FormatString.cpp revision e6ca97f2aeb301e28d20988b27c4297a9b540991
1// FormatString.cpp - Common stuff for handling printf/scanf formats -*- C++ -*-
2//
3//                     The LLVM Compiler Infrastructure
4//
5// This file is distributed under the University of Illinois Open Source
6// License. See LICENSE.TXT for details.
7//
8//===----------------------------------------------------------------------===//
9//
10// Shared details for processing format strings of printf and scanf
11// (and friends).
12//
13//===----------------------------------------------------------------------===//
14
15#include "FormatStringParsing.h"
16#include "clang/Basic/LangOptions.h"
17
18using clang::analyze_format_string::ArgTypeResult;
19using clang::analyze_format_string::FormatStringHandler;
20using clang::analyze_format_string::FormatSpecifier;
21using clang::analyze_format_string::LengthModifier;
22using clang::analyze_format_string::OptionalAmount;
23using clang::analyze_format_string::PositionContext;
24using clang::analyze_format_string::ConversionSpecifier;
25using namespace clang;
26
27// Key function to FormatStringHandler.
28FormatStringHandler::~FormatStringHandler() {}
29
30//===----------------------------------------------------------------------===//
31// Functions for parsing format strings components in both printf and
32// scanf format strings.
33//===----------------------------------------------------------------------===//
34
35OptionalAmount
36clang::analyze_format_string::ParseAmount(const char *&Beg, const char *E) {
37  const char *I = Beg;
38  UpdateOnReturn <const char*> UpdateBeg(Beg, I);
39
40  unsigned accumulator = 0;
41  bool hasDigits = false;
42
43  for ( ; I != E; ++I) {
44    char c = *I;
45    if (c >= '0' && c <= '9') {
46      hasDigits = true;
47      accumulator = (accumulator * 10) + (c - '0');
48      continue;
49    }
50
51    if (hasDigits)
52      return OptionalAmount(OptionalAmount::Constant, accumulator, Beg, I - Beg,
53          false);
54
55    break;
56  }
57
58  return OptionalAmount();
59}
60
61OptionalAmount
62clang::analyze_format_string::ParseNonPositionAmount(const char *&Beg,
63                                                     const char *E,
64                                                     unsigned &argIndex) {
65  if (*Beg == '*') {
66    ++Beg;
67    return OptionalAmount(OptionalAmount::Arg, argIndex++, Beg, 0, false);
68  }
69
70  return ParseAmount(Beg, E);
71}
72
73OptionalAmount
74clang::analyze_format_string::ParsePositionAmount(FormatStringHandler &H,
75                                                  const char *Start,
76                                                  const char *&Beg,
77                                                  const char *E,
78                                                  PositionContext p) {
79  if (*Beg == '*') {
80    const char *I = Beg + 1;
81    const OptionalAmount &Amt = ParseAmount(I, E);
82
83    if (Amt.getHowSpecified() == OptionalAmount::NotSpecified) {
84      H.HandleInvalidPosition(Beg, I - Beg, p);
85      return OptionalAmount(false);
86    }
87
88    if (I == E) {
89      // No more characters left?
90      H.HandleIncompleteSpecifier(Start, E - Start);
91      return OptionalAmount(false);
92    }
93
94    assert(Amt.getHowSpecified() == OptionalAmount::Constant);
95
96    if (*I == '$') {
97      // Handle positional arguments
98
99      // Special case: '*0$', since this is an easy mistake.
100      if (Amt.getConstantAmount() == 0) {
101        H.HandleZeroPosition(Beg, I - Beg + 1);
102        return OptionalAmount(false);
103      }
104
105      const char *Tmp = Beg;
106      Beg = ++I;
107
108      return OptionalAmount(OptionalAmount::Arg, Amt.getConstantAmount() - 1,
109                            Tmp, 0, true);
110    }
111
112    H.HandleInvalidPosition(Beg, I - Beg, p);
113    return OptionalAmount(false);
114  }
115
116  return ParseAmount(Beg, E);
117}
118
119
120bool
121clang::analyze_format_string::ParseFieldWidth(FormatStringHandler &H,
122                                              FormatSpecifier &CS,
123                                              const char *Start,
124                                              const char *&Beg, const char *E,
125                                              unsigned *argIndex) {
126  // FIXME: Support negative field widths.
127  if (argIndex) {
128    CS.setFieldWidth(ParseNonPositionAmount(Beg, E, *argIndex));
129  }
130  else {
131    const OptionalAmount Amt =
132      ParsePositionAmount(H, Start, Beg, E,
133                          analyze_format_string::FieldWidthPos);
134
135    if (Amt.isInvalid())
136      return true;
137    CS.setFieldWidth(Amt);
138  }
139  return false;
140}
141
142bool
143clang::analyze_format_string::ParseArgPosition(FormatStringHandler &H,
144                                               FormatSpecifier &FS,
145                                               const char *Start,
146                                               const char *&Beg,
147                                               const char *E) {
148  const char *I = Beg;
149
150  const OptionalAmount &Amt = ParseAmount(I, E);
151
152  if (I == E) {
153    // No more characters left?
154    H.HandleIncompleteSpecifier(Start, E - Start);
155    return true;
156  }
157
158  if (Amt.getHowSpecified() == OptionalAmount::Constant && *(I++) == '$') {
159    // Special case: '%0$', since this is an easy mistake.
160    if (Amt.getConstantAmount() == 0) {
161      H.HandleZeroPosition(Start, I - Start);
162      return true;
163    }
164
165    FS.setArgIndex(Amt.getConstantAmount() - 1);
166    FS.setUsesPositionalArg();
167    // Update the caller's pointer if we decided to consume
168    // these characters.
169    Beg = I;
170    return false;
171  }
172
173  return false;
174}
175
176bool
177clang::analyze_format_string::ParseLengthModifier(FormatSpecifier &FS,
178                                                  const char *&I,
179                                                  const char *E,
180                                                  const LangOptions &LO,
181                                                  bool IsScanf) {
182  LengthModifier::Kind lmKind = LengthModifier::None;
183  const char *lmPosition = I;
184  switch (*I) {
185    default:
186      return false;
187    case 'h':
188      ++I;
189      lmKind = (I != E && *I == 'h') ? (++I, LengthModifier::AsChar)
190                                     : LengthModifier::AsShort;
191      break;
192    case 'l':
193      ++I;
194      lmKind = (I != E && *I == 'l') ? (++I, LengthModifier::AsLongLong)
195                                     : LengthModifier::AsLong;
196      break;
197    case 'j': lmKind = LengthModifier::AsIntMax;     ++I; break;
198    case 'z': lmKind = LengthModifier::AsSizeT;      ++I; break;
199    case 't': lmKind = LengthModifier::AsPtrDiff;    ++I; break;
200    case 'L': lmKind = LengthModifier::AsLongDouble; ++I; break;
201    case 'q': lmKind = LengthModifier::AsLongLong;   ++I; break;
202    case 'a':
203      if (IsScanf && !LO.C99 && !LO.CPlusPlus0x) {
204        // For scanf in C90, look at the next character to see if this should
205        // be parsed as the GNU extension 'a' length modifier. If not, this
206        // will be parsed as a conversion specifier.
207        ++I;
208        if (I != E && (*I == 's' || *I == 'S' || *I == '[')) {
209          lmKind = LengthModifier::AsAllocate;
210          break;
211        }
212        --I;
213      }
214      return false;
215    case 'm':
216      if (IsScanf) {
217        lmKind = LengthModifier::AsMAllocate;
218        ++I;
219        break;
220      }
221      return false;
222  }
223  LengthModifier lm(lmPosition, lmKind);
224  FS.setLengthModifier(lm);
225  return true;
226}
227
228//===----------------------------------------------------------------------===//
229// Methods on ArgTypeResult.
230//===----------------------------------------------------------------------===//
231
232bool ArgTypeResult::matchesType(ASTContext &C, QualType argTy) const {
233  switch (K) {
234    case InvalidTy:
235      llvm_unreachable("ArgTypeResult must be valid");
236
237    case UnknownTy:
238      return true;
239
240    case AnyCharTy: {
241      if (const BuiltinType *BT = argTy->getAs<BuiltinType>())
242        switch (BT->getKind()) {
243          default:
244            break;
245          case BuiltinType::Char_S:
246          case BuiltinType::SChar:
247          case BuiltinType::UChar:
248          case BuiltinType::Char_U:
249            return true;
250        }
251      return false;
252    }
253
254    case SpecificTy: {
255      argTy = C.getCanonicalType(argTy).getUnqualifiedType();
256      if (T == argTy)
257        return true;
258      // Check for "compatible types".
259      if (const BuiltinType *BT = argTy->getAs<BuiltinType>())
260        switch (BT->getKind()) {
261          default:
262            break;
263          case BuiltinType::Char_S:
264          case BuiltinType::SChar:
265            return T == C.UnsignedCharTy;
266          case BuiltinType::Char_U:
267          case BuiltinType::UChar:
268            return T == C.SignedCharTy;
269          case BuiltinType::Short:
270            return T == C.UnsignedShortTy;
271          case BuiltinType::UShort:
272            return T == C.ShortTy;
273          case BuiltinType::Int:
274            return T == C.UnsignedIntTy;
275          case BuiltinType::UInt:
276            return T == C.IntTy;
277          case BuiltinType::Long:
278            return T == C.UnsignedLongTy;
279          case BuiltinType::ULong:
280            return T == C.LongTy;
281          case BuiltinType::LongLong:
282            return T == C.UnsignedLongLongTy;
283          case BuiltinType::ULongLong:
284            return T == C.LongLongTy;
285        }
286      return false;
287    }
288
289    case CStrTy: {
290      const PointerType *PT = argTy->getAs<PointerType>();
291      if (!PT)
292        return false;
293      QualType pointeeTy = PT->getPointeeType();
294      if (const BuiltinType *BT = pointeeTy->getAs<BuiltinType>())
295        switch (BT->getKind()) {
296          case BuiltinType::Void:
297          case BuiltinType::Char_U:
298          case BuiltinType::UChar:
299          case BuiltinType::Char_S:
300          case BuiltinType::SChar:
301            return true;
302          default:
303            break;
304        }
305
306      return false;
307    }
308
309    case WCStrTy: {
310      const PointerType *PT = argTy->getAs<PointerType>();
311      if (!PT)
312        return false;
313      QualType pointeeTy =
314        C.getCanonicalType(PT->getPointeeType()).getUnqualifiedType();
315      return pointeeTy == C.getWCharType();
316    }
317
318    case WIntTy: {
319      // Instead of doing a lookup for the definition of 'wint_t' (which
320      // is defined by the system headers) instead see if wchar_t and
321      // the argument type promote to the same type.
322      QualType PromoWChar =
323        C.getWCharType()->isPromotableIntegerType()
324          ? C.getPromotedIntegerType(C.getWCharType()) : C.getWCharType();
325      QualType PromoArg =
326        argTy->isPromotableIntegerType()
327          ? C.getPromotedIntegerType(argTy) : argTy;
328
329      PromoWChar = C.getCanonicalType(PromoWChar).getUnqualifiedType();
330      PromoArg = C.getCanonicalType(PromoArg).getUnqualifiedType();
331
332      return PromoWChar == PromoArg;
333    }
334
335    case CPointerTy:
336      return argTy->isPointerType() || argTy->isObjCObjectPointerType() ||
337        argTy->isNullPtrType();
338
339    case ObjCPointerTy:
340      return argTy->getAs<ObjCObjectPointerType>() ||
341             argTy->getAs<BlockPointerType>();
342  }
343
344  llvm_unreachable("Invalid ArgTypeResult Kind!");
345}
346
347QualType ArgTypeResult::getRepresentativeType(ASTContext &C) const {
348  switch (K) {
349    case InvalidTy:
350      llvm_unreachable("No representative type for Invalid ArgTypeResult");
351    case UnknownTy:
352      return QualType();
353    case AnyCharTy:
354      return C.CharTy;
355    case SpecificTy:
356      return T;
357    case CStrTy:
358      return C.getPointerType(C.CharTy);
359    case WCStrTy:
360      return C.getPointerType(C.getWCharType());
361    case ObjCPointerTy:
362      return C.ObjCBuiltinIdTy;
363    case CPointerTy:
364      return C.VoidPtrTy;
365    case WIntTy: {
366      QualType WC = C.getWCharType();
367      return WC->isPromotableIntegerType() ? C.getPromotedIntegerType(WC) : WC;
368    }
369  }
370
371  llvm_unreachable("Invalid ArgTypeResult Kind!");
372}
373
374std::string ArgTypeResult::getRepresentativeTypeName(ASTContext &C) const {
375  std::string S = getRepresentativeType(C).getAsString();
376  if (Name)
377    return std::string("'") + Name + "' (aka '" + S + "')";
378  return std::string("'") + S + "'";
379}
380
381
382//===----------------------------------------------------------------------===//
383// Methods on OptionalAmount.
384//===----------------------------------------------------------------------===//
385
386ArgTypeResult
387analyze_format_string::OptionalAmount::getArgType(ASTContext &Ctx) const {
388  return Ctx.IntTy;
389}
390
391//===----------------------------------------------------------------------===//
392// Methods on LengthModifier.
393//===----------------------------------------------------------------------===//
394
395const char *
396analyze_format_string::LengthModifier::toString() const {
397  switch (kind) {
398  case AsChar:
399    return "hh";
400  case AsShort:
401    return "h";
402  case AsLong: // or AsWideChar
403    return "l";
404  case AsLongLong:
405    return "ll";
406  case AsIntMax:
407    return "j";
408  case AsSizeT:
409    return "z";
410  case AsPtrDiff:
411    return "t";
412  case AsLongDouble:
413    return "L";
414  case AsAllocate:
415    return "a";
416  case AsMAllocate:
417    return "m";
418  case None:
419    return "";
420  }
421  return NULL;
422}
423
424//===----------------------------------------------------------------------===//
425// Methods on ConversionSpecifier.
426//===----------------------------------------------------------------------===//
427
428const char *ConversionSpecifier::toString() const {
429  switch (kind) {
430  case dArg: return "d";
431  case iArg: return "i";
432  case oArg: return "o";
433  case uArg: return "u";
434  case xArg: return "x";
435  case XArg: return "X";
436  case fArg: return "f";
437  case FArg: return "F";
438  case eArg: return "e";
439  case EArg: return "E";
440  case gArg: return "g";
441  case GArg: return "G";
442  case aArg: return "a";
443  case AArg: return "A";
444  case cArg: return "c";
445  case sArg: return "s";
446  case pArg: return "p";
447  case nArg: return "n";
448  case PercentArg:  return "%";
449  case ScanListArg: return "[";
450  case InvalidSpecifier: return NULL;
451
452  // MacOS X unicode extensions.
453  case CArg: return "C";
454  case SArg: return "S";
455
456  // Objective-C specific specifiers.
457  case ObjCObjArg: return "@";
458
459  // GlibC specific specifiers.
460  case PrintErrno: return "m";
461  }
462  return NULL;
463}
464
465//===----------------------------------------------------------------------===//
466// Methods on OptionalAmount.
467//===----------------------------------------------------------------------===//
468
469void OptionalAmount::toString(raw_ostream &os) const {
470  switch (hs) {
471  case Invalid:
472  case NotSpecified:
473    return;
474  case Arg:
475    if (UsesDotPrefix)
476        os << ".";
477    if (usesPositionalArg())
478      os << "*" << getPositionalArgIndex() << "$";
479    else
480      os << "*";
481    break;
482  case Constant:
483    if (UsesDotPrefix)
484        os << ".";
485    os << amt;
486    break;
487  }
488}
489
490bool FormatSpecifier::hasValidLengthModifier() const {
491  switch (LM.getKind()) {
492    case LengthModifier::None:
493      return true;
494
495        // Handle most integer flags
496    case LengthModifier::AsChar:
497    case LengthModifier::AsShort:
498    case LengthModifier::AsLongLong:
499    case LengthModifier::AsIntMax:
500    case LengthModifier::AsSizeT:
501    case LengthModifier::AsPtrDiff:
502      switch (CS.getKind()) {
503        case ConversionSpecifier::dArg:
504        case ConversionSpecifier::iArg:
505        case ConversionSpecifier::oArg:
506        case ConversionSpecifier::uArg:
507        case ConversionSpecifier::xArg:
508        case ConversionSpecifier::XArg:
509        case ConversionSpecifier::nArg:
510          return true;
511        default:
512          return false;
513      }
514
515        // Handle 'l' flag
516    case LengthModifier::AsLong:
517      switch (CS.getKind()) {
518        case ConversionSpecifier::dArg:
519        case ConversionSpecifier::iArg:
520        case ConversionSpecifier::oArg:
521        case ConversionSpecifier::uArg:
522        case ConversionSpecifier::xArg:
523        case ConversionSpecifier::XArg:
524        case ConversionSpecifier::aArg:
525        case ConversionSpecifier::AArg:
526        case ConversionSpecifier::fArg:
527        case ConversionSpecifier::FArg:
528        case ConversionSpecifier::eArg:
529        case ConversionSpecifier::EArg:
530        case ConversionSpecifier::gArg:
531        case ConversionSpecifier::GArg:
532        case ConversionSpecifier::nArg:
533        case ConversionSpecifier::cArg:
534        case ConversionSpecifier::sArg:
535        case ConversionSpecifier::ScanListArg:
536          return true;
537        default:
538          return false;
539      }
540
541    case LengthModifier::AsLongDouble:
542      switch (CS.getKind()) {
543        case ConversionSpecifier::aArg:
544        case ConversionSpecifier::AArg:
545        case ConversionSpecifier::fArg:
546        case ConversionSpecifier::FArg:
547        case ConversionSpecifier::eArg:
548        case ConversionSpecifier::EArg:
549        case ConversionSpecifier::gArg:
550        case ConversionSpecifier::GArg:
551          return true;
552        // GNU extension.
553        case ConversionSpecifier::dArg:
554        case ConversionSpecifier::iArg:
555        case ConversionSpecifier::oArg:
556        case ConversionSpecifier::uArg:
557        case ConversionSpecifier::xArg:
558        case ConversionSpecifier::XArg:
559          return true;
560        default:
561          return false;
562      }
563
564    case LengthModifier::AsAllocate:
565      switch (CS.getKind()) {
566        case ConversionSpecifier::sArg:
567        case ConversionSpecifier::SArg:
568        case ConversionSpecifier::ScanListArg:
569          return true;
570        default:
571          return false;
572      }
573
574    case LengthModifier::AsMAllocate:
575      switch (CS.getKind()) {
576        case ConversionSpecifier::cArg:
577        case ConversionSpecifier::CArg:
578        case ConversionSpecifier::sArg:
579        case ConversionSpecifier::SArg:
580        case ConversionSpecifier::ScanListArg:
581          return true;
582        default:
583          return false;
584      }
585  }
586  llvm_unreachable("Invalid LengthModifier Kind!");
587}
588