chk.c revision 1.51 1 /* $NetBSD: chk.c,v 1.51 2022/08/28 12:04:47 rillig Exp $ */
2
3 /*
4 * Copyright (c) 1996 Christopher G. Demetriou. All Rights Reserved.
5 * Copyright (c) 1994, 1995 Jochen Pohl
6 * All Rights Reserved.
7 *
8 * Redistribution and use in source and binary forms, with or without
9 * modification, are permitted provided that the following conditions
10 * are met:
11 * 1. Redistributions of source code must retain the above copyright
12 * notice, this list of conditions and the following disclaimer.
13 * 2. Redistributions in binary form must reproduce the above copyright
14 * notice, this list of conditions and the following disclaimer in the
15 * documentation and/or other materials provided with the distribution.
16 * 3. All advertising materials mentioning features or use of this software
17 * must display the following acknowledgement:
18 * This product includes software developed by Jochen Pohl for
19 * The NetBSD Project.
20 * 4. The name of the author may not be used to endorse or promote products
21 * derived from this software without specific prior written permission.
22 *
23 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
24 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
25 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
26 * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
27 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
28 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
29 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
30 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
31 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
32 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
33 */
34
35 #if HAVE_NBTOOL_CONFIG_H
36 #include "nbtool_config.h"
37 #endif
38
39 #include <sys/cdefs.h>
40 #if defined(__RCSID)
41 __RCSID("$NetBSD: chk.c,v 1.51 2022/08/28 12:04:47 rillig Exp $");
42 #endif
43
44 #include <ctype.h>
45 #include <limits.h>
46 #include <stdlib.h>
47 #include <string.h>
48
49 #include "lint2.h"
50
51 static void chkund(const hte_t *);
52 static void chkdnu(const hte_t *);
53 static void chkdnud(const hte_t *);
54 static void chkmd(const hte_t *);
55 static void chkvtui(const hte_t *, sym_t *, sym_t *);
56 static void chkvtdi(const hte_t *, sym_t *, sym_t *);
57 static void chkfaui(const hte_t *, sym_t *, sym_t *);
58 static void chkau(const hte_t *, int, sym_t *, sym_t *, pos_t *,
59 fcall_t *, fcall_t *, type_t *, type_t *);
60 static void chkrvu(const hte_t *, sym_t *);
61 static void chkadecl(const hte_t *, sym_t *, sym_t *);
62 static void printflike(const hte_t *, fcall_t *, int, const char *, type_t **);
63 static void scanflike(const hte_t *, fcall_t *, int, const char *, type_t **);
64 static void badfmt(const hte_t *, fcall_t *);
65 static void inconarg(const hte_t *, fcall_t *, int);
66 static void tofewarg(const hte_t *, fcall_t *);
67 static void tomanyarg(const hte_t *, fcall_t *);
68 static bool types_compatible(type_t *, type_t *, bool, bool, bool, bool *);
69 static bool prototypes_compatible(type_t *, type_t *, bool *);
70 static bool matches_no_arg_function(type_t *, bool *);
71
72
73 /*
74 * If there is a symbol named "main", mark it as used.
75 */
76 void
77 mainused(void)
78 {
79 hte_t *hte;
80
81 if ((hte = hsearch("main", false)) != NULL)
82 hte->h_used = true;
83 }
84
85 /*
86 * Performs all tests for a single name
87 */
88 void
89 chkname(const hte_t *hte)
90 {
91 sym_t *sym, *def, *pdecl, *decl;
92
93 if (uflag) {
94 chkund(hte);
95 chkdnu(hte);
96 if (xflag)
97 chkdnud(hte);
98 }
99 chkmd(hte);
100
101 /* Get definition, prototype declaration and declaration */
102 def = pdecl = decl = NULL;
103 for (sym = hte->h_syms; sym != NULL; sym = sym->s_next) {
104 if (def == NULL && (sym->s_def == DEF || sym->s_def == TDEF))
105 def = sym;
106 if (pdecl == NULL && sym->s_def == DECL &&
107 TP(sym->s_type)->t_tspec == FUNC &&
108 TP(sym->s_type)->t_proto) {
109 pdecl = sym;
110 }
111 if (decl == NULL && sym->s_def == DECL)
112 decl = sym;
113 }
114
115 /* A prototype is better than an old style declaration. */
116 if (pdecl != NULL)
117 decl = pdecl;
118
119 chkvtui(hte, def, decl);
120
121 chkvtdi(hte, def, decl);
122
123 chkfaui(hte, def, decl);
124
125 chkrvu(hte, def);
126
127 chkadecl(hte, def, decl);
128 }
129
130 /*
131 * Print a warning if the name has been used, but not defined.
132 */
133 static void
134 chkund(const hte_t *hte)
135 {
136 fcall_t *fcall;
137 usym_t *usym;
138
139 if (!hte->h_used || hte->h_def)
140 return;
141
142 if ((fcall = hte->h_calls) != NULL) {
143 /* %s used( %s ), but not defined */
144 msg(0, hte->h_name, mkpos(&fcall->f_pos));
145 } else if ((usym = hte->h_usyms) != NULL) {
146 /* %s used( %s ), but not defined */
147 msg(0, hte->h_name, mkpos(&usym->u_pos));
148 }
149 }
150
151 /*
152 * Print a warning if the name has been defined, but never used.
153 */
154 static void
155 chkdnu(const hte_t *hte)
156 {
157 sym_t *sym;
158
159 if (!hte->h_def || hte->h_used)
160 return;
161
162 for (sym = hte->h_syms; sym != NULL; sym = sym->s_next) {
163 if (sym->s_def == DEF || sym->s_def == TDEF) {
164 /* %s defined( %s ), but never used */
165 msg(1, hte->h_name, mkpos(&sym->s_pos));
166 break;
167 }
168 }
169 }
170
171 /*
172 * Print a warning if the variable has been declared, but is not used
173 * or defined.
174 */
175 static void
176 chkdnud(const hte_t *hte)
177 {
178 sym_t *sym;
179
180 if (hte->h_syms == NULL || hte->h_used || hte->h_def)
181 return;
182
183 sym = hte->h_syms;
184 if (TP(sym->s_type)->t_tspec == FUNC)
185 return;
186
187 if (sym->s_def != DECL)
188 errx(1, "internal error: chkdnud() 1");
189 /* %s declared( %s ), but never used or defined */
190 msg(2, hte->h_name, mkpos(&sym->s_pos));
191 }
192
193 /*
194 * Print a warning if there is more than one definition for
195 * this name.
196 */
197 static void
198 chkmd(const hte_t *hte)
199 {
200 sym_t *sym, *def1;
201 char *pos1;
202
203 if (!hte->h_def)
204 return;
205
206 def1 = NULL;
207 for (sym = hte->h_syms; sym != NULL; sym = sym->s_next) {
208 /*
209 * ANSI C allows tentative definitions of the same name in
210 * only one compilation unit.
211 */
212 if (sym->s_def != DEF && (!sflag || sym->s_def != TDEF))
213 continue;
214 if (sym->s_inline)
215 continue;
216 if (def1 == NULL) {
217 def1 = sym;
218 continue;
219 }
220 pos1 = xstrdup(mkpos(&def1->s_pos));
221 /* %s multiply defined \t%s :: %s */
222 msg(3, hte->h_name, pos1, mkpos(&sym->s_pos));
223 free(pos1);
224 }
225 }
226
227 /*
228 * Print a warning if the return value assumed for a function call
229 * differs from the return value of the function definition or
230 * function declaration.
231 *
232 * If no definition/declaration can be found, the assumed return values
233 * are always int. So there is no need to compare with another function
234 * call as it's done for function arguments.
235 */
236 static void
237 chkvtui(const hte_t *hte, sym_t *def, sym_t *decl)
238 {
239 fcall_t *call;
240 char *pos1;
241 type_t *tp1, *tp2;
242 bool dowarn, eq;
243 tspec_t t1;
244
245 if (hte->h_calls == NULL)
246 return;
247
248 if (def == NULL)
249 def = decl;
250 if (def == NULL)
251 return;
252
253 t1 = (tp1 = TP(def->s_type)->t_subt)->t_tspec;
254 for (call = hte->h_calls; call != NULL; call = call->f_next) {
255 tp2 = TP(call->f_type)->t_subt;
256 eq = types_compatible(tp1, tp2,
257 true, false, false, (dowarn = false, &dowarn));
258 if (!call->f_rused) {
259 /* no return value used */
260 if ((t1 == STRUCT || t1 == UNION) && !eq) {
261 /*
262 * If a function returns a struct or union it
263 * must be declared to return a struct or
264 * union, also if the return value is ignored.
265 * This is necessary because the caller must
266 * allocate stack space for the return value.
267 * If it does not, the return value would
268 * overwrite other data.
269 *
270 * XXX Following message may be confusing
271 * because it appears also if the return value
272 * was declared inconsistently. But this
273 * behavior matches pcc-based lint, so it is
274 * accepted for now.
275 */
276 pos1 = xstrdup(mkpos(&def->s_pos));
277 /* %s function value must be declared ... */
278 msg(17, hte->h_name,
279 pos1, mkpos(&call->f_pos));
280 free(pos1);
281 }
282 continue;
283 }
284 if (!eq || (sflag && dowarn)) {
285 pos1 = xstrdup(mkpos(&def->s_pos));
286 /* %s value used inconsistently \t%s :: %s */
287 msg(4, hte->h_name, pos1, mkpos(&call->f_pos));
288 free(pos1);
289 }
290 }
291 }
292
293 /*
294 * Print a warning if a definition/declaration does not match another
295 * definition/declaration of the same name. For functions, only the
296 * types of return values are tested.
297 */
298 static void
299 chkvtdi(const hte_t *hte, sym_t *def, sym_t *decl)
300 {
301 sym_t *sym;
302 type_t *tp1, *tp2;
303 bool eq, dowarn;
304 char *pos1;
305
306 if (def == NULL)
307 def = decl;
308 if (def == NULL)
309 return;
310
311 tp1 = TP(def->s_type);
312 for (sym = hte->h_syms; sym != NULL; sym = sym->s_next) {
313 type_t *xt1, *xt2;
314 if (sym == def)
315 continue;
316 tp2 = TP(sym->s_type);
317 dowarn = false;
318 if (tp1->t_tspec == FUNC && tp2->t_tspec == FUNC) {
319 eq = types_compatible(xt1 = tp1->t_subt,
320 xt2 = tp2->t_subt, true, false, false, &dowarn);
321 } else {
322 eq = types_compatible(xt1 = tp1, xt2 = tp2,
323 false, false, false, &dowarn);
324 }
325 if (!eq || (sflag && dowarn)) {
326 pos1 = xstrdup(mkpos(&def->s_pos));
327 /* %s value declared inconsistently (%s != %s) \t... */
328 msg(5, hte->h_name, type_name(xt1), type_name(xt2),
329 pos1, mkpos(&sym->s_pos));
330 free(pos1);
331 }
332 }
333 }
334
335 /*
336 * Print a warning if a function is called with arguments which does
337 * not match the function definition, declaration or another call
338 * of the same function.
339 */
340 static void
341 chkfaui(const hte_t *hte, sym_t *def, sym_t *decl)
342 {
343 type_t *tp1, *tp2, **ap1, **ap2;
344 pos_t *pos1p = NULL;
345 fcall_t *calls, *call, *call1;
346 int n, as;
347 char *pos1;
348 arginf_t *ai;
349
350 if ((calls = hte->h_calls) == NULL)
351 return;
352
353 /*
354 * If we find a function definition, we use this for comparison,
355 * otherwise the first prototype we can find. If there is no
356 * definition or prototype declaration, the first function call
357 * is used.
358 */
359 tp1 = NULL;
360 call1 = NULL;
361 if (def != NULL) {
362 if ((tp1 = TP(def->s_type))->t_tspec != FUNC)
363 return;
364 pos1p = &def->s_pos;
365 } else if (decl != NULL && TP(decl->s_type)->t_proto) {
366 if ((tp1 = TP(decl->s_type))->t_tspec != FUNC)
367 return;
368 pos1p = &decl->s_pos;
369 }
370 if (tp1 == NULL) {
371 call1 = calls;
372 calls = calls->f_next;
373 if ((tp1 = TP(call1->f_type))->t_tspec != FUNC)
374 return;
375 pos1p = &call1->f_pos;
376 }
377
378 n = 1;
379 for (call = calls; call != NULL; call = call->f_next) {
380 if ((tp2 = TP(call->f_type))->t_tspec != FUNC)
381 continue;
382 ap1 = tp1->t_args;
383 ap2 = tp2->t_args;
384 n = 0;
385 while (*ap1 != NULL && *ap2 != NULL) {
386 if (def != NULL && def->s_check_only_first_args &&
387 n >= def->s_check_num_args)
388 break;
389 n++;
390 chkau(hte, n, def, decl, pos1p, call1, call,
391 *ap1, *ap2);
392 ap1++;
393 ap2++;
394 }
395 if (*ap1 == *ap2) {
396 /* equal # of arguments */
397 } else if (def != NULL && def->s_check_only_first_args &&
398 n >= def->s_check_num_args) {
399 /*
400 * function definition with VARARGS; The # of
401 * arguments of the call must be at least as large
402 * as the parameter of VARARGS.
403 */
404 } else if (*ap2 != NULL && tp1->t_proto && tp1->t_vararg) {
405 /*
406 * prototype with ... and function call with
407 * at least the same # of arguments as declared
408 * in the prototype.
409 */
410 } else {
411 pos1 = xstrdup(mkpos(pos1p));
412 /* %s: variable # of args \t%s :: %s */
413 msg(7, hte->h_name, pos1, mkpos(&call->f_pos));
414 free(pos1);
415 continue;
416 }
417
418 /* perform SCANFLIKE/PRINTFLIKE tests */
419 if (def == NULL || (!def->s_printflike && !def->s_scanflike))
420 continue;
421 as = def->s_printflike
422 ? def->s_printflike_arg
423 : def->s_scanflike_arg;
424 for (ai = call->f_args; ai != NULL; ai = ai->a_next) {
425 if (ai->a_num == as)
426 break;
427 }
428 if (ai == NULL || !ai->a_fmt)
429 continue;
430 if (def->s_printflike) {
431 printflike(hte, call, n, ai->a_fstrg, ap2);
432 } else {
433 scanflike(hte, call, n, ai->a_fstrg, ap2);
434 }
435 }
436 }
437
438 /*
439 * Check a single argument in a function call.
440 *
441 * hte a pointer to the hash table entry of the function
442 * n the number of the argument (1..)
443 * def the function definition or NULL
444 * decl prototype declaration, old style declaration or NULL
445 * pos1p position of definition, declaration of first call
446 * call1 first call, if both def and decl are old style def/decl
447 * call checked call
448 * arg1 currently checked argument of def/decl/call1
449 * arg2 currently checked argument of call
450 *
451 */
452 static void
453 chkau(const hte_t *hte, int n, sym_t *def, sym_t *decl, pos_t *pos1p,
454 fcall_t *call1, fcall_t *call, type_t *arg1, type_t *arg2)
455 {
456 bool promote, asgn, dowarn;
457 tspec_t t1, t2;
458 arginf_t *ai, *ai1;
459 char *pos1;
460
461 /*
462 * If a function definition is available (def != NULL), we compare the
463 * function call (call) with the definition. Otherwise, if a function
464 * definition is available and it is not an old style definition
465 * (decl != NULL && TP(decl->s_type)->t_proto), we compare the call
466 * with this declaration. Otherwise we compare it with the first
467 * call we have found (call1).
468 */
469
470 /* arg1 must be promoted if it stems from an old style definition */
471 promote = def != NULL && def->s_old_style_function;
472
473 /*
474 * If we compare with a definition or declaration, we must perform
475 * the same checks for qualifiers in indirected types as in
476 * assignments.
477 */
478 asgn = def != NULL || (decl != NULL && TP(decl->s_type)->t_proto);
479
480 dowarn = false;
481 if (types_compatible(arg1, arg2, true, promote, asgn, &dowarn) &&
482 (!sflag || !dowarn))
483 return;
484
485 /*
486 * Other lint implementations print warnings as soon as the type
487 * of an argument does not match exactly the expected type. The
488 * result are lots of warnings which are really not necessary.
489 * We print a warning only if
490 * (0) at least one type is not an integer type and types differ
491 * (1) hflag is set and types differ
492 * (2) types differ, except in signedness
493 * If the argument is an integer constant whose msb is not set,
494 * signedness is ignored (e.g. 0 matches both signed and unsigned
495 * int). This is with and without hflag.
496 * If the argument is an integer constant with value 0 and the
497 * expected argument is of type pointer and the width of the
498 * integer constant is the same as the width of the pointer,
499 * no warning is printed.
500 */
501 t1 = arg1->t_tspec;
502 t2 = arg2->t_tspec;
503 if (is_integer(t1) && is_integer(t2) &&
504 !arg1->t_is_enum && !arg2->t_is_enum) {
505 if (promote) {
506 /*
507 * XXX Here is a problem: Although it is possible to
508 * pass an int where a char/short it expected, there
509 * may be loss in significant digits. We should first
510 * check for const arguments if they can be converted
511 * into the original parameter type.
512 */
513 if (t1 == FLOAT) {
514 t1 = DOUBLE;
515 } else if (t1 == CHAR || t1 == SCHAR) {
516 t1 = INT;
517 } else if (t1 == UCHAR) {
518 t1 = tflag ? UINT : INT;
519 } else if (t1 == SHORT) {
520 t1 = INT;
521 } else if (t1 == USHORT) {
522 /* CONSTCOND */
523 t1 = INT_MAX < USHRT_MAX || tflag ? UINT : INT;
524 }
525 }
526
527 if (signed_type(t1) == signed_type(t2)) {
528
529 /*
530 * types differ only in signedness; get information
531 * about arguments
532 */
533
534 /*
535 * treat a definition like a call with variable
536 * arguments
537 */
538 ai1 = call1 != NULL ? call1->f_args : NULL;
539
540 /*
541 * if two calls are compared, ai1 is set to the
542 * information for the n-th argument, if this was
543 * a constant, otherwise to NULL
544 */
545 for ( ; ai1 != NULL; ai1 = ai1->a_next) {
546 if (ai1->a_num == n)
547 break;
548 }
549 /*
550 * ai is set to the information of the n-th arg
551 * of the (second) call, if this was a constant,
552 * otherwise to NULL
553 */
554 for (ai = call->f_args; ai != NULL; ai = ai->a_next) {
555 if (ai->a_num == n)
556 break;
557 }
558
559 if (ai1 == NULL && ai == NULL) {
560 /* no constant at all */
561 if (!hflag)
562 return;
563 } else if (ai1 == NULL || ai == NULL) {
564 /* one constant */
565 if (ai == NULL)
566 ai = ai1;
567 if (ai->a_zero || ai->a_pcon)
568 /* same value in signed and unsigned */
569 return;
570 /* value (not representation) differently */
571 } else {
572 /*
573 * two constants, one signed, one unsigned;
574 * if the msb of one of the constants is set,
575 * the argument is used inconsistently.
576 */
577 if (!ai1->a_ncon && !ai->a_ncon)
578 return;
579 }
580 }
581
582 } else if (t1 == PTR && is_integer(t2)) {
583 for (ai = call->f_args; ai != NULL; ai = ai->a_next) {
584 if (ai->a_num == n)
585 break;
586 }
587 /*
588 * Vendor implementations of lint (e.g. HP-UX, Digital UNIX)
589 * don't care about the size of the integer argument,
590 * only whether or not it is zero. We do the same.
591 */
592 if (ai != NULL && ai->a_zero)
593 return;
594 }
595
596 pos1 = xstrdup(mkpos(pos1p));
597 /* %s, arg %d used inconsistently \t%s[%s] :: %s[%s] */
598 msg(6, hte->h_name, n, pos1, type_name(arg1),
599 mkpos(&call->f_pos), type_name(arg2));
600 free(pos1);
601 }
602
603 /*
604 * Compare the types in the NULL-terminated array ap with the format
605 * string fmt.
606 */
607 static void
608 printflike(const hte_t *hte, fcall_t *call, int n, const char *fmt, type_t **ap)
609 {
610 const char *fp;
611 char fc;
612 bool fwidth, prec, left, sign, space, alt, zero;
613 tspec_t sz, t1, t2 = NOTSPEC;
614 type_t *tp;
615
616 fp = fmt;
617 fc = *fp++;
618
619 for (;;) {
620 if (fc == '\0') {
621 if (*ap != NULL)
622 tomanyarg(hte, call);
623 break;
624 }
625 if (fc != '%') {
626 badfmt(hte, call);
627 break;
628 }
629 fc = *fp++;
630 fwidth = prec = left = sign = space = alt = zero = false;
631 sz = NOTSPEC;
632
633 /* Flags */
634 for (;;) {
635 if (fc == '-') {
636 if (left)
637 break;
638 left = true;
639 } else if (fc == '+') {
640 if (sign)
641 break;
642 sign = true;
643 } else if (fc == ' ') {
644 if (space)
645 break;
646 space = true;
647 } else if (fc == '#') {
648 if (alt)
649 break;
650 alt = true;
651 } else if (fc == '0') {
652 if (zero)
653 break;
654 zero = true;
655 } else {
656 break;
657 }
658 fc = *fp++;
659 }
660
661 /* field width */
662 if (ch_isdigit(fc)) {
663 fwidth = true;
664 do { fc = *fp++; } while (ch_isdigit(fc));
665 } else if (fc == '*') {
666 fwidth = true;
667 fc = *fp++;
668 if ((tp = *ap++) == NULL) {
669 tofewarg(hte, call);
670 break;
671 }
672 n++;
673 if ((t1 = tp->t_tspec) != INT && (hflag || t1 != UINT))
674 inconarg(hte, call, n);
675 }
676
677 /* precision */
678 if (fc == '.') {
679 fc = *fp++;
680 prec = true;
681 if (ch_isdigit(fc)) {
682 do { fc = *fp++; } while (ch_isdigit(fc));
683 } else if (fc == '*') {
684 fc = *fp++;
685 if ((tp = *ap++) == NULL) {
686 tofewarg(hte, call);
687 break;
688 }
689 n++;
690 if (tp->t_tspec != INT)
691 inconarg(hte, call, n);
692 } else {
693 badfmt(hte, call);
694 break;
695 }
696 }
697
698 if (fc == 'h') {
699 sz = SHORT;
700 } else if (fc == 'l') {
701 sz = LONG;
702 } else if (fc == 'q') {
703 sz = QUAD;
704 } else if (fc == 'L') {
705 sz = LDOUBLE;
706 }
707 if (sz != NOTSPEC)
708 fc = *fp++;
709
710 if (fc == '%') {
711 if (sz != NOTSPEC || left || sign || space ||
712 alt || zero || prec || fwidth) {
713 badfmt(hte, call);
714 }
715 fc = *fp++;
716 continue;
717 }
718
719 if (fc == '\0') {
720 badfmt(hte, call);
721 break;
722 }
723
724 if ((tp = *ap++) == NULL) {
725 tofewarg(hte, call);
726 break;
727 }
728 n++;
729 if ((t1 = tp->t_tspec) == PTR)
730 t2 = tp->t_subt->t_tspec;
731
732 if (fc == 'd' || fc == 'i') {
733 if (alt || sz == LDOUBLE) {
734 badfmt(hte, call);
735 break;
736 }
737 int_conv:
738 if (sz == LONG) {
739 if (t1 != LONG && (hflag || t1 != ULONG))
740 inconarg(hte, call, n);
741 } else if (sz == QUAD) {
742 if (t1 != QUAD && (hflag || t1 != UQUAD))
743 inconarg(hte, call, n);
744 } else {
745 /*
746 * SHORT is always promoted to INT, USHORT
747 * to INT or UINT.
748 */
749 if (t1 != INT && (hflag || t1 != UINT))
750 inconarg(hte, call, n);
751 }
752 } else if (fc == 'o' || fc == 'u' || fc == 'x' || fc == 'X') {
753 if ((alt && fc == 'u') || sz == LDOUBLE)
754 badfmt(hte, call);
755 uint_conv:
756 if (sz == LONG) {
757 if (t1 != ULONG && (hflag || t1 != LONG))
758 inconarg(hte, call, n);
759 } else if (sz == QUAD) {
760 if (t1 != UQUAD && (hflag || t1 != QUAD))
761 inconarg(hte, call, n);
762 } else if (sz == SHORT) {
763 /* USHORT was promoted to INT or UINT */
764 if (t1 != UINT && t1 != INT)
765 inconarg(hte, call, n);
766 } else {
767 if (t1 != UINT && (hflag || t1 != INT))
768 inconarg(hte, call, n);
769 }
770 } else if (fc == 'D' || fc == 'O' || fc == 'U') {
771 if ((alt && fc != 'O') || sz != NOTSPEC || !tflag)
772 badfmt(hte, call);
773 sz = LONG;
774 if (fc == 'D') {
775 goto int_conv;
776 } else {
777 goto uint_conv;
778 }
779 } else if (fc == 'f' || fc == 'e' || fc == 'E' ||
780 fc == 'g' || fc == 'G') {
781 if (sz == NOTSPEC)
782 sz = DOUBLE;
783 if (sz != DOUBLE && sz != LDOUBLE)
784 badfmt(hte, call);
785 if (t1 != sz)
786 inconarg(hte, call, n);
787 } else if (fc == 'c') {
788 if (sz != NOTSPEC || alt || zero)
789 badfmt(hte, call);
790 if (t1 != INT)
791 inconarg(hte, call, n);
792 } else if (fc == 's') {
793 if (sz != NOTSPEC || alt || zero)
794 badfmt(hte, call);
795 if (t1 != PTR ||
796 (t2 != CHAR && t2 != UCHAR && t2 != SCHAR)) {
797 inconarg(hte, call, n);
798 }
799 } else if (fc == 'p') {
800 if (fwidth || prec || sz != NOTSPEC || alt || zero)
801 badfmt(hte, call);
802 if (t1 != PTR || (hflag && t2 != VOID))
803 inconarg(hte, call, n);
804 } else if (fc == 'n') {
805 if (fwidth || prec || alt || zero || sz == LDOUBLE)
806 badfmt(hte, call);
807 if (t1 != PTR) {
808 inconarg(hte, call, n);
809 } else if (sz == LONG) {
810 if (t2 != LONG && t2 != ULONG)
811 inconarg(hte, call, n);
812 } else if (sz == SHORT) {
813 if (t2 != SHORT && t2 != USHORT)
814 inconarg(hte, call, n);
815 } else {
816 if (t2 != INT && t2 != UINT)
817 inconarg(hte, call, n);
818 }
819 } else {
820 badfmt(hte, call);
821 break;
822 }
823
824 fc = *fp++;
825 }
826 }
827
828 /*
829 * Compare the types in the NULL-terminated array ap with the format
830 * string fmt.
831 */
832 static void
833 scanflike(const hte_t *hte, fcall_t *call, int n, const char *fmt, type_t **ap)
834 {
835 const char *fp;
836 char fc;
837 bool noasgn, fwidth;
838 tspec_t sz, t1 = NOTSPEC, t2 = NOTSPEC;
839 type_t *tp = NULL;
840
841 fp = fmt;
842 fc = *fp++;
843
844 for (;;) {
845 if (fc == '\0') {
846 if (*ap != NULL)
847 tomanyarg(hte, call);
848 break;
849 }
850 if (fc != '%') {
851 badfmt(hte, call);
852 break;
853 }
854 fc = *fp++;
855
856 noasgn = fwidth = false;
857 sz = NOTSPEC;
858
859 if (fc == '*') {
860 noasgn = true;
861 fc = *fp++;
862 }
863
864 if (ch_isdigit(fc)) {
865 fwidth = true;
866 do { fc = *fp++; } while (ch_isdigit(fc));
867 }
868
869 if (fc == 'h') {
870 sz = SHORT;
871 } else if (fc == 'l') {
872 sz = LONG;
873 } else if (fc == 'q') {
874 sz = QUAD;
875 } else if (fc == 'L') {
876 sz = LDOUBLE;
877 }
878 if (sz != NOTSPEC)
879 fc = *fp++;
880
881 if (fc == '%') {
882 if (sz != NOTSPEC || noasgn || fwidth)
883 badfmt(hte, call);
884 fc = *fp++;
885 continue;
886 }
887
888 if (!noasgn) {
889 if ((tp = *ap++) == NULL) {
890 tofewarg(hte, call);
891 break;
892 }
893 n++;
894 if ((t1 = tp->t_tspec) == PTR)
895 t2 = tp->t_subt->t_tspec;
896 }
897
898 if (fc == 'd' || fc == 'i' || fc == 'n') {
899 if (sz == LDOUBLE)
900 badfmt(hte, call);
901 if (sz != SHORT && sz != LONG && sz != QUAD)
902 sz = INT;
903 conv:
904 if (!noasgn) {
905 if (t1 != PTR) {
906 inconarg(hte, call, n);
907 } else if (t2 != signed_type(sz)) {
908 inconarg(hte, call, n);
909 } else if (hflag && t2 != sz) {
910 inconarg(hte, call, n);
911 } else if (tp->t_subt->t_const) {
912 inconarg(hte, call, n);
913 }
914 }
915 } else if (fc == 'o' || fc == 'u' || fc == 'x') {
916 if (sz == LDOUBLE)
917 badfmt(hte, call);
918 if (sz == SHORT) {
919 sz = USHORT;
920 } else if (sz == LONG) {
921 sz = ULONG;
922 } else if (sz == QUAD) {
923 sz = UQUAD;
924 } else {
925 sz = UINT;
926 }
927 goto conv;
928 } else if (fc == 'D') {
929 if (sz != NOTSPEC || !tflag)
930 badfmt(hte, call);
931 sz = LONG;
932 goto conv;
933 } else if (fc == 'O') {
934 if (sz != NOTSPEC || !tflag)
935 badfmt(hte, call);
936 sz = ULONG;
937 goto conv;
938 } else if (fc == 'X') {
939 /*
940 * XXX valid in ANSI C, but in NetBSD's libc imple-
941 * mented as "lx". That's why it should be avoided.
942 */
943 if (sz != NOTSPEC || !tflag)
944 badfmt(hte, call);
945 sz = ULONG;
946 goto conv;
947 } else if (fc == 'E') {
948 /*
949 * XXX valid in ANSI C, but in NetBSD's libc imple-
950 * mented as "lf". That's why it should be avoided.
951 */
952 if (sz != NOTSPEC || !tflag)
953 badfmt(hte, call);
954 sz = DOUBLE;
955 goto conv;
956 } else if (fc == 'F') {
957 /* XXX only for backward compatibility */
958 if (sz != NOTSPEC || !tflag)
959 badfmt(hte, call);
960 sz = DOUBLE;
961 goto conv;
962 } else if (fc == 'G') {
963 /*
964 * XXX valid in ANSI C, but in NetBSD's libc not
965 * implemented
966 */
967 if (sz != NOTSPEC && sz != LONG && sz != LDOUBLE)
968 badfmt(hte, call);
969 goto fconv;
970 } else if (fc == 'e' || fc == 'f' || fc == 'g') {
971 fconv:
972 if (sz == NOTSPEC) {
973 sz = FLOAT;
974 } else if (sz == LONG) {
975 sz = DOUBLE;
976 } else if (sz != LDOUBLE) {
977 badfmt(hte, call);
978 sz = FLOAT;
979 }
980 goto conv;
981 } else if (fc == 's' || fc == '[' || fc == 'c') {
982 if (sz != NOTSPEC)
983 badfmt(hte, call);
984 if (fc == '[') {
985 if ((fc = *fp++) == '-') {
986 badfmt(hte, call);
987 fc = *fp++;
988 }
989 if (fc != ']') {
990 badfmt(hte, call);
991 if (fc == '\0')
992 break;
993 }
994 }
995 if (!noasgn) {
996 if (t1 != PTR) {
997 inconarg(hte, call, n);
998 } else if (t2 != CHAR && t2 != UCHAR &&
999 t2 != SCHAR) {
1000 inconarg(hte, call, n);
1001 }
1002 }
1003 } else if (fc == 'p') {
1004 if (sz != NOTSPEC)
1005 badfmt(hte, call);
1006 if (!noasgn) {
1007 if (t1 != PTR || t2 != PTR) {
1008 inconarg(hte, call, n);
1009 } else if (tp->t_subt->t_subt->t_tspec!=VOID) {
1010 if (hflag)
1011 inconarg(hte, call, n);
1012 }
1013 }
1014 } else {
1015 badfmt(hte, call);
1016 break;
1017 }
1018
1019 fc = *fp++;
1020 }
1021 }
1022
1023 static void
1024 badfmt(const hte_t *hte, fcall_t *call)
1025 {
1026
1027 /* %s: malformed format string \t%s */
1028 msg(13, hte->h_name, mkpos(&call->f_pos));
1029 }
1030
1031 static void
1032 inconarg(const hte_t *hte, fcall_t *call, int n)
1033 {
1034
1035 /* %s, arg %d inconsistent with format \t%s */
1036 msg(14, hte->h_name, n, mkpos(&call->f_pos));
1037 }
1038
1039 static void
1040 tofewarg(const hte_t *hte, fcall_t *call)
1041 {
1042
1043 /* %s: too few args for format \t%s */
1044 msg(15, hte->h_name, mkpos(&call->f_pos));
1045 }
1046
1047 static void
1048 tomanyarg(const hte_t *hte, fcall_t *call)
1049 {
1050
1051 /* %s: too many args for format \t%s */
1052 msg(16, hte->h_name, mkpos(&call->f_pos));
1053 }
1054
1055 /*
1056 * List of functions where we usually don't care about their result.
1057 * NB: Must be sorted.
1058 */
1059 static const char ignorelist[][8] = {
1060 "memcpy",
1061 "memmove",
1062 "memset",
1063 "printf",
1064 "strcat",
1065 "strcpy",
1066 "vprintf",
1067 };
1068
1069 /*
1070 * Print warnings for return values which are used, but not returned,
1071 * or return values which are always or sometimes ignored.
1072 */
1073 static void
1074 chkrvu(const hte_t *hte, sym_t *def)
1075 {
1076 fcall_t *call;
1077 bool used, ignored;
1078
1079 if (def == NULL)
1080 /* don't know whether or not the functions returns a value */
1081 return;
1082
1083 if (hte->h_calls == NULL)
1084 return;
1085
1086 if (def->s_function_has_return_value) {
1087 /*
1088 * XXX as soon as we are able to disable single warnings,
1089 * the following dependencies from hflag should be removed.
1090 * But for now I don't want to be bothered by these warnings
1091 * which are almost always useless.
1092 */
1093 if (!hflag)
1094 return;
1095 if (hflag && bsearch(hte->h_name, ignorelist,
1096 sizeof(ignorelist) / sizeof(ignorelist[0]),
1097 sizeof(ignorelist[0]),
1098 (int (*)(const void *, const void *))strcmp) != NULL)
1099 return;
1100
1101 /* function has return value */
1102 used = ignored = false;
1103 for (call = hte->h_calls; call != NULL; call = call->f_next) {
1104 used |= call->f_rused || call->f_rdisc;
1105 ignored |= !call->f_rused && !call->f_rdisc;
1106 }
1107 if (!used && ignored) {
1108 /* %s returns value which is always ignored */
1109 msg(8, hte->h_name);
1110 } else if (used && ignored) {
1111 /* %s returns value which is sometimes ignored */
1112 msg(9, hte->h_name);
1113 }
1114 } else {
1115 /* function has no return value */
1116 for (call = hte->h_calls; call != NULL; call = call->f_next) {
1117 if (call->f_rused)
1118 /* %s value is used( %s ), but none returned */
1119 msg(10, hte->h_name, mkpos(&call->f_pos));
1120 }
1121 }
1122 }
1123
1124 /*
1125 * Print warnings for inconsistent argument declarations.
1126 */
1127 static void
1128 chkadecl(const hte_t *hte, sym_t *def, sym_t *decl)
1129 {
1130 bool osdef, eq, dowarn;
1131 int n;
1132 sym_t *sym1, *sym;
1133 type_t **ap1, **ap2, *tp1, *tp2;
1134 char *pos1;
1135 const char *pos2;
1136
1137 osdef = false;
1138 if (def != NULL) {
1139 osdef = def->s_old_style_function;
1140 sym1 = def;
1141 } else if (decl != NULL && TP(decl->s_type)->t_proto) {
1142 sym1 = decl;
1143 } else {
1144 return;
1145 }
1146 if (TP(sym1->s_type)->t_tspec != FUNC)
1147 return;
1148
1149 /*
1150 * XXX Prototypes should also be compared with old style function
1151 * declarations.
1152 */
1153
1154 for (sym = hte->h_syms; sym != NULL; sym = sym->s_next) {
1155 if (sym == sym1 || !TP(sym->s_type)->t_proto)
1156 continue;
1157 ap1 = TP(sym1->s_type)->t_args;
1158 ap2 = TP(sym->s_type)->t_args;
1159 n = 0;
1160 while (*ap1 != NULL && *ap2 != NULL) {
1161 type_t *xt1, *xt2;
1162 dowarn = false;
1163 eq = types_compatible(xt1 = *ap1, xt2 = *ap2,
1164 true, osdef, false, &dowarn);
1165 if (!eq || dowarn) {
1166 pos1 = xstrdup(mkpos(&sym1->s_pos));
1167 pos2 = mkpos(&sym->s_pos);
1168 /* %s, arg %d declared inconsistently ... */
1169 msg(11, hte->h_name, n + 1,
1170 type_name(xt1), type_name(xt2), pos1, pos2);
1171 free(pos1);
1172 }
1173 n++;
1174 ap1++;
1175 ap2++;
1176 }
1177 if (*ap1 == *ap2) {
1178 tp1 = TP(sym1->s_type);
1179 tp2 = TP(sym->s_type);
1180 if (tp1->t_vararg == tp2->t_vararg)
1181 continue;
1182 if (tp2->t_vararg && sym1->s_check_only_first_args &&
1183 sym1->s_check_num_args == n && !sflag) {
1184 continue;
1185 }
1186 }
1187 pos1 = xstrdup(mkpos(&sym1->s_pos));
1188 /* %s: variable # of args declared \t%s :: %s */
1189 msg(12, hte->h_name, pos1, mkpos(&sym->s_pos));
1190 free(pos1);
1191 }
1192 }
1193
1194
1195 /*
1196 * Check compatibility of two types. Returns whether types are compatible.
1197 *
1198 * ignqual if set, ignore qualifiers of outermost type; used for
1199 * function arguments
1200 * promote if set, promote left type before comparison; used for
1201 * comparisons of arguments with parameters of old style
1202 * definitions
1203 * asgn left indirected type must have at least the same qualifiers
1204 * like right indirected type (for assignments and function
1205 * arguments)
1206 * *dowarn set to true if an old style declaration was compared with
1207 * an incompatible prototype declaration
1208 */
1209 static bool
1210 types_compatible(type_t *tp1, type_t *tp2,
1211 bool ignqual, bool promot, bool asgn, bool *dowarn)
1212 {
1213 tspec_t t, to;
1214 int indir;
1215
1216 to = NOTSPEC;
1217 indir = 0;
1218
1219 while (tp1 != NULL && tp2 != NULL) {
1220
1221 t = tp1->t_tspec;
1222 if (promot) {
1223 if (t == FLOAT) {
1224 t = DOUBLE;
1225 } else if (t == CHAR || t == SCHAR) {
1226 t = INT;
1227 } else if (t == UCHAR) {
1228 t = tflag ? UINT : INT;
1229 } else if (t == SHORT) {
1230 t = INT;
1231 } else if (t == USHORT) {
1232 /* CONSTCOND */
1233 t = INT_MAX < USHRT_MAX || tflag ? UINT : INT;
1234 }
1235 }
1236
1237 if (asgn && to == PTR) {
1238 if (indir == 1 && (t == VOID || tp2->t_tspec == VOID))
1239 return true;
1240 }
1241
1242 if (t != tp2->t_tspec) {
1243 /*
1244 * Give pointer to types which differ only in
1245 * signedness a chance if not sflag and not hflag.
1246 */
1247 if (sflag || hflag || to != PTR)
1248 return false;
1249 if (signed_type(t) != signed_type(tp2->t_tspec))
1250 return false;
1251 }
1252
1253 if (tp1->t_is_enum && tp2->t_is_enum) {
1254 if (tp1->t_istag && tp2->t_istag) {
1255 return tp1->t_tag == tp2->t_tag;
1256 } else if (tp1->t_istynam && tp2->t_istynam) {
1257 return tp1->t_tynam == tp2->t_tynam;
1258 } else if (tp1->t_isuniqpos && tp2->t_isuniqpos) {
1259 return (tp1->t_uniqpos.p_line ==
1260 tp2->t_uniqpos.p_line &&
1261 tp1->t_uniqpos.p_file ==
1262 tp2->t_uniqpos.p_file &&
1263 tp1->t_uniqpos.p_uniq ==
1264 tp2->t_uniqpos.p_uniq);
1265 } else {
1266 return false;
1267 }
1268 }
1269
1270 /*
1271 * XXX Handle combinations of enum and int if eflag is set.
1272 * But note: enum and 0 should be allowed.
1273 */
1274
1275 if (asgn && indir == 1) {
1276 if (!tp1->t_const && tp2->t_const)
1277 return false;
1278 if (!tp1->t_volatile && tp2->t_volatile)
1279 return false;
1280 } else if (!ignqual && !tflag) {
1281 if (tp1->t_const != tp2->t_const)
1282 return false;
1283 if (tp1->t_const != tp2->t_const)
1284 return false;
1285 }
1286
1287 if (t == STRUCT || t == UNION) {
1288 if (tp1->t_istag && tp2->t_istag) {
1289 return tp1->t_tag == tp2->t_tag;
1290 } else if (tp1->t_istynam && tp2->t_istynam) {
1291 return tp1->t_tynam == tp2->t_tynam;
1292 } else if (tp1->t_isuniqpos && tp2->t_isuniqpos) {
1293 return (tp1->t_uniqpos.p_line ==
1294 tp2->t_uniqpos.p_line &&
1295 tp1->t_uniqpos.p_file ==
1296 tp2->t_uniqpos.p_file &&
1297 tp1->t_uniqpos.p_uniq ==
1298 tp2->t_uniqpos.p_uniq);
1299 } else {
1300 return false;
1301 }
1302 }
1303
1304 if (t == ARRAY && tp1->t_dim != tp2->t_dim) {
1305 if (tp1->t_dim != 0 && tp2->t_dim != 0)
1306 return false;
1307 }
1308
1309 if (t == FUNC) {
1310 if (tp1->t_proto && tp2->t_proto) {
1311 if (!prototypes_compatible(tp1, tp2, dowarn))
1312 return false;
1313 } else if (tp1->t_proto) {
1314 if (!matches_no_arg_function(tp1, dowarn))
1315 return false;
1316 } else if (tp2->t_proto) {
1317 if (!matches_no_arg_function(tp2, dowarn))
1318 return false;
1319 }
1320 }
1321
1322 tp1 = tp1->t_subt;
1323 tp2 = tp2->t_subt;
1324 ignqual = promot = false;
1325 to = t;
1326 indir++;
1327
1328 }
1329
1330 return tp1 == tp2;
1331 }
1332
1333 /*
1334 * Compares arguments of two prototypes
1335 */
1336 static bool
1337 prototypes_compatible(type_t *tp1, type_t *tp2, bool *dowarn)
1338 {
1339 type_t **a1, **a2;
1340
1341 if (tp1->t_vararg != tp2->t_vararg)
1342 return false;
1343
1344 a1 = tp1->t_args;
1345 a2 = tp2->t_args;
1346
1347 while (*a1 != NULL && *a2 != NULL) {
1348
1349 if (!types_compatible(*a1, *a2, true, false, false, dowarn))
1350 return false;
1351
1352 a1++;
1353 a2++;
1354
1355 }
1356
1357 return *a1 == *a2;
1358 }
1359
1360 /*
1361 * Returns whether all parameters of a prototype are compatible with an
1362 * old-style function declaration.
1363 *
1364 * This is the case if the following conditions are met:
1365 * 1. the prototype must have a fixed number of parameters
1366 * 2. no parameter is of type float
1367 * 3. no parameter is converted to another type if integer promotion
1368 * is applied on it
1369 */
1370 static bool
1371 matches_no_arg_function(type_t *tp, bool *dowarn)
1372 {
1373 type_t **arg;
1374 tspec_t t;
1375
1376 if (tp->t_vararg && dowarn != NULL)
1377 *dowarn = true;
1378 for (arg = tp->t_args; *arg != NULL; arg++) {
1379 if ((t = (*arg)->t_tspec) == FLOAT)
1380 return false;
1381 if (t == CHAR || t == SCHAR || t == UCHAR)
1382 return false;
1383 if (t == SHORT || t == USHORT)
1384 return false;
1385 }
1386 return true;
1387 }
1388