retain-release.m revision eaedfeab9eab0d003859aab138784f2c59531408
1// RUN: clang-cc -analyze -checker-cfref -verify %s && 2// RUN: clang-cc -analyze -checker-cfref -analyzer-store=region -verify %s 3 4 5//===----------------------------------------------------------------------===// 6// The following code is reduced using delta-debugging from 7// Foundation.h (Mac OS X). 8// 9// It includes the basic definitions for the test cases below. 10// Not including Foundation.h directly makes this test case both svelte and 11// portable to non-Mac platforms. 12//===----------------------------------------------------------------------===// 13 14typedef unsigned int __darwin_natural_t; 15typedef unsigned int UInt32; 16typedef signed long CFIndex; 17typedef const void * CFTypeRef; 18typedef const struct __CFString * CFStringRef; 19typedef const struct __CFAllocator * CFAllocatorRef; 20extern const CFAllocatorRef kCFAllocatorDefault; 21extern CFTypeRef CFRetain(CFTypeRef cf); 22extern void CFRelease(CFTypeRef cf); 23typedef struct { 24} 25CFArrayCallBacks; 26extern const CFArrayCallBacks kCFTypeArrayCallBacks; 27typedef const struct __CFArray * CFArrayRef; 28typedef struct __CFArray * CFMutableArrayRef; 29extern CFMutableArrayRef CFArrayCreateMutable(CFAllocatorRef allocator, CFIndex capacity, const CFArrayCallBacks *callBacks); 30extern const void *CFArrayGetValueAtIndex(CFArrayRef theArray, CFIndex idx); 31extern void CFArrayAppendValue(CFMutableArrayRef theArray, const void *value); 32typedef const struct __CFDictionary * CFDictionaryRef; 33typedef UInt32 CFStringEncoding; 34enum { 35kCFStringEncodingMacRoman = 0, kCFStringEncodingWindowsLatin1 = 0x0500, kCFStringEncodingISOLatin1 = 0x0201, kCFStringEncodingNextStepLatin = 0x0B01, kCFStringEncodingASCII = 0x0600, kCFStringEncodingUnicode = 0x0100, kCFStringEncodingUTF8 = 0x08000100, kCFStringEncodingNonLossyASCII = 0x0BFF , kCFStringEncodingUTF16 = 0x0100, kCFStringEncodingUTF16BE = 0x10000100, kCFStringEncodingUTF16LE = 0x14000100, kCFStringEncodingUTF32 = 0x0c000100, kCFStringEncodingUTF32BE = 0x18000100, kCFStringEncodingUTF32LE = 0x1c000100 }; 36extern CFStringRef CFStringCreateWithCString(CFAllocatorRef alloc, const char *cStr, CFStringEncoding encoding); 37typedef double CFTimeInterval; 38typedef CFTimeInterval CFAbsoluteTime; 39extern CFAbsoluteTime CFAbsoluteTimeGetCurrent(void); 40typedef const struct __CFDate * CFDateRef; 41extern CFDateRef CFDateCreate(CFAllocatorRef allocator, CFAbsoluteTime at); 42extern CFAbsoluteTime CFDateGetAbsoluteTime(CFDateRef theDate); 43typedef __darwin_natural_t natural_t; 44typedef natural_t mach_port_name_t; 45typedef mach_port_name_t mach_port_t; 46typedef int kern_return_t; 47typedef kern_return_t mach_error_t; 48typedef struct objc_selector *SEL; 49typedef signed char BOOL; 50typedef unsigned long NSUInteger; 51@class NSString, Protocol; 52extern void NSLog(NSString *format, ...) __attribute__((format(__NSString__, 1, 2))); 53typedef struct _NSZone NSZone; 54@class NSInvocation, NSMethodSignature, NSCoder, NSString, NSEnumerator; 55@protocol NSObject - (BOOL)isEqual:(id)object; 56- (id)retain; 57- (oneway void)release; 58- (id)autorelease; 59@end @protocol NSCopying - (id)copyWithZone:(NSZone *)zone; 60@end @protocol NSMutableCopying - (id)mutableCopyWithZone:(NSZone *)zone; 61@end @protocol NSCoding - (void)encodeWithCoder:(NSCoder *)aCoder; 62@end @interface NSObject <NSObject> { 63} 64+ (id)allocWithZone:(NSZone *)zone; 65+ (id)alloc; 66- (void)dealloc; 67@end extern id NSAllocateObject(Class aClass, NSUInteger extraBytes, NSZone *zone); 68typedef struct { 69} 70NSFastEnumerationState; 71@protocol NSFastEnumeration - (NSUInteger)countByEnumeratingWithState:(NSFastEnumerationState *)state objects:(id *)stackbuf count:(NSUInteger)len; 72@end @class NSString, NSDictionary; 73typedef double NSTimeInterval; 74@interface NSDate : NSObject <NSCopying, NSCoding> - (NSTimeInterval)timeIntervalSinceReferenceDate; 75@end typedef unsigned short unichar; 76@interface NSString : NSObject <NSCopying, NSMutableCopying, NSCoding> - (NSUInteger)length; 77- ( const char *)UTF8String; 78- (id)initWithUTF8String:(const char *)nullTerminatedCString; 79+ (id)stringWithUTF8String:(const char *)nullTerminatedCString; 80@end @class NSDictionary; 81@interface NSDictionary : NSObject <NSCopying, NSMutableCopying, NSCoding, NSFastEnumeration> - (NSUInteger)count; 82@end @interface NSMutableDictionary : NSDictionary - (void)removeObjectForKey:(id)aKey; 83- (void)setObject:(id)anObject forKey:(id)aKey; 84@end @interface NSMutableDictionary (NSMutableDictionaryCreation) + (id)dictionaryWithCapacity:(NSUInteger)numItems; 85@end @class NSString, NSDictionary, NSArray; 86typedef mach_port_t io_object_t; 87typedef io_object_t io_service_t; 88typedef struct __DASession * DASessionRef; 89extern DASessionRef DASessionCreate( CFAllocatorRef allocator ); 90typedef struct __DADisk * DADiskRef; 91extern DADiskRef DADiskCreateFromBSDName( CFAllocatorRef allocator, DASessionRef session, const char * name ); 92extern DADiskRef DADiskCreateFromIOMedia( CFAllocatorRef allocator, DASessionRef session, io_service_t media ); 93extern CFDictionaryRef DADiskCopyDescription( DADiskRef disk ); 94extern DADiskRef DADiskCopyWholeDisk( DADiskRef disk ); 95@interface NSTask : NSObject - (id)init; 96@end extern NSString * const NSTaskDidTerminateNotification; 97@interface NSResponder : NSObject <NSCoding> { 98struct __vaFlags { 99} 100_vaFlags; 101} 102@end @protocol NSAnimatablePropertyContainer - (id)animator; 103@end extern NSString *NSAnimationTriggerOrderIn ; 104@class NSBitmapImageRep, NSCursor, NSGraphicsContext, NSImage, NSPasteboard, NSScrollView, NSTextInputContext, NSWindow, NSAttributedString; 105@interface NSView : NSResponder <NSAnimatablePropertyContainer> { 106struct __VFlags2 { 107} 108_vFlags2; 109} 110@end @class NSColor, NSFont, NSNotification; 111@interface NSTextTab : NSObject <NSCopying, NSCoding> { 112} 113@end @protocol NSValidatedUserInterfaceItem - (SEL)action; 114@end @protocol NSUserInterfaceValidations - (BOOL)validateUserInterfaceItem:(id <NSValidatedUserInterfaceItem>)anItem; 115@end @class NSArray, NSError, NSImage, NSView, NSNotificationCenter, NSURL, NSScreen, NSRunningApplication; 116@interface NSApplication : NSResponder <NSUserInterfaceValidations> { 117} 118@end enum { 119NSTerminateCancel = 0, NSTerminateNow = 1, NSTerminateLater = 2 }; 120typedef NSUInteger NSApplicationTerminateReply; 121@protocol NSApplicationDelegate <NSObject> @optional - (NSApplicationTerminateReply)applicationShouldTerminate:(NSApplication *)sender; 122@end enum { 123NSUserInterfaceLayoutDirectionLeftToRight = 0, NSUserInterfaceLayoutDirectionRightToLeft = 1 }; 124@interface NSManagedObject : NSObject { 125} 126@end enum { 127kDAReturnSuccess = 0, kDAReturnError = (((0x3e)&0x3f)<<26) | (((0x368)&0xfff)<<14) | 0x01, kDAReturnBusy = (((0x3e)&0x3f)<<26) | (((0x368)&0xfff)<<14) | 0x02, kDAReturnBadArgument = (((0x3e)&0x3f)<<26) | (((0x368)&0xfff)<<14) | 0x03, kDAReturnExclusiveAccess = (((0x3e)&0x3f)<<26) | (((0x368)&0xfff)<<14) | 0x04, kDAReturnNoResources = (((0x3e)&0x3f)<<26) | (((0x368)&0xfff)<<14) | 0x05, kDAReturnNotFound = (((0x3e)&0x3f)<<26) | (((0x368)&0xfff)<<14) | 0x06, kDAReturnNotMounted = (((0x3e)&0x3f)<<26) | (((0x368)&0xfff)<<14) | 0x07, kDAReturnNotPermitted = (((0x3e)&0x3f)<<26) | (((0x368)&0xfff)<<14) | 0x08, kDAReturnNotPrivileged = (((0x3e)&0x3f)<<26) | (((0x368)&0xfff)<<14) | 0x09, kDAReturnNotReady = (((0x3e)&0x3f)<<26) | (((0x368)&0xfff)<<14) | 0x0A, kDAReturnNotWritable = (((0x3e)&0x3f)<<26) | (((0x368)&0xfff)<<14) | 0x0B, kDAReturnUnsupported = (((0x3e)&0x3f)<<26) | (((0x368)&0xfff)<<14) | 0x0C }; 128typedef mach_error_t DAReturn; 129typedef const struct __DADissenter * DADissenterRef; 130extern DADissenterRef DADissenterCreate( CFAllocatorRef allocator, DAReturn status, CFStringRef string ); 131 132//===----------------------------------------------------------------------===// 133// Test cases. 134//===----------------------------------------------------------------------===// 135 136CFAbsoluteTime f1() { 137 CFAbsoluteTime t = CFAbsoluteTimeGetCurrent(); 138 CFDateRef date = CFDateCreate(0, t); 139 CFRetain(date); 140 CFRelease(date); 141 CFDateGetAbsoluteTime(date); // no-warning 142 CFRelease(date); 143 t = CFDateGetAbsoluteTime(date); // expected-warning{{Reference-counted object is used after it is released.}} 144 return t; 145} 146 147CFAbsoluteTime f2() { 148 CFAbsoluteTime t = CFAbsoluteTimeGetCurrent(); 149 CFDateRef date = CFDateCreate(0, t); 150 [((NSDate*) date) retain]; 151 CFRelease(date); 152 CFDateGetAbsoluteTime(date); // no-warning 153 [((NSDate*) date) release]; 154 t = CFDateGetAbsoluteTime(date); // expected-warning{{Reference-counted object is used after it is released.}} 155 return t; 156} 157 158 159NSDate* global_x; 160 161// Test to see if we supresss an error when we store the pointer 162// to a global. 163 164CFAbsoluteTime f3() { 165 CFAbsoluteTime t = CFAbsoluteTimeGetCurrent(); 166 CFDateRef date = CFDateCreate(0, t); 167 [((NSDate*) date) retain]; 168 CFRelease(date); 169 CFDateGetAbsoluteTime(date); // no-warning 170 global_x = (NSDate*) date; 171 [((NSDate*) date) release]; 172 t = CFDateGetAbsoluteTime(date); // no-warning 173 return t; 174} 175 176//--------------------------------------------------------------------------- 177// Test case 'f4' differs for region store and basic store. See 178// retain-release-region-store.m and retain-release-basic-store.m. 179//--------------------------------------------------------------------------- 180 181// Test a leak. 182 183CFAbsoluteTime f5(int x) { 184 CFAbsoluteTime t = CFAbsoluteTimeGetCurrent(); 185 CFDateRef date = CFDateCreate(0, t); // expected-warning{{leak}} 186 187 if (x) 188 CFRelease(date); 189 190 return t; 191} 192 193// Test a leak involving the return. 194 195CFDateRef f6(int x) { 196 CFDateRef date = CFDateCreate(0, CFAbsoluteTimeGetCurrent()); // expected-warning{{leak}} 197 CFRetain(date); 198 return date; 199} 200 201// Test a leak involving an overwrite. 202 203CFDateRef f7() { 204 CFDateRef date = CFDateCreate(0, CFAbsoluteTimeGetCurrent()); //expected-warning{{leak}} 205 CFRetain(date); 206 date = CFDateCreate(0, CFAbsoluteTimeGetCurrent()); 207 return date; 208} 209 210// Generalization of Create rule. MyDateCreate returns a CFXXXTypeRef, and 211// has the word create. 212CFDateRef MyDateCreate(); 213 214CFDateRef f8() { 215 CFDateRef date = MyDateCreate(); // expected-warning{{leak}} 216 CFRetain(date); 217 return date; 218} 219 220CFDateRef f9() { 221 CFDateRef date = CFDateCreate(0, CFAbsoluteTimeGetCurrent()); 222 int *p = 0; 223 // When allocations fail, CFDateCreate can return null. 224 if (!date) *p = 1; // expected-warning{{null}} 225 return date; 226} 227 228// Handle DiskArbitration API: 229// 230// http://developer.apple.com/DOCUMENTATION/DARWIN/Reference/DiscArbitrationFramework/ 231// 232void f10(io_service_t media, DADiskRef d, CFStringRef s) { 233 DADiskRef disk = DADiskCreateFromBSDName(kCFAllocatorDefault, 0, "hello"); // expected-warning{{leak}} 234 if (disk) NSLog(@"ok"); 235 236 disk = DADiskCreateFromIOMedia(kCFAllocatorDefault, 0, media); // expected-warning{{leak}} 237 if (disk) NSLog(@"ok"); 238 239 CFDictionaryRef dict = DADiskCopyDescription(d); // expected-warning{{leak}} 240 if (dict) NSLog(@"ok"); 241 242 disk = DADiskCopyWholeDisk(d); // expected-warning{{leak}} 243 if (disk) NSLog(@"ok"); 244 245 DADissenterRef dissenter = DADissenterCreate(kCFAllocatorDefault, // expected-warning{{leak}} 246 kDAReturnSuccess, s); 247 if (dissenter) NSLog(@"ok"); 248 249 DASessionRef session = DASessionCreate(kCFAllocatorDefault); // expected-warning{{leak}} 250 if (session) NSLog(@"ok"); 251} 252 253// Test retain/release checker with CFString and CFMutableArray. 254void f11() { 255 // Create the array. 256 CFMutableArrayRef A = CFArrayCreateMutable(0, 10, &kCFTypeArrayCallBacks); 257 258 // Create a string. 259 CFStringRef s1 = CFStringCreateWithCString(0, "hello world", 260 kCFStringEncodingUTF8); 261 262 // Add the string to the array. 263 CFArrayAppendValue(A, s1); 264 265 // Decrement the reference count. 266 CFRelease(s1); // no-warning 267 268 // Get the string. We don't own it. 269 s1 = (CFStringRef) CFArrayGetValueAtIndex(A, 0); 270 271 // Release the array. 272 CFRelease(A); // no-warning 273 274 // Release the string. This is a bug. 275 CFRelease(s1); // expected-warning{{Incorrect decrement of the reference count}} 276} 277 278// PR 3337: Handle functions declared using typedefs. 279typedef CFTypeRef CREATEFUN(); 280CREATEFUN MyCreateFun; 281 282void f12() { 283 CFTypeRef o = MyCreateFun(); // expected-warning {{leak}} 284} 285 286void f13_autorelease() { 287 CFMutableArrayRef A = CFArrayCreateMutable(0, 10, &kCFTypeArrayCallBacks); // no-warning 288 [(id) A autorelease]; // no-warning 289} 290 291void f13_autorelease_b() { 292 CFMutableArrayRef A = CFArrayCreateMutable(0, 10, &kCFTypeArrayCallBacks); 293 [(id) A autorelease]; 294 [(id) A autorelease]; // expected-warning{{Object sent -autorelease too many times}} 295} 296 297CFMutableArrayRef f13_autorelease_c() { 298 CFMutableArrayRef A = CFArrayCreateMutable(0, 10, &kCFTypeArrayCallBacks); 299 [(id) A autorelease]; 300 [(id) A autorelease]; 301 return A; // expected-warning{{Object sent -autorelease too many times}} 302} 303 304CFMutableArrayRef f13_autorelease_d() { 305 CFMutableArrayRef A = CFArrayCreateMutable(0, 10, &kCFTypeArrayCallBacks); 306 [(id) A autorelease]; 307 [(id) A autorelease]; 308 CFMutableArrayRef B = CFArrayCreateMutable(0, 10, &kCFTypeArrayCallBacks); // expected-warning{{Object sent -autorelease too many times}} 309 CFRelease(B); // no-warning 310} 311 312 313// This case exercises the logic where the leak site is the same as the allocation site. 314void f14_leakimmediately() { 315 CFArrayCreateMutable(0, 10, &kCFTypeArrayCallBacks); // expected-warning{{leak}} 316} 317 318// Test that we track an allocated object beyond the point where the *name* 319// of the variable storing the reference is no longer live. 320void f15() { 321 // Create the array. 322 CFMutableArrayRef A = CFArrayCreateMutable(0, 10, &kCFTypeArrayCallBacks); 323 CFMutableArrayRef *B = &A; 324 // At this point, the name 'A' is no longer live. 325 CFRelease(*B); // no-warning 326} 327 328 329// Test basic tracking of ivars associated with 'self'. For the retain/release 330// checker we currently do not want to flag leaks associated with stores 331// of tracked objects to ivars. 332@interface SelfIvarTest : NSObject { 333 id myObj; 334} 335- (void)test_self_tracking; 336@end 337 338@implementation SelfIvarTest 339- (void)test_self_tracking { 340 myObj = (id) CFArrayCreateMutable(0, 10, &kCFTypeArrayCallBacks); // no-warning 341} 342@end 343 344// <rdar://problem/6659160> 345int isFoo(char c); 346 347static void rdar_6659160(char *inkind, char *inname) 348{ 349 // We currently expect that [NSObject alloc] cannot fail. This 350 // will be a toggled flag in the future. It can indeed return null, but 351 // Cocoa programmers generally aren't expected to reason about out-of-memory 352 // conditions. 353 NSString *kind = [[NSString alloc] initWithUTF8String:inkind]; // expected-warning{{leak}} 354 355 // We do allow stringWithUTF8String to fail. This isn't really correct, as 356 // far as returning 0. In most error conditions it will throw an exception. 357 // If allocation fails it could return 0, but again this 358 // isn't expected. 359 NSString *name = [NSString stringWithUTF8String:inname]; 360 if(!name) 361 return; 362 363 const char *kindC = 0; 364 const char *nameC = 0; 365 366 // In both cases, we cannot reach a point down below where we 367 // dereference kindC or nameC with either being null. This is because 368 // we assume that [NSObject alloc] doesn't fail and that we have the guard 369 // up above. 370 371 if(kind) 372 kindC = [kind UTF8String]; 373 if(name) 374 nameC = [name UTF8String]; 375 if(!isFoo(kindC[0])) // expected-warning{{null}} 376 return; 377 if(!isFoo(nameC[0])) // no-warning 378 return; 379 380 [kind release]; 381 [name release]; // expected-warning{{Incorrect decrement of the reference count}} 382} 383 384// PR 3677 - 'allocWithZone' should be treated as following the Cocoa naming 385// conventions with respect to 'return'ing ownership. 386@interface PR3677: NSObject @end 387@implementation PR3677 388+ (id)allocWithZone:(NSZone *)inZone { 389 return [super allocWithZone:inZone]; // no-warning 390} 391@end 392 393// PR 3820 - Reason about calls to -dealloc 394void pr3820_DeallocInsteadOfRelease(void) 395{ 396 id foo = [[NSString alloc] init]; // no-warning 397 [foo dealloc]; 398 // foo is not leaked, since it has been deallocated. 399} 400 401void pr3820_ReleaseAfterDealloc(void) 402{ 403 id foo = [[NSString alloc] init]; 404 [foo dealloc]; 405 [foo release]; // expected-warning{{used after it is release}} 406 // NSInternalInconsistencyException: message sent to deallocated object 407} 408 409void pr3820_DeallocAfterRelease(void) 410{ 411 NSLog(@"\n\n[%s]", __FUNCTION__); 412 id foo = [[NSString alloc] init]; 413 [foo release]; 414 [foo dealloc]; // expected-warning{{used after it is released}} 415 // message sent to released object 416} 417 418// From <rdar://problem/6704930>. The problem here is that 'length' binds to 419// '($0 - 1)' after '--length', but SimpleConstraintManager doesn't know how to 420// reason about '($0 - 1) > constant'. As a temporary hack, we drop the value 421// of '($0 - 1)' and conjure a new symbol. 422void rdar6704930(unsigned char *s, unsigned int length) { 423 NSString* name = 0; 424 if (s != 0) { 425 if (length > 0) { 426 while (length > 0) { 427 if (*s == ':') { 428 ++s; 429 --length; 430 name = [[NSString alloc] init]; // no-warning 431 break; 432 } 433 ++s; 434 --length; 435 } 436 if ((length == 0) && (name != 0)) { 437 [name release]; 438 name = 0; 439 } 440 if (length == 0) { // no ':' found -> use it all as name 441 name = [[NSString alloc] init]; // no-warning 442 } 443 } 444 } 445 446 if (name != 0) { 447 [name release]; 448 } 449} 450 451//===----------------------------------------------------------------------===// 452// <rdar://problem/6833332> 453// One build of the analyzer accidentally stopped tracking the allocated 454// object after the 'retain'. 455//===----------------------------------------------------------------------===// 456 457@interface rdar_6833332 : NSObject <NSApplicationDelegate> { 458 NSWindow *window; 459} 460@property (nonatomic, retain) NSWindow *window; 461@end 462 463@implementation rdar_6833332 464@synthesize window; 465- (void)applicationDidFinishLaunching:(NSNotification *)aNotification { 466 NSMutableDictionary *dict = [[NSMutableDictionary dictionaryWithCapacity:4] retain]; // expected-warning{{leak}} 467 468 [dict setObject:@"foo" forKey:@"bar"]; 469 470 NSLog(@"%@", dict); 471} 472- (void)dealloc { 473 [window release]; 474 [super dealloc]; 475} 476@end 477 478//===----------------------------------------------------------------------===// 479// Tests of ownership attributes. 480//===----------------------------------------------------------------------===// 481 482@interface TestOwnershipAttr : NSObject 483- (NSString*) returnsAnOwnedString __attribute__((ns_returns_retained)); 484- (NSString*) returnsAnOwnedCFString __attribute__((cf_returns_retained)); 485@end 486 487void test_attr_1(TestOwnershipAttr *X) { 488 NSString *str = [X returnsAnOwnedString]; // expected-warning{{leak}} 489} 490 491void test_attr_1b(TestOwnershipAttr *X) { 492 NSString *str = [X returnsAnOwnedCFString]; // expected-warning{{leak}} 493} 494 495