1 //===--- SemaCast.cpp - Semantic Analysis for Casts -----------------------===//
2 //
3 //                     The LLVM Compiler Infrastructure
4 //
5 // This file is distributed under the University of Illinois Open Source
6 // License. See LICENSE.TXT for details.
7 //
8 //===----------------------------------------------------------------------===//
9 //
10 //  This file implements semantic analysis for cast expressions, including
11 //  1) C-style casts like '(int) x'
12 //  2) C++ functional casts like 'int(x)'
13 //  3) C++ named casts like 'static_cast<int>(x)'
14 //
15 //===----------------------------------------------------------------------===//
16 
17 #include "clang/Sema/SemaInternal.h"
18 #include "clang/AST/ASTContext.h"
19 #include "clang/AST/CXXInheritance.h"
20 #include "clang/AST/ExprCXX.h"
21 #include "clang/AST/ExprObjC.h"
22 #include "clang/AST/RecordLayout.h"
23 #include "clang/Basic/PartialDiagnostic.h"
24 #include "clang/Basic/TargetInfo.h"
25 #include "clang/Sema/Initialization.h"
26 #include "llvm/ADT/SmallVector.h"
27 #include <set>
28 using namespace clang;
29 
30 
31 
32 enum TryCastResult {
33   TC_NotApplicable, ///< The cast method is not applicable.
34   TC_Success,       ///< The cast method is appropriate and successful.
35   TC_Failed         ///< The cast method is appropriate, but failed. A
36                     ///< diagnostic has been emitted.
37 };
38 
39 enum CastType {
40   CT_Const,       ///< const_cast
41   CT_Static,      ///< static_cast
42   CT_Reinterpret, ///< reinterpret_cast
43   CT_Dynamic,     ///< dynamic_cast
44   CT_CStyle,      ///< (Type)expr
45   CT_Functional   ///< Type(expr)
46 };
47 
48 namespace {
49   struct CastOperation {
50     CastOperation(Sema &S, QualType destType, ExprResult src)
51       : Self(S), SrcExpr(src), DestType(destType),
52         ResultType(destType.getNonLValueExprType(S.Context)),
53         ValueKind(Expr::getValueKindForType(destType)),
54         Kind(CK_Dependent), IsARCUnbridgedCast(false) {
55 
56       if (const BuiltinType *placeholder =
57             src.get()->getType()->getAsPlaceholderType()) {
58         PlaceholderKind = placeholder->getKind();
59       } else {
60         PlaceholderKind = (BuiltinType::Kind) 0;
61       }
62     }
63 
64     Sema &Self;
65     ExprResult SrcExpr;
66     QualType DestType;
67     QualType ResultType;
68     ExprValueKind ValueKind;
69     CastKind Kind;
70     BuiltinType::Kind PlaceholderKind;
71     CXXCastPath BasePath;
72     bool IsARCUnbridgedCast;
73 
74     SourceRange OpRange;
75     SourceRange DestRange;
76 
77     // Top-level semantics-checking routines.
78     void CheckConstCast();
79     void CheckReinterpretCast();
80     void CheckStaticCast();
81     void CheckDynamicCast();
82     void CheckCXXCStyleCast(bool FunctionalCast, bool ListInitialization);
83     void CheckCStyleCast();
84 
85     /// Complete an apparently-successful cast operation that yields
86     /// the given expression.
87     ExprResult complete(CastExpr *castExpr) {
88       // If this is an unbridged cast, wrap the result in an implicit
89       // cast that yields the unbridged-cast placeholder type.
90       if (IsARCUnbridgedCast) {
91         castExpr = ImplicitCastExpr::Create(Self.Context,
92                                             Self.Context.ARCUnbridgedCastTy,
93                                             CK_Dependent, castExpr, nullptr,
94                                             castExpr->getValueKind());
95       }
96       return castExpr;
97     }
98 
99     // Internal convenience methods.
100 
101     /// Try to handle the given placeholder expression kind.  Return
102     /// true if the source expression has the appropriate placeholder
103     /// kind.  A placeholder can only be claimed once.
104     bool claimPlaceholder(BuiltinType::Kind K) {
105       if (PlaceholderKind != K) return false;
106 
107       PlaceholderKind = (BuiltinType::Kind) 0;
108       return true;
109     }
110 
111     bool isPlaceholder() const {
112       return PlaceholderKind != 0;
113     }
114     bool isPlaceholder(BuiltinType::Kind K) const {
115       return PlaceholderKind == K;
116     }
117 
118     void checkCastAlign() {
119       Self.CheckCastAlign(SrcExpr.get(), DestType, OpRange);
120     }
121 
122     void checkObjCARCConversion(Sema::CheckedConversionKind CCK) {
123       assert(Self.getLangOpts().ObjCAutoRefCount);
124 
125       Expr *src = SrcExpr.get();
126       if (Self.CheckObjCARCConversion(OpRange, DestType, src, CCK) ==
127             Sema::ACR_unbridged)
128         IsARCUnbridgedCast = true;
129       SrcExpr = src;
130     }
131 
132     /// Check for and handle non-overload placeholder expressions.
133     void checkNonOverloadPlaceholders() {
134       if (!isPlaceholder() || isPlaceholder(BuiltinType::Overload))
135         return;
136 
137       SrcExpr = Self.CheckPlaceholderExpr(SrcExpr.get());
138       if (SrcExpr.isInvalid())
139         return;
140       PlaceholderKind = (BuiltinType::Kind) 0;
141     }
142   };
143 }
144 
145 // The Try functions attempt a specific way of casting. If they succeed, they
146 // return TC_Success. If their way of casting is not appropriate for the given
147 // arguments, they return TC_NotApplicable and *may* set diag to a diagnostic
148 // to emit if no other way succeeds. If their way of casting is appropriate but
149 // fails, they return TC_Failed and *must* set diag; they can set it to 0 if
150 // they emit a specialized diagnostic.
151 // All diagnostics returned by these functions must expect the same three
152 // arguments:
153 // %0: Cast Type (a value from the CastType enumeration)
154 // %1: Source Type
155 // %2: Destination Type
156 static TryCastResult TryLValueToRValueCast(Sema &Self, Expr *SrcExpr,
157                                            QualType DestType, bool CStyle,
158                                            CastKind &Kind,
159                                            CXXCastPath &BasePath,
160                                            unsigned &msg);
161 static TryCastResult TryStaticReferenceDowncast(Sema &Self, Expr *SrcExpr,
162                                                QualType DestType, bool CStyle,
163                                                const SourceRange &OpRange,
164                                                unsigned &msg,
165                                                CastKind &Kind,
166                                                CXXCastPath &BasePath);
167 static TryCastResult TryStaticPointerDowncast(Sema &Self, QualType SrcType,
168                                               QualType DestType, bool CStyle,
169                                               const SourceRange &OpRange,
170                                               unsigned &msg,
171                                               CastKind &Kind,
172                                               CXXCastPath &BasePath);
173 static TryCastResult TryStaticDowncast(Sema &Self, CanQualType SrcType,
174                                        CanQualType DestType, bool CStyle,
175                                        const SourceRange &OpRange,
176                                        QualType OrigSrcType,
177                                        QualType OrigDestType, unsigned &msg,
178                                        CastKind &Kind,
179                                        CXXCastPath &BasePath);
180 static TryCastResult TryStaticMemberPointerUpcast(Sema &Self, ExprResult &SrcExpr,
181                                                QualType SrcType,
182                                                QualType DestType,bool CStyle,
183                                                const SourceRange &OpRange,
184                                                unsigned &msg,
185                                                CastKind &Kind,
186                                                CXXCastPath &BasePath);
187 
188 static TryCastResult TryStaticImplicitCast(Sema &Self, ExprResult &SrcExpr,
189                                            QualType DestType,
190                                            Sema::CheckedConversionKind CCK,
191                                            const SourceRange &OpRange,
192                                            unsigned &msg, CastKind &Kind,
193                                            bool ListInitialization);
194 static TryCastResult TryStaticCast(Sema &Self, ExprResult &SrcExpr,
195                                    QualType DestType,
196                                    Sema::CheckedConversionKind CCK,
197                                    const SourceRange &OpRange,
198                                    unsigned &msg, CastKind &Kind,
199                                    CXXCastPath &BasePath,
200                                    bool ListInitialization);
201 static TryCastResult TryConstCast(Sema &Self, ExprResult &SrcExpr,
202                                   QualType DestType, bool CStyle,
203                                   unsigned &msg);
204 static TryCastResult TryReinterpretCast(Sema &Self, ExprResult &SrcExpr,
205                                         QualType DestType, bool CStyle,
206                                         const SourceRange &OpRange,
207                                         unsigned &msg,
208                                         CastKind &Kind);
209 
210 
211 /// ActOnCXXNamedCast - Parse {dynamic,static,reinterpret,const}_cast's.
212 ExprResult
213 Sema::ActOnCXXNamedCast(SourceLocation OpLoc, tok::TokenKind Kind,
214                         SourceLocation LAngleBracketLoc, Declarator &D,
215                         SourceLocation RAngleBracketLoc,
216                         SourceLocation LParenLoc, Expr *E,
217                         SourceLocation RParenLoc) {
218 
219   assert(!D.isInvalidType());
220 
221   TypeSourceInfo *TInfo = GetTypeForDeclaratorCast(D, E->getType());
222   if (D.isInvalidType())
223     return ExprError();
224 
225   if (getLangOpts().CPlusPlus) {
226     // Check that there are no default arguments (C++ only).
227     CheckExtraCXXDefaultArguments(D);
228   }
229 
230   return BuildCXXNamedCast(OpLoc, Kind, TInfo, E,
231                            SourceRange(LAngleBracketLoc, RAngleBracketLoc),
232                            SourceRange(LParenLoc, RParenLoc));
233 }
234 
235 ExprResult
236 Sema::BuildCXXNamedCast(SourceLocation OpLoc, tok::TokenKind Kind,
237                         TypeSourceInfo *DestTInfo, Expr *E,
238                         SourceRange AngleBrackets, SourceRange Parens) {
239   ExprResult Ex = E;
240   QualType DestType = DestTInfo->getType();
241 
242   // If the type is dependent, we won't do the semantic analysis now.
243   bool TypeDependent =
244       DestType->isDependentType() || Ex.get()->isTypeDependent();
245 
246   CastOperation Op(*this, DestType, E);
247   Op.OpRange = SourceRange(OpLoc, Parens.getEnd());
248   Op.DestRange = AngleBrackets;
249 
250   switch (Kind) {
251   default: llvm_unreachable("Unknown C++ cast!");
252 
253   case tok::kw_const_cast:
254     if (!TypeDependent) {
255       Op.CheckConstCast();
256       if (Op.SrcExpr.isInvalid())
257         return ExprError();
258     }
259     return Op.complete(CXXConstCastExpr::Create(Context, Op.ResultType,
260                                   Op.ValueKind, Op.SrcExpr.get(), DestTInfo,
261                                                 OpLoc, Parens.getEnd(),
262                                                 AngleBrackets));
263 
264   case tok::kw_dynamic_cast: {
265     if (!TypeDependent) {
266       Op.CheckDynamicCast();
267       if (Op.SrcExpr.isInvalid())
268         return ExprError();
269     }
270     return Op.complete(CXXDynamicCastExpr::Create(Context, Op.ResultType,
271                                     Op.ValueKind, Op.Kind, Op.SrcExpr.get(),
272                                                   &Op.BasePath, DestTInfo,
273                                                   OpLoc, Parens.getEnd(),
274                                                   AngleBrackets));
275   }
276   case tok::kw_reinterpret_cast: {
277     if (!TypeDependent) {
278       Op.CheckReinterpretCast();
279       if (Op.SrcExpr.isInvalid())
280         return ExprError();
281     }
282     return Op.complete(CXXReinterpretCastExpr::Create(Context, Op.ResultType,
283                                     Op.ValueKind, Op.Kind, Op.SrcExpr.get(),
284                                                       nullptr, DestTInfo, OpLoc,
285                                                       Parens.getEnd(),
286                                                       AngleBrackets));
287   }
288   case tok::kw_static_cast: {
289     if (!TypeDependent) {
290       Op.CheckStaticCast();
291       if (Op.SrcExpr.isInvalid())
292         return ExprError();
293     }
294 
295     return Op.complete(CXXStaticCastExpr::Create(Context, Op.ResultType,
296                                    Op.ValueKind, Op.Kind, Op.SrcExpr.get(),
297                                                  &Op.BasePath, DestTInfo,
298                                                  OpLoc, Parens.getEnd(),
299                                                  AngleBrackets));
300   }
301   }
302 }
303 
304 /// Try to diagnose a failed overloaded cast.  Returns true if
305 /// diagnostics were emitted.
306 static bool tryDiagnoseOverloadedCast(Sema &S, CastType CT,
307                                       SourceRange range, Expr *src,
308                                       QualType destType,
309                                       bool listInitialization) {
310   switch (CT) {
311   // These cast kinds don't consider user-defined conversions.
312   case CT_Const:
313   case CT_Reinterpret:
314   case CT_Dynamic:
315     return false;
316 
317   // These do.
318   case CT_Static:
319   case CT_CStyle:
320   case CT_Functional:
321     break;
322   }
323 
324   QualType srcType = src->getType();
325   if (!destType->isRecordType() && !srcType->isRecordType())
326     return false;
327 
328   InitializedEntity entity = InitializedEntity::InitializeTemporary(destType);
329   InitializationKind initKind
330     = (CT == CT_CStyle)? InitializationKind::CreateCStyleCast(range.getBegin(),
331                                                       range, listInitialization)
332     : (CT == CT_Functional)? InitializationKind::CreateFunctionalCast(range,
333                                                              listInitialization)
334     : InitializationKind::CreateCast(/*type range?*/ range);
335   InitializationSequence sequence(S, entity, initKind, src);
336 
337   assert(sequence.Failed() && "initialization succeeded on second try?");
338   switch (sequence.getFailureKind()) {
339   default: return false;
340 
341   case InitializationSequence::FK_ConstructorOverloadFailed:
342   case InitializationSequence::FK_UserConversionOverloadFailed:
343     break;
344   }
345 
346   OverloadCandidateSet &candidates = sequence.getFailedCandidateSet();
347 
348   unsigned msg = 0;
349   OverloadCandidateDisplayKind howManyCandidates = OCD_AllCandidates;
350 
351   switch (sequence.getFailedOverloadResult()) {
352   case OR_Success: llvm_unreachable("successful failed overload");
353   case OR_No_Viable_Function:
354     if (candidates.empty())
355       msg = diag::err_ovl_no_conversion_in_cast;
356     else
357       msg = diag::err_ovl_no_viable_conversion_in_cast;
358     howManyCandidates = OCD_AllCandidates;
359     break;
360 
361   case OR_Ambiguous:
362     msg = diag::err_ovl_ambiguous_conversion_in_cast;
363     howManyCandidates = OCD_ViableCandidates;
364     break;
365 
366   case OR_Deleted:
367     msg = diag::err_ovl_deleted_conversion_in_cast;
368     howManyCandidates = OCD_ViableCandidates;
369     break;
370   }
371 
372   S.Diag(range.getBegin(), msg)
373     << CT << srcType << destType
374     << range << src->getSourceRange();
375 
376   candidates.NoteCandidates(S, howManyCandidates, src);
377 
378   return true;
379 }
380 
381 /// Diagnose a failed cast.
382 static void diagnoseBadCast(Sema &S, unsigned msg, CastType castType,
383                             SourceRange opRange, Expr *src, QualType destType,
384                             bool listInitialization) {
385   if (msg == diag::err_bad_cxx_cast_generic &&
386       tryDiagnoseOverloadedCast(S, castType, opRange, src, destType,
387                                 listInitialization))
388     return;
389 
390   S.Diag(opRange.getBegin(), msg) << castType
391     << src->getType() << destType << opRange << src->getSourceRange();
392 
393   // Detect if both types are (ptr to) class, and note any incompleteness.
394   int DifferentPtrness = 0;
395   QualType From = destType;
396   if (auto Ptr = From->getAs<PointerType>()) {
397     From = Ptr->getPointeeType();
398     DifferentPtrness++;
399   }
400   QualType To = src->getType();
401   if (auto Ptr = To->getAs<PointerType>()) {
402     To = Ptr->getPointeeType();
403     DifferentPtrness--;
404   }
405   if (!DifferentPtrness) {
406     auto RecFrom = From->getAs<RecordType>();
407     auto RecTo = To->getAs<RecordType>();
408     if (RecFrom && RecTo) {
409       auto DeclFrom = RecFrom->getAsCXXRecordDecl();
410       if (!DeclFrom->isCompleteDefinition())
411         S.Diag(DeclFrom->getLocation(), diag::note_type_incomplete)
412           << DeclFrom->getDeclName();
413       auto DeclTo = RecTo->getAsCXXRecordDecl();
414       if (!DeclTo->isCompleteDefinition())
415         S.Diag(DeclTo->getLocation(), diag::note_type_incomplete)
416           << DeclTo->getDeclName();
417     }
418   }
419 }
420 
421 /// UnwrapDissimilarPointerTypes - Like Sema::UnwrapSimilarPointerTypes,
422 /// this removes one level of indirection from both types, provided that they're
423 /// the same kind of pointer (plain or to-member). Unlike the Sema function,
424 /// this one doesn't care if the two pointers-to-member don't point into the
425 /// same class. This is because CastsAwayConstness doesn't care.
426 static bool UnwrapDissimilarPointerTypes(QualType& T1, QualType& T2) {
427   const PointerType *T1PtrType = T1->getAs<PointerType>(),
428                     *T2PtrType = T2->getAs<PointerType>();
429   if (T1PtrType && T2PtrType) {
430     T1 = T1PtrType->getPointeeType();
431     T2 = T2PtrType->getPointeeType();
432     return true;
433   }
434   const ObjCObjectPointerType *T1ObjCPtrType =
435                                             T1->getAs<ObjCObjectPointerType>(),
436                               *T2ObjCPtrType =
437                                             T2->getAs<ObjCObjectPointerType>();
438   if (T1ObjCPtrType) {
439     if (T2ObjCPtrType) {
440       T1 = T1ObjCPtrType->getPointeeType();
441       T2 = T2ObjCPtrType->getPointeeType();
442       return true;
443     }
444     else if (T2PtrType) {
445       T1 = T1ObjCPtrType->getPointeeType();
446       T2 = T2PtrType->getPointeeType();
447       return true;
448     }
449   }
450   else if (T2ObjCPtrType) {
451     if (T1PtrType) {
452       T2 = T2ObjCPtrType->getPointeeType();
453       T1 = T1PtrType->getPointeeType();
454       return true;
455     }
456   }
457 
458   const MemberPointerType *T1MPType = T1->getAs<MemberPointerType>(),
459                           *T2MPType = T2->getAs<MemberPointerType>();
460   if (T1MPType && T2MPType) {
461     T1 = T1MPType->getPointeeType();
462     T2 = T2MPType->getPointeeType();
463     return true;
464   }
465 
466   const BlockPointerType *T1BPType = T1->getAs<BlockPointerType>(),
467                          *T2BPType = T2->getAs<BlockPointerType>();
468   if (T1BPType && T2BPType) {
469     T1 = T1BPType->getPointeeType();
470     T2 = T2BPType->getPointeeType();
471     return true;
472   }
473 
474   return false;
475 }
476 
477 /// CastsAwayConstness - Check if the pointer conversion from SrcType to
478 /// DestType casts away constness as defined in C++ 5.2.11p8ff. This is used by
479 /// the cast checkers.  Both arguments must denote pointer (possibly to member)
480 /// types.
481 ///
482 /// \param CheckCVR Whether to check for const/volatile/restrict qualifiers.
483 ///
484 /// \param CheckObjCLifetime Whether to check Objective-C lifetime qualifiers.
485 static bool
486 CastsAwayConstness(Sema &Self, QualType SrcType, QualType DestType,
487                    bool CheckCVR, bool CheckObjCLifetime,
488                    QualType *TheOffendingSrcType = nullptr,
489                    QualType *TheOffendingDestType = nullptr,
490                    Qualifiers *CastAwayQualifiers = nullptr) {
491   // If the only checking we care about is for Objective-C lifetime qualifiers,
492   // and we're not in ARC mode, there's nothing to check.
493   if (!CheckCVR && CheckObjCLifetime &&
494       !Self.Context.getLangOpts().ObjCAutoRefCount)
495     return false;
496 
497   // Casting away constness is defined in C++ 5.2.11p8 with reference to
498   // C++ 4.4. We piggyback on Sema::IsQualificationConversion for this, since
499   // the rules are non-trivial. So first we construct Tcv *...cv* as described
500   // in C++ 5.2.11p8.
501   assert((SrcType->isAnyPointerType() || SrcType->isMemberPointerType() ||
502           SrcType->isBlockPointerType()) &&
503          "Source type is not pointer or pointer to member.");
504   assert((DestType->isAnyPointerType() || DestType->isMemberPointerType() ||
505           DestType->isBlockPointerType()) &&
506          "Destination type is not pointer or pointer to member.");
507 
508   QualType UnwrappedSrcType = Self.Context.getCanonicalType(SrcType),
509            UnwrappedDestType = Self.Context.getCanonicalType(DestType);
510   SmallVector<Qualifiers, 8> cv1, cv2;
511 
512   // Find the qualifiers. We only care about cvr-qualifiers for the
513   // purpose of this check, because other qualifiers (address spaces,
514   // Objective-C GC, etc.) are part of the type's identity.
515   QualType PrevUnwrappedSrcType = UnwrappedSrcType;
516   QualType PrevUnwrappedDestType = UnwrappedDestType;
517   while (UnwrapDissimilarPointerTypes(UnwrappedSrcType, UnwrappedDestType)) {
518     // Determine the relevant qualifiers at this level.
519     Qualifiers SrcQuals, DestQuals;
520     Self.Context.getUnqualifiedArrayType(UnwrappedSrcType, SrcQuals);
521     Self.Context.getUnqualifiedArrayType(UnwrappedDestType, DestQuals);
522 
523     Qualifiers RetainedSrcQuals, RetainedDestQuals;
524     if (CheckCVR) {
525       RetainedSrcQuals.setCVRQualifiers(SrcQuals.getCVRQualifiers());
526       RetainedDestQuals.setCVRQualifiers(DestQuals.getCVRQualifiers());
527 
528       if (RetainedSrcQuals != RetainedDestQuals && TheOffendingSrcType &&
529           TheOffendingDestType && CastAwayQualifiers) {
530         *TheOffendingSrcType = PrevUnwrappedSrcType;
531         *TheOffendingDestType = PrevUnwrappedDestType;
532         *CastAwayQualifiers = RetainedSrcQuals - RetainedDestQuals;
533       }
534     }
535 
536     if (CheckObjCLifetime &&
537         !DestQuals.compatiblyIncludesObjCLifetime(SrcQuals))
538       return true;
539 
540     cv1.push_back(RetainedSrcQuals);
541     cv2.push_back(RetainedDestQuals);
542 
543     PrevUnwrappedSrcType = UnwrappedSrcType;
544     PrevUnwrappedDestType = UnwrappedDestType;
545   }
546   if (cv1.empty())
547     return false;
548 
549   // Construct void pointers with those qualifiers (in reverse order of
550   // unwrapping, of course).
551   QualType SrcConstruct = Self.Context.VoidTy;
552   QualType DestConstruct = Self.Context.VoidTy;
553   ASTContext &Context = Self.Context;
554   for (SmallVectorImpl<Qualifiers>::reverse_iterator i1 = cv1.rbegin(),
555                                                      i2 = cv2.rbegin();
556        i1 != cv1.rend(); ++i1, ++i2) {
557     SrcConstruct
558       = Context.getPointerType(Context.getQualifiedType(SrcConstruct, *i1));
559     DestConstruct
560       = Context.getPointerType(Context.getQualifiedType(DestConstruct, *i2));
561   }
562 
563   // Test if they're compatible.
564   bool ObjCLifetimeConversion;
565   return SrcConstruct != DestConstruct &&
566     !Self.IsQualificationConversion(SrcConstruct, DestConstruct, false,
567                                     ObjCLifetimeConversion);
568 }
569 
570 /// CheckDynamicCast - Check that a dynamic_cast\<DestType\>(SrcExpr) is valid.
571 /// Refer to C++ 5.2.7 for details. Dynamic casts are used mostly for runtime-
572 /// checked downcasts in class hierarchies.
573 void CastOperation::CheckDynamicCast() {
574   if (ValueKind == VK_RValue)
575     SrcExpr = Self.DefaultFunctionArrayLvalueConversion(SrcExpr.get());
576   else if (isPlaceholder())
577     SrcExpr = Self.CheckPlaceholderExpr(SrcExpr.get());
578   if (SrcExpr.isInvalid()) // if conversion failed, don't report another error
579     return;
580 
581   QualType OrigSrcType = SrcExpr.get()->getType();
582   QualType DestType = Self.Context.getCanonicalType(this->DestType);
583 
584   // C++ 5.2.7p1: T shall be a pointer or reference to a complete class type,
585   //   or "pointer to cv void".
586 
587   QualType DestPointee;
588   const PointerType *DestPointer = DestType->getAs<PointerType>();
589   const ReferenceType *DestReference = nullptr;
590   if (DestPointer) {
591     DestPointee = DestPointer->getPointeeType();
592   } else if ((DestReference = DestType->getAs<ReferenceType>())) {
593     DestPointee = DestReference->getPointeeType();
594   } else {
595     Self.Diag(OpRange.getBegin(), diag::err_bad_dynamic_cast_not_ref_or_ptr)
596       << this->DestType << DestRange;
597     SrcExpr = ExprError();
598     return;
599   }
600 
601   const RecordType *DestRecord = DestPointee->getAs<RecordType>();
602   if (DestPointee->isVoidType()) {
603     assert(DestPointer && "Reference to void is not possible");
604   } else if (DestRecord) {
605     if (Self.RequireCompleteType(OpRange.getBegin(), DestPointee,
606                                  diag::err_bad_dynamic_cast_incomplete,
607                                  DestRange)) {
608       SrcExpr = ExprError();
609       return;
610     }
611   } else {
612     Self.Diag(OpRange.getBegin(), diag::err_bad_dynamic_cast_not_class)
613       << DestPointee.getUnqualifiedType() << DestRange;
614     SrcExpr = ExprError();
615     return;
616   }
617 
618   // C++0x 5.2.7p2: If T is a pointer type, v shall be an rvalue of a pointer to
619   //   complete class type, [...]. If T is an lvalue reference type, v shall be
620   //   an lvalue of a complete class type, [...]. If T is an rvalue reference
621   //   type, v shall be an expression having a complete class type, [...]
622   QualType SrcType = Self.Context.getCanonicalType(OrigSrcType);
623   QualType SrcPointee;
624   if (DestPointer) {
625     if (const PointerType *SrcPointer = SrcType->getAs<PointerType>()) {
626       SrcPointee = SrcPointer->getPointeeType();
627     } else {
628       Self.Diag(OpRange.getBegin(), diag::err_bad_dynamic_cast_not_ptr)
629         << OrigSrcType << SrcExpr.get()->getSourceRange();
630       SrcExpr = ExprError();
631       return;
632     }
633   } else if (DestReference->isLValueReferenceType()) {
634     if (!SrcExpr.get()->isLValue()) {
635       Self.Diag(OpRange.getBegin(), diag::err_bad_cxx_cast_rvalue)
636         << CT_Dynamic << OrigSrcType << this->DestType << OpRange;
637     }
638     SrcPointee = SrcType;
639   } else {
640     // If we're dynamic_casting from a prvalue to an rvalue reference, we need
641     // to materialize the prvalue before we bind the reference to it.
642     if (SrcExpr.get()->isRValue())
643       SrcExpr = new (Self.Context) MaterializeTemporaryExpr(
644           SrcType, SrcExpr.get(), /*IsLValueReference*/false);
645     SrcPointee = SrcType;
646   }
647 
648   const RecordType *SrcRecord = SrcPointee->getAs<RecordType>();
649   if (SrcRecord) {
650     if (Self.RequireCompleteType(OpRange.getBegin(), SrcPointee,
651                                  diag::err_bad_dynamic_cast_incomplete,
652                                  SrcExpr.get())) {
653       SrcExpr = ExprError();
654       return;
655     }
656   } else {
657     Self.Diag(OpRange.getBegin(), diag::err_bad_dynamic_cast_not_class)
658       << SrcPointee.getUnqualifiedType() << SrcExpr.get()->getSourceRange();
659     SrcExpr = ExprError();
660     return;
661   }
662 
663   assert((DestPointer || DestReference) &&
664     "Bad destination non-ptr/ref slipped through.");
665   assert((DestRecord || DestPointee->isVoidType()) &&
666     "Bad destination pointee slipped through.");
667   assert(SrcRecord && "Bad source pointee slipped through.");
668 
669   // C++ 5.2.7p1: The dynamic_cast operator shall not cast away constness.
670   if (!DestPointee.isAtLeastAsQualifiedAs(SrcPointee)) {
671     Self.Diag(OpRange.getBegin(), diag::err_bad_cxx_cast_qualifiers_away)
672       << CT_Dynamic << OrigSrcType << this->DestType << OpRange;
673     SrcExpr = ExprError();
674     return;
675   }
676 
677   // C++ 5.2.7p3: If the type of v is the same as the required result type,
678   //   [except for cv].
679   if (DestRecord == SrcRecord) {
680     Kind = CK_NoOp;
681     return;
682   }
683 
684   // C++ 5.2.7p5
685   // Upcasts are resolved statically.
686   if (DestRecord && Self.IsDerivedFrom(SrcPointee, DestPointee)) {
687     if (Self.CheckDerivedToBaseConversion(SrcPointee, DestPointee,
688                                            OpRange.getBegin(), OpRange,
689                                            &BasePath)) {
690       SrcExpr = ExprError();
691       return;
692     }
693 
694     Kind = CK_DerivedToBase;
695     return;
696   }
697 
698   // C++ 5.2.7p6: Otherwise, v shall be [polymorphic].
699   const RecordDecl *SrcDecl = SrcRecord->getDecl()->getDefinition();
700   assert(SrcDecl && "Definition missing");
701   if (!cast<CXXRecordDecl>(SrcDecl)->isPolymorphic()) {
702     Self.Diag(OpRange.getBegin(), diag::err_bad_dynamic_cast_not_polymorphic)
703       << SrcPointee.getUnqualifiedType() << SrcExpr.get()->getSourceRange();
704     SrcExpr = ExprError();
705   }
706 
707   // dynamic_cast is not available with -fno-rtti.
708   // As an exception, dynamic_cast to void* is available because it doesn't
709   // use RTTI.
710   if (!Self.getLangOpts().RTTI && !DestPointee->isVoidType()) {
711     Self.Diag(OpRange.getBegin(), diag::err_no_dynamic_cast_with_fno_rtti);
712     SrcExpr = ExprError();
713     return;
714   }
715 
716   // Done. Everything else is run-time checks.
717   Kind = CK_Dynamic;
718 }
719 
720 /// CheckConstCast - Check that a const_cast\<DestType\>(SrcExpr) is valid.
721 /// Refer to C++ 5.2.11 for details. const_cast is typically used in code
722 /// like this:
723 /// const char *str = "literal";
724 /// legacy_function(const_cast\<char*\>(str));
725 void CastOperation::CheckConstCast() {
726   if (ValueKind == VK_RValue)
727     SrcExpr = Self.DefaultFunctionArrayLvalueConversion(SrcExpr.get());
728   else if (isPlaceholder())
729     SrcExpr = Self.CheckPlaceholderExpr(SrcExpr.get());
730   if (SrcExpr.isInvalid()) // if conversion failed, don't report another error
731     return;
732 
733   unsigned msg = diag::err_bad_cxx_cast_generic;
734   if (TryConstCast(Self, SrcExpr, DestType, /*CStyle*/false, msg) != TC_Success
735       && msg != 0) {
736     Self.Diag(OpRange.getBegin(), msg) << CT_Const
737       << SrcExpr.get()->getType() << DestType << OpRange;
738     SrcExpr = ExprError();
739   }
740 }
741 
742 /// Check that a reinterpret_cast\<DestType\>(SrcExpr) is not used as upcast
743 /// or downcast between respective pointers or references.
744 static void DiagnoseReinterpretUpDownCast(Sema &Self, const Expr *SrcExpr,
745                                           QualType DestType,
746                                           SourceRange OpRange) {
747   QualType SrcType = SrcExpr->getType();
748   // When casting from pointer or reference, get pointee type; use original
749   // type otherwise.
750   const CXXRecordDecl *SrcPointeeRD = SrcType->getPointeeCXXRecordDecl();
751   const CXXRecordDecl *SrcRD =
752     SrcPointeeRD ? SrcPointeeRD : SrcType->getAsCXXRecordDecl();
753 
754   // Examining subobjects for records is only possible if the complete and
755   // valid definition is available.  Also, template instantiation is not
756   // allowed here.
757   if (!SrcRD || !SrcRD->isCompleteDefinition() || SrcRD->isInvalidDecl())
758     return;
759 
760   const CXXRecordDecl *DestRD = DestType->getPointeeCXXRecordDecl();
761 
762   if (!DestRD || !DestRD->isCompleteDefinition() || DestRD->isInvalidDecl())
763     return;
764 
765   enum {
766     ReinterpretUpcast,
767     ReinterpretDowncast
768   } ReinterpretKind;
769 
770   CXXBasePaths BasePaths;
771 
772   if (SrcRD->isDerivedFrom(DestRD, BasePaths))
773     ReinterpretKind = ReinterpretUpcast;
774   else if (DestRD->isDerivedFrom(SrcRD, BasePaths))
775     ReinterpretKind = ReinterpretDowncast;
776   else
777     return;
778 
779   bool VirtualBase = true;
780   bool NonZeroOffset = false;
781   for (CXXBasePaths::const_paths_iterator I = BasePaths.begin(),
782                                           E = BasePaths.end();
783        I != E; ++I) {
784     const CXXBasePath &Path = *I;
785     CharUnits Offset = CharUnits::Zero();
786     bool IsVirtual = false;
787     for (CXXBasePath::const_iterator IElem = Path.begin(), EElem = Path.end();
788          IElem != EElem; ++IElem) {
789       IsVirtual = IElem->Base->isVirtual();
790       if (IsVirtual)
791         break;
792       const CXXRecordDecl *BaseRD = IElem->Base->getType()->getAsCXXRecordDecl();
793       assert(BaseRD && "Base type should be a valid unqualified class type");
794       // Don't check if any base has invalid declaration or has no definition
795       // since it has no layout info.
796       const CXXRecordDecl *Class = IElem->Class,
797                           *ClassDefinition = Class->getDefinition();
798       if (Class->isInvalidDecl() || !ClassDefinition ||
799           !ClassDefinition->isCompleteDefinition())
800         return;
801 
802       const ASTRecordLayout &DerivedLayout =
803           Self.Context.getASTRecordLayout(Class);
804       Offset += DerivedLayout.getBaseClassOffset(BaseRD);
805     }
806     if (!IsVirtual) {
807       // Don't warn if any path is a non-virtually derived base at offset zero.
808       if (Offset.isZero())
809         return;
810       // Offset makes sense only for non-virtual bases.
811       else
812         NonZeroOffset = true;
813     }
814     VirtualBase = VirtualBase && IsVirtual;
815   }
816 
817   (void) NonZeroOffset; // Silence set but not used warning.
818   assert((VirtualBase || NonZeroOffset) &&
819          "Should have returned if has non-virtual base with zero offset");
820 
821   QualType BaseType =
822       ReinterpretKind == ReinterpretUpcast? DestType : SrcType;
823   QualType DerivedType =
824       ReinterpretKind == ReinterpretUpcast? SrcType : DestType;
825 
826   SourceLocation BeginLoc = OpRange.getBegin();
827   Self.Diag(BeginLoc, diag::warn_reinterpret_different_from_static)
828     << DerivedType << BaseType << !VirtualBase << int(ReinterpretKind)
829     << OpRange;
830   Self.Diag(BeginLoc, diag::note_reinterpret_updowncast_use_static)
831     << int(ReinterpretKind)
832     << FixItHint::CreateReplacement(BeginLoc, "static_cast");
833 }
834 
835 /// CheckReinterpretCast - Check that a reinterpret_cast\<DestType\>(SrcExpr) is
836 /// valid.
837 /// Refer to C++ 5.2.10 for details. reinterpret_cast is typically used in code
838 /// like this:
839 /// char *bytes = reinterpret_cast\<char*\>(int_ptr);
840 void CastOperation::CheckReinterpretCast() {
841   if (ValueKind == VK_RValue && !isPlaceholder(BuiltinType::Overload))
842     SrcExpr = Self.DefaultFunctionArrayLvalueConversion(SrcExpr.get());
843   else
844     checkNonOverloadPlaceholders();
845   if (SrcExpr.isInvalid()) // if conversion failed, don't report another error
846     return;
847 
848   unsigned msg = diag::err_bad_cxx_cast_generic;
849   TryCastResult tcr =
850     TryReinterpretCast(Self, SrcExpr, DestType,
851                        /*CStyle*/false, OpRange, msg, Kind);
852   if (tcr != TC_Success && msg != 0)
853   {
854     if (SrcExpr.isInvalid()) // if conversion failed, don't report another error
855       return;
856     if (SrcExpr.get()->getType() == Self.Context.OverloadTy) {
857       //FIXME: &f<int>; is overloaded and resolvable
858       Self.Diag(OpRange.getBegin(), diag::err_bad_reinterpret_cast_overload)
859         << OverloadExpr::find(SrcExpr.get()).Expression->getName()
860         << DestType << OpRange;
861       Self.NoteAllOverloadCandidates(SrcExpr.get());
862 
863     } else {
864       diagnoseBadCast(Self, msg, CT_Reinterpret, OpRange, SrcExpr.get(),
865                       DestType, /*listInitialization=*/false);
866     }
867     SrcExpr = ExprError();
868   } else if (tcr == TC_Success) {
869     if (Self.getLangOpts().ObjCAutoRefCount)
870       checkObjCARCConversion(Sema::CCK_OtherCast);
871     DiagnoseReinterpretUpDownCast(Self, SrcExpr.get(), DestType, OpRange);
872   }
873 }
874 
875 
876 /// CheckStaticCast - Check that a static_cast\<DestType\>(SrcExpr) is valid.
877 /// Refer to C++ 5.2.9 for details. Static casts are mostly used for making
878 /// implicit conversions explicit and getting rid of data loss warnings.
879 void CastOperation::CheckStaticCast() {
880   if (isPlaceholder()) {
881     checkNonOverloadPlaceholders();
882     if (SrcExpr.isInvalid())
883       return;
884   }
885 
886   // This test is outside everything else because it's the only case where
887   // a non-lvalue-reference target type does not lead to decay.
888   // C++ 5.2.9p4: Any expression can be explicitly converted to type "cv void".
889   if (DestType->isVoidType()) {
890     Kind = CK_ToVoid;
891 
892     if (claimPlaceholder(BuiltinType::Overload)) {
893       Self.ResolveAndFixSingleFunctionTemplateSpecialization(SrcExpr,
894                 false, // Decay Function to ptr
895                 true, // Complain
896                 OpRange, DestType, diag::err_bad_static_cast_overload);
897       if (SrcExpr.isInvalid())
898         return;
899     }
900 
901     SrcExpr = Self.IgnoredValueConversions(SrcExpr.get());
902     return;
903   }
904 
905   if (ValueKind == VK_RValue && !DestType->isRecordType() &&
906       !isPlaceholder(BuiltinType::Overload)) {
907     SrcExpr = Self.DefaultFunctionArrayLvalueConversion(SrcExpr.get());
908     if (SrcExpr.isInvalid()) // if conversion failed, don't report another error
909       return;
910   }
911 
912   unsigned msg = diag::err_bad_cxx_cast_generic;
913   TryCastResult tcr
914     = TryStaticCast(Self, SrcExpr, DestType, Sema::CCK_OtherCast, OpRange, msg,
915                     Kind, BasePath, /*ListInitialization=*/false);
916   if (tcr != TC_Success && msg != 0) {
917     if (SrcExpr.isInvalid())
918       return;
919     if (SrcExpr.get()->getType() == Self.Context.OverloadTy) {
920       OverloadExpr* oe = OverloadExpr::find(SrcExpr.get()).Expression;
921       Self.Diag(OpRange.getBegin(), diag::err_bad_static_cast_overload)
922         << oe->getName() << DestType << OpRange
923         << oe->getQualifierLoc().getSourceRange();
924       Self.NoteAllOverloadCandidates(SrcExpr.get());
925     } else {
926       diagnoseBadCast(Self, msg, CT_Static, OpRange, SrcExpr.get(), DestType,
927                       /*listInitialization=*/false);
928     }
929     SrcExpr = ExprError();
930   } else if (tcr == TC_Success) {
931     if (Kind == CK_BitCast)
932       checkCastAlign();
933     if (Self.getLangOpts().ObjCAutoRefCount)
934       checkObjCARCConversion(Sema::CCK_OtherCast);
935   } else if (Kind == CK_BitCast) {
936     checkCastAlign();
937   }
938 }
939 
940 /// TryStaticCast - Check if a static cast can be performed, and do so if
941 /// possible. If @p CStyle, ignore access restrictions on hierarchy casting
942 /// and casting away constness.
943 static TryCastResult TryStaticCast(Sema &Self, ExprResult &SrcExpr,
944                                    QualType DestType,
945                                    Sema::CheckedConversionKind CCK,
946                                    const SourceRange &OpRange, unsigned &msg,
947                                    CastKind &Kind, CXXCastPath &BasePath,
948                                    bool ListInitialization) {
949   // Determine whether we have the semantics of a C-style cast.
950   bool CStyle
951     = (CCK == Sema::CCK_CStyleCast || CCK == Sema::CCK_FunctionalCast);
952 
953   // The order the tests is not entirely arbitrary. There is one conversion
954   // that can be handled in two different ways. Given:
955   // struct A {};
956   // struct B : public A {
957   //   B(); B(const A&);
958   // };
959   // const A &a = B();
960   // the cast static_cast<const B&>(a) could be seen as either a static
961   // reference downcast, or an explicit invocation of the user-defined
962   // conversion using B's conversion constructor.
963   // DR 427 specifies that the downcast is to be applied here.
964 
965   // C++ 5.2.9p4: Any expression can be explicitly converted to type "cv void".
966   // Done outside this function.
967 
968   TryCastResult tcr;
969 
970   // C++ 5.2.9p5, reference downcast.
971   // See the function for details.
972   // DR 427 specifies that this is to be applied before paragraph 2.
973   tcr = TryStaticReferenceDowncast(Self, SrcExpr.get(), DestType, CStyle,
974                                    OpRange, msg, Kind, BasePath);
975   if (tcr != TC_NotApplicable)
976     return tcr;
977 
978   // C++0x [expr.static.cast]p3:
979   //   A glvalue of type "cv1 T1" can be cast to type "rvalue reference to cv2
980   //   T2" if "cv2 T2" is reference-compatible with "cv1 T1".
981   tcr = TryLValueToRValueCast(Self, SrcExpr.get(), DestType, CStyle, Kind,
982                               BasePath, msg);
983   if (tcr != TC_NotApplicable)
984     return tcr;
985 
986   // C++ 5.2.9p2: An expression e can be explicitly converted to a type T
987   //   [...] if the declaration "T t(e);" is well-formed, [...].
988   tcr = TryStaticImplicitCast(Self, SrcExpr, DestType, CCK, OpRange, msg,
989                               Kind, ListInitialization);
990   if (SrcExpr.isInvalid())
991     return TC_Failed;
992   if (tcr != TC_NotApplicable)
993     return tcr;
994 
995   // C++ 5.2.9p6: May apply the reverse of any standard conversion, except
996   // lvalue-to-rvalue, array-to-pointer, function-to-pointer, and boolean
997   // conversions, subject to further restrictions.
998   // Also, C++ 5.2.9p1 forbids casting away constness, which makes reversal
999   // of qualification conversions impossible.
1000   // In the CStyle case, the earlier attempt to const_cast should have taken
1001   // care of reverse qualification conversions.
1002 
1003   QualType SrcType = Self.Context.getCanonicalType(SrcExpr.get()->getType());
1004 
1005   // C++0x 5.2.9p9: A value of a scoped enumeration type can be explicitly
1006   // converted to an integral type. [...] A value of a scoped enumeration type
1007   // can also be explicitly converted to a floating-point type [...].
1008   if (const EnumType *Enum = SrcType->getAs<EnumType>()) {
1009     if (Enum->getDecl()->isScoped()) {
1010       if (DestType->isBooleanType()) {
1011         Kind = CK_IntegralToBoolean;
1012         return TC_Success;
1013       } else if (DestType->isIntegralType(Self.Context)) {
1014         Kind = CK_IntegralCast;
1015         return TC_Success;
1016       } else if (DestType->isRealFloatingType()) {
1017         Kind = CK_IntegralToFloating;
1018         return TC_Success;
1019       }
1020     }
1021   }
1022 
1023   // Reverse integral promotion/conversion. All such conversions are themselves
1024   // again integral promotions or conversions and are thus already handled by
1025   // p2 (TryDirectInitialization above).
1026   // (Note: any data loss warnings should be suppressed.)
1027   // The exception is the reverse of enum->integer, i.e. integer->enum (and
1028   // enum->enum). See also C++ 5.2.9p7.
1029   // The same goes for reverse floating point promotion/conversion and
1030   // floating-integral conversions. Again, only floating->enum is relevant.
1031   if (DestType->isEnumeralType()) {
1032     if (SrcType->isIntegralOrEnumerationType()) {
1033       Kind = CK_IntegralCast;
1034       return TC_Success;
1035     } else if (SrcType->isRealFloatingType())   {
1036       Kind = CK_FloatingToIntegral;
1037       return TC_Success;
1038     }
1039   }
1040 
1041   // Reverse pointer upcast. C++ 4.10p3 specifies pointer upcast.
1042   // C++ 5.2.9p8 additionally disallows a cast path through virtual inheritance.
1043   tcr = TryStaticPointerDowncast(Self, SrcType, DestType, CStyle, OpRange, msg,
1044                                  Kind, BasePath);
1045   if (tcr != TC_NotApplicable)
1046     return tcr;
1047 
1048   // Reverse member pointer conversion. C++ 4.11 specifies member pointer
1049   // conversion. C++ 5.2.9p9 has additional information.
1050   // DR54's access restrictions apply here also.
1051   tcr = TryStaticMemberPointerUpcast(Self, SrcExpr, SrcType, DestType, CStyle,
1052                                      OpRange, msg, Kind, BasePath);
1053   if (tcr != TC_NotApplicable)
1054     return tcr;
1055 
1056   // Reverse pointer conversion to void*. C++ 4.10.p2 specifies conversion to
1057   // void*. C++ 5.2.9p10 specifies additional restrictions, which really is
1058   // just the usual constness stuff.
1059   if (const PointerType *SrcPointer = SrcType->getAs<PointerType>()) {
1060     QualType SrcPointee = SrcPointer->getPointeeType();
1061     if (SrcPointee->isVoidType()) {
1062       if (const PointerType *DestPointer = DestType->getAs<PointerType>()) {
1063         QualType DestPointee = DestPointer->getPointeeType();
1064         if (DestPointee->isIncompleteOrObjectType()) {
1065           // This is definitely the intended conversion, but it might fail due
1066           // to a qualifier violation. Note that we permit Objective-C lifetime
1067           // and GC qualifier mismatches here.
1068           if (!CStyle) {
1069             Qualifiers DestPointeeQuals = DestPointee.getQualifiers();
1070             Qualifiers SrcPointeeQuals = SrcPointee.getQualifiers();
1071             DestPointeeQuals.removeObjCGCAttr();
1072             DestPointeeQuals.removeObjCLifetime();
1073             SrcPointeeQuals.removeObjCGCAttr();
1074             SrcPointeeQuals.removeObjCLifetime();
1075             if (DestPointeeQuals != SrcPointeeQuals &&
1076                 !DestPointeeQuals.compatiblyIncludes(SrcPointeeQuals)) {
1077               msg = diag::err_bad_cxx_cast_qualifiers_away;
1078               return TC_Failed;
1079             }
1080           }
1081           Kind = CK_BitCast;
1082           return TC_Success;
1083         }
1084 
1085         // Microsoft permits static_cast from 'pointer-to-void' to
1086         // 'pointer-to-function'.
1087         if (Self.getLangOpts().MSVCCompat && DestPointee->isFunctionType()) {
1088           Self.Diag(OpRange.getBegin(), diag::ext_ms_cast_fn_obj) << OpRange;
1089           Kind = CK_BitCast;
1090           return TC_Success;
1091         }
1092       }
1093       else if (DestType->isObjCObjectPointerType()) {
1094         // allow both c-style cast and static_cast of objective-c pointers as
1095         // they are pervasive.
1096         Kind = CK_CPointerToObjCPointerCast;
1097         return TC_Success;
1098       }
1099       else if (CStyle && DestType->isBlockPointerType()) {
1100         // allow c-style cast of void * to block pointers.
1101         Kind = CK_AnyPointerToBlockPointerCast;
1102         return TC_Success;
1103       }
1104     }
1105   }
1106   // Allow arbitray objective-c pointer conversion with static casts.
1107   if (SrcType->isObjCObjectPointerType() &&
1108       DestType->isObjCObjectPointerType()) {
1109     Kind = CK_BitCast;
1110     return TC_Success;
1111   }
1112   // Allow ns-pointer to cf-pointer conversion in either direction
1113   // with static casts.
1114   if (!CStyle &&
1115       Self.CheckTollFreeBridgeStaticCast(DestType, SrcExpr.get(), Kind))
1116     return TC_Success;
1117 
1118   // See if it looks like the user is trying to convert between
1119   // related record types, and select a better diagnostic if so.
1120   if (auto SrcPointer = SrcType->getAs<PointerType>())
1121     if (auto DestPointer = DestType->getAs<PointerType>())
1122       if (SrcPointer->getPointeeType()->getAs<RecordType>() &&
1123           DestPointer->getPointeeType()->getAs<RecordType>())
1124        msg = diag::err_bad_cxx_cast_unrelated_class;
1125 
1126   // We tried everything. Everything! Nothing works! :-(
1127   return TC_NotApplicable;
1128 }
1129 
1130 /// Tests whether a conversion according to N2844 is valid.
1131 TryCastResult
1132 TryLValueToRValueCast(Sema &Self, Expr *SrcExpr, QualType DestType,
1133                       bool CStyle, CastKind &Kind, CXXCastPath &BasePath,
1134                       unsigned &msg) {
1135   // C++0x [expr.static.cast]p3:
1136   //   A glvalue of type "cv1 T1" can be cast to type "rvalue reference to
1137   //   cv2 T2" if "cv2 T2" is reference-compatible with "cv1 T1".
1138   const RValueReferenceType *R = DestType->getAs<RValueReferenceType>();
1139   if (!R)
1140     return TC_NotApplicable;
1141 
1142   if (!SrcExpr->isGLValue())
1143     return TC_NotApplicable;
1144 
1145   // Because we try the reference downcast before this function, from now on
1146   // this is the only cast possibility, so we issue an error if we fail now.
1147   // FIXME: Should allow casting away constness if CStyle.
1148   bool DerivedToBase;
1149   bool ObjCConversion;
1150   bool ObjCLifetimeConversion;
1151   QualType FromType = SrcExpr->getType();
1152   QualType ToType = R->getPointeeType();
1153   if (CStyle) {
1154     FromType = FromType.getUnqualifiedType();
1155     ToType = ToType.getUnqualifiedType();
1156   }
1157 
1158   if (Self.CompareReferenceRelationship(SrcExpr->getLocStart(),
1159                                         ToType, FromType,
1160                                         DerivedToBase, ObjCConversion,
1161                                         ObjCLifetimeConversion)
1162         < Sema::Ref_Compatible_With_Added_Qualification) {
1163     msg = diag::err_bad_lvalue_to_rvalue_cast;
1164     return TC_Failed;
1165   }
1166 
1167   if (DerivedToBase) {
1168     Kind = CK_DerivedToBase;
1169     CXXBasePaths Paths(/*FindAmbiguities=*/true, /*RecordPaths=*/true,
1170                        /*DetectVirtual=*/true);
1171     if (!Self.IsDerivedFrom(SrcExpr->getType(), R->getPointeeType(), Paths))
1172       return TC_NotApplicable;
1173 
1174     Self.BuildBasePathArray(Paths, BasePath);
1175   } else
1176     Kind = CK_NoOp;
1177 
1178   return TC_Success;
1179 }
1180 
1181 /// Tests whether a conversion according to C++ 5.2.9p5 is valid.
1182 TryCastResult
1183 TryStaticReferenceDowncast(Sema &Self, Expr *SrcExpr, QualType DestType,
1184                            bool CStyle, const SourceRange &OpRange,
1185                            unsigned &msg, CastKind &Kind,
1186                            CXXCastPath &BasePath) {
1187   // C++ 5.2.9p5: An lvalue of type "cv1 B", where B is a class type, can be
1188   //   cast to type "reference to cv2 D", where D is a class derived from B,
1189   //   if a valid standard conversion from "pointer to D" to "pointer to B"
1190   //   exists, cv2 >= cv1, and B is not a virtual base class of D.
1191   // In addition, DR54 clarifies that the base must be accessible in the
1192   // current context. Although the wording of DR54 only applies to the pointer
1193   // variant of this rule, the intent is clearly for it to apply to the this
1194   // conversion as well.
1195 
1196   const ReferenceType *DestReference = DestType->getAs<ReferenceType>();
1197   if (!DestReference) {
1198     return TC_NotApplicable;
1199   }
1200   bool RValueRef = DestReference->isRValueReferenceType();
1201   if (!RValueRef && !SrcExpr->isLValue()) {
1202     // We know the left side is an lvalue reference, so we can suggest a reason.
1203     msg = diag::err_bad_cxx_cast_rvalue;
1204     return TC_NotApplicable;
1205   }
1206 
1207   QualType DestPointee = DestReference->getPointeeType();
1208 
1209   // FIXME: If the source is a prvalue, we should issue a warning (because the
1210   // cast always has undefined behavior), and for AST consistency, we should
1211   // materialize a temporary.
1212   return TryStaticDowncast(Self,
1213                            Self.Context.getCanonicalType(SrcExpr->getType()),
1214                            Self.Context.getCanonicalType(DestPointee), CStyle,
1215                            OpRange, SrcExpr->getType(), DestType, msg, Kind,
1216                            BasePath);
1217 }
1218 
1219 /// Tests whether a conversion according to C++ 5.2.9p8 is valid.
1220 TryCastResult
1221 TryStaticPointerDowncast(Sema &Self, QualType SrcType, QualType DestType,
1222                          bool CStyle, const SourceRange &OpRange,
1223                          unsigned &msg, CastKind &Kind,
1224                          CXXCastPath &BasePath) {
1225   // C++ 5.2.9p8: An rvalue of type "pointer to cv1 B", where B is a class
1226   //   type, can be converted to an rvalue of type "pointer to cv2 D", where D
1227   //   is a class derived from B, if a valid standard conversion from "pointer
1228   //   to D" to "pointer to B" exists, cv2 >= cv1, and B is not a virtual base
1229   //   class of D.
1230   // In addition, DR54 clarifies that the base must be accessible in the
1231   // current context.
1232 
1233   const PointerType *DestPointer = DestType->getAs<PointerType>();
1234   if (!DestPointer) {
1235     return TC_NotApplicable;
1236   }
1237 
1238   const PointerType *SrcPointer = SrcType->getAs<PointerType>();
1239   if (!SrcPointer) {
1240     msg = diag::err_bad_static_cast_pointer_nonpointer;
1241     return TC_NotApplicable;
1242   }
1243 
1244   return TryStaticDowncast(Self,
1245                    Self.Context.getCanonicalType(SrcPointer->getPointeeType()),
1246                   Self.Context.getCanonicalType(DestPointer->getPointeeType()),
1247                            CStyle, OpRange, SrcType, DestType, msg, Kind,
1248                            BasePath);
1249 }
1250 
1251 /// TryStaticDowncast - Common functionality of TryStaticReferenceDowncast and
1252 /// TryStaticPointerDowncast. Tests whether a static downcast from SrcType to
1253 /// DestType is possible and allowed.
1254 TryCastResult
1255 TryStaticDowncast(Sema &Self, CanQualType SrcType, CanQualType DestType,
1256                   bool CStyle, const SourceRange &OpRange, QualType OrigSrcType,
1257                   QualType OrigDestType, unsigned &msg,
1258                   CastKind &Kind, CXXCastPath &BasePath) {
1259   // We can only work with complete types. But don't complain if it doesn't work
1260   if (Self.RequireCompleteType(OpRange.getBegin(), SrcType, 0) ||
1261       Self.RequireCompleteType(OpRange.getBegin(), DestType, 0))
1262     return TC_NotApplicable;
1263 
1264   // Downcast can only happen in class hierarchies, so we need classes.
1265   if (!DestType->getAs<RecordType>() || !SrcType->getAs<RecordType>()) {
1266     return TC_NotApplicable;
1267   }
1268 
1269   CXXBasePaths Paths(/*FindAmbiguities=*/true, /*RecordPaths=*/true,
1270                      /*DetectVirtual=*/true);
1271   if (!Self.IsDerivedFrom(DestType, SrcType, Paths)) {
1272     return TC_NotApplicable;
1273   }
1274 
1275   // Target type does derive from source type. Now we're serious. If an error
1276   // appears now, it's not ignored.
1277   // This may not be entirely in line with the standard. Take for example:
1278   // struct A {};
1279   // struct B : virtual A {
1280   //   B(A&);
1281   // };
1282   //
1283   // void f()
1284   // {
1285   //   (void)static_cast<const B&>(*((A*)0));
1286   // }
1287   // As far as the standard is concerned, p5 does not apply (A is virtual), so
1288   // p2 should be used instead - "const B& t(*((A*)0));" is perfectly valid.
1289   // However, both GCC and Comeau reject this example, and accepting it would
1290   // mean more complex code if we're to preserve the nice error message.
1291   // FIXME: Being 100% compliant here would be nice to have.
1292 
1293   // Must preserve cv, as always, unless we're in C-style mode.
1294   if (!CStyle && !DestType.isAtLeastAsQualifiedAs(SrcType)) {
1295     msg = diag::err_bad_cxx_cast_qualifiers_away;
1296     return TC_Failed;
1297   }
1298 
1299   if (Paths.isAmbiguous(SrcType.getUnqualifiedType())) {
1300     // This code is analoguous to that in CheckDerivedToBaseConversion, except
1301     // that it builds the paths in reverse order.
1302     // To sum up: record all paths to the base and build a nice string from
1303     // them. Use it to spice up the error message.
1304     if (!Paths.isRecordingPaths()) {
1305       Paths.clear();
1306       Paths.setRecordingPaths(true);
1307       Self.IsDerivedFrom(DestType, SrcType, Paths);
1308     }
1309     std::string PathDisplayStr;
1310     std::set<unsigned> DisplayedPaths;
1311     for (CXXBasePaths::paths_iterator PI = Paths.begin(), PE = Paths.end();
1312          PI != PE; ++PI) {
1313       if (DisplayedPaths.insert(PI->back().SubobjectNumber).second) {
1314         // We haven't displayed a path to this particular base
1315         // class subobject yet.
1316         PathDisplayStr += "\n    ";
1317         for (CXXBasePath::const_reverse_iterator EI = PI->rbegin(),
1318                                                  EE = PI->rend();
1319              EI != EE; ++EI)
1320           PathDisplayStr += EI->Base->getType().getAsString() + " -> ";
1321         PathDisplayStr += QualType(DestType).getAsString();
1322       }
1323     }
1324 
1325     Self.Diag(OpRange.getBegin(), diag::err_ambiguous_base_to_derived_cast)
1326       << QualType(SrcType).getUnqualifiedType()
1327       << QualType(DestType).getUnqualifiedType()
1328       << PathDisplayStr << OpRange;
1329     msg = 0;
1330     return TC_Failed;
1331   }
1332 
1333   if (Paths.getDetectedVirtual() != nullptr) {
1334     QualType VirtualBase(Paths.getDetectedVirtual(), 0);
1335     Self.Diag(OpRange.getBegin(), diag::err_static_downcast_via_virtual)
1336       << OrigSrcType << OrigDestType << VirtualBase << OpRange;
1337     msg = 0;
1338     return TC_Failed;
1339   }
1340 
1341   if (!CStyle) {
1342     switch (Self.CheckBaseClassAccess(OpRange.getBegin(),
1343                                       SrcType, DestType,
1344                                       Paths.front(),
1345                                 diag::err_downcast_from_inaccessible_base)) {
1346     case Sema::AR_accessible:
1347     case Sema::AR_delayed:     // be optimistic
1348     case Sema::AR_dependent:   // be optimistic
1349       break;
1350 
1351     case Sema::AR_inaccessible:
1352       msg = 0;
1353       return TC_Failed;
1354     }
1355   }
1356 
1357   Self.BuildBasePathArray(Paths, BasePath);
1358   Kind = CK_BaseToDerived;
1359   return TC_Success;
1360 }
1361 
1362 /// TryStaticMemberPointerUpcast - Tests whether a conversion according to
1363 /// C++ 5.2.9p9 is valid:
1364 ///
1365 ///   An rvalue of type "pointer to member of D of type cv1 T" can be
1366 ///   converted to an rvalue of type "pointer to member of B of type cv2 T",
1367 ///   where B is a base class of D [...].
1368 ///
1369 TryCastResult
1370 TryStaticMemberPointerUpcast(Sema &Self, ExprResult &SrcExpr, QualType SrcType,
1371                              QualType DestType, bool CStyle,
1372                              const SourceRange &OpRange,
1373                              unsigned &msg, CastKind &Kind,
1374                              CXXCastPath &BasePath) {
1375   const MemberPointerType *DestMemPtr = DestType->getAs<MemberPointerType>();
1376   if (!DestMemPtr)
1377     return TC_NotApplicable;
1378 
1379   bool WasOverloadedFunction = false;
1380   DeclAccessPair FoundOverload;
1381   if (SrcExpr.get()->getType() == Self.Context.OverloadTy) {
1382     if (FunctionDecl *Fn
1383           = Self.ResolveAddressOfOverloadedFunction(SrcExpr.get(), DestType, false,
1384                                                     FoundOverload)) {
1385       CXXMethodDecl *M = cast<CXXMethodDecl>(Fn);
1386       SrcType = Self.Context.getMemberPointerType(Fn->getType(),
1387                       Self.Context.getTypeDeclType(M->getParent()).getTypePtr());
1388       WasOverloadedFunction = true;
1389     }
1390   }
1391 
1392   const MemberPointerType *SrcMemPtr = SrcType->getAs<MemberPointerType>();
1393   if (!SrcMemPtr) {
1394     msg = diag::err_bad_static_cast_member_pointer_nonmp;
1395     return TC_NotApplicable;
1396   }
1397 
1398   // T == T, modulo cv
1399   if (!Self.Context.hasSameUnqualifiedType(SrcMemPtr->getPointeeType(),
1400                                            DestMemPtr->getPointeeType()))
1401     return TC_NotApplicable;
1402 
1403   // B base of D
1404   QualType SrcClass(SrcMemPtr->getClass(), 0);
1405   QualType DestClass(DestMemPtr->getClass(), 0);
1406   CXXBasePaths Paths(/*FindAmbiguities=*/true, /*RecordPaths=*/true,
1407                   /*DetectVirtual=*/true);
1408   if (Self.RequireCompleteType(OpRange.getBegin(), SrcClass, 0) ||
1409       !Self.IsDerivedFrom(SrcClass, DestClass, Paths)) {
1410     return TC_NotApplicable;
1411   }
1412 
1413   // B is a base of D. But is it an allowed base? If not, it's a hard error.
1414   if (Paths.isAmbiguous(Self.Context.getCanonicalType(DestClass))) {
1415     Paths.clear();
1416     Paths.setRecordingPaths(true);
1417     bool StillOkay = Self.IsDerivedFrom(SrcClass, DestClass, Paths);
1418     assert(StillOkay);
1419     (void)StillOkay;
1420     std::string PathDisplayStr = Self.getAmbiguousPathsDisplayString(Paths);
1421     Self.Diag(OpRange.getBegin(), diag::err_ambiguous_memptr_conv)
1422       << 1 << SrcClass << DestClass << PathDisplayStr << OpRange;
1423     msg = 0;
1424     return TC_Failed;
1425   }
1426 
1427   if (const RecordType *VBase = Paths.getDetectedVirtual()) {
1428     Self.Diag(OpRange.getBegin(), diag::err_memptr_conv_via_virtual)
1429       << SrcClass << DestClass << QualType(VBase, 0) << OpRange;
1430     msg = 0;
1431     return TC_Failed;
1432   }
1433 
1434   if (!CStyle) {
1435     switch (Self.CheckBaseClassAccess(OpRange.getBegin(),
1436                                       DestClass, SrcClass,
1437                                       Paths.front(),
1438                                       diag::err_upcast_to_inaccessible_base)) {
1439     case Sema::AR_accessible:
1440     case Sema::AR_delayed:
1441     case Sema::AR_dependent:
1442       // Optimistically assume that the delayed and dependent cases
1443       // will work out.
1444       break;
1445 
1446     case Sema::AR_inaccessible:
1447       msg = 0;
1448       return TC_Failed;
1449     }
1450   }
1451 
1452   if (WasOverloadedFunction) {
1453     // Resolve the address of the overloaded function again, this time
1454     // allowing complaints if something goes wrong.
1455     FunctionDecl *Fn = Self.ResolveAddressOfOverloadedFunction(SrcExpr.get(),
1456                                                                DestType,
1457                                                                true,
1458                                                                FoundOverload);
1459     if (!Fn) {
1460       msg = 0;
1461       return TC_Failed;
1462     }
1463 
1464     SrcExpr = Self.FixOverloadedFunctionReference(SrcExpr, FoundOverload, Fn);
1465     if (!SrcExpr.isUsable()) {
1466       msg = 0;
1467       return TC_Failed;
1468     }
1469   }
1470 
1471   Self.BuildBasePathArray(Paths, BasePath);
1472   Kind = CK_DerivedToBaseMemberPointer;
1473   return TC_Success;
1474 }
1475 
1476 /// TryStaticImplicitCast - Tests whether a conversion according to C++ 5.2.9p2
1477 /// is valid:
1478 ///
1479 ///   An expression e can be explicitly converted to a type T using a
1480 ///   @c static_cast if the declaration "T t(e);" is well-formed [...].
1481 TryCastResult
1482 TryStaticImplicitCast(Sema &Self, ExprResult &SrcExpr, QualType DestType,
1483                       Sema::CheckedConversionKind CCK,
1484                       const SourceRange &OpRange, unsigned &msg,
1485                       CastKind &Kind, bool ListInitialization) {
1486   if (DestType->isRecordType()) {
1487     if (Self.RequireCompleteType(OpRange.getBegin(), DestType,
1488                                  diag::err_bad_dynamic_cast_incomplete) ||
1489         Self.RequireNonAbstractType(OpRange.getBegin(), DestType,
1490                                     diag::err_allocation_of_abstract_type)) {
1491       msg = 0;
1492       return TC_Failed;
1493     }
1494   } else if (DestType->isMemberPointerType()) {
1495     if (Self.Context.getTargetInfo().getCXXABI().isMicrosoft()) {
1496       Self.RequireCompleteType(OpRange.getBegin(), DestType, 0);
1497     }
1498   }
1499 
1500   InitializedEntity Entity = InitializedEntity::InitializeTemporary(DestType);
1501   InitializationKind InitKind
1502     = (CCK == Sema::CCK_CStyleCast)
1503         ? InitializationKind::CreateCStyleCast(OpRange.getBegin(), OpRange,
1504                                                ListInitialization)
1505     : (CCK == Sema::CCK_FunctionalCast)
1506         ? InitializationKind::CreateFunctionalCast(OpRange, ListInitialization)
1507     : InitializationKind::CreateCast(OpRange);
1508   Expr *SrcExprRaw = SrcExpr.get();
1509   InitializationSequence InitSeq(Self, Entity, InitKind, SrcExprRaw);
1510 
1511   // At this point of CheckStaticCast, if the destination is a reference,
1512   // or the expression is an overload expression this has to work.
1513   // There is no other way that works.
1514   // On the other hand, if we're checking a C-style cast, we've still got
1515   // the reinterpret_cast way.
1516   bool CStyle
1517     = (CCK == Sema::CCK_CStyleCast || CCK == Sema::CCK_FunctionalCast);
1518   if (InitSeq.Failed() && (CStyle || !DestType->isReferenceType()))
1519     return TC_NotApplicable;
1520 
1521   ExprResult Result = InitSeq.Perform(Self, Entity, InitKind, SrcExprRaw);
1522   if (Result.isInvalid()) {
1523     msg = 0;
1524     return TC_Failed;
1525   }
1526 
1527   if (InitSeq.isConstructorInitialization())
1528     Kind = CK_ConstructorConversion;
1529   else
1530     Kind = CK_NoOp;
1531 
1532   SrcExpr = Result;
1533   return TC_Success;
1534 }
1535 
1536 /// TryConstCast - See if a const_cast from source to destination is allowed,
1537 /// and perform it if it is.
1538 static TryCastResult TryConstCast(Sema &Self, ExprResult &SrcExpr,
1539                                   QualType DestType, bool CStyle,
1540                                   unsigned &msg) {
1541   DestType = Self.Context.getCanonicalType(DestType);
1542   QualType SrcType = SrcExpr.get()->getType();
1543   bool NeedToMaterializeTemporary = false;
1544 
1545   if (const ReferenceType *DestTypeTmp =DestType->getAs<ReferenceType>()) {
1546     // C++11 5.2.11p4:
1547     //   if a pointer to T1 can be explicitly converted to the type "pointer to
1548     //   T2" using a const_cast, then the following conversions can also be
1549     //   made:
1550     //    -- an lvalue of type T1 can be explicitly converted to an lvalue of
1551     //       type T2 using the cast const_cast<T2&>;
1552     //    -- a glvalue of type T1 can be explicitly converted to an xvalue of
1553     //       type T2 using the cast const_cast<T2&&>; and
1554     //    -- if T1 is a class type, a prvalue of type T1 can be explicitly
1555     //       converted to an xvalue of type T2 using the cast const_cast<T2&&>.
1556 
1557     if (isa<LValueReferenceType>(DestTypeTmp) && !SrcExpr.get()->isLValue()) {
1558       // Cannot const_cast non-lvalue to lvalue reference type. But if this
1559       // is C-style, static_cast might find a way, so we simply suggest a
1560       // message and tell the parent to keep searching.
1561       msg = diag::err_bad_cxx_cast_rvalue;
1562       return TC_NotApplicable;
1563     }
1564 
1565     if (isa<RValueReferenceType>(DestTypeTmp) && SrcExpr.get()->isRValue()) {
1566       if (!SrcType->isRecordType()) {
1567         // Cannot const_cast non-class prvalue to rvalue reference type. But if
1568         // this is C-style, static_cast can do this.
1569         msg = diag::err_bad_cxx_cast_rvalue;
1570         return TC_NotApplicable;
1571       }
1572 
1573       // Materialize the class prvalue so that the const_cast can bind a
1574       // reference to it.
1575       NeedToMaterializeTemporary = true;
1576     }
1577 
1578     // It's not completely clear under the standard whether we can
1579     // const_cast bit-field gl-values.  Doing so would not be
1580     // intrinsically complicated, but for now, we say no for
1581     // consistency with other compilers and await the word of the
1582     // committee.
1583     if (SrcExpr.get()->refersToBitField()) {
1584       msg = diag::err_bad_cxx_cast_bitfield;
1585       return TC_NotApplicable;
1586     }
1587 
1588     DestType = Self.Context.getPointerType(DestTypeTmp->getPointeeType());
1589     SrcType = Self.Context.getPointerType(SrcType);
1590   }
1591 
1592   // C++ 5.2.11p5: For a const_cast involving pointers to data members [...]
1593   //   the rules for const_cast are the same as those used for pointers.
1594 
1595   if (!DestType->isPointerType() &&
1596       !DestType->isMemberPointerType() &&
1597       !DestType->isObjCObjectPointerType()) {
1598     // Cannot cast to non-pointer, non-reference type. Note that, if DestType
1599     // was a reference type, we converted it to a pointer above.
1600     // The status of rvalue references isn't entirely clear, but it looks like
1601     // conversion to them is simply invalid.
1602     // C++ 5.2.11p3: For two pointer types [...]
1603     if (!CStyle)
1604       msg = diag::err_bad_const_cast_dest;
1605     return TC_NotApplicable;
1606   }
1607   if (DestType->isFunctionPointerType() ||
1608       DestType->isMemberFunctionPointerType()) {
1609     // Cannot cast direct function pointers.
1610     // C++ 5.2.11p2: [...] where T is any object type or the void type [...]
1611     // T is the ultimate pointee of source and target type.
1612     if (!CStyle)
1613       msg = diag::err_bad_const_cast_dest;
1614     return TC_NotApplicable;
1615   }
1616   SrcType = Self.Context.getCanonicalType(SrcType);
1617 
1618   // Unwrap the pointers. Ignore qualifiers. Terminate early if the types are
1619   // completely equal.
1620   // C++ 5.2.11p3 describes the core semantics of const_cast. All cv specifiers
1621   // in multi-level pointers may change, but the level count must be the same,
1622   // as must be the final pointee type.
1623   while (SrcType != DestType &&
1624          Self.Context.UnwrapSimilarPointerTypes(SrcType, DestType)) {
1625     Qualifiers SrcQuals, DestQuals;
1626     SrcType = Self.Context.getUnqualifiedArrayType(SrcType, SrcQuals);
1627     DestType = Self.Context.getUnqualifiedArrayType(DestType, DestQuals);
1628 
1629     // const_cast is permitted to strip cvr-qualifiers, only. Make sure that
1630     // the other qualifiers (e.g., address spaces) are identical.
1631     SrcQuals.removeCVRQualifiers();
1632     DestQuals.removeCVRQualifiers();
1633     if (SrcQuals != DestQuals)
1634       return TC_NotApplicable;
1635   }
1636 
1637   // Since we're dealing in canonical types, the remainder must be the same.
1638   if (SrcType != DestType)
1639     return TC_NotApplicable;
1640 
1641   if (NeedToMaterializeTemporary)
1642     // This is a const_cast from a class prvalue to an rvalue reference type.
1643     // Materialize a temporary to store the result of the conversion.
1644     SrcExpr = new (Self.Context) MaterializeTemporaryExpr(
1645         SrcType, SrcExpr.get(), /*IsLValueReference*/ false);
1646 
1647   return TC_Success;
1648 }
1649 
1650 // Checks for undefined behavior in reinterpret_cast.
1651 // The cases that is checked for is:
1652 // *reinterpret_cast<T*>(&a)
1653 // reinterpret_cast<T&>(a)
1654 // where accessing 'a' as type 'T' will result in undefined behavior.
1655 void Sema::CheckCompatibleReinterpretCast(QualType SrcType, QualType DestType,
1656                                           bool IsDereference,
1657                                           SourceRange Range) {
1658   unsigned DiagID = IsDereference ?
1659                         diag::warn_pointer_indirection_from_incompatible_type :
1660                         diag::warn_undefined_reinterpret_cast;
1661 
1662   if (Diags.isIgnored(DiagID, Range.getBegin()))
1663     return;
1664 
1665   QualType SrcTy, DestTy;
1666   if (IsDereference) {
1667     if (!SrcType->getAs<PointerType>() || !DestType->getAs<PointerType>()) {
1668       return;
1669     }
1670     SrcTy = SrcType->getPointeeType();
1671     DestTy = DestType->getPointeeType();
1672   } else {
1673     if (!DestType->getAs<ReferenceType>()) {
1674       return;
1675     }
1676     SrcTy = SrcType;
1677     DestTy = DestType->getPointeeType();
1678   }
1679 
1680   // Cast is compatible if the types are the same.
1681   if (Context.hasSameUnqualifiedType(DestTy, SrcTy)) {
1682     return;
1683   }
1684   // or one of the types is a char or void type
1685   if (DestTy->isAnyCharacterType() || DestTy->isVoidType() ||
1686       SrcTy->isAnyCharacterType() || SrcTy->isVoidType()) {
1687     return;
1688   }
1689   // or one of the types is a tag type.
1690   if (SrcTy->getAs<TagType>() || DestTy->getAs<TagType>()) {
1691     return;
1692   }
1693 
1694   // FIXME: Scoped enums?
1695   if ((SrcTy->isUnsignedIntegerType() && DestTy->isSignedIntegerType()) ||
1696       (SrcTy->isSignedIntegerType() && DestTy->isUnsignedIntegerType())) {
1697     if (Context.getTypeSize(DestTy) == Context.getTypeSize(SrcTy)) {
1698       return;
1699     }
1700   }
1701 
1702   Diag(Range.getBegin(), DiagID) << SrcType << DestType << Range;
1703 }
1704 
1705 static void DiagnoseCastOfObjCSEL(Sema &Self, const ExprResult &SrcExpr,
1706                                   QualType DestType) {
1707   QualType SrcType = SrcExpr.get()->getType();
1708   if (Self.Context.hasSameType(SrcType, DestType))
1709     return;
1710   if (const PointerType *SrcPtrTy = SrcType->getAs<PointerType>())
1711     if (SrcPtrTy->isObjCSelType()) {
1712       QualType DT = DestType;
1713       if (isa<PointerType>(DestType))
1714         DT = DestType->getPointeeType();
1715       if (!DT.getUnqualifiedType()->isVoidType())
1716         Self.Diag(SrcExpr.get()->getExprLoc(),
1717                   diag::warn_cast_pointer_from_sel)
1718         << SrcType << DestType << SrcExpr.get()->getSourceRange();
1719     }
1720 }
1721 
1722 static void checkIntToPointerCast(bool CStyle, SourceLocation Loc,
1723                                   const Expr *SrcExpr, QualType DestType,
1724                                   Sema &Self) {
1725   QualType SrcType = SrcExpr->getType();
1726 
1727   // Not warning on reinterpret_cast, boolean, constant expressions, etc
1728   // are not explicit design choices, but consistent with GCC's behavior.
1729   // Feel free to modify them if you've reason/evidence for an alternative.
1730   if (CStyle && SrcType->isIntegralType(Self.Context)
1731       && !SrcType->isBooleanType()
1732       && !SrcType->isEnumeralType()
1733       && !SrcExpr->isIntegerConstantExpr(Self.Context)
1734       && Self.Context.getTypeSize(DestType) >
1735          Self.Context.getTypeSize(SrcType)) {
1736     // Separate between casts to void* and non-void* pointers.
1737     // Some APIs use (abuse) void* for something like a user context,
1738     // and often that value is an integer even if it isn't a pointer itself.
1739     // Having a separate warning flag allows users to control the warning
1740     // for their workflow.
1741     unsigned Diag = DestType->isVoidPointerType() ?
1742                       diag::warn_int_to_void_pointer_cast
1743                     : diag::warn_int_to_pointer_cast;
1744     Self.Diag(Loc, Diag) << SrcType << DestType;
1745   }
1746 }
1747 
1748 static TryCastResult TryReinterpretCast(Sema &Self, ExprResult &SrcExpr,
1749                                         QualType DestType, bool CStyle,
1750                                         const SourceRange &OpRange,
1751                                         unsigned &msg,
1752                                         CastKind &Kind) {
1753   bool IsLValueCast = false;
1754 
1755   DestType = Self.Context.getCanonicalType(DestType);
1756   QualType SrcType = SrcExpr.get()->getType();
1757 
1758   // Is the source an overloaded name? (i.e. &foo)
1759   // If so, reinterpret_cast can not help us here (13.4, p1, bullet 5) ...
1760   if (SrcType == Self.Context.OverloadTy) {
1761     // ... unless foo<int> resolves to an lvalue unambiguously.
1762     // TODO: what if this fails because of DiagnoseUseOfDecl or something
1763     // like it?
1764     ExprResult SingleFunctionExpr = SrcExpr;
1765     if (Self.ResolveAndFixSingleFunctionTemplateSpecialization(
1766           SingleFunctionExpr,
1767           Expr::getValueKindForType(DestType) == VK_RValue // Convert Fun to Ptr
1768         ) && SingleFunctionExpr.isUsable()) {
1769       SrcExpr = SingleFunctionExpr;
1770       SrcType = SrcExpr.get()->getType();
1771     } else {
1772       return TC_NotApplicable;
1773     }
1774   }
1775 
1776   if (const ReferenceType *DestTypeTmp = DestType->getAs<ReferenceType>()) {
1777     if (!SrcExpr.get()->isGLValue()) {
1778       // Cannot cast non-glvalue to (lvalue or rvalue) reference type. See the
1779       // similar comment in const_cast.
1780       msg = diag::err_bad_cxx_cast_rvalue;
1781       return TC_NotApplicable;
1782     }
1783 
1784     if (!CStyle) {
1785       Self.CheckCompatibleReinterpretCast(SrcType, DestType,
1786                                           /*isDereference=*/false, OpRange);
1787     }
1788 
1789     // C++ 5.2.10p10: [...] a reference cast reinterpret_cast<T&>(x) has the
1790     //   same effect as the conversion *reinterpret_cast<T*>(&x) with the
1791     //   built-in & and * operators.
1792 
1793     const char *inappropriate = nullptr;
1794     switch (SrcExpr.get()->getObjectKind()) {
1795     case OK_Ordinary:
1796       break;
1797     case OK_BitField:        inappropriate = "bit-field";           break;
1798     case OK_VectorComponent: inappropriate = "vector element";      break;
1799     case OK_ObjCProperty:    inappropriate = "property expression"; break;
1800     case OK_ObjCSubscript:   inappropriate = "container subscripting expression";
1801                              break;
1802     }
1803     if (inappropriate) {
1804       Self.Diag(OpRange.getBegin(), diag::err_bad_reinterpret_cast_reference)
1805           << inappropriate << DestType
1806           << OpRange << SrcExpr.get()->getSourceRange();
1807       msg = 0; SrcExpr = ExprError();
1808       return TC_NotApplicable;
1809     }
1810 
1811     // This code does this transformation for the checked types.
1812     DestType = Self.Context.getPointerType(DestTypeTmp->getPointeeType());
1813     SrcType = Self.Context.getPointerType(SrcType);
1814 
1815     IsLValueCast = true;
1816   }
1817 
1818   // Canonicalize source for comparison.
1819   SrcType = Self.Context.getCanonicalType(SrcType);
1820 
1821   const MemberPointerType *DestMemPtr = DestType->getAs<MemberPointerType>(),
1822                           *SrcMemPtr = SrcType->getAs<MemberPointerType>();
1823   if (DestMemPtr && SrcMemPtr) {
1824     // C++ 5.2.10p9: An rvalue of type "pointer to member of X of type T1"
1825     //   can be explicitly converted to an rvalue of type "pointer to member
1826     //   of Y of type T2" if T1 and T2 are both function types or both object
1827     //   types.
1828     if (DestMemPtr->isMemberFunctionPointer() !=
1829         SrcMemPtr->isMemberFunctionPointer())
1830       return TC_NotApplicable;
1831 
1832     // C++ 5.2.10p2: The reinterpret_cast operator shall not cast away
1833     //   constness.
1834     // A reinterpret_cast followed by a const_cast can, though, so in C-style,
1835     // we accept it.
1836     if (CastsAwayConstness(Self, SrcType, DestType, /*CheckCVR=*/!CStyle,
1837                            /*CheckObjCLifetime=*/CStyle)) {
1838       msg = diag::err_bad_cxx_cast_qualifiers_away;
1839       return TC_Failed;
1840     }
1841 
1842     if (Self.Context.getTargetInfo().getCXXABI().isMicrosoft()) {
1843       // We need to determine the inheritance model that the class will use if
1844       // haven't yet.
1845       Self.RequireCompleteType(OpRange.getBegin(), SrcType, 0);
1846       Self.RequireCompleteType(OpRange.getBegin(), DestType, 0);
1847     }
1848 
1849     // Don't allow casting between member pointers of different sizes.
1850     if (Self.Context.getTypeSize(DestMemPtr) !=
1851         Self.Context.getTypeSize(SrcMemPtr)) {
1852       msg = diag::err_bad_cxx_cast_member_pointer_size;
1853       return TC_Failed;
1854     }
1855 
1856     // A valid member pointer cast.
1857     assert(!IsLValueCast);
1858     Kind = CK_ReinterpretMemberPointer;
1859     return TC_Success;
1860   }
1861 
1862   // See below for the enumeral issue.
1863   if (SrcType->isNullPtrType() && DestType->isIntegralType(Self.Context)) {
1864     // C++0x 5.2.10p4: A pointer can be explicitly converted to any integral
1865     //   type large enough to hold it. A value of std::nullptr_t can be
1866     //   converted to an integral type; the conversion has the same meaning
1867     //   and validity as a conversion of (void*)0 to the integral type.
1868     if (Self.Context.getTypeSize(SrcType) >
1869         Self.Context.getTypeSize(DestType)) {
1870       msg = diag::err_bad_reinterpret_cast_small_int;
1871       return TC_Failed;
1872     }
1873     Kind = CK_PointerToIntegral;
1874     return TC_Success;
1875   }
1876 
1877   bool destIsVector = DestType->isVectorType();
1878   bool srcIsVector = SrcType->isVectorType();
1879   if (srcIsVector || destIsVector) {
1880     // FIXME: Should this also apply to floating point types?
1881     bool srcIsScalar = SrcType->isIntegralType(Self.Context);
1882     bool destIsScalar = DestType->isIntegralType(Self.Context);
1883 
1884     // Check if this is a cast between a vector and something else.
1885     if (!(srcIsScalar && destIsVector) && !(srcIsVector && destIsScalar) &&
1886         !(srcIsVector && destIsVector))
1887       return TC_NotApplicable;
1888 
1889     // If both types have the same size, we can successfully cast.
1890     if (Self.Context.getTypeSize(SrcType)
1891           == Self.Context.getTypeSize(DestType)) {
1892       Kind = CK_BitCast;
1893       return TC_Success;
1894     }
1895 
1896     if (destIsScalar)
1897       msg = diag::err_bad_cxx_cast_vector_to_scalar_different_size;
1898     else if (srcIsScalar)
1899       msg = diag::err_bad_cxx_cast_scalar_to_vector_different_size;
1900     else
1901       msg = diag::err_bad_cxx_cast_vector_to_vector_different_size;
1902 
1903     return TC_Failed;
1904   }
1905 
1906   if (SrcType == DestType) {
1907     // C++ 5.2.10p2 has a note that mentions that, subject to all other
1908     // restrictions, a cast to the same type is allowed so long as it does not
1909     // cast away constness. In C++98, the intent was not entirely clear here,
1910     // since all other paragraphs explicitly forbid casts to the same type.
1911     // C++11 clarifies this case with p2.
1912     //
1913     // The only allowed types are: integral, enumeration, pointer, or
1914     // pointer-to-member types.  We also won't restrict Obj-C pointers either.
1915     Kind = CK_NoOp;
1916     TryCastResult Result = TC_NotApplicable;
1917     if (SrcType->isIntegralOrEnumerationType() ||
1918         SrcType->isAnyPointerType() ||
1919         SrcType->isMemberPointerType() ||
1920         SrcType->isBlockPointerType()) {
1921       Result = TC_Success;
1922     }
1923     return Result;
1924   }
1925 
1926   bool destIsPtr = DestType->isAnyPointerType() ||
1927                    DestType->isBlockPointerType();
1928   bool srcIsPtr = SrcType->isAnyPointerType() ||
1929                   SrcType->isBlockPointerType();
1930   if (!destIsPtr && !srcIsPtr) {
1931     // Except for std::nullptr_t->integer and lvalue->reference, which are
1932     // handled above, at least one of the two arguments must be a pointer.
1933     return TC_NotApplicable;
1934   }
1935 
1936   if (DestType->isIntegralType(Self.Context)) {
1937     assert(srcIsPtr && "One type must be a pointer");
1938     // C++ 5.2.10p4: A pointer can be explicitly converted to any integral
1939     //   type large enough to hold it; except in Microsoft mode, where the
1940     //   integral type size doesn't matter (except we don't allow bool).
1941     bool MicrosoftException = Self.getLangOpts().MicrosoftExt &&
1942                               !DestType->isBooleanType();
1943     if ((Self.Context.getTypeSize(SrcType) >
1944          Self.Context.getTypeSize(DestType)) &&
1945          !MicrosoftException) {
1946       msg = diag::err_bad_reinterpret_cast_small_int;
1947       return TC_Failed;
1948     }
1949     Kind = CK_PointerToIntegral;
1950     return TC_Success;
1951   }
1952 
1953   if (SrcType->isIntegralOrEnumerationType()) {
1954     assert(destIsPtr && "One type must be a pointer");
1955     checkIntToPointerCast(CStyle, OpRange.getBegin(), SrcExpr.get(), DestType,
1956                           Self);
1957     // C++ 5.2.10p5: A value of integral or enumeration type can be explicitly
1958     //   converted to a pointer.
1959     // C++ 5.2.10p9: [Note: ...a null pointer constant of integral type is not
1960     //   necessarily converted to a null pointer value.]
1961     Kind = CK_IntegralToPointer;
1962     return TC_Success;
1963   }
1964 
1965   if (!destIsPtr || !srcIsPtr) {
1966     // With the valid non-pointer conversions out of the way, we can be even
1967     // more stringent.
1968     return TC_NotApplicable;
1969   }
1970 
1971   // C++ 5.2.10p2: The reinterpret_cast operator shall not cast away constness.
1972   // The C-style cast operator can.
1973   if (CastsAwayConstness(Self, SrcType, DestType, /*CheckCVR=*/!CStyle,
1974                          /*CheckObjCLifetime=*/CStyle)) {
1975     msg = diag::err_bad_cxx_cast_qualifiers_away;
1976     return TC_Failed;
1977   }
1978 
1979   // Cannot convert between block pointers and Objective-C object pointers.
1980   if ((SrcType->isBlockPointerType() && DestType->isObjCObjectPointerType()) ||
1981       (DestType->isBlockPointerType() && SrcType->isObjCObjectPointerType()))
1982     return TC_NotApplicable;
1983 
1984   if (IsLValueCast) {
1985     Kind = CK_LValueBitCast;
1986   } else if (DestType->isObjCObjectPointerType()) {
1987     Kind = Self.PrepareCastToObjCObjectPointer(SrcExpr);
1988   } else if (DestType->isBlockPointerType()) {
1989     if (!SrcType->isBlockPointerType()) {
1990       Kind = CK_AnyPointerToBlockPointerCast;
1991     } else {
1992       Kind = CK_BitCast;
1993     }
1994   } else {
1995     Kind = CK_BitCast;
1996   }
1997 
1998   // Any pointer can be cast to an Objective-C pointer type with a C-style
1999   // cast.
2000   if (CStyle && DestType->isObjCObjectPointerType()) {
2001     return TC_Success;
2002   }
2003   if (CStyle)
2004     DiagnoseCastOfObjCSEL(Self, SrcExpr, DestType);
2005 
2006   // Not casting away constness, so the only remaining check is for compatible
2007   // pointer categories.
2008 
2009   if (SrcType->isFunctionPointerType()) {
2010     if (DestType->isFunctionPointerType()) {
2011       // C++ 5.2.10p6: A pointer to a function can be explicitly converted to
2012       // a pointer to a function of a different type.
2013       return TC_Success;
2014     }
2015 
2016     // C++0x 5.2.10p8: Converting a pointer to a function into a pointer to
2017     //   an object type or vice versa is conditionally-supported.
2018     // Compilers support it in C++03 too, though, because it's necessary for
2019     // casting the return value of dlsym() and GetProcAddress().
2020     // FIXME: Conditionally-supported behavior should be configurable in the
2021     // TargetInfo or similar.
2022     Self.Diag(OpRange.getBegin(),
2023               Self.getLangOpts().CPlusPlus11 ?
2024                 diag::warn_cxx98_compat_cast_fn_obj : diag::ext_cast_fn_obj)
2025       << OpRange;
2026     return TC_Success;
2027   }
2028 
2029   if (DestType->isFunctionPointerType()) {
2030     // See above.
2031     Self.Diag(OpRange.getBegin(),
2032               Self.getLangOpts().CPlusPlus11 ?
2033                 diag::warn_cxx98_compat_cast_fn_obj : diag::ext_cast_fn_obj)
2034       << OpRange;
2035     return TC_Success;
2036   }
2037 
2038   // C++ 5.2.10p7: A pointer to an object can be explicitly converted to
2039   //   a pointer to an object of different type.
2040   // Void pointers are not specified, but supported by every compiler out there.
2041   // So we finish by allowing everything that remains - it's got to be two
2042   // object pointers.
2043   return TC_Success;
2044 }
2045 
2046 void CastOperation::CheckCXXCStyleCast(bool FunctionalStyle,
2047                                        bool ListInitialization) {
2048   // Handle placeholders.
2049   if (isPlaceholder()) {
2050     // C-style casts can resolve __unknown_any types.
2051     if (claimPlaceholder(BuiltinType::UnknownAny)) {
2052       SrcExpr = Self.checkUnknownAnyCast(DestRange, DestType,
2053                                          SrcExpr.get(), Kind,
2054                                          ValueKind, BasePath);
2055       return;
2056     }
2057 
2058     checkNonOverloadPlaceholders();
2059     if (SrcExpr.isInvalid())
2060       return;
2061   }
2062 
2063   // C++ 5.2.9p4: Any expression can be explicitly converted to type "cv void".
2064   // This test is outside everything else because it's the only case where
2065   // a non-lvalue-reference target type does not lead to decay.
2066   if (DestType->isVoidType()) {
2067     Kind = CK_ToVoid;
2068 
2069     if (claimPlaceholder(BuiltinType::Overload)) {
2070       Self.ResolveAndFixSingleFunctionTemplateSpecialization(
2071                   SrcExpr, /* Decay Function to ptr */ false,
2072                   /* Complain */ true, DestRange, DestType,
2073                   diag::err_bad_cstyle_cast_overload);
2074       if (SrcExpr.isInvalid())
2075         return;
2076     }
2077 
2078     SrcExpr = Self.IgnoredValueConversions(SrcExpr.get());
2079     return;
2080   }
2081 
2082   // If the type is dependent, we won't do any other semantic analysis now.
2083   if (DestType->isDependentType() || SrcExpr.get()->isTypeDependent() ||
2084       SrcExpr.get()->isValueDependent()) {
2085     assert(Kind == CK_Dependent);
2086     return;
2087   }
2088 
2089   if (ValueKind == VK_RValue && !DestType->isRecordType() &&
2090       !isPlaceholder(BuiltinType::Overload)) {
2091     SrcExpr = Self.DefaultFunctionArrayLvalueConversion(SrcExpr.get());
2092     if (SrcExpr.isInvalid())
2093       return;
2094   }
2095 
2096   // AltiVec vector initialization with a single literal.
2097   if (const VectorType *vecTy = DestType->getAs<VectorType>())
2098     if (vecTy->getVectorKind() == VectorType::AltiVecVector
2099         && (SrcExpr.get()->getType()->isIntegerType()
2100             || SrcExpr.get()->getType()->isFloatingType())) {
2101       Kind = CK_VectorSplat;
2102       return;
2103     }
2104 
2105   // C++ [expr.cast]p5: The conversions performed by
2106   //   - a const_cast,
2107   //   - a static_cast,
2108   //   - a static_cast followed by a const_cast,
2109   //   - a reinterpret_cast, or
2110   //   - a reinterpret_cast followed by a const_cast,
2111   //   can be performed using the cast notation of explicit type conversion.
2112   //   [...] If a conversion can be interpreted in more than one of the ways
2113   //   listed above, the interpretation that appears first in the list is used,
2114   //   even if a cast resulting from that interpretation is ill-formed.
2115   // In plain language, this means trying a const_cast ...
2116   unsigned msg = diag::err_bad_cxx_cast_generic;
2117   TryCastResult tcr = TryConstCast(Self, SrcExpr, DestType,
2118                                    /*CStyle*/true, msg);
2119   if (SrcExpr.isInvalid())
2120     return;
2121   if (tcr == TC_Success)
2122     Kind = CK_NoOp;
2123 
2124   Sema::CheckedConversionKind CCK
2125     = FunctionalStyle? Sema::CCK_FunctionalCast
2126                      : Sema::CCK_CStyleCast;
2127   if (tcr == TC_NotApplicable) {
2128     // ... or if that is not possible, a static_cast, ignoring const, ...
2129     tcr = TryStaticCast(Self, SrcExpr, DestType, CCK, OpRange,
2130                         msg, Kind, BasePath, ListInitialization);
2131     if (SrcExpr.isInvalid())
2132       return;
2133 
2134     if (tcr == TC_NotApplicable) {
2135       // ... and finally a reinterpret_cast, ignoring const.
2136       tcr = TryReinterpretCast(Self, SrcExpr, DestType, /*CStyle*/true,
2137                                OpRange, msg, Kind);
2138       if (SrcExpr.isInvalid())
2139         return;
2140     }
2141   }
2142 
2143   if (Self.getLangOpts().ObjCAutoRefCount && tcr == TC_Success)
2144     checkObjCARCConversion(CCK);
2145 
2146   if (tcr != TC_Success && msg != 0) {
2147     if (SrcExpr.get()->getType() == Self.Context.OverloadTy) {
2148       DeclAccessPair Found;
2149       FunctionDecl *Fn = Self.ResolveAddressOfOverloadedFunction(SrcExpr.get(),
2150                                 DestType,
2151                                 /*Complain*/ true,
2152                                 Found);
2153       if (Fn) {
2154         // If DestType is a function type (not to be confused with the function
2155         // pointer type), it will be possible to resolve the function address,
2156         // but the type cast should be considered as failure.
2157         OverloadExpr *OE = OverloadExpr::find(SrcExpr.get()).Expression;
2158         Self.Diag(OpRange.getBegin(), diag::err_bad_cstyle_cast_overload)
2159           << OE->getName() << DestType << OpRange
2160           << OE->getQualifierLoc().getSourceRange();
2161         Self.NoteAllOverloadCandidates(SrcExpr.get());
2162       }
2163     } else {
2164       diagnoseBadCast(Self, msg, (FunctionalStyle ? CT_Functional : CT_CStyle),
2165                       OpRange, SrcExpr.get(), DestType, ListInitialization);
2166     }
2167   } else if (Kind == CK_BitCast) {
2168     checkCastAlign();
2169   }
2170 
2171   // Clear out SrcExpr if there was a fatal error.
2172   if (tcr != TC_Success)
2173     SrcExpr = ExprError();
2174 }
2175 
2176 /// DiagnoseBadFunctionCast - Warn whenever a function call is cast to a
2177 ///  non-matching type. Such as enum function call to int, int call to
2178 /// pointer; etc. Cast to 'void' is an exception.
2179 static void DiagnoseBadFunctionCast(Sema &Self, const ExprResult &SrcExpr,
2180                                   QualType DestType) {
2181   if (Self.Diags.isIgnored(diag::warn_bad_function_cast,
2182                            SrcExpr.get()->getExprLoc()))
2183     return;
2184 
2185   if (!isa<CallExpr>(SrcExpr.get()))
2186     return;
2187 
2188   QualType SrcType = SrcExpr.get()->getType();
2189   if (DestType.getUnqualifiedType()->isVoidType())
2190     return;
2191   if ((SrcType->isAnyPointerType() || SrcType->isBlockPointerType())
2192       && (DestType->isAnyPointerType() || DestType->isBlockPointerType()))
2193     return;
2194   if (SrcType->isIntegerType() && DestType->isIntegerType() &&
2195       (SrcType->isBooleanType() == DestType->isBooleanType()) &&
2196       (SrcType->isEnumeralType() == DestType->isEnumeralType()))
2197     return;
2198   if (SrcType->isRealFloatingType() && DestType->isRealFloatingType())
2199     return;
2200   if (SrcType->isEnumeralType() && DestType->isEnumeralType())
2201     return;
2202   if (SrcType->isComplexType() && DestType->isComplexType())
2203     return;
2204   if (SrcType->isComplexIntegerType() && DestType->isComplexIntegerType())
2205     return;
2206 
2207   Self.Diag(SrcExpr.get()->getExprLoc(),
2208             diag::warn_bad_function_cast)
2209             << SrcType << DestType << SrcExpr.get()->getSourceRange();
2210 }
2211 
2212 /// Check the semantics of a C-style cast operation, in C.
2213 void CastOperation::CheckCStyleCast() {
2214   assert(!Self.getLangOpts().CPlusPlus);
2215 
2216   // C-style casts can resolve __unknown_any types.
2217   if (claimPlaceholder(BuiltinType::UnknownAny)) {
2218     SrcExpr = Self.checkUnknownAnyCast(DestRange, DestType,
2219                                        SrcExpr.get(), Kind,
2220                                        ValueKind, BasePath);
2221     return;
2222   }
2223 
2224   // C99 6.5.4p2: the cast type needs to be void or scalar and the expression
2225   // type needs to be scalar.
2226   if (DestType->isVoidType()) {
2227     // We don't necessarily do lvalue-to-rvalue conversions on this.
2228     SrcExpr = Self.IgnoredValueConversions(SrcExpr.get());
2229     if (SrcExpr.isInvalid())
2230       return;
2231 
2232     // Cast to void allows any expr type.
2233     Kind = CK_ToVoid;
2234     return;
2235   }
2236 
2237   SrcExpr = Self.DefaultFunctionArrayLvalueConversion(SrcExpr.get());
2238   if (SrcExpr.isInvalid())
2239     return;
2240   QualType SrcType = SrcExpr.get()->getType();
2241 
2242   assert(!SrcType->isPlaceholderType());
2243 
2244   // OpenCL v1 s6.5: Casting a pointer to address space A to a pointer to
2245   // address space B is illegal.
2246   if (Self.getLangOpts().OpenCL && DestType->isPointerType() &&
2247       SrcType->isPointerType()) {
2248     const PointerType *DestPtr = DestType->getAs<PointerType>();
2249     if (!DestPtr->isAddressSpaceOverlapping(*SrcType->getAs<PointerType>())) {
2250       Self.Diag(OpRange.getBegin(),
2251                 diag::err_typecheck_incompatible_address_space)
2252           << SrcType << DestType << Sema::AA_Casting
2253           << SrcExpr.get()->getSourceRange();
2254       SrcExpr = ExprError();
2255       return;
2256     }
2257   }
2258 
2259   if (Self.RequireCompleteType(OpRange.getBegin(), DestType,
2260                                diag::err_typecheck_cast_to_incomplete)) {
2261     SrcExpr = ExprError();
2262     return;
2263   }
2264 
2265   if (!DestType->isScalarType() && !DestType->isVectorType()) {
2266     const RecordType *DestRecordTy = DestType->getAs<RecordType>();
2267 
2268     if (DestRecordTy && Self.Context.hasSameUnqualifiedType(DestType, SrcType)){
2269       // GCC struct/union extension: allow cast to self.
2270       Self.Diag(OpRange.getBegin(), diag::ext_typecheck_cast_nonscalar)
2271         << DestType << SrcExpr.get()->getSourceRange();
2272       Kind = CK_NoOp;
2273       return;
2274     }
2275 
2276     // GCC's cast to union extension.
2277     if (DestRecordTy && DestRecordTy->getDecl()->isUnion()) {
2278       RecordDecl *RD = DestRecordTy->getDecl();
2279       RecordDecl::field_iterator Field, FieldEnd;
2280       for (Field = RD->field_begin(), FieldEnd = RD->field_end();
2281            Field != FieldEnd; ++Field) {
2282         if (Self.Context.hasSameUnqualifiedType(Field->getType(), SrcType) &&
2283             !Field->isUnnamedBitfield()) {
2284           Self.Diag(OpRange.getBegin(), diag::ext_typecheck_cast_to_union)
2285             << SrcExpr.get()->getSourceRange();
2286           break;
2287         }
2288       }
2289       if (Field == FieldEnd) {
2290         Self.Diag(OpRange.getBegin(), diag::err_typecheck_cast_to_union_no_type)
2291           << SrcType << SrcExpr.get()->getSourceRange();
2292         SrcExpr = ExprError();
2293         return;
2294       }
2295       Kind = CK_ToUnion;
2296       return;
2297     }
2298 
2299     // Reject any other conversions to non-scalar types.
2300     Self.Diag(OpRange.getBegin(), diag::err_typecheck_cond_expect_scalar)
2301       << DestType << SrcExpr.get()->getSourceRange();
2302     SrcExpr = ExprError();
2303     return;
2304   }
2305 
2306   // The type we're casting to is known to be a scalar or vector.
2307 
2308   // Require the operand to be a scalar or vector.
2309   if (!SrcType->isScalarType() && !SrcType->isVectorType()) {
2310     Self.Diag(SrcExpr.get()->getExprLoc(),
2311               diag::err_typecheck_expect_scalar_operand)
2312       << SrcType << SrcExpr.get()->getSourceRange();
2313     SrcExpr = ExprError();
2314     return;
2315   }
2316 
2317   if (DestType->isExtVectorType()) {
2318     SrcExpr = Self.CheckExtVectorCast(OpRange, DestType, SrcExpr.get(), Kind);
2319     return;
2320   }
2321 
2322   if (const VectorType *DestVecTy = DestType->getAs<VectorType>()) {
2323     if (DestVecTy->getVectorKind() == VectorType::AltiVecVector &&
2324           (SrcType->isIntegerType() || SrcType->isFloatingType())) {
2325       Kind = CK_VectorSplat;
2326     } else if (Self.CheckVectorCast(OpRange, DestType, SrcType, Kind)) {
2327       SrcExpr = ExprError();
2328     }
2329     return;
2330   }
2331 
2332   if (SrcType->isVectorType()) {
2333     if (Self.CheckVectorCast(OpRange, SrcType, DestType, Kind))
2334       SrcExpr = ExprError();
2335     return;
2336   }
2337 
2338   // The source and target types are both scalars, i.e.
2339   //   - arithmetic types (fundamental, enum, and complex)
2340   //   - all kinds of pointers
2341   // Note that member pointers were filtered out with C++, above.
2342 
2343   if (isa<ObjCSelectorExpr>(SrcExpr.get())) {
2344     Self.Diag(SrcExpr.get()->getExprLoc(), diag::err_cast_selector_expr);
2345     SrcExpr = ExprError();
2346     return;
2347   }
2348 
2349   // If either type is a pointer, the other type has to be either an
2350   // integer or a pointer.
2351   if (!DestType->isArithmeticType()) {
2352     if (!SrcType->isIntegralType(Self.Context) && SrcType->isArithmeticType()) {
2353       Self.Diag(SrcExpr.get()->getExprLoc(),
2354                 diag::err_cast_pointer_from_non_pointer_int)
2355         << SrcType << SrcExpr.get()->getSourceRange();
2356       SrcExpr = ExprError();
2357       return;
2358     }
2359     checkIntToPointerCast(/* CStyle */ true, OpRange.getBegin(), SrcExpr.get(),
2360                           DestType, Self);
2361   } else if (!SrcType->isArithmeticType()) {
2362     if (!DestType->isIntegralType(Self.Context) &&
2363         DestType->isArithmeticType()) {
2364       Self.Diag(SrcExpr.get()->getLocStart(),
2365            diag::err_cast_pointer_to_non_pointer_int)
2366         << DestType << SrcExpr.get()->getSourceRange();
2367       SrcExpr = ExprError();
2368       return;
2369     }
2370   }
2371 
2372   if (Self.getLangOpts().OpenCL && !Self.getOpenCLOptions().cl_khr_fp16) {
2373     if (DestType->isHalfType()) {
2374       Self.Diag(SrcExpr.get()->getLocStart(), diag::err_opencl_cast_to_half)
2375         << DestType << SrcExpr.get()->getSourceRange();
2376       SrcExpr = ExprError();
2377       return;
2378     }
2379   }
2380 
2381   // ARC imposes extra restrictions on casts.
2382   if (Self.getLangOpts().ObjCAutoRefCount) {
2383     checkObjCARCConversion(Sema::CCK_CStyleCast);
2384     if (SrcExpr.isInvalid())
2385       return;
2386 
2387     if (const PointerType *CastPtr = DestType->getAs<PointerType>()) {
2388       if (const PointerType *ExprPtr = SrcType->getAs<PointerType>()) {
2389         Qualifiers CastQuals = CastPtr->getPointeeType().getQualifiers();
2390         Qualifiers ExprQuals = ExprPtr->getPointeeType().getQualifiers();
2391         if (CastPtr->getPointeeType()->isObjCLifetimeType() &&
2392             ExprPtr->getPointeeType()->isObjCLifetimeType() &&
2393             !CastQuals.compatiblyIncludesObjCLifetime(ExprQuals)) {
2394           Self.Diag(SrcExpr.get()->getLocStart(),
2395                     diag::err_typecheck_incompatible_ownership)
2396             << SrcType << DestType << Sema::AA_Casting
2397             << SrcExpr.get()->getSourceRange();
2398           return;
2399         }
2400       }
2401     }
2402     else if (!Self.CheckObjCARCUnavailableWeakConversion(DestType, SrcType)) {
2403       Self.Diag(SrcExpr.get()->getLocStart(),
2404                 diag::err_arc_convesion_of_weak_unavailable)
2405         << 1 << SrcType << DestType << SrcExpr.get()->getSourceRange();
2406       SrcExpr = ExprError();
2407       return;
2408     }
2409   }
2410 
2411   DiagnoseCastOfObjCSEL(Self, SrcExpr, DestType);
2412   DiagnoseBadFunctionCast(Self, SrcExpr, DestType);
2413   Kind = Self.PrepareScalarCast(SrcExpr, DestType);
2414   if (SrcExpr.isInvalid())
2415     return;
2416 
2417   if (Kind == CK_BitCast)
2418     checkCastAlign();
2419 
2420   // -Wcast-qual
2421   QualType TheOffendingSrcType, TheOffendingDestType;
2422   Qualifiers CastAwayQualifiers;
2423   if (SrcType->isAnyPointerType() && DestType->isAnyPointerType() &&
2424       CastsAwayConstness(Self, SrcType, DestType, true, false,
2425                          &TheOffendingSrcType, &TheOffendingDestType,
2426                          &CastAwayQualifiers)) {
2427     int qualifiers = -1;
2428     if (CastAwayQualifiers.hasConst() && CastAwayQualifiers.hasVolatile()) {
2429       qualifiers = 0;
2430     } else if (CastAwayQualifiers.hasConst()) {
2431       qualifiers = 1;
2432     } else if (CastAwayQualifiers.hasVolatile()) {
2433       qualifiers = 2;
2434     }
2435     // This is a variant of int **x; const int **y = (const int **)x;
2436     if (qualifiers == -1)
2437       Self.Diag(SrcExpr.get()->getLocStart(), diag::warn_cast_qual2) <<
2438         SrcType << DestType;
2439     else
2440       Self.Diag(SrcExpr.get()->getLocStart(), diag::warn_cast_qual) <<
2441         TheOffendingSrcType << TheOffendingDestType << qualifiers;
2442   }
2443 }
2444 
2445 ExprResult Sema::BuildCStyleCastExpr(SourceLocation LPLoc,
2446                                      TypeSourceInfo *CastTypeInfo,
2447                                      SourceLocation RPLoc,
2448                                      Expr *CastExpr) {
2449   CastOperation Op(*this, CastTypeInfo->getType(), CastExpr);
2450   Op.DestRange = CastTypeInfo->getTypeLoc().getSourceRange();
2451   Op.OpRange = SourceRange(LPLoc, CastExpr->getLocEnd());
2452 
2453   if (getLangOpts().CPlusPlus) {
2454     Op.CheckCXXCStyleCast(/*FunctionalStyle=*/ false,
2455                           isa<InitListExpr>(CastExpr));
2456   } else {
2457     Op.CheckCStyleCast();
2458   }
2459 
2460   if (Op.SrcExpr.isInvalid())
2461     return ExprError();
2462 
2463   return Op.complete(CStyleCastExpr::Create(Context, Op.ResultType,
2464                               Op.ValueKind, Op.Kind, Op.SrcExpr.get(),
2465                               &Op.BasePath, CastTypeInfo, LPLoc, RPLoc));
2466 }
2467 
2468 ExprResult Sema::BuildCXXFunctionalCastExpr(TypeSourceInfo *CastTypeInfo,
2469                                             SourceLocation LPLoc,
2470                                             Expr *CastExpr,
2471                                             SourceLocation RPLoc) {
2472   assert(LPLoc.isValid() && "List-initialization shouldn't get here.");
2473   CastOperation Op(*this, CastTypeInfo->getType(), CastExpr);
2474   Op.DestRange = CastTypeInfo->getTypeLoc().getSourceRange();
2475   Op.OpRange = SourceRange(Op.DestRange.getBegin(), CastExpr->getLocEnd());
2476 
2477   Op.CheckCXXCStyleCast(/*FunctionalStyle=*/true, /*ListInit=*/false);
2478   if (Op.SrcExpr.isInvalid())
2479     return ExprError();
2480 
2481   if (CXXConstructExpr *ConstructExpr = dyn_cast<CXXConstructExpr>(Op.SrcExpr.get()))
2482     ConstructExpr->setParenOrBraceRange(SourceRange(LPLoc, RPLoc));
2483 
2484   return Op.complete(CXXFunctionalCastExpr::Create(Context, Op.ResultType,
2485                          Op.ValueKind, CastTypeInfo, Op.Kind,
2486                          Op.SrcExpr.get(), &Op.BasePath, LPLoc, RPLoc));
2487 }
2488