analyzer: fix ICE on escaped unknown pointers [PR96611]
authorDavid Malcolm <dmalcolm@redhat.com>
Fri, 14 Aug 2020 14:48:30 +0000 (10:48 -0400)
committerDavid Malcolm <dmalcolm@redhat.com>
Fri, 14 Aug 2020 20:56:28 +0000 (16:56 -0400)
commitee88b536069db8f870c444c441182a9c76ec5bba
tree437fb885cb40faf78632bd8965ab2141497c9c40
parent7e625038623df83b341a509ecd9c6a85f7837ecf
analyzer: fix ICE on escaped unknown pointers [PR96611]

PR analyzer/96611 reports an ICE within the handling for unknown
functions, when passing a pointer to something accessed via a
global pointer, after an unknown function has already been called.

The first unknown function leads to the store being flagged, so
the access to the global pointer leads to (*unknown_svalue) for
the base region of the argument to the 2nd function, and thus
*unknown_svalue being reachable by the 2nd unknown function,
triggering an assertion failure.

Handle this case by rejecting attempts to get a cluster for
the unknown pointer, fixing the ICE.

gcc/analyzer/ChangeLog:
PR analyzer/96611
* store.cc (store::mark_as_escaped): Reject attempts to
get a cluster for an unknown pointer.

gcc/testsuite/ChangeLog:
PR analyzer/96611
* gcc.dg/analyzer/pr96611.c: New test.
gcc/analyzer/store.cc
gcc/testsuite/gcc.dg/analyzer/pr96611.c [new file with mode: 0644]