Re-land "[analyzer] Make it a noop when initializing a field of empty record" (#138951)

The original commit assumes that
`CXXConstructExpr->getType()->getAsRecordDecl()` is always a
`CXXRecordDecl` but it is not true for ObjC programs.

This relanding changes
`cast<CXXRecordDecl>(CXXConstructExpr->getType()->getAsRecordDecl())`
to
`dyn_cast_or_null<CXXRecordDecl>(CXXConstructExpr->getType()->getAsRecordDecl())`

This reverts commit 9048c2d4f2.
rdar://146753089
This commit is contained in:
Ziqing Luo
2025-05-07 15:08:44 -07:00
committed by Ziqing Luo
parent 0d0ef58c8f
commit b756c82bfa
2 changed files with 57 additions and 1 deletions

View File

@@ -10,6 +10,7 @@
//
//===----------------------------------------------------------------------===//
#include "clang/AST/ASTContext.h"
#include "clang/AST/AttrIterator.h"
#include "clang/AST/DeclCXX.h"
#include "clang/AST/ParentMap.h"
@@ -23,6 +24,7 @@
#include "clang/StaticAnalyzer/Core/PathSensitive/SVals.h"
#include "llvm/ADT/STLExtras.h"
#include "llvm/ADT/Sequence.h"
#include "llvm/Support/Casting.h"
#include <optional>
using namespace clang;
@@ -715,7 +717,11 @@ void ExprEngine::handleConstructor(const Expr *E,
// actually make things worse. Placement new makes this tricky as well,
// since it's then possible to be initializing one part of a multi-
// dimensional array.
State = State->bindDefaultZero(Target, LCtx);
const CXXRecordDecl *TargetHeldRecord =
dyn_cast_or_null<CXXRecordDecl>(CE->getType()->getAsRecordDecl());
if (!TargetHeldRecord || !TargetHeldRecord->isEmpty())
State = State->bindDefaultZero(Target, LCtx);
}
Bldr.generateNode(CE, N, State, /*tag=*/nullptr,

View File

@@ -0,0 +1,50 @@
// RUN: %clang_analyze_cc1 -analyzer-checker=cplusplus -verify %s
// RUN: %clang_analyze_cc1 -analyzer-checker=cplusplus -verify %s -DEMPTY_CLASS
// UNSUPPORTED: system-windows
// expected-no-diagnostics
// This test reproduces the issue that previously the static analyzer
// initialized an [[no_unique_address]] empty field to zero,
// over-writing a non-empty field with the same offset.
namespace std {
#ifdef EMPTY_CLASS
struct default_delete {};
template <class _Tp, class _Dp = default_delete >
#else
// Class with methods and static members is still empty:
template <typename T>
class default_delete {
T dump();
static T x;
};
template <class _Tp, class _Dp = default_delete<_Tp> >
#endif
class unique_ptr {
[[no_unique_address]] _Tp * __ptr_;
[[no_unique_address]] _Dp __deleter_;
public:
explicit unique_ptr(_Tp* __p) noexcept
: __ptr_(__p),
__deleter_() {}
~unique_ptr() {
delete __ptr_;
}
};
}
struct X {};
int main()
{
// Previously a leak falsely reported here. It was because the
// Static Analyzer engine simulated the initialization of
// `__deleter__` incorrectly. The engine assigned zero to
// `__deleter__`--an empty record sharing offset with `__ptr__`.
// The assignment over wrote `__ptr__`.
std::unique_ptr<X> a(new X());
return 0;
}