analyzer: fix false positives from -Wanalyzer-infinite-recursion [PR108524]
authorDavid Malcolm <dmalcolm@redhat.com>
Thu, 26 Jan 2023 14:12:21 +0000 (09:12 -0500)
committerDavid Malcolm <dmalcolm@redhat.com>
Thu, 26 Jan 2023 14:12:21 +0000 (09:12 -0500)
commit7bffea89f1f164efc10dd37d979a83c4c5fbfa7e
tree43016790064bdf55f9225fe531fb1996c15f6abd
parent2e445d9e99814644e7edabac4c3feb5df50303d9
analyzer: fix false positives from -Wanalyzer-infinite-recursion [PR108524]

Reject -Wanalyzer-infinite-recursion diagnostics in which control flow
has been affected by conjured_svalues between the initial call to a
function and the subsequent entry to that function.  This prevents false
positives such as in qemu's recursive JSON parser where function calls are
changing state in the rest of the program (e.g. consuming tokens), despite
the modelled state being effectively identical at both nested entrypoints.

gcc/analyzer/ChangeLog:
PR analyzer/108524
* analyzer.h (class feasible_node): New forward decl.
* diagnostic-manager.cc (epath_finder::get_best_epath): Add "pd"
param.
(epath_finder::explore_feasible_paths): Likewise.
(epath_finder::process_worklist_item): Likewise.  Use it to call
pending_diagnostic::check_valid_fpath_p on the final fpath to
give pending_diagnostic a way to add additional restrictions on
feasibility.
(saved_diagnostic::calc_best_epath): Pass pending_diagnostic to
epath_finder::get_best_epath.
* infinite-recursion.cc: Include "analyzer/feasible-graph.h".
(infinite_recursion_diagnostic::check_valid_fpath_p): New.
(infinite_recursion_diagnostic::fedge_uses_conjured_svalue_p): New.
(infinite_recursion_diagnostic::expr_uses_conjured_svalue_p): New.
* pending-diagnostic.h (pending_diagnostic::check_valid_fpath_p):
New vfunc.

gcc/testsuite/ChangeLog:
PR analyzer/108524
* gcc.dg/analyzer/infinite-recursion-pr108524-1.c: New test.
* gcc.dg/analyzer/infinite-recursion-pr108524-2.c: New test.
* gcc.dg/analyzer/infinite-recursion-pr108524-qobject-json-parser.c:
New test.

Signed-off-by: David Malcolm <dmalcolm@redhat.com>
gcc/analyzer/analyzer.h
gcc/analyzer/diagnostic-manager.cc
gcc/analyzer/infinite-recursion.cc
gcc/analyzer/pending-diagnostic.h
gcc/testsuite/gcc.dg/analyzer/infinite-recursion-pr108524-1.c [new file with mode: 0644]
gcc/testsuite/gcc.dg/analyzer/infinite-recursion-pr108524-2.c [new file with mode: 0644]
gcc/testsuite/gcc.dg/analyzer/infinite-recursion-pr108524-qobject-json-parser.c [new file with mode: 0644]