1e5dd7070Spatrick //== RetainSummaryManager.cpp - Summaries for reference counting --*- C++ -*--//
2e5dd7070Spatrick //
3e5dd7070Spatrick // Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
4e5dd7070Spatrick // See https://llvm.org/LICENSE.txt for license information.
5e5dd7070Spatrick // SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
6e5dd7070Spatrick //
7e5dd7070Spatrick //===----------------------------------------------------------------------===//
8e5dd7070Spatrick //
9e5dd7070Spatrick //  This file defines summaries implementation for retain counting, which
10e5dd7070Spatrick //  implements a reference count checker for Core Foundation, Cocoa
11e5dd7070Spatrick //  and OSObject (on Mac OS X).
12e5dd7070Spatrick //
13e5dd7070Spatrick //===----------------------------------------------------------------------===//
14e5dd7070Spatrick 
15e5dd7070Spatrick #include "clang/Analysis/DomainSpecific/CocoaConventions.h"
16e5dd7070Spatrick #include "clang/Analysis/RetainSummaryManager.h"
17e5dd7070Spatrick #include "clang/AST/Attr.h"
18e5dd7070Spatrick #include "clang/AST/DeclCXX.h"
19e5dd7070Spatrick #include "clang/AST/DeclObjC.h"
20e5dd7070Spatrick #include "clang/AST/ParentMap.h"
21e5dd7070Spatrick #include "clang/ASTMatchers/ASTMatchFinder.h"
22*12c85518Srobert #include <optional>
23e5dd7070Spatrick 
24e5dd7070Spatrick using namespace clang;
25e5dd7070Spatrick using namespace ento;
26e5dd7070Spatrick 
27e5dd7070Spatrick template <class T>
isOneOf()28e5dd7070Spatrick constexpr static bool isOneOf() {
29e5dd7070Spatrick   return false;
30e5dd7070Spatrick }
31e5dd7070Spatrick 
32e5dd7070Spatrick /// Helper function to check whether the class is one of the
33e5dd7070Spatrick /// rest of varargs.
34e5dd7070Spatrick template <class T, class P, class... ToCompare>
isOneOf()35e5dd7070Spatrick constexpr static bool isOneOf() {
36*12c85518Srobert   return std::is_same_v<T, P> || isOneOf<T, ToCompare...>();
37e5dd7070Spatrick }
38e5dd7070Spatrick 
39e5dd7070Spatrick namespace {
40e5dd7070Spatrick 
41e5dd7070Spatrick /// Fake attribute class for RC* attributes.
42e5dd7070Spatrick struct GeneralizedReturnsRetainedAttr {
classof__anon780979460111::GeneralizedReturnsRetainedAttr43e5dd7070Spatrick   static bool classof(const Attr *A) {
44e5dd7070Spatrick     if (auto AA = dyn_cast<AnnotateAttr>(A))
45e5dd7070Spatrick       return AA->getAnnotation() == "rc_ownership_returns_retained";
46e5dd7070Spatrick     return false;
47e5dd7070Spatrick   }
48e5dd7070Spatrick };
49e5dd7070Spatrick 
50e5dd7070Spatrick struct GeneralizedReturnsNotRetainedAttr {
classof__anon780979460111::GeneralizedReturnsNotRetainedAttr51e5dd7070Spatrick   static bool classof(const Attr *A) {
52e5dd7070Spatrick     if (auto AA = dyn_cast<AnnotateAttr>(A))
53e5dd7070Spatrick       return AA->getAnnotation() == "rc_ownership_returns_not_retained";
54e5dd7070Spatrick     return false;
55e5dd7070Spatrick   }
56e5dd7070Spatrick };
57e5dd7070Spatrick 
58e5dd7070Spatrick struct GeneralizedConsumedAttr {
classof__anon780979460111::GeneralizedConsumedAttr59e5dd7070Spatrick   static bool classof(const Attr *A) {
60e5dd7070Spatrick     if (auto AA = dyn_cast<AnnotateAttr>(A))
61e5dd7070Spatrick       return AA->getAnnotation() == "rc_ownership_consumed";
62e5dd7070Spatrick     return false;
63e5dd7070Spatrick   }
64e5dd7070Spatrick };
65e5dd7070Spatrick 
66e5dd7070Spatrick }
67e5dd7070Spatrick 
68e5dd7070Spatrick template <class T>
hasAnyEnabledAttrOf(const Decl * D,QualType QT)69*12c85518Srobert std::optional<ObjKind> RetainSummaryManager::hasAnyEnabledAttrOf(const Decl *D,
70e5dd7070Spatrick                                                                  QualType QT) {
71e5dd7070Spatrick   ObjKind K;
72e5dd7070Spatrick   if (isOneOf<T, CFConsumedAttr, CFReturnsRetainedAttr,
73e5dd7070Spatrick               CFReturnsNotRetainedAttr>()) {
74e5dd7070Spatrick     if (!TrackObjCAndCFObjects)
75*12c85518Srobert       return std::nullopt;
76e5dd7070Spatrick 
77e5dd7070Spatrick     K = ObjKind::CF;
78e5dd7070Spatrick   } else if (isOneOf<T, NSConsumedAttr, NSConsumesSelfAttr,
79e5dd7070Spatrick                      NSReturnsAutoreleasedAttr, NSReturnsRetainedAttr,
80e5dd7070Spatrick                      NSReturnsNotRetainedAttr, NSConsumesSelfAttr>()) {
81e5dd7070Spatrick 
82e5dd7070Spatrick     if (!TrackObjCAndCFObjects)
83*12c85518Srobert       return std::nullopt;
84e5dd7070Spatrick 
85e5dd7070Spatrick     if (isOneOf<T, NSReturnsRetainedAttr, NSReturnsAutoreleasedAttr,
86e5dd7070Spatrick                 NSReturnsNotRetainedAttr>() &&
87e5dd7070Spatrick         !cocoa::isCocoaObjectRef(QT))
88*12c85518Srobert       return std::nullopt;
89e5dd7070Spatrick     K = ObjKind::ObjC;
90e5dd7070Spatrick   } else if (isOneOf<T, OSConsumedAttr, OSConsumesThisAttr,
91e5dd7070Spatrick                      OSReturnsNotRetainedAttr, OSReturnsRetainedAttr,
92e5dd7070Spatrick                      OSReturnsRetainedOnZeroAttr,
93e5dd7070Spatrick                      OSReturnsRetainedOnNonZeroAttr>()) {
94e5dd7070Spatrick     if (!TrackOSObjects)
95*12c85518Srobert       return std::nullopt;
96e5dd7070Spatrick     K = ObjKind::OS;
97e5dd7070Spatrick   } else if (isOneOf<T, GeneralizedReturnsNotRetainedAttr,
98e5dd7070Spatrick                      GeneralizedReturnsRetainedAttr,
99e5dd7070Spatrick                      GeneralizedConsumedAttr>()) {
100e5dd7070Spatrick     K = ObjKind::Generalized;
101e5dd7070Spatrick   } else {
102e5dd7070Spatrick     llvm_unreachable("Unexpected attribute");
103e5dd7070Spatrick   }
104e5dd7070Spatrick   if (D->hasAttr<T>())
105e5dd7070Spatrick     return K;
106*12c85518Srobert   return std::nullopt;
107e5dd7070Spatrick }
108e5dd7070Spatrick 
109e5dd7070Spatrick template <class T1, class T2, class... Others>
hasAnyEnabledAttrOf(const Decl * D,QualType QT)110*12c85518Srobert std::optional<ObjKind> RetainSummaryManager::hasAnyEnabledAttrOf(const Decl *D,
111e5dd7070Spatrick                                                                  QualType QT) {
112e5dd7070Spatrick   if (auto Out = hasAnyEnabledAttrOf<T1>(D, QT))
113e5dd7070Spatrick     return Out;
114e5dd7070Spatrick   return hasAnyEnabledAttrOf<T2, Others...>(D, QT);
115e5dd7070Spatrick }
116e5dd7070Spatrick 
117e5dd7070Spatrick const RetainSummary *
getPersistentSummary(const RetainSummary & OldSumm)118e5dd7070Spatrick RetainSummaryManager::getPersistentSummary(const RetainSummary &OldSumm) {
119e5dd7070Spatrick   // Unique "simple" summaries -- those without ArgEffects.
120e5dd7070Spatrick   if (OldSumm.isSimple()) {
121e5dd7070Spatrick     ::llvm::FoldingSetNodeID ID;
122e5dd7070Spatrick     OldSumm.Profile(ID);
123e5dd7070Spatrick 
124e5dd7070Spatrick     void *Pos;
125e5dd7070Spatrick     CachedSummaryNode *N = SimpleSummaries.FindNodeOrInsertPos(ID, Pos);
126e5dd7070Spatrick 
127e5dd7070Spatrick     if (!N) {
128e5dd7070Spatrick       N = (CachedSummaryNode *) BPAlloc.Allocate<CachedSummaryNode>();
129e5dd7070Spatrick       new (N) CachedSummaryNode(OldSumm);
130e5dd7070Spatrick       SimpleSummaries.InsertNode(N, Pos);
131e5dd7070Spatrick     }
132e5dd7070Spatrick 
133e5dd7070Spatrick     return &N->getValue();
134e5dd7070Spatrick   }
135e5dd7070Spatrick 
136e5dd7070Spatrick   RetainSummary *Summ = (RetainSummary *) BPAlloc.Allocate<RetainSummary>();
137e5dd7070Spatrick   new (Summ) RetainSummary(OldSumm);
138e5dd7070Spatrick   return Summ;
139e5dd7070Spatrick }
140e5dd7070Spatrick 
isSubclass(const Decl * D,StringRef ClassName)141e5dd7070Spatrick static bool isSubclass(const Decl *D,
142e5dd7070Spatrick                        StringRef ClassName) {
143e5dd7070Spatrick   using namespace ast_matchers;
144ec727ea7Spatrick   DeclarationMatcher SubclassM =
145ec727ea7Spatrick       cxxRecordDecl(isSameOrDerivedFrom(std::string(ClassName)));
146e5dd7070Spatrick   return !(match(SubclassM, *D, D->getASTContext()).empty());
147e5dd7070Spatrick }
148e5dd7070Spatrick 
isExactClass(const Decl * D,StringRef ClassName)149a9ac8606Spatrick static bool isExactClass(const Decl *D, StringRef ClassName) {
150a9ac8606Spatrick   using namespace ast_matchers;
151a9ac8606Spatrick   DeclarationMatcher sameClassM =
152a9ac8606Spatrick       cxxRecordDecl(hasName(std::string(ClassName)));
153a9ac8606Spatrick   return !(match(sameClassM, *D, D->getASTContext()).empty());
154e5dd7070Spatrick }
155e5dd7070Spatrick 
isOSObjectSubclass(const Decl * D)156a9ac8606Spatrick static bool isOSObjectSubclass(const Decl *D) {
157a9ac8606Spatrick   return D && isSubclass(D, "OSMetaClassBase") &&
158a9ac8606Spatrick          !isExactClass(D, "OSMetaClass");
159e5dd7070Spatrick }
160e5dd7070Spatrick 
isOSObjectDynamicCast(StringRef S)161a9ac8606Spatrick static bool isOSObjectDynamicCast(StringRef S) { return S == "safeMetaCast"; }
162a9ac8606Spatrick 
isOSObjectRequiredCast(StringRef S)163e5dd7070Spatrick static bool isOSObjectRequiredCast(StringRef S) {
164e5dd7070Spatrick   return S == "requiredMetaCast";
165e5dd7070Spatrick }
166e5dd7070Spatrick 
isOSObjectThisCast(StringRef S)167e5dd7070Spatrick static bool isOSObjectThisCast(StringRef S) {
168e5dd7070Spatrick   return S == "metaCast";
169e5dd7070Spatrick }
170e5dd7070Spatrick 
171e5dd7070Spatrick 
isOSObjectPtr(QualType QT)172e5dd7070Spatrick static bool isOSObjectPtr(QualType QT) {
173e5dd7070Spatrick   return isOSObjectSubclass(QT->getPointeeCXXRecordDecl());
174e5dd7070Spatrick }
175e5dd7070Spatrick 
isISLObjectRef(QualType Ty)176e5dd7070Spatrick static bool isISLObjectRef(QualType Ty) {
177e5dd7070Spatrick   return StringRef(Ty.getAsString()).startswith("isl_");
178e5dd7070Spatrick }
179e5dd7070Spatrick 
isOSIteratorSubclass(const Decl * D)180e5dd7070Spatrick static bool isOSIteratorSubclass(const Decl *D) {
181e5dd7070Spatrick   return isSubclass(D, "OSIterator");
182e5dd7070Spatrick }
183e5dd7070Spatrick 
hasRCAnnotation(const Decl * D,StringRef rcAnnotation)184e5dd7070Spatrick static bool hasRCAnnotation(const Decl *D, StringRef rcAnnotation) {
185e5dd7070Spatrick   for (const auto *Ann : D->specific_attrs<AnnotateAttr>()) {
186e5dd7070Spatrick     if (Ann->getAnnotation() == rcAnnotation)
187e5dd7070Spatrick       return true;
188e5dd7070Spatrick   }
189e5dd7070Spatrick   return false;
190e5dd7070Spatrick }
191e5dd7070Spatrick 
isRetain(const FunctionDecl * FD,StringRef FName)192e5dd7070Spatrick static bool isRetain(const FunctionDecl *FD, StringRef FName) {
193a9ac8606Spatrick   return FName.startswith_insensitive("retain") ||
194a9ac8606Spatrick          FName.endswith_insensitive("retain");
195e5dd7070Spatrick }
196e5dd7070Spatrick 
isRelease(const FunctionDecl * FD,StringRef FName)197e5dd7070Spatrick static bool isRelease(const FunctionDecl *FD, StringRef FName) {
198a9ac8606Spatrick   return FName.startswith_insensitive("release") ||
199a9ac8606Spatrick          FName.endswith_insensitive("release");
200e5dd7070Spatrick }
201e5dd7070Spatrick 
isAutorelease(const FunctionDecl * FD,StringRef FName)202e5dd7070Spatrick static bool isAutorelease(const FunctionDecl *FD, StringRef FName) {
203a9ac8606Spatrick   return FName.startswith_insensitive("autorelease") ||
204a9ac8606Spatrick          FName.endswith_insensitive("autorelease");
205e5dd7070Spatrick }
206e5dd7070Spatrick 
isMakeCollectable(StringRef FName)207e5dd7070Spatrick static bool isMakeCollectable(StringRef FName) {
208a9ac8606Spatrick   return FName.contains_insensitive("MakeCollectable");
209e5dd7070Spatrick }
210e5dd7070Spatrick 
211e5dd7070Spatrick /// A function is OSObject related if it is declared on a subclass
212e5dd7070Spatrick /// of OSObject, or any of the parameters is a subclass of an OSObject.
isOSObjectRelated(const CXXMethodDecl * MD)213e5dd7070Spatrick static bool isOSObjectRelated(const CXXMethodDecl *MD) {
214e5dd7070Spatrick   if (isOSObjectSubclass(MD->getParent()))
215e5dd7070Spatrick     return true;
216e5dd7070Spatrick 
217e5dd7070Spatrick   for (ParmVarDecl *Param : MD->parameters()) {
218e5dd7070Spatrick     QualType PT = Param->getType()->getPointeeType();
219e5dd7070Spatrick     if (!PT.isNull())
220e5dd7070Spatrick       if (CXXRecordDecl *RD = PT->getAsCXXRecordDecl())
221e5dd7070Spatrick         if (isOSObjectSubclass(RD))
222e5dd7070Spatrick           return true;
223e5dd7070Spatrick   }
224e5dd7070Spatrick 
225e5dd7070Spatrick   return false;
226e5dd7070Spatrick }
227e5dd7070Spatrick 
228e5dd7070Spatrick bool
isKnownSmartPointer(QualType QT)229e5dd7070Spatrick RetainSummaryManager::isKnownSmartPointer(QualType QT) {
230e5dd7070Spatrick   QT = QT.getCanonicalType();
231e5dd7070Spatrick   const auto *RD = QT->getAsCXXRecordDecl();
232e5dd7070Spatrick   if (!RD)
233e5dd7070Spatrick     return false;
234e5dd7070Spatrick   const IdentifierInfo *II = RD->getIdentifier();
235e5dd7070Spatrick   if (II && II->getName() == "smart_ptr")
236e5dd7070Spatrick     if (const auto *ND = dyn_cast<NamespaceDecl>(RD->getDeclContext()))
237e5dd7070Spatrick       if (ND->getNameAsString() == "os")
238e5dd7070Spatrick         return true;
239e5dd7070Spatrick   return false;
240e5dd7070Spatrick }
241e5dd7070Spatrick 
242e5dd7070Spatrick const RetainSummary *
getSummaryForOSObject(const FunctionDecl * FD,StringRef FName,QualType RetTy)243e5dd7070Spatrick RetainSummaryManager::getSummaryForOSObject(const FunctionDecl *FD,
244e5dd7070Spatrick                                             StringRef FName, QualType RetTy) {
245e5dd7070Spatrick   assert(TrackOSObjects &&
246e5dd7070Spatrick          "Requesting a summary for an OSObject but OSObjects are not tracked");
247e5dd7070Spatrick 
248e5dd7070Spatrick   if (RetTy->isPointerType()) {
249e5dd7070Spatrick     const CXXRecordDecl *PD = RetTy->getPointeeType()->getAsCXXRecordDecl();
250e5dd7070Spatrick     if (PD && isOSObjectSubclass(PD)) {
251e5dd7070Spatrick       if (isOSObjectDynamicCast(FName) || isOSObjectRequiredCast(FName) ||
252e5dd7070Spatrick           isOSObjectThisCast(FName))
253e5dd7070Spatrick         return getDefaultSummary();
254e5dd7070Spatrick 
255e5dd7070Spatrick       // TODO: Add support for the slightly common *Matching(table) idiom.
256e5dd7070Spatrick       // Cf. IOService::nameMatching() etc. - these function have an unusual
257e5dd7070Spatrick       // contract of returning at +0 or +1 depending on their last argument.
258e5dd7070Spatrick       if (FName.endswith("Matching")) {
259e5dd7070Spatrick         return getPersistentStopSummary();
260e5dd7070Spatrick       }
261e5dd7070Spatrick 
262e5dd7070Spatrick       // All objects returned with functions *not* starting with 'get',
263e5dd7070Spatrick       // or iterators, are returned at +1.
264e5dd7070Spatrick       if ((!FName.startswith("get") && !FName.startswith("Get")) ||
265e5dd7070Spatrick           isOSIteratorSubclass(PD)) {
266e5dd7070Spatrick         return getOSSummaryCreateRule(FD);
267e5dd7070Spatrick       } else {
268e5dd7070Spatrick         return getOSSummaryGetRule(FD);
269e5dd7070Spatrick       }
270e5dd7070Spatrick     }
271e5dd7070Spatrick   }
272e5dd7070Spatrick 
273e5dd7070Spatrick   if (const auto *MD = dyn_cast<CXXMethodDecl>(FD)) {
274e5dd7070Spatrick     const CXXRecordDecl *Parent = MD->getParent();
275e5dd7070Spatrick     if (Parent && isOSObjectSubclass(Parent)) {
276e5dd7070Spatrick       if (FName == "release" || FName == "taggedRelease")
277e5dd7070Spatrick         return getOSSummaryReleaseRule(FD);
278e5dd7070Spatrick 
279e5dd7070Spatrick       if (FName == "retain" || FName == "taggedRetain")
280e5dd7070Spatrick         return getOSSummaryRetainRule(FD);
281e5dd7070Spatrick 
282e5dd7070Spatrick       if (FName == "free")
283e5dd7070Spatrick         return getOSSummaryFreeRule(FD);
284e5dd7070Spatrick 
285e5dd7070Spatrick       if (MD->getOverloadedOperator() == OO_New)
286e5dd7070Spatrick         return getOSSummaryCreateRule(MD);
287e5dd7070Spatrick     }
288e5dd7070Spatrick   }
289e5dd7070Spatrick 
290e5dd7070Spatrick   return nullptr;
291e5dd7070Spatrick }
292e5dd7070Spatrick 
getSummaryForObjCOrCFObject(const FunctionDecl * FD,StringRef FName,QualType RetTy,const FunctionType * FT,bool & AllowAnnotations)293e5dd7070Spatrick const RetainSummary *RetainSummaryManager::getSummaryForObjCOrCFObject(
294e5dd7070Spatrick     const FunctionDecl *FD,
295e5dd7070Spatrick     StringRef FName,
296e5dd7070Spatrick     QualType RetTy,
297e5dd7070Spatrick     const FunctionType *FT,
298e5dd7070Spatrick     bool &AllowAnnotations) {
299e5dd7070Spatrick 
300e5dd7070Spatrick   ArgEffects ScratchArgs(AF.getEmptyMap());
301e5dd7070Spatrick 
302e5dd7070Spatrick   std::string RetTyName = RetTy.getAsString();
303e5dd7070Spatrick   if (FName == "pthread_create" || FName == "pthread_setspecific") {
304e5dd7070Spatrick     // Part of: <rdar://problem/7299394> and <rdar://problem/11282706>.
305e5dd7070Spatrick     // This will be addressed better with IPA.
306e5dd7070Spatrick     return getPersistentStopSummary();
307e5dd7070Spatrick   } else if(FName == "NSMakeCollectable") {
308e5dd7070Spatrick     // Handle: id NSMakeCollectable(CFTypeRef)
309e5dd7070Spatrick     AllowAnnotations = false;
310e5dd7070Spatrick     return RetTy->isObjCIdType() ? getUnarySummary(FT, DoNothing)
311e5dd7070Spatrick                                  : getPersistentStopSummary();
312e5dd7070Spatrick   } else if (FName == "CMBufferQueueDequeueAndRetain" ||
313e5dd7070Spatrick              FName == "CMBufferQueueDequeueIfDataReadyAndRetain") {
314e5dd7070Spatrick     // Part of: <rdar://problem/39390714>.
315e5dd7070Spatrick     return getPersistentSummary(RetEffect::MakeOwned(ObjKind::CF),
316e5dd7070Spatrick                                 ScratchArgs,
317e5dd7070Spatrick                                 ArgEffect(DoNothing),
318e5dd7070Spatrick                                 ArgEffect(DoNothing));
319e5dd7070Spatrick   } else if (FName == "CFPlugInInstanceCreate") {
320e5dd7070Spatrick     return getPersistentSummary(RetEffect::MakeNoRet(), ScratchArgs);
321e5dd7070Spatrick   } else if (FName == "IORegistryEntrySearchCFProperty" ||
322e5dd7070Spatrick              (RetTyName == "CFMutableDictionaryRef" &&
323e5dd7070Spatrick               (FName == "IOBSDNameMatching" || FName == "IOServiceMatching" ||
324e5dd7070Spatrick                FName == "IOServiceNameMatching" ||
325e5dd7070Spatrick                FName == "IORegistryEntryIDMatching" ||
326e5dd7070Spatrick                FName == "IOOpenFirmwarePathMatching"))) {
327e5dd7070Spatrick     // Part of <rdar://problem/6961230>. (IOKit)
328e5dd7070Spatrick     // This should be addressed using a API table.
329e5dd7070Spatrick     return getPersistentSummary(RetEffect::MakeOwned(ObjKind::CF), ScratchArgs,
330e5dd7070Spatrick                                 ArgEffect(DoNothing), ArgEffect(DoNothing));
331e5dd7070Spatrick   } else if (FName == "IOServiceGetMatchingService" ||
332e5dd7070Spatrick              FName == "IOServiceGetMatchingServices") {
333e5dd7070Spatrick     // FIXES: <rdar://problem/6326900>
334e5dd7070Spatrick     // This should be addressed using a API table.  This strcmp is also
335e5dd7070Spatrick     // a little gross, but there is no need to super optimize here.
336e5dd7070Spatrick     ScratchArgs = AF.add(ScratchArgs, 1, ArgEffect(DecRef, ObjKind::CF));
337e5dd7070Spatrick     return getPersistentSummary(RetEffect::MakeNoRet(),
338e5dd7070Spatrick                                 ScratchArgs,
339e5dd7070Spatrick                                 ArgEffect(DoNothing), ArgEffect(DoNothing));
340e5dd7070Spatrick   } else if (FName == "IOServiceAddNotification" ||
341e5dd7070Spatrick              FName == "IOServiceAddMatchingNotification") {
342e5dd7070Spatrick     // Part of <rdar://problem/6961230>. (IOKit)
343e5dd7070Spatrick     // This should be addressed using a API table.
344e5dd7070Spatrick     ScratchArgs = AF.add(ScratchArgs, 2, ArgEffect(DecRef, ObjKind::CF));
345e5dd7070Spatrick     return getPersistentSummary(RetEffect::MakeNoRet(),
346e5dd7070Spatrick                                 ScratchArgs,
347e5dd7070Spatrick                                 ArgEffect(DoNothing), ArgEffect(DoNothing));
348e5dd7070Spatrick   } else if (FName == "CVPixelBufferCreateWithBytes") {
349e5dd7070Spatrick     // FIXES: <rdar://problem/7283567>
350e5dd7070Spatrick     // Eventually this can be improved by recognizing that the pixel
351e5dd7070Spatrick     // buffer passed to CVPixelBufferCreateWithBytes is released via
352e5dd7070Spatrick     // a callback and doing full IPA to make sure this is done correctly.
353e5dd7070Spatrick     // FIXME: This function has an out parameter that returns an
354e5dd7070Spatrick     // allocated object.
355e5dd7070Spatrick     ScratchArgs = AF.add(ScratchArgs, 7, ArgEffect(StopTracking));
356e5dd7070Spatrick     return getPersistentSummary(RetEffect::MakeNoRet(),
357e5dd7070Spatrick                                 ScratchArgs,
358e5dd7070Spatrick                                 ArgEffect(DoNothing), ArgEffect(DoNothing));
359e5dd7070Spatrick   } else if (FName == "CGBitmapContextCreateWithData") {
360e5dd7070Spatrick     // FIXES: <rdar://problem/7358899>
361e5dd7070Spatrick     // Eventually this can be improved by recognizing that 'releaseInfo'
362e5dd7070Spatrick     // passed to CGBitmapContextCreateWithData is released via
363e5dd7070Spatrick     // a callback and doing full IPA to make sure this is done correctly.
364e5dd7070Spatrick     ScratchArgs = AF.add(ScratchArgs, 8, ArgEffect(ArgEffect(StopTracking)));
365e5dd7070Spatrick     return getPersistentSummary(RetEffect::MakeOwned(ObjKind::CF), ScratchArgs,
366e5dd7070Spatrick                                 ArgEffect(DoNothing), ArgEffect(DoNothing));
367e5dd7070Spatrick   } else if (FName == "CVPixelBufferCreateWithPlanarBytes") {
368e5dd7070Spatrick     // FIXES: <rdar://problem/7283567>
369e5dd7070Spatrick     // Eventually this can be improved by recognizing that the pixel
370e5dd7070Spatrick     // buffer passed to CVPixelBufferCreateWithPlanarBytes is released
371e5dd7070Spatrick     // via a callback and doing full IPA to make sure this is done
372e5dd7070Spatrick     // correctly.
373e5dd7070Spatrick     ScratchArgs = AF.add(ScratchArgs, 12, ArgEffect(StopTracking));
374e5dd7070Spatrick     return getPersistentSummary(RetEffect::MakeNoRet(),
375e5dd7070Spatrick                                 ScratchArgs,
376e5dd7070Spatrick                                 ArgEffect(DoNothing), ArgEffect(DoNothing));
377e5dd7070Spatrick   } else if (FName == "VTCompressionSessionEncodeFrame") {
378e5dd7070Spatrick     // The context argument passed to VTCompressionSessionEncodeFrame()
379e5dd7070Spatrick     // is passed to the callback specified when creating the session
380e5dd7070Spatrick     // (e.g. with VTCompressionSessionCreate()) which can release it.
381e5dd7070Spatrick     // To account for this possibility, conservatively stop tracking
382e5dd7070Spatrick     // the context.
383e5dd7070Spatrick     ScratchArgs = AF.add(ScratchArgs, 5, ArgEffect(StopTracking));
384e5dd7070Spatrick     return getPersistentSummary(RetEffect::MakeNoRet(),
385e5dd7070Spatrick                                 ScratchArgs,
386e5dd7070Spatrick                                 ArgEffect(DoNothing), ArgEffect(DoNothing));
387e5dd7070Spatrick   } else if (FName == "dispatch_set_context" ||
388e5dd7070Spatrick              FName == "xpc_connection_set_context") {
389e5dd7070Spatrick     // <rdar://problem/11059275> - The analyzer currently doesn't have
390e5dd7070Spatrick     // a good way to reason about the finalizer function for libdispatch.
391e5dd7070Spatrick     // If we pass a context object that is memory managed, stop tracking it.
392e5dd7070Spatrick     // <rdar://problem/13783514> - Same problem, but for XPC.
393e5dd7070Spatrick     // FIXME: this hack should possibly go away once we can handle
394e5dd7070Spatrick     // libdispatch and XPC finalizers.
395e5dd7070Spatrick     ScratchArgs = AF.add(ScratchArgs, 1, ArgEffect(StopTracking));
396e5dd7070Spatrick     return getPersistentSummary(RetEffect::MakeNoRet(),
397e5dd7070Spatrick                                 ScratchArgs,
398e5dd7070Spatrick                                 ArgEffect(DoNothing), ArgEffect(DoNothing));
399e5dd7070Spatrick   } else if (FName.startswith("NSLog")) {
400e5dd7070Spatrick     return getDoNothingSummary();
401*12c85518Srobert   } else if (FName.startswith("NS") && FName.contains("Insert")) {
402*12c85518Srobert     // Allowlist NSXXInsertXX, for example NSMapInsertIfAbsent, since they can
403e5dd7070Spatrick     // be deallocated by NSMapRemove. (radar://11152419)
404e5dd7070Spatrick     ScratchArgs = AF.add(ScratchArgs, 1, ArgEffect(StopTracking));
405e5dd7070Spatrick     ScratchArgs = AF.add(ScratchArgs, 2, ArgEffect(StopTracking));
406e5dd7070Spatrick     return getPersistentSummary(RetEffect::MakeNoRet(),
407e5dd7070Spatrick                                 ScratchArgs, ArgEffect(DoNothing),
408e5dd7070Spatrick                                 ArgEffect(DoNothing));
409e5dd7070Spatrick   }
410e5dd7070Spatrick 
411e5dd7070Spatrick   if (RetTy->isPointerType()) {
412e5dd7070Spatrick 
413e5dd7070Spatrick     // For CoreFoundation ('CF') types.
414e5dd7070Spatrick     if (cocoa::isRefType(RetTy, "CF", FName)) {
415e5dd7070Spatrick       if (isRetain(FD, FName)) {
416e5dd7070Spatrick         // CFRetain isn't supposed to be annotated. However, this may as
417e5dd7070Spatrick         // well be a user-made "safe" CFRetain function that is incorrectly
418e5dd7070Spatrick         // annotated as cf_returns_retained due to lack of better options.
419e5dd7070Spatrick         // We want to ignore such annotation.
420e5dd7070Spatrick         AllowAnnotations = false;
421e5dd7070Spatrick 
422e5dd7070Spatrick         return getUnarySummary(FT, IncRef);
423e5dd7070Spatrick       } else if (isAutorelease(FD, FName)) {
424e5dd7070Spatrick         // The headers use cf_consumed, but we can fully model CFAutorelease
425e5dd7070Spatrick         // ourselves.
426e5dd7070Spatrick         AllowAnnotations = false;
427e5dd7070Spatrick 
428e5dd7070Spatrick         return getUnarySummary(FT, Autorelease);
429e5dd7070Spatrick       } else if (isMakeCollectable(FName)) {
430e5dd7070Spatrick         AllowAnnotations = false;
431e5dd7070Spatrick         return getUnarySummary(FT, DoNothing);
432e5dd7070Spatrick       } else {
433e5dd7070Spatrick         return getCFCreateGetRuleSummary(FD);
434e5dd7070Spatrick       }
435e5dd7070Spatrick     }
436e5dd7070Spatrick 
437e5dd7070Spatrick     // For CoreGraphics ('CG') and CoreVideo ('CV') types.
438e5dd7070Spatrick     if (cocoa::isRefType(RetTy, "CG", FName) ||
439e5dd7070Spatrick         cocoa::isRefType(RetTy, "CV", FName)) {
440e5dd7070Spatrick       if (isRetain(FD, FName))
441e5dd7070Spatrick         return getUnarySummary(FT, IncRef);
442e5dd7070Spatrick       else
443e5dd7070Spatrick         return getCFCreateGetRuleSummary(FD);
444e5dd7070Spatrick     }
445e5dd7070Spatrick 
446e5dd7070Spatrick     // For all other CF-style types, use the Create/Get
447e5dd7070Spatrick     // rule for summaries but don't support Retain functions
448e5dd7070Spatrick     // with framework-specific prefixes.
449e5dd7070Spatrick     if (coreFoundation::isCFObjectRef(RetTy)) {
450e5dd7070Spatrick       return getCFCreateGetRuleSummary(FD);
451e5dd7070Spatrick     }
452e5dd7070Spatrick 
453e5dd7070Spatrick     if (FD->hasAttr<CFAuditedTransferAttr>()) {
454e5dd7070Spatrick       return getCFCreateGetRuleSummary(FD);
455e5dd7070Spatrick     }
456e5dd7070Spatrick   }
457e5dd7070Spatrick 
458e5dd7070Spatrick   // Check for release functions, the only kind of functions that we care
459e5dd7070Spatrick   // about that don't return a pointer type.
460e5dd7070Spatrick   if (FName.startswith("CG") || FName.startswith("CF")) {
461e5dd7070Spatrick     // Test for 'CGCF'.
462e5dd7070Spatrick     FName = FName.substr(FName.startswith("CGCF") ? 4 : 2);
463e5dd7070Spatrick 
464e5dd7070Spatrick     if (isRelease(FD, FName))
465e5dd7070Spatrick       return getUnarySummary(FT, DecRef);
466e5dd7070Spatrick     else {
467e5dd7070Spatrick       assert(ScratchArgs.isEmpty());
468e5dd7070Spatrick       // Remaining CoreFoundation and CoreGraphics functions.
469e5dd7070Spatrick       // We use to assume that they all strictly followed the ownership idiom
470e5dd7070Spatrick       // and that ownership cannot be transferred.  While this is technically
471e5dd7070Spatrick       // correct, many methods allow a tracked object to escape.  For example:
472e5dd7070Spatrick       //
473e5dd7070Spatrick       //   CFMutableDictionaryRef x = CFDictionaryCreateMutable(...);
474e5dd7070Spatrick       //   CFDictionaryAddValue(y, key, x);
475e5dd7070Spatrick       //   CFRelease(x);
476e5dd7070Spatrick       //   ... it is okay to use 'x' since 'y' has a reference to it
477e5dd7070Spatrick       //
478e5dd7070Spatrick       // We handle this and similar cases with the follow heuristic.  If the
479e5dd7070Spatrick       // function name contains "InsertValue", "SetValue", "AddValue",
480e5dd7070Spatrick       // "AppendValue", or "SetAttribute", then we assume that arguments may
481e5dd7070Spatrick       // "escape."  This means that something else holds on to the object,
482e5dd7070Spatrick       // allowing it be used even after its local retain count drops to 0.
483e5dd7070Spatrick       ArgEffectKind E =
484e5dd7070Spatrick           (StrInStrNoCase(FName, "InsertValue") != StringRef::npos ||
485e5dd7070Spatrick            StrInStrNoCase(FName, "AddValue") != StringRef::npos ||
486e5dd7070Spatrick            StrInStrNoCase(FName, "SetValue") != StringRef::npos ||
487e5dd7070Spatrick            StrInStrNoCase(FName, "AppendValue") != StringRef::npos ||
488e5dd7070Spatrick            StrInStrNoCase(FName, "SetAttribute") != StringRef::npos)
489e5dd7070Spatrick               ? MayEscape
490e5dd7070Spatrick               : DoNothing;
491e5dd7070Spatrick 
492e5dd7070Spatrick       return getPersistentSummary(RetEffect::MakeNoRet(), ScratchArgs,
493e5dd7070Spatrick                                   ArgEffect(DoNothing), ArgEffect(E, ObjKind::CF));
494e5dd7070Spatrick     }
495e5dd7070Spatrick   }
496e5dd7070Spatrick 
497e5dd7070Spatrick   return nullptr;
498e5dd7070Spatrick }
499e5dd7070Spatrick 
500e5dd7070Spatrick const RetainSummary *
generateSummary(const FunctionDecl * FD,bool & AllowAnnotations)501e5dd7070Spatrick RetainSummaryManager::generateSummary(const FunctionDecl *FD,
502e5dd7070Spatrick                                       bool &AllowAnnotations) {
503e5dd7070Spatrick   // We generate "stop" summaries for implicitly defined functions.
504e5dd7070Spatrick   if (FD->isImplicit())
505e5dd7070Spatrick     return getPersistentStopSummary();
506e5dd7070Spatrick 
507e5dd7070Spatrick   const IdentifierInfo *II = FD->getIdentifier();
508e5dd7070Spatrick 
509e5dd7070Spatrick   StringRef FName = II ? II->getName() : "";
510e5dd7070Spatrick 
511e5dd7070Spatrick   // Strip away preceding '_'.  Doing this here will effect all the checks
512e5dd7070Spatrick   // down below.
513e5dd7070Spatrick   FName = FName.substr(FName.find_first_not_of('_'));
514e5dd7070Spatrick 
515e5dd7070Spatrick   // Inspect the result type. Strip away any typedefs.
516e5dd7070Spatrick   const auto *FT = FD->getType()->castAs<FunctionType>();
517e5dd7070Spatrick   QualType RetTy = FT->getReturnType();
518e5dd7070Spatrick 
519e5dd7070Spatrick   if (TrackOSObjects)
520e5dd7070Spatrick     if (const RetainSummary *S = getSummaryForOSObject(FD, FName, RetTy))
521e5dd7070Spatrick       return S;
522e5dd7070Spatrick 
523e5dd7070Spatrick   if (const auto *MD = dyn_cast<CXXMethodDecl>(FD))
524e5dd7070Spatrick     if (!isOSObjectRelated(MD))
525e5dd7070Spatrick       return getPersistentSummary(RetEffect::MakeNoRet(),
526e5dd7070Spatrick                                   ArgEffects(AF.getEmptyMap()),
527e5dd7070Spatrick                                   ArgEffect(DoNothing),
528e5dd7070Spatrick                                   ArgEffect(StopTracking),
529e5dd7070Spatrick                                   ArgEffect(DoNothing));
530e5dd7070Spatrick 
531e5dd7070Spatrick   if (TrackObjCAndCFObjects)
532e5dd7070Spatrick     if (const RetainSummary *S =
533e5dd7070Spatrick             getSummaryForObjCOrCFObject(FD, FName, RetTy, FT, AllowAnnotations))
534e5dd7070Spatrick       return S;
535e5dd7070Spatrick 
536e5dd7070Spatrick   return getDefaultSummary();
537e5dd7070Spatrick }
538e5dd7070Spatrick 
539e5dd7070Spatrick const RetainSummary *
getFunctionSummary(const FunctionDecl * FD)540e5dd7070Spatrick RetainSummaryManager::getFunctionSummary(const FunctionDecl *FD) {
541e5dd7070Spatrick   // If we don't know what function we're calling, use our default summary.
542e5dd7070Spatrick   if (!FD)
543e5dd7070Spatrick     return getDefaultSummary();
544e5dd7070Spatrick 
545e5dd7070Spatrick   // Look up a summary in our cache of FunctionDecls -> Summaries.
546e5dd7070Spatrick   FuncSummariesTy::iterator I = FuncSummaries.find(FD);
547e5dd7070Spatrick   if (I != FuncSummaries.end())
548e5dd7070Spatrick     return I->second;
549e5dd7070Spatrick 
550e5dd7070Spatrick   // No summary?  Generate one.
551e5dd7070Spatrick   bool AllowAnnotations = true;
552e5dd7070Spatrick   const RetainSummary *S = generateSummary(FD, AllowAnnotations);
553e5dd7070Spatrick 
554e5dd7070Spatrick   // Annotations override defaults.
555e5dd7070Spatrick   if (AllowAnnotations)
556e5dd7070Spatrick     updateSummaryFromAnnotations(S, FD);
557e5dd7070Spatrick 
558e5dd7070Spatrick   FuncSummaries[FD] = S;
559e5dd7070Spatrick   return S;
560e5dd7070Spatrick }
561e5dd7070Spatrick 
562e5dd7070Spatrick //===----------------------------------------------------------------------===//
563e5dd7070Spatrick // Summary creation for functions (largely uses of Core Foundation).
564e5dd7070Spatrick //===----------------------------------------------------------------------===//
565e5dd7070Spatrick 
getStopTrackingHardEquivalent(ArgEffect E)566e5dd7070Spatrick static ArgEffect getStopTrackingHardEquivalent(ArgEffect E) {
567e5dd7070Spatrick   switch (E.getKind()) {
568e5dd7070Spatrick   case DoNothing:
569e5dd7070Spatrick   case Autorelease:
570e5dd7070Spatrick   case DecRefBridgedTransferred:
571e5dd7070Spatrick   case IncRef:
572e5dd7070Spatrick   case UnretainedOutParameter:
573e5dd7070Spatrick   case RetainedOutParameter:
574e5dd7070Spatrick   case RetainedOutParameterOnZero:
575e5dd7070Spatrick   case RetainedOutParameterOnNonZero:
576e5dd7070Spatrick   case MayEscape:
577e5dd7070Spatrick   case StopTracking:
578e5dd7070Spatrick   case StopTrackingHard:
579e5dd7070Spatrick     return E.withKind(StopTrackingHard);
580e5dd7070Spatrick   case DecRef:
581e5dd7070Spatrick   case DecRefAndStopTrackingHard:
582e5dd7070Spatrick     return E.withKind(DecRefAndStopTrackingHard);
583e5dd7070Spatrick   case Dealloc:
584e5dd7070Spatrick     return E.withKind(Dealloc);
585e5dd7070Spatrick   }
586e5dd7070Spatrick 
587e5dd7070Spatrick   llvm_unreachable("Unknown ArgEffect kind");
588e5dd7070Spatrick }
589e5dd7070Spatrick 
590e5dd7070Spatrick const RetainSummary *
updateSummaryForNonZeroCallbackArg(const RetainSummary * S,AnyCall & C)591e5dd7070Spatrick RetainSummaryManager::updateSummaryForNonZeroCallbackArg(const RetainSummary *S,
592e5dd7070Spatrick                                                          AnyCall &C) {
593e5dd7070Spatrick   ArgEffect RecEffect = getStopTrackingHardEquivalent(S->getReceiverEffect());
594e5dd7070Spatrick   ArgEffect DefEffect = getStopTrackingHardEquivalent(S->getDefaultArgEffect());
595e5dd7070Spatrick 
596e5dd7070Spatrick   ArgEffects ScratchArgs(AF.getEmptyMap());
597e5dd7070Spatrick   ArgEffects CustomArgEffects = S->getArgEffects();
598e5dd7070Spatrick   for (ArgEffects::iterator I = CustomArgEffects.begin(),
599e5dd7070Spatrick                             E = CustomArgEffects.end();
600e5dd7070Spatrick        I != E; ++I) {
601e5dd7070Spatrick     ArgEffect Translated = getStopTrackingHardEquivalent(I->second);
602e5dd7070Spatrick     if (Translated.getKind() != DefEffect.getKind())
603e5dd7070Spatrick       ScratchArgs = AF.add(ScratchArgs, I->first, Translated);
604e5dd7070Spatrick   }
605e5dd7070Spatrick 
606e5dd7070Spatrick   RetEffect RE = RetEffect::MakeNoRetHard();
607e5dd7070Spatrick 
608e5dd7070Spatrick   // Special cases where the callback argument CANNOT free the return value.
609e5dd7070Spatrick   // This can generally only happen if we know that the callback will only be
610e5dd7070Spatrick   // called when the return value is already being deallocated.
611e5dd7070Spatrick   if (const IdentifierInfo *Name = C.getIdentifier()) {
612e5dd7070Spatrick     // When the CGBitmapContext is deallocated, the callback here will free
613e5dd7070Spatrick     // the associated data buffer.
614e5dd7070Spatrick     // The callback in dispatch_data_create frees the buffer, but not
615e5dd7070Spatrick     // the data object.
616e5dd7070Spatrick     if (Name->isStr("CGBitmapContextCreateWithData") ||
617e5dd7070Spatrick         Name->isStr("dispatch_data_create"))
618e5dd7070Spatrick       RE = S->getRetEffect();
619e5dd7070Spatrick   }
620e5dd7070Spatrick 
621e5dd7070Spatrick   return getPersistentSummary(RE, ScratchArgs, RecEffect, DefEffect);
622e5dd7070Spatrick }
623e5dd7070Spatrick 
updateSummaryForReceiverUnconsumedSelf(const RetainSummary * & S)624e5dd7070Spatrick void RetainSummaryManager::updateSummaryForReceiverUnconsumedSelf(
625e5dd7070Spatrick     const RetainSummary *&S) {
626e5dd7070Spatrick 
627e5dd7070Spatrick   RetainSummaryTemplate Template(S, *this);
628e5dd7070Spatrick 
629e5dd7070Spatrick   Template->setReceiverEffect(ArgEffect(DoNothing));
630e5dd7070Spatrick   Template->setRetEffect(RetEffect::MakeNoRet());
631e5dd7070Spatrick }
632e5dd7070Spatrick 
633e5dd7070Spatrick 
updateSummaryForArgumentTypes(const AnyCall & C,const RetainSummary * & RS)634e5dd7070Spatrick void RetainSummaryManager::updateSummaryForArgumentTypes(
635e5dd7070Spatrick   const AnyCall &C, const RetainSummary *&RS) {
636e5dd7070Spatrick   RetainSummaryTemplate Template(RS, *this);
637e5dd7070Spatrick 
638e5dd7070Spatrick   unsigned parm_idx = 0;
639e5dd7070Spatrick   for (auto pi = C.param_begin(), pe = C.param_end(); pi != pe;
640e5dd7070Spatrick        ++pi, ++parm_idx) {
641e5dd7070Spatrick     QualType QT = (*pi)->getType();
642e5dd7070Spatrick 
643e5dd7070Spatrick     // Skip already created values.
644e5dd7070Spatrick     if (RS->getArgEffects().contains(parm_idx))
645e5dd7070Spatrick       continue;
646e5dd7070Spatrick 
647e5dd7070Spatrick     ObjKind K = ObjKind::AnyObj;
648e5dd7070Spatrick 
649e5dd7070Spatrick     if (isISLObjectRef(QT)) {
650e5dd7070Spatrick       K = ObjKind::Generalized;
651e5dd7070Spatrick     } else if (isOSObjectPtr(QT)) {
652e5dd7070Spatrick       K = ObjKind::OS;
653e5dd7070Spatrick     } else if (cocoa::isCocoaObjectRef(QT)) {
654e5dd7070Spatrick       K = ObjKind::ObjC;
655e5dd7070Spatrick     } else if (coreFoundation::isCFObjectRef(QT)) {
656e5dd7070Spatrick       K = ObjKind::CF;
657e5dd7070Spatrick     }
658e5dd7070Spatrick 
659e5dd7070Spatrick     if (K != ObjKind::AnyObj)
660e5dd7070Spatrick       Template->addArg(AF, parm_idx,
661e5dd7070Spatrick                        ArgEffect(RS->getDefaultArgEffect().getKind(), K));
662e5dd7070Spatrick   }
663e5dd7070Spatrick }
664e5dd7070Spatrick 
665e5dd7070Spatrick const RetainSummary *
getSummary(AnyCall C,bool HasNonZeroCallbackArg,bool IsReceiverUnconsumedSelf,QualType ReceiverType)666e5dd7070Spatrick RetainSummaryManager::getSummary(AnyCall C,
667e5dd7070Spatrick                                  bool HasNonZeroCallbackArg,
668e5dd7070Spatrick                                  bool IsReceiverUnconsumedSelf,
669e5dd7070Spatrick                                  QualType ReceiverType) {
670e5dd7070Spatrick   const RetainSummary *Summ;
671e5dd7070Spatrick   switch (C.getKind()) {
672e5dd7070Spatrick   case AnyCall::Function:
673e5dd7070Spatrick   case AnyCall::Constructor:
674ec727ea7Spatrick   case AnyCall::InheritedConstructor:
675e5dd7070Spatrick   case AnyCall::Allocator:
676e5dd7070Spatrick   case AnyCall::Deallocator:
677e5dd7070Spatrick     Summ = getFunctionSummary(cast_or_null<FunctionDecl>(C.getDecl()));
678e5dd7070Spatrick     break;
679e5dd7070Spatrick   case AnyCall::Block:
680e5dd7070Spatrick   case AnyCall::Destructor:
681e5dd7070Spatrick     // FIXME: These calls are currently unsupported.
682e5dd7070Spatrick     return getPersistentStopSummary();
683e5dd7070Spatrick   case AnyCall::ObjCMethod: {
684e5dd7070Spatrick     const auto *ME = cast_or_null<ObjCMessageExpr>(C.getExpr());
685e5dd7070Spatrick     if (!ME) {
686e5dd7070Spatrick       Summ = getMethodSummary(cast<ObjCMethodDecl>(C.getDecl()));
687e5dd7070Spatrick     } else if (ME->isInstanceMessage()) {
688e5dd7070Spatrick       Summ = getInstanceMethodSummary(ME, ReceiverType);
689e5dd7070Spatrick     } else {
690e5dd7070Spatrick       Summ = getClassMethodSummary(ME);
691e5dd7070Spatrick     }
692e5dd7070Spatrick     break;
693e5dd7070Spatrick   }
694e5dd7070Spatrick   }
695e5dd7070Spatrick 
696e5dd7070Spatrick   if (HasNonZeroCallbackArg)
697e5dd7070Spatrick     Summ = updateSummaryForNonZeroCallbackArg(Summ, C);
698e5dd7070Spatrick 
699e5dd7070Spatrick   if (IsReceiverUnconsumedSelf)
700e5dd7070Spatrick     updateSummaryForReceiverUnconsumedSelf(Summ);
701e5dd7070Spatrick 
702e5dd7070Spatrick   updateSummaryForArgumentTypes(C, Summ);
703e5dd7070Spatrick 
704e5dd7070Spatrick   assert(Summ && "Unknown call type?");
705e5dd7070Spatrick   return Summ;
706e5dd7070Spatrick }
707e5dd7070Spatrick 
708e5dd7070Spatrick 
709e5dd7070Spatrick const RetainSummary *
getCFCreateGetRuleSummary(const FunctionDecl * FD)710e5dd7070Spatrick RetainSummaryManager::getCFCreateGetRuleSummary(const FunctionDecl *FD) {
711e5dd7070Spatrick   if (coreFoundation::followsCreateRule(FD))
712e5dd7070Spatrick     return getCFSummaryCreateRule(FD);
713e5dd7070Spatrick 
714e5dd7070Spatrick   return getCFSummaryGetRule(FD);
715e5dd7070Spatrick }
716e5dd7070Spatrick 
isTrustedReferenceCountImplementation(const Decl * FD)717e5dd7070Spatrick bool RetainSummaryManager::isTrustedReferenceCountImplementation(
718e5dd7070Spatrick     const Decl *FD) {
719e5dd7070Spatrick   return hasRCAnnotation(FD, "rc_ownership_trusted_implementation");
720e5dd7070Spatrick }
721e5dd7070Spatrick 
722*12c85518Srobert std::optional<RetainSummaryManager::BehaviorSummary>
canEval(const CallExpr * CE,const FunctionDecl * FD,bool & hasTrustedImplementationAnnotation)723e5dd7070Spatrick RetainSummaryManager::canEval(const CallExpr *CE, const FunctionDecl *FD,
724e5dd7070Spatrick                               bool &hasTrustedImplementationAnnotation) {
725e5dd7070Spatrick 
726e5dd7070Spatrick   IdentifierInfo *II = FD->getIdentifier();
727e5dd7070Spatrick   if (!II)
728*12c85518Srobert     return std::nullopt;
729e5dd7070Spatrick 
730e5dd7070Spatrick   StringRef FName = II->getName();
731e5dd7070Spatrick   FName = FName.substr(FName.find_first_not_of('_'));
732e5dd7070Spatrick 
733e5dd7070Spatrick   QualType ResultTy = CE->getCallReturnType(Ctx);
734e5dd7070Spatrick   if (ResultTy->isObjCIdType()) {
735e5dd7070Spatrick     if (II->isStr("NSMakeCollectable"))
736e5dd7070Spatrick       return BehaviorSummary::Identity;
737e5dd7070Spatrick   } else if (ResultTy->isPointerType()) {
738e5dd7070Spatrick     // Handle: (CF|CG|CV)Retain
739e5dd7070Spatrick     //         CFAutorelease
740e5dd7070Spatrick     // It's okay to be a little sloppy here.
741e5dd7070Spatrick     if (FName == "CMBufferQueueDequeueAndRetain" ||
742e5dd7070Spatrick         FName == "CMBufferQueueDequeueIfDataReadyAndRetain") {
743e5dd7070Spatrick       // Part of: <rdar://problem/39390714>.
744e5dd7070Spatrick       // These are not retain. They just return something and retain it.
745*12c85518Srobert       return std::nullopt;
746e5dd7070Spatrick     }
747e5dd7070Spatrick     if (CE->getNumArgs() == 1 &&
748e5dd7070Spatrick         (cocoa::isRefType(ResultTy, "CF", FName) ||
749e5dd7070Spatrick          cocoa::isRefType(ResultTy, "CG", FName) ||
750e5dd7070Spatrick          cocoa::isRefType(ResultTy, "CV", FName)) &&
751e5dd7070Spatrick         (isRetain(FD, FName) || isAutorelease(FD, FName) ||
752e5dd7070Spatrick          isMakeCollectable(FName)))
753e5dd7070Spatrick       return BehaviorSummary::Identity;
754e5dd7070Spatrick 
755e5dd7070Spatrick     // safeMetaCast is called by OSDynamicCast.
756e5dd7070Spatrick     // We assume that OSDynamicCast is either an identity (cast is OK,
757e5dd7070Spatrick     // the input was non-zero),
758e5dd7070Spatrick     // or that it returns zero (when the cast failed, or the input
759e5dd7070Spatrick     // was zero).
760e5dd7070Spatrick     if (TrackOSObjects) {
761e5dd7070Spatrick       if (isOSObjectDynamicCast(FName) && FD->param_size() >= 1) {
762e5dd7070Spatrick         return BehaviorSummary::IdentityOrZero;
763e5dd7070Spatrick       } else if (isOSObjectRequiredCast(FName) && FD->param_size() >= 1) {
764e5dd7070Spatrick         return BehaviorSummary::Identity;
765e5dd7070Spatrick       } else if (isOSObjectThisCast(FName) && isa<CXXMethodDecl>(FD) &&
766e5dd7070Spatrick                  !cast<CXXMethodDecl>(FD)->isStatic()) {
767e5dd7070Spatrick         return BehaviorSummary::IdentityThis;
768e5dd7070Spatrick       }
769e5dd7070Spatrick     }
770e5dd7070Spatrick 
771e5dd7070Spatrick     const FunctionDecl* FDD = FD->getDefinition();
772e5dd7070Spatrick     if (FDD && isTrustedReferenceCountImplementation(FDD)) {
773e5dd7070Spatrick       hasTrustedImplementationAnnotation = true;
774e5dd7070Spatrick       return BehaviorSummary::Identity;
775e5dd7070Spatrick     }
776e5dd7070Spatrick   }
777e5dd7070Spatrick 
778e5dd7070Spatrick   if (const auto *MD = dyn_cast<CXXMethodDecl>(FD)) {
779e5dd7070Spatrick     const CXXRecordDecl *Parent = MD->getParent();
780e5dd7070Spatrick     if (TrackOSObjects && Parent && isOSObjectSubclass(Parent))
781e5dd7070Spatrick       if (FName == "release" || FName == "retain")
782e5dd7070Spatrick         return BehaviorSummary::NoOp;
783e5dd7070Spatrick   }
784e5dd7070Spatrick 
785*12c85518Srobert   return std::nullopt;
786e5dd7070Spatrick }
787e5dd7070Spatrick 
788e5dd7070Spatrick const RetainSummary *
getUnarySummary(const FunctionType * FT,ArgEffectKind AE)789e5dd7070Spatrick RetainSummaryManager::getUnarySummary(const FunctionType* FT,
790e5dd7070Spatrick                                       ArgEffectKind AE) {
791e5dd7070Spatrick 
792e5dd7070Spatrick   // Unary functions have no arg effects by definition.
793e5dd7070Spatrick   ArgEffects ScratchArgs(AF.getEmptyMap());
794e5dd7070Spatrick 
795*12c85518Srobert   // Verify that this is *really* a unary function.  This can
796e5dd7070Spatrick   // happen if people do weird things.
797e5dd7070Spatrick   const FunctionProtoType* FTP = dyn_cast<FunctionProtoType>(FT);
798e5dd7070Spatrick   if (!FTP || FTP->getNumParams() != 1)
799e5dd7070Spatrick     return getPersistentStopSummary();
800e5dd7070Spatrick 
801e5dd7070Spatrick   ArgEffect Effect(AE, ObjKind::CF);
802e5dd7070Spatrick 
803e5dd7070Spatrick   ScratchArgs = AF.add(ScratchArgs, 0, Effect);
804e5dd7070Spatrick   return getPersistentSummary(RetEffect::MakeNoRet(),
805e5dd7070Spatrick                               ScratchArgs,
806e5dd7070Spatrick                               ArgEffect(DoNothing), ArgEffect(DoNothing));
807e5dd7070Spatrick }
808e5dd7070Spatrick 
809e5dd7070Spatrick const RetainSummary *
getOSSummaryRetainRule(const FunctionDecl * FD)810e5dd7070Spatrick RetainSummaryManager::getOSSummaryRetainRule(const FunctionDecl *FD) {
811e5dd7070Spatrick   return getPersistentSummary(RetEffect::MakeNoRet(),
812e5dd7070Spatrick                               AF.getEmptyMap(),
813e5dd7070Spatrick                               /*ReceiverEff=*/ArgEffect(DoNothing),
814e5dd7070Spatrick                               /*DefaultEff=*/ArgEffect(DoNothing),
815e5dd7070Spatrick                               /*ThisEff=*/ArgEffect(IncRef, ObjKind::OS));
816e5dd7070Spatrick }
817e5dd7070Spatrick 
818e5dd7070Spatrick const RetainSummary *
getOSSummaryReleaseRule(const FunctionDecl * FD)819e5dd7070Spatrick RetainSummaryManager::getOSSummaryReleaseRule(const FunctionDecl *FD) {
820e5dd7070Spatrick   return getPersistentSummary(RetEffect::MakeNoRet(),
821e5dd7070Spatrick                               AF.getEmptyMap(),
822e5dd7070Spatrick                               /*ReceiverEff=*/ArgEffect(DoNothing),
823e5dd7070Spatrick                               /*DefaultEff=*/ArgEffect(DoNothing),
824e5dd7070Spatrick                               /*ThisEff=*/ArgEffect(DecRef, ObjKind::OS));
825e5dd7070Spatrick }
826e5dd7070Spatrick 
827e5dd7070Spatrick const RetainSummary *
getOSSummaryFreeRule(const FunctionDecl * FD)828e5dd7070Spatrick RetainSummaryManager::getOSSummaryFreeRule(const FunctionDecl *FD) {
829e5dd7070Spatrick   return getPersistentSummary(RetEffect::MakeNoRet(),
830e5dd7070Spatrick                               AF.getEmptyMap(),
831e5dd7070Spatrick                               /*ReceiverEff=*/ArgEffect(DoNothing),
832e5dd7070Spatrick                               /*DefaultEff=*/ArgEffect(DoNothing),
833e5dd7070Spatrick                               /*ThisEff=*/ArgEffect(Dealloc, ObjKind::OS));
834e5dd7070Spatrick }
835e5dd7070Spatrick 
836e5dd7070Spatrick const RetainSummary *
getOSSummaryCreateRule(const FunctionDecl * FD)837e5dd7070Spatrick RetainSummaryManager::getOSSummaryCreateRule(const FunctionDecl *FD) {
838e5dd7070Spatrick   return getPersistentSummary(RetEffect::MakeOwned(ObjKind::OS),
839e5dd7070Spatrick                               AF.getEmptyMap());
840e5dd7070Spatrick }
841e5dd7070Spatrick 
842e5dd7070Spatrick const RetainSummary *
getOSSummaryGetRule(const FunctionDecl * FD)843e5dd7070Spatrick RetainSummaryManager::getOSSummaryGetRule(const FunctionDecl *FD) {
844e5dd7070Spatrick   return getPersistentSummary(RetEffect::MakeNotOwned(ObjKind::OS),
845e5dd7070Spatrick                               AF.getEmptyMap());
846e5dd7070Spatrick }
847e5dd7070Spatrick 
848e5dd7070Spatrick const RetainSummary *
getCFSummaryCreateRule(const FunctionDecl * FD)849e5dd7070Spatrick RetainSummaryManager::getCFSummaryCreateRule(const FunctionDecl *FD) {
850e5dd7070Spatrick   return getPersistentSummary(RetEffect::MakeOwned(ObjKind::CF),
851e5dd7070Spatrick                               ArgEffects(AF.getEmptyMap()));
852e5dd7070Spatrick }
853e5dd7070Spatrick 
854e5dd7070Spatrick const RetainSummary *
getCFSummaryGetRule(const FunctionDecl * FD)855e5dd7070Spatrick RetainSummaryManager::getCFSummaryGetRule(const FunctionDecl *FD) {
856e5dd7070Spatrick   return getPersistentSummary(RetEffect::MakeNotOwned(ObjKind::CF),
857e5dd7070Spatrick                               ArgEffects(AF.getEmptyMap()),
858e5dd7070Spatrick                               ArgEffect(DoNothing), ArgEffect(DoNothing));
859e5dd7070Spatrick }
860e5dd7070Spatrick 
861e5dd7070Spatrick 
862e5dd7070Spatrick 
863e5dd7070Spatrick 
864e5dd7070Spatrick //===----------------------------------------------------------------------===//
865e5dd7070Spatrick // Summary creation for Selectors.
866e5dd7070Spatrick //===----------------------------------------------------------------------===//
867e5dd7070Spatrick 
868*12c85518Srobert std::optional<RetEffect>
getRetEffectFromAnnotations(QualType RetTy,const Decl * D)869e5dd7070Spatrick RetainSummaryManager::getRetEffectFromAnnotations(QualType RetTy,
870e5dd7070Spatrick                                                   const Decl *D) {
871e5dd7070Spatrick   if (hasAnyEnabledAttrOf<NSReturnsRetainedAttr>(D, RetTy))
872e5dd7070Spatrick     return ObjCAllocRetE;
873e5dd7070Spatrick 
874e5dd7070Spatrick   if (auto K = hasAnyEnabledAttrOf<CFReturnsRetainedAttr, OSReturnsRetainedAttr,
875e5dd7070Spatrick                                    GeneralizedReturnsRetainedAttr>(D, RetTy))
876e5dd7070Spatrick     return RetEffect::MakeOwned(*K);
877e5dd7070Spatrick 
878e5dd7070Spatrick   if (auto K = hasAnyEnabledAttrOf<
879e5dd7070Spatrick           CFReturnsNotRetainedAttr, OSReturnsNotRetainedAttr,
880e5dd7070Spatrick           GeneralizedReturnsNotRetainedAttr, NSReturnsNotRetainedAttr,
881e5dd7070Spatrick           NSReturnsAutoreleasedAttr>(D, RetTy))
882e5dd7070Spatrick     return RetEffect::MakeNotOwned(*K);
883e5dd7070Spatrick 
884e5dd7070Spatrick   if (const auto *MD = dyn_cast<CXXMethodDecl>(D))
885e5dd7070Spatrick     for (const auto *PD : MD->overridden_methods())
886e5dd7070Spatrick       if (auto RE = getRetEffectFromAnnotations(RetTy, PD))
887e5dd7070Spatrick         return RE;
888e5dd7070Spatrick 
889*12c85518Srobert   return std::nullopt;
890e5dd7070Spatrick }
891e5dd7070Spatrick 
892a9ac8606Spatrick /// \return Whether the chain of typedefs starting from @c QT
893a9ac8606Spatrick /// has a typedef with a given name @c Name.
hasTypedefNamed(QualType QT,StringRef Name)894e5dd7070Spatrick static bool hasTypedefNamed(QualType QT,
895e5dd7070Spatrick                             StringRef Name) {
896*12c85518Srobert   while (auto *T = QT->getAs<TypedefType>()) {
897e5dd7070Spatrick     const auto &Context = T->getDecl()->getASTContext();
898e5dd7070Spatrick     if (T->getDecl()->getIdentifier() == &Context.Idents.get(Name))
899e5dd7070Spatrick       return true;
900e5dd7070Spatrick     QT = T->getDecl()->getUnderlyingType();
901e5dd7070Spatrick   }
902e5dd7070Spatrick   return false;
903e5dd7070Spatrick }
904e5dd7070Spatrick 
getCallableReturnType(const NamedDecl * ND)905e5dd7070Spatrick static QualType getCallableReturnType(const NamedDecl *ND) {
906e5dd7070Spatrick   if (const auto *FD = dyn_cast<FunctionDecl>(ND)) {
907e5dd7070Spatrick     return FD->getReturnType();
908e5dd7070Spatrick   } else if (const auto *MD = dyn_cast<ObjCMethodDecl>(ND)) {
909e5dd7070Spatrick     return MD->getReturnType();
910e5dd7070Spatrick   } else {
911e5dd7070Spatrick     llvm_unreachable("Unexpected decl");
912e5dd7070Spatrick   }
913e5dd7070Spatrick }
914e5dd7070Spatrick 
applyParamAnnotationEffect(const ParmVarDecl * pd,unsigned parm_idx,const NamedDecl * FD,RetainSummaryTemplate & Template)915e5dd7070Spatrick bool RetainSummaryManager::applyParamAnnotationEffect(
916e5dd7070Spatrick     const ParmVarDecl *pd, unsigned parm_idx, const NamedDecl *FD,
917e5dd7070Spatrick     RetainSummaryTemplate &Template) {
918e5dd7070Spatrick   QualType QT = pd->getType();
919e5dd7070Spatrick   if (auto K =
920e5dd7070Spatrick           hasAnyEnabledAttrOf<NSConsumedAttr, CFConsumedAttr, OSConsumedAttr,
921e5dd7070Spatrick                               GeneralizedConsumedAttr>(pd, QT)) {
922e5dd7070Spatrick     Template->addArg(AF, parm_idx, ArgEffect(DecRef, *K));
923e5dd7070Spatrick     return true;
924e5dd7070Spatrick   } else if (auto K = hasAnyEnabledAttrOf<
925e5dd7070Spatrick                  CFReturnsRetainedAttr, OSReturnsRetainedAttr,
926e5dd7070Spatrick                  OSReturnsRetainedOnNonZeroAttr, OSReturnsRetainedOnZeroAttr,
927e5dd7070Spatrick                  GeneralizedReturnsRetainedAttr>(pd, QT)) {
928e5dd7070Spatrick 
929e5dd7070Spatrick     // For OSObjects, we try to guess whether the object is created based
930e5dd7070Spatrick     // on the return value.
931e5dd7070Spatrick     if (K == ObjKind::OS) {
932e5dd7070Spatrick       QualType QT = getCallableReturnType(FD);
933e5dd7070Spatrick 
934e5dd7070Spatrick       bool HasRetainedOnZero = pd->hasAttr<OSReturnsRetainedOnZeroAttr>();
935e5dd7070Spatrick       bool HasRetainedOnNonZero = pd->hasAttr<OSReturnsRetainedOnNonZeroAttr>();
936e5dd7070Spatrick 
937e5dd7070Spatrick       // The usual convention is to create an object on non-zero return, but
938e5dd7070Spatrick       // it's reverted if the typedef chain has a typedef kern_return_t,
939e5dd7070Spatrick       // because kReturnSuccess constant is defined as zero.
940e5dd7070Spatrick       // The convention can be overwritten by custom attributes.
941e5dd7070Spatrick       bool SuccessOnZero =
942e5dd7070Spatrick           HasRetainedOnZero ||
943e5dd7070Spatrick           (hasTypedefNamed(QT, "kern_return_t") && !HasRetainedOnNonZero);
944e5dd7070Spatrick       bool ShouldSplit = !QT.isNull() && !QT->isVoidType();
945e5dd7070Spatrick       ArgEffectKind AK = RetainedOutParameter;
946e5dd7070Spatrick       if (ShouldSplit && SuccessOnZero) {
947e5dd7070Spatrick         AK = RetainedOutParameterOnZero;
948e5dd7070Spatrick       } else if (ShouldSplit && (!SuccessOnZero || HasRetainedOnNonZero)) {
949e5dd7070Spatrick         AK = RetainedOutParameterOnNonZero;
950e5dd7070Spatrick       }
951e5dd7070Spatrick       Template->addArg(AF, parm_idx, ArgEffect(AK, ObjKind::OS));
952e5dd7070Spatrick     }
953e5dd7070Spatrick 
954e5dd7070Spatrick     // For others:
955e5dd7070Spatrick     // Do nothing. Retained out parameters will either point to a +1 reference
956e5dd7070Spatrick     // or NULL, but the way you check for failure differs depending on the
957e5dd7070Spatrick     // API. Consequently, we don't have a good way to track them yet.
958e5dd7070Spatrick     return true;
959e5dd7070Spatrick   } else if (auto K = hasAnyEnabledAttrOf<CFReturnsNotRetainedAttr,
960e5dd7070Spatrick                                           OSReturnsNotRetainedAttr,
961e5dd7070Spatrick                                           GeneralizedReturnsNotRetainedAttr>(
962e5dd7070Spatrick                  pd, QT)) {
963e5dd7070Spatrick     Template->addArg(AF, parm_idx, ArgEffect(UnretainedOutParameter, *K));
964e5dd7070Spatrick     return true;
965e5dd7070Spatrick   }
966e5dd7070Spatrick 
967e5dd7070Spatrick   if (const auto *MD = dyn_cast<CXXMethodDecl>(FD)) {
968e5dd7070Spatrick     for (const auto *OD : MD->overridden_methods()) {
969e5dd7070Spatrick       const ParmVarDecl *OP = OD->parameters()[parm_idx];
970e5dd7070Spatrick       if (applyParamAnnotationEffect(OP, parm_idx, OD, Template))
971e5dd7070Spatrick         return true;
972e5dd7070Spatrick     }
973e5dd7070Spatrick   }
974e5dd7070Spatrick 
975e5dd7070Spatrick   return false;
976e5dd7070Spatrick }
977e5dd7070Spatrick 
978e5dd7070Spatrick void
updateSummaryFromAnnotations(const RetainSummary * & Summ,const FunctionDecl * FD)979e5dd7070Spatrick RetainSummaryManager::updateSummaryFromAnnotations(const RetainSummary *&Summ,
980e5dd7070Spatrick                                                    const FunctionDecl *FD) {
981e5dd7070Spatrick   if (!FD)
982e5dd7070Spatrick     return;
983e5dd7070Spatrick 
984e5dd7070Spatrick   assert(Summ && "Must have a summary to add annotations to.");
985e5dd7070Spatrick   RetainSummaryTemplate Template(Summ, *this);
986e5dd7070Spatrick 
987e5dd7070Spatrick   // Effects on the parameters.
988e5dd7070Spatrick   unsigned parm_idx = 0;
989e5dd7070Spatrick   for (auto pi = FD->param_begin(),
990e5dd7070Spatrick          pe = FD->param_end(); pi != pe; ++pi, ++parm_idx)
991e5dd7070Spatrick     applyParamAnnotationEffect(*pi, parm_idx, FD, Template);
992e5dd7070Spatrick 
993e5dd7070Spatrick   QualType RetTy = FD->getReturnType();
994*12c85518Srobert   if (std::optional<RetEffect> RetE = getRetEffectFromAnnotations(RetTy, FD))
995e5dd7070Spatrick     Template->setRetEffect(*RetE);
996e5dd7070Spatrick 
997e5dd7070Spatrick   if (hasAnyEnabledAttrOf<OSConsumesThisAttr>(FD, RetTy))
998e5dd7070Spatrick     Template->setThisEffect(ArgEffect(DecRef, ObjKind::OS));
999e5dd7070Spatrick }
1000e5dd7070Spatrick 
1001e5dd7070Spatrick void
updateSummaryFromAnnotations(const RetainSummary * & Summ,const ObjCMethodDecl * MD)1002e5dd7070Spatrick RetainSummaryManager::updateSummaryFromAnnotations(const RetainSummary *&Summ,
1003e5dd7070Spatrick                                                    const ObjCMethodDecl *MD) {
1004e5dd7070Spatrick   if (!MD)
1005e5dd7070Spatrick     return;
1006e5dd7070Spatrick 
1007e5dd7070Spatrick   assert(Summ && "Must have a valid summary to add annotations to");
1008e5dd7070Spatrick   RetainSummaryTemplate Template(Summ, *this);
1009e5dd7070Spatrick 
1010e5dd7070Spatrick   // Effects on the receiver.
1011e5dd7070Spatrick   if (hasAnyEnabledAttrOf<NSConsumesSelfAttr>(MD, MD->getReturnType()))
1012e5dd7070Spatrick     Template->setReceiverEffect(ArgEffect(DecRef, ObjKind::ObjC));
1013e5dd7070Spatrick 
1014e5dd7070Spatrick   // Effects on the parameters.
1015e5dd7070Spatrick   unsigned parm_idx = 0;
1016e5dd7070Spatrick   for (auto pi = MD->param_begin(), pe = MD->param_end(); pi != pe;
1017e5dd7070Spatrick        ++pi, ++parm_idx)
1018e5dd7070Spatrick     applyParamAnnotationEffect(*pi, parm_idx, MD, Template);
1019e5dd7070Spatrick 
1020e5dd7070Spatrick   QualType RetTy = MD->getReturnType();
1021*12c85518Srobert   if (std::optional<RetEffect> RetE = getRetEffectFromAnnotations(RetTy, MD))
1022e5dd7070Spatrick     Template->setRetEffect(*RetE);
1023e5dd7070Spatrick }
1024e5dd7070Spatrick 
1025e5dd7070Spatrick const RetainSummary *
getStandardMethodSummary(const ObjCMethodDecl * MD,Selector S,QualType RetTy)1026e5dd7070Spatrick RetainSummaryManager::getStandardMethodSummary(const ObjCMethodDecl *MD,
1027e5dd7070Spatrick                                                Selector S, QualType RetTy) {
1028e5dd7070Spatrick   // Any special effects?
1029e5dd7070Spatrick   ArgEffect ReceiverEff = ArgEffect(DoNothing, ObjKind::ObjC);
1030e5dd7070Spatrick   RetEffect ResultEff = RetEffect::MakeNoRet();
1031e5dd7070Spatrick 
1032e5dd7070Spatrick   // Check the method family, and apply any default annotations.
1033e5dd7070Spatrick   switch (MD ? MD->getMethodFamily() : S.getMethodFamily()) {
1034e5dd7070Spatrick     case OMF_None:
1035e5dd7070Spatrick     case OMF_initialize:
1036e5dd7070Spatrick     case OMF_performSelector:
1037e5dd7070Spatrick       // Assume all Objective-C methods follow Cocoa Memory Management rules.
1038e5dd7070Spatrick       // FIXME: Does the non-threaded performSelector family really belong here?
1039e5dd7070Spatrick       // The selector could be, say, @selector(copy).
1040e5dd7070Spatrick       if (cocoa::isCocoaObjectRef(RetTy))
1041e5dd7070Spatrick         ResultEff = RetEffect::MakeNotOwned(ObjKind::ObjC);
1042e5dd7070Spatrick       else if (coreFoundation::isCFObjectRef(RetTy)) {
1043e5dd7070Spatrick         // ObjCMethodDecl currently doesn't consider CF objects as valid return
1044e5dd7070Spatrick         // values for alloc, new, copy, or mutableCopy, so we have to
1045e5dd7070Spatrick         // double-check with the selector. This is ugly, but there aren't that
1046e5dd7070Spatrick         // many Objective-C methods that return CF objects, right?
1047e5dd7070Spatrick         if (MD) {
1048e5dd7070Spatrick           switch (S.getMethodFamily()) {
1049e5dd7070Spatrick           case OMF_alloc:
1050e5dd7070Spatrick           case OMF_new:
1051e5dd7070Spatrick           case OMF_copy:
1052e5dd7070Spatrick           case OMF_mutableCopy:
1053e5dd7070Spatrick             ResultEff = RetEffect::MakeOwned(ObjKind::CF);
1054e5dd7070Spatrick             break;
1055e5dd7070Spatrick           default:
1056e5dd7070Spatrick             ResultEff = RetEffect::MakeNotOwned(ObjKind::CF);
1057e5dd7070Spatrick             break;
1058e5dd7070Spatrick           }
1059e5dd7070Spatrick         } else {
1060e5dd7070Spatrick           ResultEff = RetEffect::MakeNotOwned(ObjKind::CF);
1061e5dd7070Spatrick         }
1062e5dd7070Spatrick       }
1063e5dd7070Spatrick       break;
1064e5dd7070Spatrick     case OMF_init:
1065e5dd7070Spatrick       ResultEff = ObjCInitRetE;
1066e5dd7070Spatrick       ReceiverEff = ArgEffect(DecRef, ObjKind::ObjC);
1067e5dd7070Spatrick       break;
1068e5dd7070Spatrick     case OMF_alloc:
1069e5dd7070Spatrick     case OMF_new:
1070e5dd7070Spatrick     case OMF_copy:
1071e5dd7070Spatrick     case OMF_mutableCopy:
1072e5dd7070Spatrick       if (cocoa::isCocoaObjectRef(RetTy))
1073e5dd7070Spatrick         ResultEff = ObjCAllocRetE;
1074e5dd7070Spatrick       else if (coreFoundation::isCFObjectRef(RetTy))
1075e5dd7070Spatrick         ResultEff = RetEffect::MakeOwned(ObjKind::CF);
1076e5dd7070Spatrick       break;
1077e5dd7070Spatrick     case OMF_autorelease:
1078e5dd7070Spatrick       ReceiverEff = ArgEffect(Autorelease, ObjKind::ObjC);
1079e5dd7070Spatrick       break;
1080e5dd7070Spatrick     case OMF_retain:
1081e5dd7070Spatrick       ReceiverEff = ArgEffect(IncRef, ObjKind::ObjC);
1082e5dd7070Spatrick       break;
1083e5dd7070Spatrick     case OMF_release:
1084e5dd7070Spatrick       ReceiverEff = ArgEffect(DecRef, ObjKind::ObjC);
1085e5dd7070Spatrick       break;
1086e5dd7070Spatrick     case OMF_dealloc:
1087e5dd7070Spatrick       ReceiverEff = ArgEffect(Dealloc, ObjKind::ObjC);
1088e5dd7070Spatrick       break;
1089e5dd7070Spatrick     case OMF_self:
1090e5dd7070Spatrick       // -self is handled specially by the ExprEngine to propagate the receiver.
1091e5dd7070Spatrick       break;
1092e5dd7070Spatrick     case OMF_retainCount:
1093e5dd7070Spatrick     case OMF_finalize:
1094e5dd7070Spatrick       // These methods don't return objects.
1095e5dd7070Spatrick       break;
1096e5dd7070Spatrick   }
1097e5dd7070Spatrick 
1098e5dd7070Spatrick   // If one of the arguments in the selector has the keyword 'delegate' we
1099e5dd7070Spatrick   // should stop tracking the reference count for the receiver.  This is
1100e5dd7070Spatrick   // because the reference count is quite possibly handled by a delegate
1101e5dd7070Spatrick   // method.
1102e5dd7070Spatrick   if (S.isKeywordSelector()) {
1103e5dd7070Spatrick     for (unsigned i = 0, e = S.getNumArgs(); i != e; ++i) {
1104e5dd7070Spatrick       StringRef Slot = S.getNameForSlot(i);
1105a9ac8606Spatrick       if (Slot.substr(Slot.size() - 8).equals_insensitive("delegate")) {
1106e5dd7070Spatrick         if (ResultEff == ObjCInitRetE)
1107e5dd7070Spatrick           ResultEff = RetEffect::MakeNoRetHard();
1108e5dd7070Spatrick         else
1109e5dd7070Spatrick           ReceiverEff = ArgEffect(StopTrackingHard, ObjKind::ObjC);
1110e5dd7070Spatrick       }
1111e5dd7070Spatrick     }
1112e5dd7070Spatrick   }
1113e5dd7070Spatrick 
1114e5dd7070Spatrick   if (ReceiverEff.getKind() == DoNothing &&
1115e5dd7070Spatrick       ResultEff.getKind() == RetEffect::NoRet)
1116e5dd7070Spatrick     return getDefaultSummary();
1117e5dd7070Spatrick 
1118e5dd7070Spatrick   return getPersistentSummary(ResultEff, ArgEffects(AF.getEmptyMap()),
1119e5dd7070Spatrick                               ArgEffect(ReceiverEff), ArgEffect(MayEscape));
1120e5dd7070Spatrick }
1121e5dd7070Spatrick 
1122e5dd7070Spatrick const RetainSummary *
getClassMethodSummary(const ObjCMessageExpr * ME)1123e5dd7070Spatrick RetainSummaryManager::getClassMethodSummary(const ObjCMessageExpr *ME) {
1124e5dd7070Spatrick   assert(!ME->isInstanceMessage());
1125e5dd7070Spatrick   const ObjCInterfaceDecl *Class = ME->getReceiverInterface();
1126e5dd7070Spatrick 
1127e5dd7070Spatrick   return getMethodSummary(ME->getSelector(), Class, ME->getMethodDecl(),
1128e5dd7070Spatrick                           ME->getType(), ObjCClassMethodSummaries);
1129e5dd7070Spatrick }
1130e5dd7070Spatrick 
getInstanceMethodSummary(const ObjCMessageExpr * ME,QualType ReceiverType)1131e5dd7070Spatrick const RetainSummary *RetainSummaryManager::getInstanceMethodSummary(
1132e5dd7070Spatrick     const ObjCMessageExpr *ME,
1133e5dd7070Spatrick     QualType ReceiverType) {
1134e5dd7070Spatrick   const ObjCInterfaceDecl *ReceiverClass = nullptr;
1135e5dd7070Spatrick 
1136e5dd7070Spatrick   // We do better tracking of the type of the object than the core ExprEngine.
1137e5dd7070Spatrick   // See if we have its type in our private state.
1138e5dd7070Spatrick   if (!ReceiverType.isNull())
1139e5dd7070Spatrick     if (const auto *PT = ReceiverType->getAs<ObjCObjectPointerType>())
1140e5dd7070Spatrick       ReceiverClass = PT->getInterfaceDecl();
1141e5dd7070Spatrick 
1142e5dd7070Spatrick   // If we don't know what kind of object this is, fall back to its static type.
1143e5dd7070Spatrick   if (!ReceiverClass)
1144e5dd7070Spatrick     ReceiverClass = ME->getReceiverInterface();
1145e5dd7070Spatrick 
1146e5dd7070Spatrick   // FIXME: The receiver could be a reference to a class, meaning that
1147e5dd7070Spatrick   //  we should use the class method.
1148e5dd7070Spatrick   // id x = [NSObject class];
1149e5dd7070Spatrick   // [x performSelector:... withObject:... afterDelay:...];
1150e5dd7070Spatrick   Selector S = ME->getSelector();
1151e5dd7070Spatrick   const ObjCMethodDecl *Method = ME->getMethodDecl();
1152e5dd7070Spatrick   if (!Method && ReceiverClass)
1153e5dd7070Spatrick     Method = ReceiverClass->getInstanceMethod(S);
1154e5dd7070Spatrick 
1155e5dd7070Spatrick   return getMethodSummary(S, ReceiverClass, Method, ME->getType(),
1156e5dd7070Spatrick                           ObjCMethodSummaries);
1157e5dd7070Spatrick }
1158e5dd7070Spatrick 
1159e5dd7070Spatrick const RetainSummary *
getMethodSummary(Selector S,const ObjCInterfaceDecl * ID,const ObjCMethodDecl * MD,QualType RetTy,ObjCMethodSummariesTy & CachedSummaries)1160e5dd7070Spatrick RetainSummaryManager::getMethodSummary(Selector S,
1161e5dd7070Spatrick                                        const ObjCInterfaceDecl *ID,
1162e5dd7070Spatrick                                        const ObjCMethodDecl *MD, QualType RetTy,
1163e5dd7070Spatrick                                        ObjCMethodSummariesTy &CachedSummaries) {
1164e5dd7070Spatrick 
1165e5dd7070Spatrick   // Objective-C method summaries are only applicable to ObjC and CF objects.
1166e5dd7070Spatrick   if (!TrackObjCAndCFObjects)
1167e5dd7070Spatrick     return getDefaultSummary();
1168e5dd7070Spatrick 
1169e5dd7070Spatrick   // Look up a summary in our summary cache.
1170e5dd7070Spatrick   const RetainSummary *Summ = CachedSummaries.find(ID, S);
1171e5dd7070Spatrick 
1172e5dd7070Spatrick   if (!Summ) {
1173e5dd7070Spatrick     Summ = getStandardMethodSummary(MD, S, RetTy);
1174e5dd7070Spatrick 
1175e5dd7070Spatrick     // Annotations override defaults.
1176e5dd7070Spatrick     updateSummaryFromAnnotations(Summ, MD);
1177e5dd7070Spatrick 
1178e5dd7070Spatrick     // Memoize the summary.
1179e5dd7070Spatrick     CachedSummaries[ObjCSummaryKey(ID, S)] = Summ;
1180e5dd7070Spatrick   }
1181e5dd7070Spatrick 
1182e5dd7070Spatrick   return Summ;
1183e5dd7070Spatrick }
1184e5dd7070Spatrick 
InitializeClassMethodSummaries()1185e5dd7070Spatrick void RetainSummaryManager::InitializeClassMethodSummaries() {
1186e5dd7070Spatrick   ArgEffects ScratchArgs = AF.getEmptyMap();
1187e5dd7070Spatrick 
1188e5dd7070Spatrick   // Create the [NSAssertionHandler currentHander] summary.
1189e5dd7070Spatrick   addClassMethSummary("NSAssertionHandler", "currentHandler",
1190e5dd7070Spatrick                 getPersistentSummary(RetEffect::MakeNotOwned(ObjKind::ObjC),
1191e5dd7070Spatrick                                      ScratchArgs));
1192e5dd7070Spatrick 
1193e5dd7070Spatrick   // Create the [NSAutoreleasePool addObject:] summary.
1194e5dd7070Spatrick   ScratchArgs = AF.add(ScratchArgs, 0, ArgEffect(Autorelease));
1195e5dd7070Spatrick   addClassMethSummary("NSAutoreleasePool", "addObject",
1196e5dd7070Spatrick                       getPersistentSummary(RetEffect::MakeNoRet(), ScratchArgs,
1197e5dd7070Spatrick                                            ArgEffect(DoNothing),
1198e5dd7070Spatrick                                            ArgEffect(Autorelease)));
1199e5dd7070Spatrick }
1200e5dd7070Spatrick 
InitializeMethodSummaries()1201e5dd7070Spatrick void RetainSummaryManager::InitializeMethodSummaries() {
1202e5dd7070Spatrick 
1203e5dd7070Spatrick   ArgEffects ScratchArgs = AF.getEmptyMap();
1204e5dd7070Spatrick   // Create the "init" selector.  It just acts as a pass-through for the
1205e5dd7070Spatrick   // receiver.
1206e5dd7070Spatrick   const RetainSummary *InitSumm = getPersistentSummary(
1207e5dd7070Spatrick       ObjCInitRetE, ScratchArgs, ArgEffect(DecRef, ObjKind::ObjC));
1208e5dd7070Spatrick   addNSObjectMethSummary(GetNullarySelector("init", Ctx), InitSumm);
1209e5dd7070Spatrick 
1210e5dd7070Spatrick   // awakeAfterUsingCoder: behaves basically like an 'init' method.  It
1211e5dd7070Spatrick   // claims the receiver and returns a retained object.
1212e5dd7070Spatrick   addNSObjectMethSummary(GetUnarySelector("awakeAfterUsingCoder", Ctx),
1213e5dd7070Spatrick                          InitSumm);
1214e5dd7070Spatrick 
1215e5dd7070Spatrick   // The next methods are allocators.
1216e5dd7070Spatrick   const RetainSummary *AllocSumm = getPersistentSummary(ObjCAllocRetE,
1217e5dd7070Spatrick                                                         ScratchArgs);
1218e5dd7070Spatrick   const RetainSummary *CFAllocSumm =
1219e5dd7070Spatrick     getPersistentSummary(RetEffect::MakeOwned(ObjKind::CF), ScratchArgs);
1220e5dd7070Spatrick 
1221e5dd7070Spatrick   // Create the "retain" selector.
1222e5dd7070Spatrick   RetEffect NoRet = RetEffect::MakeNoRet();
1223e5dd7070Spatrick   const RetainSummary *Summ = getPersistentSummary(
1224e5dd7070Spatrick       NoRet, ScratchArgs, ArgEffect(IncRef, ObjKind::ObjC));
1225e5dd7070Spatrick   addNSObjectMethSummary(GetNullarySelector("retain", Ctx), Summ);
1226e5dd7070Spatrick 
1227e5dd7070Spatrick   // Create the "release" selector.
1228e5dd7070Spatrick   Summ = getPersistentSummary(NoRet, ScratchArgs,
1229e5dd7070Spatrick                               ArgEffect(DecRef, ObjKind::ObjC));
1230e5dd7070Spatrick   addNSObjectMethSummary(GetNullarySelector("release", Ctx), Summ);
1231e5dd7070Spatrick 
1232e5dd7070Spatrick   // Create the -dealloc summary.
1233e5dd7070Spatrick   Summ = getPersistentSummary(NoRet, ScratchArgs, ArgEffect(Dealloc,
1234e5dd7070Spatrick                                                             ObjKind::ObjC));
1235e5dd7070Spatrick   addNSObjectMethSummary(GetNullarySelector("dealloc", Ctx), Summ);
1236e5dd7070Spatrick 
1237e5dd7070Spatrick   // Create the "autorelease" selector.
1238e5dd7070Spatrick   Summ = getPersistentSummary(NoRet, ScratchArgs, ArgEffect(Autorelease,
1239e5dd7070Spatrick                                                             ObjKind::ObjC));
1240e5dd7070Spatrick   addNSObjectMethSummary(GetNullarySelector("autorelease", Ctx), Summ);
1241e5dd7070Spatrick 
1242e5dd7070Spatrick   // For NSWindow, allocated objects are (initially) self-owned.
1243e5dd7070Spatrick   // FIXME: For now we opt for false negatives with NSWindow, as these objects
1244e5dd7070Spatrick   //  self-own themselves.  However, they only do this once they are displayed.
1245e5dd7070Spatrick   //  Thus, we need to track an NSWindow's display status.
1246e5dd7070Spatrick   //  This is tracked in <rdar://problem/6062711>.
1247e5dd7070Spatrick   //  See also http://llvm.org/bugs/show_bug.cgi?id=3714.
1248e5dd7070Spatrick   const RetainSummary *NoTrackYet =
1249e5dd7070Spatrick       getPersistentSummary(RetEffect::MakeNoRet(), ScratchArgs,
1250e5dd7070Spatrick                            ArgEffect(StopTracking), ArgEffect(StopTracking));
1251e5dd7070Spatrick 
1252e5dd7070Spatrick   addClassMethSummary("NSWindow", "alloc", NoTrackYet);
1253e5dd7070Spatrick 
1254e5dd7070Spatrick   // For NSPanel (which subclasses NSWindow), allocated objects are not
1255e5dd7070Spatrick   //  self-owned.
1256e5dd7070Spatrick   // FIXME: For now we don't track NSPanels. object for the same reason
1257e5dd7070Spatrick   //   as for NSWindow objects.
1258e5dd7070Spatrick   addClassMethSummary("NSPanel", "alloc", NoTrackYet);
1259e5dd7070Spatrick 
1260e5dd7070Spatrick   // For NSNull, objects returned by +null are singletons that ignore
1261e5dd7070Spatrick   // retain/release semantics.  Just don't track them.
1262e5dd7070Spatrick   // <rdar://problem/12858915>
1263e5dd7070Spatrick   addClassMethSummary("NSNull", "null", NoTrackYet);
1264e5dd7070Spatrick 
1265e5dd7070Spatrick   // Don't track allocated autorelease pools, as it is okay to prematurely
1266e5dd7070Spatrick   // exit a method.
1267e5dd7070Spatrick   addClassMethSummary("NSAutoreleasePool", "alloc", NoTrackYet);
1268e5dd7070Spatrick   addClassMethSummary("NSAutoreleasePool", "allocWithZone", NoTrackYet, false);
1269e5dd7070Spatrick   addClassMethSummary("NSAutoreleasePool", "new", NoTrackYet);
1270e5dd7070Spatrick 
1271e5dd7070Spatrick   // Create summaries QCRenderer/QCView -createSnapShotImageOfType:
1272e5dd7070Spatrick   addInstMethSummary("QCRenderer", AllocSumm, "createSnapshotImageOfType");
1273e5dd7070Spatrick   addInstMethSummary("QCView", AllocSumm, "createSnapshotImageOfType");
1274e5dd7070Spatrick 
1275e5dd7070Spatrick   // Create summaries for CIContext, 'createCGImage' and
1276e5dd7070Spatrick   // 'createCGLayerWithSize'.  These objects are CF objects, and are not
1277e5dd7070Spatrick   // automatically garbage collected.
1278e5dd7070Spatrick   addInstMethSummary("CIContext", CFAllocSumm, "createCGImage", "fromRect");
1279e5dd7070Spatrick   addInstMethSummary("CIContext", CFAllocSumm, "createCGImage", "fromRect",
1280e5dd7070Spatrick                      "format", "colorSpace");
1281e5dd7070Spatrick   addInstMethSummary("CIContext", CFAllocSumm, "createCGLayerWithSize", "info");
1282e5dd7070Spatrick }
1283e5dd7070Spatrick 
1284e5dd7070Spatrick const RetainSummary *
getMethodSummary(const ObjCMethodDecl * MD)1285e5dd7070Spatrick RetainSummaryManager::getMethodSummary(const ObjCMethodDecl *MD) {
1286e5dd7070Spatrick   const ObjCInterfaceDecl *ID = MD->getClassInterface();
1287e5dd7070Spatrick   Selector S = MD->getSelector();
1288e5dd7070Spatrick   QualType ResultTy = MD->getReturnType();
1289e5dd7070Spatrick 
1290e5dd7070Spatrick   ObjCMethodSummariesTy *CachedSummaries;
1291e5dd7070Spatrick   if (MD->isInstanceMethod())
1292e5dd7070Spatrick     CachedSummaries = &ObjCMethodSummaries;
1293e5dd7070Spatrick   else
1294e5dd7070Spatrick     CachedSummaries = &ObjCClassMethodSummaries;
1295e5dd7070Spatrick 
1296e5dd7070Spatrick   return getMethodSummary(S, ID, MD, ResultTy, *CachedSummaries);
1297e5dd7070Spatrick }
1298