Index: clang/include/clang/StaticAnalyzer/Checkers/Checkers.td =================================================================== --- clang/include/clang/StaticAnalyzer/Checkers/Checkers.td +++ clang/include/clang/StaticAnalyzer/Checkers/Checkers.td @@ -569,6 +569,10 @@ let ParentPackage = Cocoa in { +def RunLoopAutoreleaseLeakChecker : Checker<"RunLoopAutoreleaseLeak">, + HelpText<"Check for detecting memory loops from autorelease loops wrapping run loops">, + DescFile<"RunLoopAutoreleaseLeakChecker.cpp">; + def ObjCAtSyncChecker : Checker<"AtSync">, HelpText<"Check for nil pointers used as mutexes for @synchronized">, DescFile<"ObjCAtSyncChecker.cpp">; Index: clang/lib/StaticAnalyzer/Checkers/CMakeLists.txt =================================================================== --- clang/lib/StaticAnalyzer/Checkers/CMakeLists.txt +++ clang/lib/StaticAnalyzer/Checkers/CMakeLists.txt @@ -79,6 +79,7 @@ RetainCountChecker.cpp ReturnPointerRangeChecker.cpp ReturnUndefChecker.cpp + RunLoopAutoreleaseLeakChecker.cpp SimpleStreamChecker.cpp StackAddrEscapeChecker.cpp StdLibraryFunctionsChecker.cpp Index: clang/lib/StaticAnalyzer/Checkers/RunLoopAutoreleaseLeakChecker.cpp =================================================================== --- /dev/null +++ clang/lib/StaticAnalyzer/Checkers/RunLoopAutoreleaseLeakChecker.cpp @@ -0,0 +1,210 @@ +//=- RunLoopAutoreleaseLeakChecker.cpp --------------------------*- C++ -*-==// +// +// The LLVM Compiler Infrastructure +// +// This file is distributed under the University of Illinois Open Source +// License. See LICENSE.TXT for details. +// +// +//===----------------------------------------------------------------------===// +// +// A checker for detecting leaks resulting from allocating temporary +// autoreleasing objects before starting the main run loop. +// +// Checks for two antipatterns: +// 1. ObjCMessageExpr followed by [[NARunLoop mainRunLoop] run] in the same +// autorelease pool. +// 2. ObjCMessageExpr followed by [[NARunLoop mainRunLoop] run] in no +// autorelease pool. +// +//===----------------------------------------------------------------------===// +// + +#include "ClangSACheckers.h" +#include "clang/AST/Decl.h" +#include "clang/AST/DeclObjC.h" +#include "clang/ASTMatchers/ASTMatchFinder.h" +#include "clang/StaticAnalyzer/Core/BugReporter/BugReporter.h" +#include "clang/StaticAnalyzer/Core/BugReporter/BugType.h" +#include "clang/StaticAnalyzer/Core/Checker.h" +#include "clang/StaticAnalyzer/Core/CheckerManager.h" +#include "clang/StaticAnalyzer/Core/PathSensitive/CallEvent.h" +#include "clang/StaticAnalyzer/Core/PathSensitive/CheckerContext.h" +#include "clang/StaticAnalyzer/Core/PathSensitive/ExprEngine.h" + +using namespace clang; +using namespace ento; +using namespace ast_matchers; + +namespace { + +const char * RunLoopBind = "NSRunLoopM"; +const char * RunLoopRunBind = "RunLoopRunM"; +const char * OtherMsgBind = "OtherMessageSentM"; +const char * AutoreleasePoolBind = "AutoreleasePoolM"; + +class RunLoopAutoreleaseLeakChecker : public Checker< + check::ASTCodeBody> { + +public: + void checkASTCodeBody(const Decl *D, + AnalysisManager &AM, + BugReporter &BR) const; + +}; + +} // end anonymous namespace + + +using TriBoolTy = Optional; +using MemoizationMapTy = llvm::DenseMap>; + +static TriBoolTy +seenBeforeRec(const Stmt *Parent, const Stmt *A, const Stmt *B, + MemoizationMapTy &Memoization) { + for (const Stmt *C : Parent->children()) { + if (C == A) + return true; + + if (C == B) + return false; + + Optional &Cached = Memoization[C]; + if (!Cached) + Cached = seenBeforeRec(C, A, B, Memoization); + + if (Cached->hasValue()) + return Cached->getValue(); + } + + return None; +} + +/// \return Whether {@code A} occurs before {@code B} in traversal of +/// {@code Parent}. +/// Conceptually a very incomplete/unsound approximation of happens-before +/// relationship (A is likely to be evaluated before B), +/// but useful enough in this case. +static bool seenBefore(const Stmt *Parent, const Stmt *A, const Stmt *B) { + MemoizationMapTy Memoization; + TriBoolTy Val = seenBeforeRec(Parent, A, B, Memoization); + assert(Val.hasValue() && "Neither statement found in parent"); + return Val.getValue(); +} + +static void emitDiagnostics(BoundNodes &Match, + const Decl *D, + BugReporter &BR, + AnalysisManager &AM, + const RunLoopAutoreleaseLeakChecker *Checker) { + + assert(D->hasBody()); + const Stmt *DeclBody = D->getBody(); + + AnalysisDeclContext *ADC = AM.getAnalysisDeclContext(D); + + const auto *ME = Match.getNodeAs(OtherMsgBind); + assert(ME); + + const auto *AP = + Match.getNodeAs(AutoreleasePoolBind); + bool HasAutoreleasePool = (AP != nullptr); + + const auto *RLR = Match.getNodeAs(RunLoopRunBind); + assert(RLR); + + assert(ME != RLR); + if (HasAutoreleasePool && seenBefore(AP, RLR, ME)) + return; + + if (!HasAutoreleasePool && seenBefore(DeclBody, RLR, ME)) + return; + + PathDiagnosticLocation Location = PathDiagnosticLocation::createBegin( + ME, BR.getSourceManager(), ADC); + SourceRange Range = ME->getSourceRange(); + + BR.EmitBasicReport(ADC->getDecl(), Checker, + /*Name=*/"Memory leak inside autorelease pool", + /*Category=*/"Memory", + /*Name=*/ + (Twine("Temporary objects allocated in the") + + " autorelease pool " + + (HasAutoreleasePool ? "" : "of last resort ") + + "followed by the launch of mainRunLoop " + "may never get released, consider moving them to a " + "separate autorelease pool") + .str(), + Location, Range); +} + +static StatementMatcher getRunLoopRunM(StatementMatcher Extra = anything()) { + StatementMatcher MainRunLoopM = + objcMessageExpr(hasSelector("mainRunLoop"), + hasReceiverType(asString("NSRunLoop")), + Extra) + .bind(RunLoopBind); + + return objcMessageExpr(hasSelector("run"), + hasReceiver(MainRunLoopM), + Extra) + .bind(RunLoopRunBind); +} + +static StatementMatcher getOtherMessageSentM(StatementMatcher Extra = anything()) { + return objcMessageExpr(unless(anyOf(equalsBoundNode(RunLoopBind), + equalsBoundNode(RunLoopRunBind))), + Extra) + .bind(OtherMsgBind); +} + +static void +checkTempObjectsInSamePool(const Decl *D, AnalysisManager &AM, BugReporter &BR, + const RunLoopAutoreleaseLeakChecker *Chkr) { + StatementMatcher RunLoopRunM = getRunLoopRunM(); + StatementMatcher OtherMessageSentM = getOtherMessageSentM(); + + StatementMatcher RunLoopInAutorelease = + autoreleasePoolStmt( + hasDescendant(RunLoopRunM), + hasDescendant(OtherMessageSentM)).bind(AutoreleasePoolBind); + + DeclarationMatcher GroupM = decl(hasDescendant(RunLoopInAutorelease)); + + auto Matches = match(GroupM, *D, AM.getASTContext()); + for (BoundNodes Match : Matches) + emitDiagnostics(Match, D, BR, AM, Chkr); +} + +static void +checkTempObjectsInNoPool(const Decl *D, AnalysisManager &AM, BugReporter &BR, + const RunLoopAutoreleaseLeakChecker *Chkr) { + + auto NoPoolM = unless(hasAncestor(autoreleasePoolStmt())); + + StatementMatcher RunLoopRunM = getRunLoopRunM(NoPoolM); + StatementMatcher OtherMessageSentM = getOtherMessageSentM(NoPoolM); + + DeclarationMatcher GroupM = namedDecl( + anyOf(hasName("main"), hasName("xpc_main")), + hasDescendant(RunLoopRunM), + hasDescendant(OtherMessageSentM) + ); + + auto Matches = match(GroupM, *D, AM.getASTContext()); + + for (BoundNodes Match : Matches) + emitDiagnostics(Match, D, BR, AM, Chkr); + +} + +void RunLoopAutoreleaseLeakChecker::checkASTCodeBody(const Decl *D, + AnalysisManager &AM, + BugReporter &BR) const { + checkTempObjectsInSamePool(D, AM, BR, this); + checkTempObjectsInNoPool(D, AM, BR, this); +} + +void ento::registerRunLoopAutoreleaseLeakChecker(CheckerManager &mgr) { + mgr.registerChecker(); +} Index: clang/test/Analysis/Checkers/RunLoopAutoreleaseLeakChecker.m =================================================================== --- /dev/null +++ clang/test/Analysis/Checkers/RunLoopAutoreleaseLeakChecker.m @@ -0,0 +1,103 @@ +// UNSUPPORTED: system-windows +// RUN: %clang_analyze_cc1 -fobjc-arc -analyzer-checker=core,osx.cocoa.RunLoopAutoreleaseLeak %s -triple x86_64-darwin -verify +// RUN: %clang_analyze_cc1 -DEXTRA=1 -DAP1=1 -fobjc-arc -analyzer-checker=core,osx.cocoa.RunLoopAutoreleaseLeak %s -triple x86_64-darwin -verify +// RUN: %clang_analyze_cc1 -DEXTRA=1 -DAP2=1 -fobjc-arc -analyzer-checker=core,osx.cocoa.RunLoopAutoreleaseLeak %s -triple x86_64-darwin -verify +// RUN: %clang_analyze_cc1 -DEXTRA=1 -DAP3=1 -fobjc-arc -analyzer-checker=core,osx.cocoa.RunLoopAutoreleaseLeak %s -triple x86_64-darwin -verify + +#include "../Inputs/system-header-simulator-for-objc-dealloc.h" + +#ifndef EXTRA + +void just_runloop() { // No warning: no statements in between + @autoreleasepool { + [[NSRunLoop mainRunLoop] run]; // no-warning + } +} + +void runloop_init_before() { // Warning: object created before the loop. + @autoreleasepool { + NSObject *object = [[NSObject alloc] init]; // expected-warning{{Temporary objects allocated in the autorelease pool followed by the launch of mainRunLoop may never get released, consider moving them to a separate autorelease pool}} + (void) object; + [[NSRunLoop mainRunLoop] run]; + } +} + +void runloop_init_before_two_objects() { // Warning: object created before the loop. + @autoreleasepool { + NSObject *object = [[NSObject alloc] init]; // expected-warning{{Temporary objects allocated in the autorelease pool followed by the launch of mainRunLoop may never get released, consider moving them to a separate autorelease pool}} + NSObject *object2 = [[NSObject alloc] init]; // no-warning, warning on the first one is enough. + (void) object; + (void) object2; + [[NSRunLoop mainRunLoop] run]; + } +} + +void runloop_no_autoreleasepool() { + NSObject *object = [[NSObject alloc] init]; // no-warning + (void)object; + [[NSRunLoop mainRunLoop] run]; +} + +void runloop_init_after() { // No warning: objects created after the loop + @autoreleasepool { + [[NSRunLoop mainRunLoop] run]; + NSObject *object = [[NSObject alloc] init]; // no-warning + (void) object; + } +} + +#endif + +#ifdef AP1 +int main() { + NSObject *object = [[NSObject alloc] init]; // expected-warning{{Temporary objects allocated in the autorelease pool of last resort followed by the launch of mainRunLoop may never get released, consider moving them to a separate autorelease pool}} + (void) object; + [[NSRunLoop mainRunLoop] run]; + return 0; +} + +int xpc_main() { + NSObject *object = [[NSObject alloc] init]; // expected-warning{{Temporary objects allocated in the autorelease pool of last resort followed by the launch of mainRunLoop may never get released, consider moving them to a separate autorelease pool}} + (void) object; + [[NSRunLoop mainRunLoop] run]; + return 0; +} +#endif + +#ifdef AP2 +// expected-no-diagnostics +int main() { + NSObject *object = [[NSObject alloc] init]; // no-warning + (void) object; + @autoreleasepool { + [[NSRunLoop mainRunLoop] run]; + } + return 0; +} + +int xpc_main() { + NSObject *object = [[NSObject alloc] init]; // no-warning + (void) object; + @autoreleasepool { + [[NSRunLoop mainRunLoop] run]; + } + return 0; +} +#endif + +#ifdef AP3 +// expected-no-diagnostics +int main() { + [[NSRunLoop mainRunLoop] run]; + NSObject *object = [[NSObject alloc] init]; // no-warning + (void) object; + return 0; +} + +int xpc_main() { + [[NSRunLoop mainRunLoop] run]; + NSObject *object = [[NSObject alloc] init]; // no-warning + (void) object; + return 0; +} +#endif Index: clang/test/Analysis/Inputs/system-header-simulator-for-objc-dealloc.h =================================================================== --- clang/test/Analysis/Inputs/system-header-simulator-for-objc-dealloc.h +++ clang/test/Analysis/Inputs/system-header-simulator-for-objc-dealloc.h @@ -18,6 +18,8 @@ @interface NSRunLoop : NSObject + (NSRunLoop *)currentRunLoop; ++ (NSRunLoop *)mainRunLoop; +- (void) run; - (void)cancelPerformSelectorsWithTarget:(id)target; @end Index: clang/test/Analysis/html_diagnostics/relevant_lines/macros_same_file.c =================================================================== --- clang/test/Analysis/html_diagnostics/relevant_lines/macros_same_file.c +++ clang/test/Analysis/html_diagnostics/relevant_lines/macros_same_file.c @@ -13,3 +13,4 @@ // RUN: %clang_analyze_cc1 -analyze -analyzer-checker=core -analyzer-output html -o %t.output %s // RUN: cat %t.output/* | FileCheck %s --match-full-lines // CHECK: var relevant_lines = {"1": {"3": 1, "4": 1, "5": 1, "6": 1}}; +// CHECK-NEXT: fail