   1088  1.152    rillig 
   1089  1.152    rillig 	expr(retn, true, false, true, false);
   1090  1.152    rillig }
   1091  1.152    rillig 
   1092    1.1       cgd /*
   1093    1.1       cgd  * T_RETURN T_SEMI
   1094    1.1       cgd  * T_RETURN expr T_SEMI
   1095    1.1       cgd  */
   1096    1.1       cgd void
   1097  1.126    rillig do_return(bool sys, tnode_t *tn)
   1098    1.1       cgd {
   1099  1.152    rillig 	control_statement *cs = cstmt;
   1100    1.1       cgd 
   1101  1.115    rillig 	if (cs == NULL) {
   1102  1.109    rillig 		/* syntax error '%s' */
   1103  1.109    rillig 		error(249, "return outside function");
   1104  1.109    rillig 		return;
   1105  1.109    rillig 	}
   1106  1.109    rillig 
   1107  1.115    rillig 	for (; cs->c_surrounding != NULL; cs = cs->c_surrounding)
   1108   1.14     lukem 		continue;
   1109    1.1       cgd 
   1110   1.82    rillig 	if (tn != NULL)
   1111  1.115    rillig 		cs->c_had_return_value = true;
   1112   1.82    rillig 	else
   1113  1.115    rillig 		cs->c_had_return_noval = true;
   1114    1.1       cgd 
   1115    1.1       cgd 	if (tn != NULL && funcsym->s_type->t_subt->t_tspec == VOID) {
   1116  1.142    rillig 		/* void function '%s' cannot return value */
   1117    1.1       cgd 		error(213, funcsym->s_name);
   1118   1.99    rillig 		expr_free_all();
   1119    1.1       cgd 		tn = NULL;
   1120    1.1       cgd 	} else if (tn == NULL && funcsym->s_type->t_subt->t_tspec != VOID) {
   1121    1.1       cgd 		/*
   1122    1.1       cgd 		 * Assume that the function has a return value only if it
   1123    1.1       cgd 		 * is explicitly declared.
   1124    1.1       cgd 		 */
   1125   1.69    rillig 		if (!funcsym->s_return_type_implicit_int)
   1126  1.119    rillig 			/* function '%s' expects to return value */
   1127    1.1       cgd 			warning(214, funcsym->s_name);
   1128    1.1       cgd 	}
   1129    1.1       cgd 
   1130  1.152    rillig 	if (tn != NULL)
   1131  1.152    rillig 		check_return_value(sys, tn);
   1132  1.152    rillig 	else
   1133   1.31    rillig 		check_statement_reachable();
   1134    1.1       cgd 
   1135   1.93    rillig 	set_reached(false);
   1136    1.1       cgd }
   1137    1.1       cgd 
   1138    1.1       cgd /*
   1139    1.7       jpo  * Do some cleanup after a global declaration or definition.
   1140   1.28    rillig  * Especially remove information about unused lint comments.
   1141    1.1       cgd  */
   1142    1.1       cgd void
   1143   1.59    rillig global_clean_up_decl(bool silent)
   1144    1.1       cgd {
   1145    1.1       cgd 
   1146    1.1       cgd 	if (nargusg != -1) {
   1147    1.6       jpo 		if (!silent) {
   1148  1.142    rillig 			/* comment ** %s ** must precede function definition */
   1149  1.105    rillig 			warning_at(282, &argsused_pos, "ARGSUSED");
   1150    1.1       cgd 		}
   1151    1.1       cgd 		nargusg = -1;
   1152    1.1       cgd 	}
   1153    1.1       cgd 	if (nvararg != -1) {
   1154    1.6       jpo 		if (!silent) {
   1155  1.142    rillig 			/* comment ** %s ** must precede function definition */
   1156  1.105    rillig 			warning_at(282, &vapos, "VARARGS");
   1157    1.1       cgd 		}
   1158    1.1       cgd 		nvararg = -1;
   1159    1.1       cgd 	}
   1160   1.49    rillig 	if (printflike_argnum != -1) {
   1161    1.6       jpo 		if (!silent) {
   1162  1.142    rillig 			/* comment ** %s ** must precede function definition */
   1163  1.105    rillig 			warning_at(282, &printflike_pos, "PRINTFLIKE");
   1164    1.1       cgd 		}
   1165   1.49    rillig 		printflike_argnum = -1;
   1166    1.1       cgd 	}
   1167   1.49    rillig 	if (scanflike_argnum != -1) {
   1168    1.6       jpo 		if (!silent) {
   1169  1.143    rillig 			/* comment ** %s ** must precede function definition */
   1170  1.105    rillig 			warning_at(282, &scanflike_pos, "SCANFLIKE");
   1171    1.1       cgd 		}
   1172   1.49    rillig 		scanflike_argnum = -1;
   1173    1.1       cgd 	}
   1174    1.1       cgd 
   1175   1.59    rillig 	dcs->d_asm = false;
   1176  1.107    rillig 
   1177  1.107    rillig 	/*
   1178  1.107    rillig 	 * Needed for BSD yacc in case of parse errors; GNU Bison 3.0.4 is
   1179  1.125    rillig 	 * fine.  See test gcc_attribute.c, function_with_unknown_attribute.
   1180  1.107    rillig 	 */
   1181  1.125    rillig 	in_gcc_attribute = false;
   1182  1.130    rillig 	while (dcs->d_enclosing != NULL)
   1183  1.130    rillig 		end_declaration_level();
   1184    1.1       cgd }
   1185    1.1       cgd 
   1186    1.1       cgd /*
   1187    1.1       cgd  * ARGSUSED comment
   1188    1.1       cgd  *
   1189    1.1       cgd  * Only the first n arguments of the following function are checked
   1190    1.1       cgd  * for usage. A missing argument is taken to be 0.
   1191    1.1       cgd  */
   1192    1.1       cgd void
   1193   1.14     lukem argsused(int n)
   1194    1.1       cgd {
   1195   1.14     lukem 
   1196    1.1       cgd 	if (n == -1)
   1197    1.1       cgd 		n = 0;
   1198    1.1       cgd 
   1199  1.132    rillig 	if (dcs->d_kind != DK_EXTERN) {
   1200  1.142    rillig 		/* comment ** %s ** must be outside function */
   1201    1.1       cgd 		warning(280, "ARGSUSED");
   1202    1.1       cgd 		return;
   1203    1.1       cgd 	}
   1204    1.1       cgd 	if (nargusg != -1) {
   1205  1.142    rillig 		/* duplicate comment ** %s ** */
   1206    1.1       cgd 		warning(281, "ARGSUSED");
   1207    1.1       cgd 	}
   1208    1.1       cgd 	nargusg = n;
   1209   1.36    rillig 	argsused_pos = curr_pos;
   1210    1.1       cgd }
   1211    1.1       cgd 
   1212    1.1       cgd /*
   1213    1.1       cgd  * VARARGS comment
   1214    1.1       cgd  *
   1215   1.28    rillig  * Causes lint2 to check only the first n arguments for compatibility
   1216   1.28    rillig  * with the function definition. A missing argument is taken to be 0.
   1217    1.1       cgd  */
   1218    1.1       cgd void
   1219   1.14     lukem varargs(int n)
   1220    1.1       cgd {
   1221   1.14     lukem 
   1222    1.1       cgd 	if (n == -1)
   1223    1.1       cgd 		n = 0;
   1224    1.1       cgd 
   1225  1.132    rillig 	if (dcs->d_kind != DK_EXTERN) {
   1226  1.142    rillig 		/* comment ** %s ** must be outside function */
   1227    1.1       cgd 		warning(280, "VARARGS");
   1228    1.1       cgd 		return;
   1229    1.1       cgd 	}
   1230    1.1       cgd 	if (nvararg != -1) {
   1231  1.142    rillig 		/* duplicate comment ** %s ** */
   1232    1.1       cgd 		warning(281, "VARARGS");
   1233    1.1       cgd 	}
   1234    1.1       cgd 	nvararg = n;
   1235   1.36    rillig 	vapos = curr_pos;
   1236    1.1       cgd }
   1237    1.1       cgd 
   1238    1.1       cgd /*
   1239    1.1       cgd  * PRINTFLIKE comment
   1240    1.1       cgd  *
   1241    1.1       cgd  * Check all arguments until the (n-1)-th as usual. The n-th argument is
   1242    1.1       cgd  * used the check the types of remaining arguments.
   1243    1.1       cgd  */
   1244    1.1       cgd void
   1245   1.14     lukem printflike(int n)
   1246    1.1       cgd {
   1247   1.14     lukem 
   1248    1.1       cgd 	if (n == -1)
   1249    1.1       cgd 		n = 0;
   1250    1.1       cgd 
   1251  1.132    rillig 	if (dcs->d_kind != DK_EXTERN) {
   1252  1.142    rillig 		/* comment ** %s ** must be outside function */
   1253    1.1       cgd 		warning(280, "PRINTFLIKE");
   1254    1.1       cgd 		return;
   1255    1.1       cgd 	}
   1256   1.49    rillig 	if (printflike_argnum != -1) {
   1257  1.142    rillig 		/* duplicate comment ** %s ** */
   1258    1.1       cgd 		warning(281, "PRINTFLIKE");
   1259    1.1       cgd 	}
   1260   1.49    rillig 	printflike_argnum = n;
   1261   1.36    rillig 	printflike_pos = curr_pos;
   1262    1.1       cgd }
   1263    1.1       cgd 
   1264    1.1       cgd /*
   1265    1.1       cgd  * SCANFLIKE comment
   1266    1.1       cgd  *
   1267    1.1       cgd  * Check all arguments until the (n-1)-th as usual. The n-th argument is
   1268    1.1       cgd  * used the check the types of remaining arguments.
   1269    1.1       cgd  */
   1270    1.1       cgd void
   1271   1.14     lukem scanflike(int n)
   1272    1.1       cgd {
   1273   1.14     lukem 
   1274    1.1       cgd 	if (n == -1)
   1275    1.1       cgd 		n = 0;
   1276    1.1       cgd 
   1277  1.132    rillig 	if (dcs->d_kind != DK_EXTERN) {
   1278  1.142    rillig 		/* comment ** %s ** must be outside function */
   1279    1.1       cgd 		warning(280, "SCANFLIKE");
   1280    1.1       cgd 		return;
   1281    1.1       cgd 	}
   1282   1.49    rillig 	if (scanflike_argnum != -1) {
   1283  1.142    rillig 		/* duplicate comment ** %s ** */
   1284    1.1       cgd 		warning(281, "SCANFLIKE");
   1285    1.1       cgd 	}
   1286   1.49    rillig 	scanflike_argnum = n;
   1287   1.36    rillig 	scanflike_pos = curr_pos;
   1288    1.1       cgd }
   1289    1.1       cgd 
   1290    1.1       cgd /*
   1291   1.50    rillig  * Set the line number for a CONSTCOND comment. At this and the following
   1292    1.1       cgd  * line no warnings about constants in conditional contexts are printed.
   1293    1.1       cgd  */
   1294    1.1       cgd /* ARGSUSED */
   1295    1.1       cgd void
   1296   1.14     lukem constcond(int n)
   1297    1.1       cgd {
   1298   1.14     lukem 
   1299   1.59    rillig 	constcond_flag = true;
   1300    1.1       cgd }
   1301    1.1       cgd 
   1302    1.1       cgd /*
   1303    1.1       cgd  * Suppress printing of "fallthrough on ..." warnings until next
   1304    1.1       cgd  * statement.
   1305    1.1       cgd  */
   1306    1.1       cgd /* ARGSUSED */
   1307    1.1       cgd void
   1308   1.14     lukem fallthru(int n)
   1309    1.1       cgd {
   1310   1.14     lukem 
   1311   1.78    rillig 	seen_fallthrough = true;
   1312    1.1       cgd }
   1313    1.1       cgd 
   1314    1.1       cgd /*
   1315    1.1       cgd  * Stop warnings about statements which cannot be reached. Also tells lint
   1316    1.1       cgd  * that the following statements cannot be reached (e.g. after exit()).
   1317    1.1       cgd  */
   1318    1.1       cgd /* ARGSUSED */
   1319    1.1       cgd void
   1320   1.89    rillig not_reached(int n)
   1321    1.1       cgd {
   1322   1.14     lukem 
   1323   1.93    rillig 	set_reached(false);
   1324   1.94    rillig 	warn_about_unreachable = false;
   1325    1.1       cgd }
   1326    1.1       cgd 
   1327    1.1       cgd /* ARGSUSED */
   1328    1.1       cgd void
   1329   1.14     lukem lintlib(int n)
   1330    1.1       cgd {
   1331   1.14     lukem 
   1332  1.132    rillig 	if (dcs->d_kind != DK_EXTERN) {
   1333  1.142    rillig 		/* comment ** %s ** must be outside function */
   1334    1.1       cgd 		warning(280, "LINTLIBRARY");
   1335    1.1       cgd 		return;
   1336    1.1       cgd 	}
   1337   1.59    rillig 	llibflg = true;
   1338   1.59    rillig 	vflag = false;
   1339    1.1       cgd }
   1340    1.1       cgd 
   1341  1.151    rillig /* Suppress one or most warnings at the current and the following line. */
   1342    1.1       cgd void
   1343   1.14     lukem linted(int n)
   1344    1.1       cgd {
   1345   1.14     lukem 
   1346  1.118    rillig 	debug_step("set lwarn %d", n);
   1347   1.25  christos 	lwarn = n;
   1348   1.16   thorpej }
   1349   1.16   thorpej 
   1350   1.16   thorpej /*
   1351   1.16   thorpej  * Suppress bitfield type errors on the current line.
   1352   1.16   thorpej  */
   1353   1.16   thorpej /* ARGSUSED */
   1354   1.16   thorpej void
   1355   1.16   thorpej bitfieldtype(int n)
   1356   1.16   thorpej {
   1357   1.16   thorpej 
   1358  1.117    rillig 	debug_step("%s, %d: bitfieldtype_ok = true",
   1359  1.117    rillig 	    curr_pos.p_file, curr_pos.p_line);
   1360   1.47    rillig 	bitfieldtype_ok = true;
   1361    1.1       cgd }
   1362    1.1       cgd 
   1363    1.1       cgd /*
   1364   1.28    rillig  * PROTOLIB in conjunction with LINTLIBRARY can be used to handle
   1365    1.1       cgd  * prototypes like function definitions. This is done if the argument
   1366   1.28    rillig  * to PROTOLIB is nonzero. Otherwise prototypes are handled normally.
   1367    1.1       cgd  */
   1368    1.1       cgd void
   1369   1.14     lukem protolib(int n)
   1370    1.1       cgd {
   1371   1.14     lukem 
   1372  1.132    rillig 	if (dcs->d_kind != DK_EXTERN) {
   1373  1.142    rillig 		/* comment ** %s ** must be outside function */
   1374    1.1       cgd 		warning(280, "PROTOLIB");
   1375    1.1       cgd 		return;
   1376    1.1       cgd 	}
   1377   1.59    rillig 	plibflg = n != 0;
   1378    1.6       jpo }
   1379    1.6       jpo 
   1380   1.59    rillig /* The next statement/declaration may use "long long" without a diagnostic. */
   1381    1.6       jpo /* ARGSUSED */
   1382    1.6       jpo void
   1383   1.14     lukem longlong(int n)
   1384    1.6       jpo {
   1385   1.14     lukem 
   1386   1.59    rillig 	quadflg = true;
   1387    1.1       cgd }
   1388