diff options
| author | Dimitry Andric <dim@FreeBSD.org> | 2013-04-08 18:45:10 +0000 |
|---|---|---|
| committer | Dimitry Andric <dim@FreeBSD.org> | 2013-04-08 18:45:10 +0000 |
| commit | 809500fc2c13c8173a16b052304d983864e4a1e1 (patch) | |
| tree | 4fc2f184c499d106f29a386c452b49e5197bf63d /test/Analysis/Malloc+MismatchedDeallocator+NewDelete.cpp | |
| parent | be7c9ec198dcdb5bf73a35bfbb00b3333cb87909 (diff) | |
Notes
Diffstat (limited to 'test/Analysis/Malloc+MismatchedDeallocator+NewDelete.cpp')
| -rw-r--r-- | test/Analysis/Malloc+MismatchedDeallocator+NewDelete.cpp | 71 |
1 files changed, 71 insertions, 0 deletions
diff --git a/test/Analysis/Malloc+MismatchedDeallocator+NewDelete.cpp b/test/Analysis/Malloc+MismatchedDeallocator+NewDelete.cpp new file mode 100644 index 0000000000000..b0bb1735b4945 --- /dev/null +++ b/test/Analysis/Malloc+MismatchedDeallocator+NewDelete.cpp @@ -0,0 +1,71 @@ +// RUN: %clang_cc1 -analyze -analyzer-checker=core,unix.Malloc,unix.MismatchedDeallocator,alpha.cplusplus.NewDelete -analyzer-store region -std=c++11 -verify %s + +typedef __typeof(sizeof(int)) size_t; +void *malloc(size_t); +void free(void *); + +//-------------------------------------------------- +// Check that unix.Malloc catches all types of bugs. +//-------------------------------------------------- +void testMallocDoubleFree() { + int *p = (int *)malloc(sizeof(int)); + free(p); + free(p); // expected-warning{{Attempt to free released memory}} +} + +void testMallocLeak() { + int *p = (int *)malloc(sizeof(int)); +} // expected-warning{{Memory is never released; potential leak of memory pointed to by 'p'}} + +void testMallocUseAfterFree() { + int *p = (int *)malloc(sizeof(int)); + free(p); + int j = *p; // expected-warning{{Use of memory after it is freed}} +} + +void testMallocBadFree() { + int i; + free(&i); // expected-warning{{Argument to free() is the address of the local variable 'i', which is not memory allocated by malloc()}} +} + +void testMallocOffsetFree() { + int *p = (int *)malloc(sizeof(int)); + free(++p); // expected-warning{{Argument to free() is offset by 4 bytes from the start of memory allocated by malloc()}} +} + +//----------------------------------------------------------------- +// Check that unix.MismatchedDeallocator catches all types of bugs. +//----------------------------------------------------------------- +void testMismatchedDeallocator() { + int *x = (int *)malloc(sizeof(int)); + delete x; // expected-warning{{Memory allocated by malloc() should be deallocated by free(), not 'delete'}} +} + +//---------------------------------------------------------------- +// Check that alpha.cplusplus.NewDelete catches all types of bugs. +//---------------------------------------------------------------- +void testNewDoubleFree() { + int *p = new int; + delete p; + delete p; // expected-warning{{Attempt to free released memory}} +} + +void testNewLeak() { + int *p = new int; +} // expected-warning{{Memory is never released; potential leak of memory pointed to by 'p'}} + +void testNewUseAfterFree() { + int *p = (int *)operator new(0); + delete p; + int j = *p; // expected-warning{{Use of memory after it is freed}} +} + +void testNewBadFree() { + int i; + delete &i; // expected-warning{{Argument to 'delete' is the address of the local variable 'i', which is not memory allocated by 'new'}} +} + +void testNewOffsetFree() { + int *p = new int; + operator delete(++p); // expected-warning{{Argument to operator delete is offset by 4 bytes from the start of memory allocated by 'new'}} +} |
