2018-05-30 10:15:50 +02:00
|
|
|
use crate::utils::{iter_input_pats, span_lint, type_is_unsafe_function};
|
2018-11-27 21:14:15 +01:00
|
|
|
use matches::matches;
|
2018-12-29 16:04:45 +01:00
|
|
|
use rustc::hir;
|
|
|
|
use rustc::hir::def::Def;
|
|
|
|
use rustc::hir::intravisit;
|
|
|
|
use rustc::lint::{LateContext, LateLintPass, LintArray, LintPass};
|
|
|
|
use rustc::ty;
|
|
|
|
use rustc::{declare_tool_lint, lint_array};
|
|
|
|
use rustc_data_structures::fx::FxHashSet;
|
|
|
|
use rustc_target::spec::abi::Abi;
|
|
|
|
use syntax::ast;
|
|
|
|
use syntax::source_map::Span;
|
2016-03-09 00:48:10 +01:00
|
|
|
|
2016-08-06 09:55:04 +02:00
|
|
|
/// **What it does:** Checks for functions with too many parameters.
|
2016-03-09 00:48:10 +01:00
|
|
|
///
|
2016-08-06 09:55:04 +02:00
|
|
|
/// **Why is this bad?** Functions with lots of parameters are considered bad
|
|
|
|
/// style and reduce readability (“what does the 5th parameter mean?”). Consider
|
|
|
|
/// grouping some parameters into a new type.
|
2016-03-09 00:48:10 +01:00
|
|
|
///
|
|
|
|
/// **Known problems:** None.
|
|
|
|
///
|
|
|
|
/// **Example:**
|
2016-06-07 16:55:55 +02:00
|
|
|
/// ```rust
|
2018-11-27 21:14:15 +01:00
|
|
|
/// fn foo(x: u32, y: u32, name: &str, c: Color, w: f32, h: f32, a: f32, b: f32) {
|
|
|
|
/// ..
|
|
|
|
/// }
|
2016-03-09 00:48:10 +01:00
|
|
|
/// ```
|
2018-03-28 15:24:26 +02:00
|
|
|
declare_clippy_lint! {
|
2016-03-09 00:48:10 +01:00
|
|
|
pub TOO_MANY_ARGUMENTS,
|
2018-03-29 13:41:53 +02:00
|
|
|
complexity,
|
2016-03-09 00:48:10 +01:00
|
|
|
"functions with too many arguments"
|
|
|
|
}
|
|
|
|
|
2016-08-06 09:55:04 +02:00
|
|
|
/// **What it does:** Checks for public functions that dereferences raw pointer
|
|
|
|
/// arguments but are not marked unsafe.
|
2016-06-07 16:55:55 +02:00
|
|
|
///
|
2016-08-06 09:55:04 +02:00
|
|
|
/// **Why is this bad?** The function should probably be marked `unsafe`, since
|
|
|
|
/// for an arbitrary raw pointer, there is no way of telling for sure if it is
|
|
|
|
/// valid.
|
2016-06-07 16:55:55 +02:00
|
|
|
///
|
|
|
|
/// **Known problems:**
|
|
|
|
///
|
2016-08-06 09:55:04 +02:00
|
|
|
/// * It does not check functions recursively so if the pointer is passed to a
|
2017-08-09 09:30:56 +02:00
|
|
|
/// private non-`unsafe` function which does the dereferencing, the lint won't
|
|
|
|
/// trigger.
|
2016-08-06 09:55:04 +02:00
|
|
|
/// * It only checks for arguments whose type are raw pointers, not raw pointers
|
|
|
|
/// got from an argument in some other way (`fn foo(bar: &[*const u8])` or
|
|
|
|
/// `some_argument.get_raw_ptr()`).
|
2016-06-07 16:55:55 +02:00
|
|
|
///
|
|
|
|
/// **Example:**
|
|
|
|
/// ```rust
|
2018-11-27 21:14:15 +01:00
|
|
|
/// pub fn foo(x: *const u8) {
|
|
|
|
/// println!("{}", unsafe { *x });
|
|
|
|
/// }
|
2016-06-07 16:55:55 +02:00
|
|
|
/// ```
|
2018-03-28 15:24:26 +02:00
|
|
|
declare_clippy_lint! {
|
2016-06-07 16:55:55 +02:00
|
|
|
pub NOT_UNSAFE_PTR_ARG_DEREF,
|
2018-03-28 15:24:26 +02:00
|
|
|
correctness,
|
2016-06-07 16:55:55 +02:00
|
|
|
"public functions dereferencing raw pointer arguments but not marked `unsafe`"
|
|
|
|
}
|
|
|
|
|
2017-08-09 09:30:56 +02:00
|
|
|
#[derive(Copy, Clone)]
|
2016-03-09 00:48:10 +01:00
|
|
|
pub struct Functions {
|
|
|
|
threshold: u64,
|
|
|
|
}
|
|
|
|
|
|
|
|
impl Functions {
|
2017-08-21 13:32:12 +02:00
|
|
|
pub fn new(threshold: u64) -> Self {
|
2018-11-27 21:14:15 +01:00
|
|
|
Self { threshold }
|
2016-03-09 00:48:10 +01:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
impl LintPass for Functions {
|
|
|
|
fn get_lints(&self) -> LintArray {
|
2016-06-07 16:55:55 +02:00
|
|
|
lint_array!(TOO_MANY_ARGUMENTS, NOT_UNSAFE_PTR_ARG_DEREF)
|
2016-03-09 00:48:10 +01:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2016-12-07 13:13:40 +01:00
|
|
|
impl<'a, 'tcx> LateLintPass<'a, 'tcx> for Functions {
|
2016-12-21 10:25:14 +01:00
|
|
|
fn check_fn(
|
2016-12-21 12:14:54 +01:00
|
|
|
&mut self,
|
|
|
|
cx: &LateContext<'a, 'tcx>,
|
|
|
|
kind: intravisit::FnKind<'tcx>,
|
|
|
|
decl: &'tcx hir::FnDecl,
|
2017-01-03 23:40:42 -05:00
|
|
|
body: &'tcx hir::Body,
|
2016-12-21 12:14:54 +01:00
|
|
|
span: Span,
|
2017-08-09 09:30:56 +02:00
|
|
|
nodeid: ast::NodeId,
|
2016-12-21 10:25:14 +01:00
|
|
|
) {
|
2018-12-08 01:56:03 +01:00
|
|
|
let is_impl = if let Some(hir::Node::Item(item)) = cx.tcx.hir().find(cx.tcx.hir().get_parent_node(nodeid)) {
|
2018-07-16 15:07:39 +02:00
|
|
|
matches!(item.node, hir::ItemKind::Impl(_, _, _, _, Some(_), _, _))
|
2016-06-07 16:55:55 +02:00
|
|
|
} else {
|
|
|
|
false
|
|
|
|
};
|
|
|
|
|
|
|
|
let unsafety = match kind {
|
2018-06-24 15:32:40 +02:00
|
|
|
hir::intravisit::FnKind::ItemFn(_, _, hir::FnHeader { unsafety, .. }, _, _) => unsafety,
|
|
|
|
hir::intravisit::FnKind::Method(_, sig, _, _) => sig.header.unsafety,
|
2016-06-07 16:55:55 +02:00
|
|
|
hir::intravisit::FnKind::Closure(_) => return,
|
|
|
|
};
|
|
|
|
|
|
|
|
// don't warn for implementations, it's not their fault
|
|
|
|
if !is_impl {
|
2016-08-08 17:21:47 +02:00
|
|
|
// don't lint extern functions decls, it's not their fault either
|
|
|
|
match kind {
|
2018-11-27 21:14:15 +01:00
|
|
|
hir::intravisit::FnKind::Method(
|
|
|
|
_,
|
|
|
|
&hir::MethodSig {
|
|
|
|
header: hir::FnHeader { abi: Abi::Rust, .. },
|
|
|
|
..
|
|
|
|
},
|
|
|
|
_,
|
|
|
|
_,
|
|
|
|
)
|
|
|
|
| hir::intravisit::FnKind::ItemFn(_, _, hir::FnHeader { abi: Abi::Rust, .. }, _, _) => {
|
|
|
|
self.check_arg_number(cx, decl, span)
|
|
|
|
},
|
2016-08-08 17:21:47 +02:00
|
|
|
_ => {},
|
|
|
|
}
|
2016-03-09 00:48:10 +01:00
|
|
|
}
|
|
|
|
|
2017-01-04 15:48:34 -08:00
|
|
|
self.check_raw_ptr(cx, unsafety, decl, body, nodeid);
|
2016-03-09 00:48:10 +01:00
|
|
|
}
|
|
|
|
|
2016-12-07 13:13:40 +01:00
|
|
|
fn check_trait_item(&mut self, cx: &LateContext<'a, 'tcx>, item: &'tcx hir::TraitItem) {
|
2017-01-04 14:14:22 -08:00
|
|
|
if let hir::TraitItemKind::Method(ref sig, ref eid) = item.node {
|
2016-08-08 17:21:47 +02:00
|
|
|
// don't lint extern functions decls, it's not their fault
|
2018-06-24 15:32:40 +02:00
|
|
|
if sig.header.abi == Abi::Rust {
|
2016-08-08 17:21:47 +02:00
|
|
|
self.check_arg_number(cx, &sig.decl, item.span);
|
|
|
|
}
|
2016-06-07 16:55:55 +02:00
|
|
|
|
2017-01-04 14:14:22 -08:00
|
|
|
if let hir::TraitMethod::Provided(eid) = *eid {
|
2018-12-08 01:56:03 +01:00
|
|
|
let body = cx.tcx.hir().body(eid);
|
2018-06-24 15:32:40 +02:00
|
|
|
self.check_raw_ptr(cx, sig.header.unsafety, &sig.decl, body, item.id);
|
2016-06-07 16:55:55 +02:00
|
|
|
}
|
2016-03-09 00:48:10 +01:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2016-12-07 13:13:40 +01:00
|
|
|
impl<'a, 'tcx> Functions {
|
2018-07-23 13:01:12 +02:00
|
|
|
fn check_arg_number(self, cx: &LateContext<'_, '_>, decl: &hir::FnDecl, span: Span) {
|
2016-03-09 00:48:10 +01:00
|
|
|
let args = decl.inputs.len() as u64;
|
|
|
|
if args > self.threshold {
|
2017-08-09 09:30:56 +02:00
|
|
|
span_lint(
|
|
|
|
cx,
|
|
|
|
TOO_MANY_ARGUMENTS,
|
|
|
|
span,
|
|
|
|
&format!("this function has too many arguments ({}/{})", args, self.threshold),
|
|
|
|
);
|
2016-03-09 00:48:10 +01:00
|
|
|
}
|
|
|
|
}
|
2016-06-07 16:55:55 +02:00
|
|
|
|
2016-12-21 10:25:14 +01:00
|
|
|
fn check_raw_ptr(
|
2018-05-31 20:15:48 +02:00
|
|
|
self,
|
2016-12-21 12:14:54 +01:00
|
|
|
cx: &LateContext<'a, 'tcx>,
|
|
|
|
unsafety: hir::Unsafety,
|
|
|
|
decl: &'tcx hir::FnDecl,
|
2017-01-04 13:46:41 -08:00
|
|
|
body: &'tcx hir::Body,
|
2017-08-09 09:30:56 +02:00
|
|
|
nodeid: ast::NodeId,
|
2016-12-21 10:25:14 +01:00
|
|
|
) {
|
2017-01-04 13:46:41 -08:00
|
|
|
let expr = &body.value;
|
2016-06-07 16:55:55 +02:00
|
|
|
if unsafety == hir::Unsafety::Normal && cx.access_levels.is_exported(nodeid) {
|
2017-01-04 15:53:16 -08:00
|
|
|
let raw_ptrs = iter_input_pats(decl, body)
|
|
|
|
.zip(decl.inputs.iter())
|
|
|
|
.filter_map(|(arg, ty)| raw_ptr_arg(arg, ty))
|
2018-09-12 01:34:52 +02:00
|
|
|
.collect::<FxHashSet<_>>();
|
2016-06-07 16:55:55 +02:00
|
|
|
|
|
|
|
if !raw_ptrs.is_empty() {
|
2017-08-21 12:57:33 +02:00
|
|
|
let tables = cx.tcx.body_tables(body.id());
|
2016-06-07 16:55:55 +02:00
|
|
|
let mut v = DerefVisitor {
|
2018-03-15 16:07:15 +01:00
|
|
|
cx,
|
2016-06-07 16:55:55 +02:00
|
|
|
ptrs: raw_ptrs,
|
2017-08-21 12:57:33 +02:00
|
|
|
tables,
|
2016-06-07 16:55:55 +02:00
|
|
|
};
|
|
|
|
|
2016-11-16 21:57:56 +01:00
|
|
|
hir::intravisit::walk_expr(&mut v, expr);
|
2016-06-07 16:55:55 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2017-09-12 14:26:40 +02:00
|
|
|
fn raw_ptr_arg(arg: &hir::Arg, ty: &hir::Ty) -> Option<ast::NodeId> {
|
2018-07-12 16:03:06 +08:00
|
|
|
if let (&hir::PatKind::Binding(_, id, _, _), &hir::TyKind::Ptr(_)) = (&arg.pat.node, &ty.node) {
|
2017-09-12 14:26:40 +02:00
|
|
|
Some(id)
|
2016-06-07 16:55:55 +02:00
|
|
|
} else {
|
|
|
|
None
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
struct DerefVisitor<'a, 'tcx: 'a> {
|
|
|
|
cx: &'a LateContext<'a, 'tcx>,
|
2018-09-12 01:34:52 +02:00
|
|
|
ptrs: FxHashSet<ast::NodeId>,
|
2017-08-21 12:57:33 +02:00
|
|
|
tables: &'a ty::TypeckTables<'tcx>,
|
2016-06-07 16:55:55 +02:00
|
|
|
}
|
|
|
|
|
2016-12-06 11:32:21 +01:00
|
|
|
impl<'a, 'tcx> hir::intravisit::Visitor<'tcx> for DerefVisitor<'a, 'tcx> {
|
|
|
|
fn visit_expr(&mut self, expr: &'tcx hir::Expr) {
|
2016-06-07 17:29:22 +02:00
|
|
|
match expr.node {
|
2018-07-12 15:30:57 +08:00
|
|
|
hir::ExprKind::Call(ref f, ref args) => {
|
2017-08-21 12:57:33 +02:00
|
|
|
let ty = self.tables.expr_ty(f);
|
2016-06-07 17:29:22 +02:00
|
|
|
|
2017-06-29 21:38:25 +08:00
|
|
|
if type_is_unsafe_function(self.cx, ty) {
|
2016-06-07 17:29:22 +02:00
|
|
|
for arg in args {
|
|
|
|
self.check_arg(arg);
|
|
|
|
}
|
|
|
|
}
|
2016-12-20 18:21:30 +01:00
|
|
|
},
|
2018-07-12 15:30:57 +08:00
|
|
|
hir::ExprKind::MethodCall(_, _, ref args) => {
|
2017-08-21 12:57:33 +02:00
|
|
|
let def_id = self.tables.type_dependent_defs()[expr.hir_id].def_id();
|
2017-06-02 12:13:04 +08:00
|
|
|
let base_type = self.cx.tcx.type_of(def_id);
|
2016-06-07 16:55:55 +02:00
|
|
|
|
2017-06-29 21:38:25 +08:00
|
|
|
if type_is_unsafe_function(self.cx, base_type) {
|
2016-06-07 17:29:22 +02:00
|
|
|
for arg in args {
|
|
|
|
self.check_arg(arg);
|
|
|
|
}
|
2016-06-07 16:55:55 +02:00
|
|
|
}
|
2016-12-20 18:21:30 +01:00
|
|
|
},
|
2018-07-12 15:30:57 +08:00
|
|
|
hir::ExprKind::Unary(hir::UnDeref, ref ptr) => self.check_arg(ptr),
|
2016-06-07 17:29:22 +02:00
|
|
|
_ => (),
|
2016-06-07 16:55:55 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
hir::intravisit::walk_expr(self, expr);
|
|
|
|
}
|
2016-12-06 11:32:21 +01:00
|
|
|
fn nested_visit_map<'this>(&'this mut self) -> intravisit::NestedVisitorMap<'this, 'tcx> {
|
2017-05-12 12:02:42 +02:00
|
|
|
intravisit::NestedVisitorMap::None
|
2016-12-06 11:32:21 +01:00
|
|
|
}
|
2016-03-09 00:48:10 +01:00
|
|
|
}
|
2016-06-07 17:29:22 +02:00
|
|
|
|
|
|
|
impl<'a, 'tcx: 'a> DerefVisitor<'a, 'tcx> {
|
|
|
|
fn check_arg(&self, ptr: &hir::Expr) {
|
2018-07-12 15:30:57 +08:00
|
|
|
if let hir::ExprKind::Path(ref qpath) = ptr.node {
|
2017-09-12 14:26:40 +02:00
|
|
|
if let Def::Local(id) = self.cx.tables.qpath_def(qpath, ptr.hir_id) {
|
|
|
|
if self.ptrs.contains(&id) {
|
|
|
|
span_lint(
|
|
|
|
self.cx,
|
|
|
|
NOT_UNSAFE_PTR_ARG_DEREF,
|
|
|
|
ptr.span,
|
|
|
|
"this public function dereferences a raw pointer but is not marked `unsafe`",
|
|
|
|
);
|
|
|
|
}
|
2016-06-07 17:29:22 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|