1 //===--- SemaExpr.cpp - Semantic Analysis for Expressions -----------------===//
2 //
3 //                     The LLVM Compiler Infrastructure
4 //
5 // This file is distributed under the University of Illinois Open Source
6 // License. See LICENSE.TXT for details.
7 //
8 //===----------------------------------------------------------------------===//
9 //
10 //  This file implements semantic analysis for expressions.
11 //
12 //===----------------------------------------------------------------------===//
13 
14 #include "clang/Sema/SemaInternal.h"
15 #include "TreeTransform.h"
16 #include "clang/AST/ASTConsumer.h"
17 #include "clang/AST/ASTContext.h"
18 #include "clang/AST/ASTMutationListener.h"
19 #include "clang/AST/CXXInheritance.h"
20 #include "clang/AST/DeclObjC.h"
21 #include "clang/AST/DeclTemplate.h"
22 #include "clang/AST/EvaluatedExprVisitor.h"
23 #include "clang/AST/Expr.h"
24 #include "clang/AST/ExprCXX.h"
25 #include "clang/AST/ExprObjC.h"
26 #include "clang/AST/RecursiveASTVisitor.h"
27 #include "clang/AST/TypeLoc.h"
28 #include "clang/Basic/PartialDiagnostic.h"
29 #include "clang/Basic/SourceManager.h"
30 #include "clang/Basic/TargetInfo.h"
31 #include "clang/Lex/LiteralSupport.h"
32 #include "clang/Lex/Preprocessor.h"
33 #include "clang/Sema/AnalysisBasedWarnings.h"
34 #include "clang/Sema/DeclSpec.h"
35 #include "clang/Sema/DelayedDiagnostic.h"
36 #include "clang/Sema/Designator.h"
37 #include "clang/Sema/Initialization.h"
38 #include "clang/Sema/Lookup.h"
39 #include "clang/Sema/ParsedTemplate.h"
40 #include "clang/Sema/Scope.h"
41 #include "clang/Sema/ScopeInfo.h"
42 #include "clang/Sema/SemaFixItUtils.h"
43 #include "clang/Sema/Template.h"
44 using namespace clang;
45 using namespace sema;
46 
47 /// \brief Determine whether the use of this declaration is valid, without
48 /// emitting diagnostics.
49 bool Sema::CanUseDecl(NamedDecl *D) {
50   // See if this is an auto-typed variable whose initializer we are parsing.
51   if (ParsingInitForAutoVars.count(D))
52     return false;
53 
54   // See if this is a deleted function.
55   if (FunctionDecl *FD = dyn_cast<FunctionDecl>(D)) {
56     if (FD->isDeleted())
57       return false;
58 
59     // If the function has a deduced return type, and we can't deduce it,
60     // then we can't use it either.
61     if (getLangOpts().CPlusPlus1y && FD->getResultType()->isUndeducedType() &&
62         DeduceReturnType(FD, SourceLocation(), /*Diagnose*/false))
63       return false;
64   }
65 
66   // See if this function is unavailable.
67   if (D->getAvailability() == AR_Unavailable &&
68       cast<Decl>(CurContext)->getAvailability() != AR_Unavailable)
69     return false;
70 
71   return true;
72 }
73 
74 static void DiagnoseUnusedOfDecl(Sema &S, NamedDecl *D, SourceLocation Loc) {
75   // Warn if this is used but marked unused.
76   if (D->hasAttr<UnusedAttr>()) {
77     const Decl *DC = cast<Decl>(S.getCurObjCLexicalContext());
78     if (!DC->hasAttr<UnusedAttr>())
79       S.Diag(Loc, diag::warn_used_but_marked_unused) << D->getDeclName();
80   }
81 }
82 
83 static AvailabilityResult DiagnoseAvailabilityOfDecl(Sema &S,
84                               NamedDecl *D, SourceLocation Loc,
85                               const ObjCInterfaceDecl *UnknownObjCClass) {
86   // See if this declaration is unavailable or deprecated.
87   std::string Message;
88   AvailabilityResult Result = D->getAvailability(&Message);
89   if (const EnumConstantDecl *ECD = dyn_cast<EnumConstantDecl>(D))
90     if (Result == AR_Available) {
91       const DeclContext *DC = ECD->getDeclContext();
92       if (const EnumDecl *TheEnumDecl = dyn_cast<EnumDecl>(DC))
93         Result = TheEnumDecl->getAvailability(&Message);
94     }
95 
96   const ObjCPropertyDecl *ObjCPDecl = 0;
97   if (Result == AR_Deprecated || Result == AR_Unavailable) {
98     if (const ObjCMethodDecl *MD = dyn_cast<ObjCMethodDecl>(D)) {
99       if (const ObjCPropertyDecl *PD = MD->findPropertyDecl()) {
100         AvailabilityResult PDeclResult = PD->getAvailability(0);
101         if (PDeclResult == Result)
102           ObjCPDecl = PD;
103       }
104     }
105   }
106 
107   switch (Result) {
108     case AR_Available:
109     case AR_NotYetIntroduced:
110       break;
111 
112     case AR_Deprecated:
113       S.EmitDeprecationWarning(D, Message, Loc, UnknownObjCClass, ObjCPDecl);
114       break;
115 
116     case AR_Unavailable:
117       if (S.getCurContextAvailability() != AR_Unavailable) {
118         if (Message.empty()) {
119           if (!UnknownObjCClass) {
120             S.Diag(Loc, diag::err_unavailable) << D->getDeclName();
121             if (ObjCPDecl)
122               S.Diag(ObjCPDecl->getLocation(), diag::note_property_attribute)
123                 << ObjCPDecl->getDeclName() << 1;
124           }
125           else
126             S.Diag(Loc, diag::warn_unavailable_fwdclass_message)
127               << D->getDeclName();
128         }
129         else
130           S.Diag(Loc, diag::err_unavailable_message)
131             << D->getDeclName() << Message;
132         S.Diag(D->getLocation(), diag::note_unavailable_here)
133                   << isa<FunctionDecl>(D) << false;
134         if (ObjCPDecl)
135           S.Diag(ObjCPDecl->getLocation(), diag::note_property_attribute)
136           << ObjCPDecl->getDeclName() << 1;
137       }
138       break;
139     }
140     return Result;
141 }
142 
143 /// \brief Emit a note explaining that this function is deleted.
144 void Sema::NoteDeletedFunction(FunctionDecl *Decl) {
145   assert(Decl->isDeleted());
146 
147   CXXMethodDecl *Method = dyn_cast<CXXMethodDecl>(Decl);
148 
149   if (Method && Method->isDeleted() && Method->isDefaulted()) {
150     // If the method was explicitly defaulted, point at that declaration.
151     if (!Method->isImplicit())
152       Diag(Decl->getLocation(), diag::note_implicitly_deleted);
153 
154     // Try to diagnose why this special member function was implicitly
155     // deleted. This might fail, if that reason no longer applies.
156     CXXSpecialMember CSM = getSpecialMember(Method);
157     if (CSM != CXXInvalid)
158       ShouldDeleteSpecialMember(Method, CSM, /*Diagnose=*/true);
159 
160     return;
161   }
162 
163   if (CXXConstructorDecl *CD = dyn_cast<CXXConstructorDecl>(Decl)) {
164     if (CXXConstructorDecl *BaseCD =
165             const_cast<CXXConstructorDecl*>(CD->getInheritedConstructor())) {
166       Diag(Decl->getLocation(), diag::note_inherited_deleted_here);
167       if (BaseCD->isDeleted()) {
168         NoteDeletedFunction(BaseCD);
169       } else {
170         // FIXME: An explanation of why exactly it can't be inherited
171         // would be nice.
172         Diag(BaseCD->getLocation(), diag::note_cannot_inherit);
173       }
174       return;
175     }
176   }
177 
178   Diag(Decl->getLocation(), diag::note_unavailable_here)
179     << 1 << true;
180 }
181 
182 /// \brief Determine whether a FunctionDecl was ever declared with an
183 /// explicit storage class.
184 static bool hasAnyExplicitStorageClass(const FunctionDecl *D) {
185   for (FunctionDecl::redecl_iterator I = D->redecls_begin(),
186                                      E = D->redecls_end();
187        I != E; ++I) {
188     if (I->getStorageClass() != SC_None)
189       return true;
190   }
191   return false;
192 }
193 
194 /// \brief Check whether we're in an extern inline function and referring to a
195 /// variable or function with internal linkage (C11 6.7.4p3).
196 ///
197 /// This is only a warning because we used to silently accept this code, but
198 /// in many cases it will not behave correctly. This is not enabled in C++ mode
199 /// because the restriction language is a bit weaker (C++11 [basic.def.odr]p6)
200 /// and so while there may still be user mistakes, most of the time we can't
201 /// prove that there are errors.
202 static void diagnoseUseOfInternalDeclInInlineFunction(Sema &S,
203                                                       const NamedDecl *D,
204                                                       SourceLocation Loc) {
205   // This is disabled under C++; there are too many ways for this to fire in
206   // contexts where the warning is a false positive, or where it is technically
207   // correct but benign.
208   if (S.getLangOpts().CPlusPlus)
209     return;
210 
211   // Check if this is an inlined function or method.
212   FunctionDecl *Current = S.getCurFunctionDecl();
213   if (!Current)
214     return;
215   if (!Current->isInlined())
216     return;
217   if (!Current->isExternallyVisible())
218     return;
219 
220   // Check if the decl has internal linkage.
221   if (D->getFormalLinkage() != InternalLinkage)
222     return;
223 
224   // Downgrade from ExtWarn to Extension if
225   //  (1) the supposedly external inline function is in the main file,
226   //      and probably won't be included anywhere else.
227   //  (2) the thing we're referencing is a pure function.
228   //  (3) the thing we're referencing is another inline function.
229   // This last can give us false negatives, but it's better than warning on
230   // wrappers for simple C library functions.
231   const FunctionDecl *UsedFn = dyn_cast<FunctionDecl>(D);
232   bool DowngradeWarning = S.getSourceManager().isInMainFile(Loc);
233   if (!DowngradeWarning && UsedFn)
234     DowngradeWarning = UsedFn->isInlined() || UsedFn->hasAttr<ConstAttr>();
235 
236   S.Diag(Loc, DowngradeWarning ? diag::ext_internal_in_extern_inline
237                                : diag::warn_internal_in_extern_inline)
238     << /*IsVar=*/!UsedFn << D;
239 
240   S.MaybeSuggestAddingStaticToDecl(Current);
241 
242   S.Diag(D->getCanonicalDecl()->getLocation(),
243          diag::note_internal_decl_declared_here)
244     << D;
245 }
246 
247 void Sema::MaybeSuggestAddingStaticToDecl(const FunctionDecl *Cur) {
248   const FunctionDecl *First = Cur->getFirstDecl();
249 
250   // Suggest "static" on the function, if possible.
251   if (!hasAnyExplicitStorageClass(First)) {
252     SourceLocation DeclBegin = First->getSourceRange().getBegin();
253     Diag(DeclBegin, diag::note_convert_inline_to_static)
254       << Cur << FixItHint::CreateInsertion(DeclBegin, "static ");
255   }
256 }
257 
258 /// \brief Determine whether the use of this declaration is valid, and
259 /// emit any corresponding diagnostics.
260 ///
261 /// This routine diagnoses various problems with referencing
262 /// declarations that can occur when using a declaration. For example,
263 /// it might warn if a deprecated or unavailable declaration is being
264 /// used, or produce an error (and return true) if a C++0x deleted
265 /// function is being used.
266 ///
267 /// \returns true if there was an error (this declaration cannot be
268 /// referenced), false otherwise.
269 ///
270 bool Sema::DiagnoseUseOfDecl(NamedDecl *D, SourceLocation Loc,
271                              const ObjCInterfaceDecl *UnknownObjCClass) {
272   if (getLangOpts().CPlusPlus && isa<FunctionDecl>(D)) {
273     // If there were any diagnostics suppressed by template argument deduction,
274     // emit them now.
275     SuppressedDiagnosticsMap::iterator
276       Pos = SuppressedDiagnostics.find(D->getCanonicalDecl());
277     if (Pos != SuppressedDiagnostics.end()) {
278       SmallVectorImpl<PartialDiagnosticAt> &Suppressed = Pos->second;
279       for (unsigned I = 0, N = Suppressed.size(); I != N; ++I)
280         Diag(Suppressed[I].first, Suppressed[I].second);
281 
282       // Clear out the list of suppressed diagnostics, so that we don't emit
283       // them again for this specialization. However, we don't obsolete this
284       // entry from the table, because we want to avoid ever emitting these
285       // diagnostics again.
286       Suppressed.clear();
287     }
288   }
289 
290   // See if this is an auto-typed variable whose initializer we are parsing.
291   if (ParsingInitForAutoVars.count(D)) {
292     Diag(Loc, diag::err_auto_variable_cannot_appear_in_own_initializer)
293       << D->getDeclName();
294     return true;
295   }
296 
297   // See if this is a deleted function.
298   if (FunctionDecl *FD = dyn_cast<FunctionDecl>(D)) {
299     if (FD->isDeleted()) {
300       Diag(Loc, diag::err_deleted_function_use);
301       NoteDeletedFunction(FD);
302       return true;
303     }
304 
305     // If the function has a deduced return type, and we can't deduce it,
306     // then we can't use it either.
307     if (getLangOpts().CPlusPlus1y && FD->getResultType()->isUndeducedType() &&
308         DeduceReturnType(FD, Loc))
309       return true;
310   }
311   DiagnoseAvailabilityOfDecl(*this, D, Loc, UnknownObjCClass);
312 
313   DiagnoseUnusedOfDecl(*this, D, Loc);
314 
315   diagnoseUseOfInternalDeclInInlineFunction(*this, D, Loc);
316 
317   return false;
318 }
319 
320 /// \brief Retrieve the message suffix that should be added to a
321 /// diagnostic complaining about the given function being deleted or
322 /// unavailable.
323 std::string Sema::getDeletedOrUnavailableSuffix(const FunctionDecl *FD) {
324   std::string Message;
325   if (FD->getAvailability(&Message))
326     return ": " + Message;
327 
328   return std::string();
329 }
330 
331 /// DiagnoseSentinelCalls - This routine checks whether a call or
332 /// message-send is to a declaration with the sentinel attribute, and
333 /// if so, it checks that the requirements of the sentinel are
334 /// satisfied.
335 void Sema::DiagnoseSentinelCalls(NamedDecl *D, SourceLocation Loc,
336                                  ArrayRef<Expr *> Args) {
337   const SentinelAttr *attr = D->getAttr<SentinelAttr>();
338   if (!attr)
339     return;
340 
341   // The number of formal parameters of the declaration.
342   unsigned numFormalParams;
343 
344   // The kind of declaration.  This is also an index into a %select in
345   // the diagnostic.
346   enum CalleeType { CT_Function, CT_Method, CT_Block } calleeType;
347 
348   if (ObjCMethodDecl *MD = dyn_cast<ObjCMethodDecl>(D)) {
349     numFormalParams = MD->param_size();
350     calleeType = CT_Method;
351   } else if (FunctionDecl *FD = dyn_cast<FunctionDecl>(D)) {
352     numFormalParams = FD->param_size();
353     calleeType = CT_Function;
354   } else if (isa<VarDecl>(D)) {
355     QualType type = cast<ValueDecl>(D)->getType();
356     const FunctionType *fn = 0;
357     if (const PointerType *ptr = type->getAs<PointerType>()) {
358       fn = ptr->getPointeeType()->getAs<FunctionType>();
359       if (!fn) return;
360       calleeType = CT_Function;
361     } else if (const BlockPointerType *ptr = type->getAs<BlockPointerType>()) {
362       fn = ptr->getPointeeType()->castAs<FunctionType>();
363       calleeType = CT_Block;
364     } else {
365       return;
366     }
367 
368     if (const FunctionProtoType *proto = dyn_cast<FunctionProtoType>(fn)) {
369       numFormalParams = proto->getNumArgs();
370     } else {
371       numFormalParams = 0;
372     }
373   } else {
374     return;
375   }
376 
377   // "nullPos" is the number of formal parameters at the end which
378   // effectively count as part of the variadic arguments.  This is
379   // useful if you would prefer to not have *any* formal parameters,
380   // but the language forces you to have at least one.
381   unsigned nullPos = attr->getNullPos();
382   assert((nullPos == 0 || nullPos == 1) && "invalid null position on sentinel");
383   numFormalParams = (nullPos > numFormalParams ? 0 : numFormalParams - nullPos);
384 
385   // The number of arguments which should follow the sentinel.
386   unsigned numArgsAfterSentinel = attr->getSentinel();
387 
388   // If there aren't enough arguments for all the formal parameters,
389   // the sentinel, and the args after the sentinel, complain.
390   if (Args.size() < numFormalParams + numArgsAfterSentinel + 1) {
391     Diag(Loc, diag::warn_not_enough_argument) << D->getDeclName();
392     Diag(D->getLocation(), diag::note_sentinel_here) << int(calleeType);
393     return;
394   }
395 
396   // Otherwise, find the sentinel expression.
397   Expr *sentinelExpr = Args[Args.size() - numArgsAfterSentinel - 1];
398   if (!sentinelExpr) return;
399   if (sentinelExpr->isValueDependent()) return;
400   if (Context.isSentinelNullExpr(sentinelExpr)) return;
401 
402   // Pick a reasonable string to insert.  Optimistically use 'nil' or
403   // 'NULL' if those are actually defined in the context.  Only use
404   // 'nil' for ObjC methods, where it's much more likely that the
405   // variadic arguments form a list of object pointers.
406   SourceLocation MissingNilLoc
407     = PP.getLocForEndOfToken(sentinelExpr->getLocEnd());
408   std::string NullValue;
409   if (calleeType == CT_Method &&
410       PP.getIdentifierInfo("nil")->hasMacroDefinition())
411     NullValue = "nil";
412   else if (PP.getIdentifierInfo("NULL")->hasMacroDefinition())
413     NullValue = "NULL";
414   else
415     NullValue = "(void*) 0";
416 
417   if (MissingNilLoc.isInvalid())
418     Diag(Loc, diag::warn_missing_sentinel) << int(calleeType);
419   else
420     Diag(MissingNilLoc, diag::warn_missing_sentinel)
421       << int(calleeType)
422       << FixItHint::CreateInsertion(MissingNilLoc, ", " + NullValue);
423   Diag(D->getLocation(), diag::note_sentinel_here) << int(calleeType);
424 }
425 
426 SourceRange Sema::getExprRange(Expr *E) const {
427   return E ? E->getSourceRange() : SourceRange();
428 }
429 
430 //===----------------------------------------------------------------------===//
431 //  Standard Promotions and Conversions
432 //===----------------------------------------------------------------------===//
433 
434 /// DefaultFunctionArrayConversion (C99 6.3.2.1p3, C99 6.3.2.1p4).
435 ExprResult Sema::DefaultFunctionArrayConversion(Expr *E) {
436   // Handle any placeholder expressions which made it here.
437   if (E->getType()->isPlaceholderType()) {
438     ExprResult result = CheckPlaceholderExpr(E);
439     if (result.isInvalid()) return ExprError();
440     E = result.take();
441   }
442 
443   QualType Ty = E->getType();
444   assert(!Ty.isNull() && "DefaultFunctionArrayConversion - missing type");
445 
446   if (Ty->isFunctionType())
447     E = ImpCastExprToType(E, Context.getPointerType(Ty),
448                           CK_FunctionToPointerDecay).take();
449   else if (Ty->isArrayType()) {
450     // In C90 mode, arrays only promote to pointers if the array expression is
451     // an lvalue.  The relevant legalese is C90 6.2.2.1p3: "an lvalue that has
452     // type 'array of type' is converted to an expression that has type 'pointer
453     // to type'...".  In C99 this was changed to: C99 6.3.2.1p3: "an expression
454     // that has type 'array of type' ...".  The relevant change is "an lvalue"
455     // (C90) to "an expression" (C99).
456     //
457     // C++ 4.2p1:
458     // An lvalue or rvalue of type "array of N T" or "array of unknown bound of
459     // T" can be converted to an rvalue of type "pointer to T".
460     //
461     if (getLangOpts().C99 || getLangOpts().CPlusPlus || E->isLValue())
462       E = ImpCastExprToType(E, Context.getArrayDecayedType(Ty),
463                             CK_ArrayToPointerDecay).take();
464   }
465   return Owned(E);
466 }
467 
468 static void CheckForNullPointerDereference(Sema &S, Expr *E) {
469   // Check to see if we are dereferencing a null pointer.  If so,
470   // and if not volatile-qualified, this is undefined behavior that the
471   // optimizer will delete, so warn about it.  People sometimes try to use this
472   // to get a deterministic trap and are surprised by clang's behavior.  This
473   // only handles the pattern "*null", which is a very syntactic check.
474   if (UnaryOperator *UO = dyn_cast<UnaryOperator>(E->IgnoreParenCasts()))
475     if (UO->getOpcode() == UO_Deref &&
476         UO->getSubExpr()->IgnoreParenCasts()->
477           isNullPointerConstant(S.Context, Expr::NPC_ValueDependentIsNotNull) &&
478         !UO->getType().isVolatileQualified()) {
479     S.DiagRuntimeBehavior(UO->getOperatorLoc(), UO,
480                           S.PDiag(diag::warn_indirection_through_null)
481                             << UO->getSubExpr()->getSourceRange());
482     S.DiagRuntimeBehavior(UO->getOperatorLoc(), UO,
483                         S.PDiag(diag::note_indirection_through_null));
484   }
485 }
486 
487 static void DiagnoseDirectIsaAccess(Sema &S, const ObjCIvarRefExpr *OIRE,
488                                     SourceLocation AssignLoc,
489                                     const Expr* RHS) {
490   const ObjCIvarDecl *IV = OIRE->getDecl();
491   if (!IV)
492     return;
493 
494   DeclarationName MemberName = IV->getDeclName();
495   IdentifierInfo *Member = MemberName.getAsIdentifierInfo();
496   if (!Member || !Member->isStr("isa"))
497     return;
498 
499   const Expr *Base = OIRE->getBase();
500   QualType BaseType = Base->getType();
501   if (OIRE->isArrow())
502     BaseType = BaseType->getPointeeType();
503   if (const ObjCObjectType *OTy = BaseType->getAs<ObjCObjectType>())
504     if (ObjCInterfaceDecl *IDecl = OTy->getInterface()) {
505       ObjCInterfaceDecl *ClassDeclared = 0;
506       ObjCIvarDecl *IV = IDecl->lookupInstanceVariable(Member, ClassDeclared);
507       if (!ClassDeclared->getSuperClass()
508           && (*ClassDeclared->ivar_begin()) == IV) {
509         if (RHS) {
510           NamedDecl *ObjectSetClass =
511             S.LookupSingleName(S.TUScope,
512                                &S.Context.Idents.get("object_setClass"),
513                                SourceLocation(), S.LookupOrdinaryName);
514           if (ObjectSetClass) {
515             SourceLocation RHSLocEnd = S.PP.getLocForEndOfToken(RHS->getLocEnd());
516             S.Diag(OIRE->getExprLoc(), diag::warn_objc_isa_assign) <<
517             FixItHint::CreateInsertion(OIRE->getLocStart(), "object_setClass(") <<
518             FixItHint::CreateReplacement(SourceRange(OIRE->getOpLoc(),
519                                                      AssignLoc), ",") <<
520             FixItHint::CreateInsertion(RHSLocEnd, ")");
521           }
522           else
523             S.Diag(OIRE->getLocation(), diag::warn_objc_isa_assign);
524         } else {
525           NamedDecl *ObjectGetClass =
526             S.LookupSingleName(S.TUScope,
527                                &S.Context.Idents.get("object_getClass"),
528                                SourceLocation(), S.LookupOrdinaryName);
529           if (ObjectGetClass)
530             S.Diag(OIRE->getExprLoc(), diag::warn_objc_isa_use) <<
531             FixItHint::CreateInsertion(OIRE->getLocStart(), "object_getClass(") <<
532             FixItHint::CreateReplacement(
533                                          SourceRange(OIRE->getOpLoc(),
534                                                      OIRE->getLocEnd()), ")");
535           else
536             S.Diag(OIRE->getLocation(), diag::warn_objc_isa_use);
537         }
538         S.Diag(IV->getLocation(), diag::note_ivar_decl);
539       }
540     }
541 }
542 
543 ExprResult Sema::DefaultLvalueConversion(Expr *E) {
544   // Handle any placeholder expressions which made it here.
545   if (E->getType()->isPlaceholderType()) {
546     ExprResult result = CheckPlaceholderExpr(E);
547     if (result.isInvalid()) return ExprError();
548     E = result.take();
549   }
550 
551   // C++ [conv.lval]p1:
552   //   A glvalue of a non-function, non-array type T can be
553   //   converted to a prvalue.
554   if (!E->isGLValue()) return Owned(E);
555 
556   QualType T = E->getType();
557   assert(!T.isNull() && "r-value conversion on typeless expression?");
558 
559   // We don't want to throw lvalue-to-rvalue casts on top of
560   // expressions of certain types in C++.
561   if (getLangOpts().CPlusPlus &&
562       (E->getType() == Context.OverloadTy ||
563        T->isDependentType() ||
564        T->isRecordType()))
565     return Owned(E);
566 
567   // The C standard is actually really unclear on this point, and
568   // DR106 tells us what the result should be but not why.  It's
569   // generally best to say that void types just doesn't undergo
570   // lvalue-to-rvalue at all.  Note that expressions of unqualified
571   // 'void' type are never l-values, but qualified void can be.
572   if (T->isVoidType())
573     return Owned(E);
574 
575   // OpenCL usually rejects direct accesses to values of 'half' type.
576   if (getLangOpts().OpenCL && !getOpenCLOptions().cl_khr_fp16 &&
577       T->isHalfType()) {
578     Diag(E->getExprLoc(), diag::err_opencl_half_load_store)
579       << 0 << T;
580     return ExprError();
581   }
582 
583   CheckForNullPointerDereference(*this, E);
584   if (const ObjCIsaExpr *OISA = dyn_cast<ObjCIsaExpr>(E->IgnoreParenCasts())) {
585     NamedDecl *ObjectGetClass = LookupSingleName(TUScope,
586                                      &Context.Idents.get("object_getClass"),
587                                      SourceLocation(), LookupOrdinaryName);
588     if (ObjectGetClass)
589       Diag(E->getExprLoc(), diag::warn_objc_isa_use) <<
590         FixItHint::CreateInsertion(OISA->getLocStart(), "object_getClass(") <<
591         FixItHint::CreateReplacement(
592                     SourceRange(OISA->getOpLoc(), OISA->getIsaMemberLoc()), ")");
593     else
594       Diag(E->getExprLoc(), diag::warn_objc_isa_use);
595   }
596   else if (const ObjCIvarRefExpr *OIRE =
597             dyn_cast<ObjCIvarRefExpr>(E->IgnoreParenCasts()))
598     DiagnoseDirectIsaAccess(*this, OIRE, SourceLocation(), /* Expr*/0);
599 
600   // C++ [conv.lval]p1:
601   //   [...] If T is a non-class type, the type of the prvalue is the
602   //   cv-unqualified version of T. Otherwise, the type of the
603   //   rvalue is T.
604   //
605   // C99 6.3.2.1p2:
606   //   If the lvalue has qualified type, the value has the unqualified
607   //   version of the type of the lvalue; otherwise, the value has the
608   //   type of the lvalue.
609   if (T.hasQualifiers())
610     T = T.getUnqualifiedType();
611 
612   UpdateMarkingForLValueToRValue(E);
613 
614   // Loading a __weak object implicitly retains the value, so we need a cleanup to
615   // balance that.
616   if (getLangOpts().ObjCAutoRefCount &&
617       E->getType().getObjCLifetime() == Qualifiers::OCL_Weak)
618     ExprNeedsCleanups = true;
619 
620   ExprResult Res = Owned(ImplicitCastExpr::Create(Context, T, CK_LValueToRValue,
621                                                   E, 0, VK_RValue));
622 
623   // C11 6.3.2.1p2:
624   //   ... if the lvalue has atomic type, the value has the non-atomic version
625   //   of the type of the lvalue ...
626   if (const AtomicType *Atomic = T->getAs<AtomicType>()) {
627     T = Atomic->getValueType().getUnqualifiedType();
628     Res = Owned(ImplicitCastExpr::Create(Context, T, CK_AtomicToNonAtomic,
629                                          Res.get(), 0, VK_RValue));
630   }
631 
632   return Res;
633 }
634 
635 ExprResult Sema::DefaultFunctionArrayLvalueConversion(Expr *E) {
636   ExprResult Res = DefaultFunctionArrayConversion(E);
637   if (Res.isInvalid())
638     return ExprError();
639   Res = DefaultLvalueConversion(Res.take());
640   if (Res.isInvalid())
641     return ExprError();
642   return Res;
643 }
644 
645 
646 /// UsualUnaryConversions - Performs various conversions that are common to most
647 /// operators (C99 6.3). The conversions of array and function types are
648 /// sometimes suppressed. For example, the array->pointer conversion doesn't
649 /// apply if the array is an argument to the sizeof or address (&) operators.
650 /// In these instances, this routine should *not* be called.
651 ExprResult Sema::UsualUnaryConversions(Expr *E) {
652   // First, convert to an r-value.
653   ExprResult Res = DefaultFunctionArrayLvalueConversion(E);
654   if (Res.isInvalid())
655     return ExprError();
656   E = Res.take();
657 
658   QualType Ty = E->getType();
659   assert(!Ty.isNull() && "UsualUnaryConversions - missing type");
660 
661   // Half FP have to be promoted to float unless it is natively supported
662   if (Ty->isHalfType() && !getLangOpts().NativeHalfType)
663     return ImpCastExprToType(Res.take(), Context.FloatTy, CK_FloatingCast);
664 
665   // Try to perform integral promotions if the object has a theoretically
666   // promotable type.
667   if (Ty->isIntegralOrUnscopedEnumerationType()) {
668     // C99 6.3.1.1p2:
669     //
670     //   The following may be used in an expression wherever an int or
671     //   unsigned int may be used:
672     //     - an object or expression with an integer type whose integer
673     //       conversion rank is less than or equal to the rank of int
674     //       and unsigned int.
675     //     - A bit-field of type _Bool, int, signed int, or unsigned int.
676     //
677     //   If an int can represent all values of the original type, the
678     //   value is converted to an int; otherwise, it is converted to an
679     //   unsigned int. These are called the integer promotions. All
680     //   other types are unchanged by the integer promotions.
681 
682     QualType PTy = Context.isPromotableBitField(E);
683     if (!PTy.isNull()) {
684       E = ImpCastExprToType(E, PTy, CK_IntegralCast).take();
685       return Owned(E);
686     }
687     if (Ty->isPromotableIntegerType()) {
688       QualType PT = Context.getPromotedIntegerType(Ty);
689       E = ImpCastExprToType(E, PT, CK_IntegralCast).take();
690       return Owned(E);
691     }
692   }
693   return Owned(E);
694 }
695 
696 /// DefaultArgumentPromotion (C99 6.5.2.2p6). Used for function calls that
697 /// do not have a prototype. Arguments that have type float or __fp16
698 /// are promoted to double. All other argument types are converted by
699 /// UsualUnaryConversions().
700 ExprResult Sema::DefaultArgumentPromotion(Expr *E) {
701   QualType Ty = E->getType();
702   assert(!Ty.isNull() && "DefaultArgumentPromotion - missing type");
703 
704   ExprResult Res = UsualUnaryConversions(E);
705   if (Res.isInvalid())
706     return ExprError();
707   E = Res.take();
708 
709   // If this is a 'float' or '__fp16' (CVR qualified or typedef) promote to
710   // double.
711   const BuiltinType *BTy = Ty->getAs<BuiltinType>();
712   if (BTy && (BTy->getKind() == BuiltinType::Half ||
713               BTy->getKind() == BuiltinType::Float))
714     E = ImpCastExprToType(E, Context.DoubleTy, CK_FloatingCast).take();
715 
716   // C++ performs lvalue-to-rvalue conversion as a default argument
717   // promotion, even on class types, but note:
718   //   C++11 [conv.lval]p2:
719   //     When an lvalue-to-rvalue conversion occurs in an unevaluated
720   //     operand or a subexpression thereof the value contained in the
721   //     referenced object is not accessed. Otherwise, if the glvalue
722   //     has a class type, the conversion copy-initializes a temporary
723   //     of type T from the glvalue and the result of the conversion
724   //     is a prvalue for the temporary.
725   // FIXME: add some way to gate this entire thing for correctness in
726   // potentially potentially evaluated contexts.
727   if (getLangOpts().CPlusPlus && E->isGLValue() && !isUnevaluatedContext()) {
728     ExprResult Temp = PerformCopyInitialization(
729                        InitializedEntity::InitializeTemporary(E->getType()),
730                                                 E->getExprLoc(),
731                                                 Owned(E));
732     if (Temp.isInvalid())
733       return ExprError();
734     E = Temp.get();
735   }
736 
737   return Owned(E);
738 }
739 
740 /// Determine the degree of POD-ness for an expression.
741 /// Incomplete types are considered POD, since this check can be performed
742 /// when we're in an unevaluated context.
743 Sema::VarArgKind Sema::isValidVarArgType(const QualType &Ty) {
744   if (Ty->isIncompleteType()) {
745     // C++11 [expr.call]p7:
746     //   After these conversions, if the argument does not have arithmetic,
747     //   enumeration, pointer, pointer to member, or class type, the program
748     //   is ill-formed.
749     //
750     // Since we've already performed array-to-pointer and function-to-pointer
751     // decay, the only such type in C++ is cv void. This also handles
752     // initializer lists as variadic arguments.
753     if (Ty->isVoidType())
754       return VAK_Invalid;
755 
756     if (Ty->isObjCObjectType())
757       return VAK_Invalid;
758     return VAK_Valid;
759   }
760 
761   if (Ty.isCXX98PODType(Context))
762     return VAK_Valid;
763 
764   // C++11 [expr.call]p7:
765   //   Passing a potentially-evaluated argument of class type (Clause 9)
766   //   having a non-trivial copy constructor, a non-trivial move constructor,
767   //   or a non-trivial destructor, with no corresponding parameter,
768   //   is conditionally-supported with implementation-defined semantics.
769   if (getLangOpts().CPlusPlus11 && !Ty->isDependentType())
770     if (CXXRecordDecl *Record = Ty->getAsCXXRecordDecl())
771       if (!Record->hasNonTrivialCopyConstructor() &&
772           !Record->hasNonTrivialMoveConstructor() &&
773           !Record->hasNonTrivialDestructor())
774         return VAK_ValidInCXX11;
775 
776   if (getLangOpts().ObjCAutoRefCount && Ty->isObjCLifetimeType())
777     return VAK_Valid;
778 
779   if (Ty->isObjCObjectType())
780     return VAK_Invalid;
781 
782   // FIXME: In C++11, these cases are conditionally-supported, meaning we're
783   // permitted to reject them. We should consider doing so.
784   return VAK_Undefined;
785 }
786 
787 void Sema::checkVariadicArgument(const Expr *E, VariadicCallType CT) {
788   // Don't allow one to pass an Objective-C interface to a vararg.
789   const QualType &Ty = E->getType();
790   VarArgKind VAK = isValidVarArgType(Ty);
791 
792   // Complain about passing non-POD types through varargs.
793   switch (VAK) {
794   case VAK_Valid:
795     break;
796 
797   case VAK_ValidInCXX11:
798     DiagRuntimeBehavior(
799         E->getLocStart(), 0,
800         PDiag(diag::warn_cxx98_compat_pass_non_pod_arg_to_vararg)
801           << E->getType() << CT);
802     break;
803 
804   case VAK_Undefined:
805     DiagRuntimeBehavior(
806         E->getLocStart(), 0,
807         PDiag(diag::warn_cannot_pass_non_pod_arg_to_vararg)
808           << getLangOpts().CPlusPlus11 << Ty << CT);
809     break;
810 
811   case VAK_Invalid:
812     if (Ty->isObjCObjectType())
813       DiagRuntimeBehavior(
814           E->getLocStart(), 0,
815           PDiag(diag::err_cannot_pass_objc_interface_to_vararg)
816             << Ty << CT);
817     else
818       Diag(E->getLocStart(), diag::err_cannot_pass_to_vararg)
819         << isa<InitListExpr>(E) << Ty << CT;
820     break;
821   }
822 }
823 
824 /// DefaultVariadicArgumentPromotion - Like DefaultArgumentPromotion, but
825 /// will create a trap if the resulting type is not a POD type.
826 ExprResult Sema::DefaultVariadicArgumentPromotion(Expr *E, VariadicCallType CT,
827                                                   FunctionDecl *FDecl) {
828   if (const BuiltinType *PlaceholderTy = E->getType()->getAsPlaceholderType()) {
829     // Strip the unbridged-cast placeholder expression off, if applicable.
830     if (PlaceholderTy->getKind() == BuiltinType::ARCUnbridgedCast &&
831         (CT == VariadicMethod ||
832          (FDecl && FDecl->hasAttr<CFAuditedTransferAttr>()))) {
833       E = stripARCUnbridgedCast(E);
834 
835     // Otherwise, do normal placeholder checking.
836     } else {
837       ExprResult ExprRes = CheckPlaceholderExpr(E);
838       if (ExprRes.isInvalid())
839         return ExprError();
840       E = ExprRes.take();
841     }
842   }
843 
844   ExprResult ExprRes = DefaultArgumentPromotion(E);
845   if (ExprRes.isInvalid())
846     return ExprError();
847   E = ExprRes.take();
848 
849   // Diagnostics regarding non-POD argument types are
850   // emitted along with format string checking in Sema::CheckFunctionCall().
851   if (isValidVarArgType(E->getType()) == VAK_Undefined) {
852     // Turn this into a trap.
853     CXXScopeSpec SS;
854     SourceLocation TemplateKWLoc;
855     UnqualifiedId Name;
856     Name.setIdentifier(PP.getIdentifierInfo("__builtin_trap"),
857                        E->getLocStart());
858     ExprResult TrapFn = ActOnIdExpression(TUScope, SS, TemplateKWLoc,
859                                           Name, true, false);
860     if (TrapFn.isInvalid())
861       return ExprError();
862 
863     ExprResult Call = ActOnCallExpr(TUScope, TrapFn.get(),
864                                     E->getLocStart(), None,
865                                     E->getLocEnd());
866     if (Call.isInvalid())
867       return ExprError();
868 
869     ExprResult Comma = ActOnBinOp(TUScope, E->getLocStart(), tok::comma,
870                                   Call.get(), E);
871     if (Comma.isInvalid())
872       return ExprError();
873     return Comma.get();
874   }
875 
876   if (!getLangOpts().CPlusPlus &&
877       RequireCompleteType(E->getExprLoc(), E->getType(),
878                           diag::err_call_incomplete_argument))
879     return ExprError();
880 
881   return Owned(E);
882 }
883 
884 /// \brief Converts an integer to complex float type.  Helper function of
885 /// UsualArithmeticConversions()
886 ///
887 /// \return false if the integer expression is an integer type and is
888 /// successfully converted to the complex type.
889 static bool handleIntegerToComplexFloatConversion(Sema &S, ExprResult &IntExpr,
890                                                   ExprResult &ComplexExpr,
891                                                   QualType IntTy,
892                                                   QualType ComplexTy,
893                                                   bool SkipCast) {
894   if (IntTy->isComplexType() || IntTy->isRealFloatingType()) return true;
895   if (SkipCast) return false;
896   if (IntTy->isIntegerType()) {
897     QualType fpTy = cast<ComplexType>(ComplexTy)->getElementType();
898     IntExpr = S.ImpCastExprToType(IntExpr.take(), fpTy, CK_IntegralToFloating);
899     IntExpr = S.ImpCastExprToType(IntExpr.take(), ComplexTy,
900                                   CK_FloatingRealToComplex);
901   } else {
902     assert(IntTy->isComplexIntegerType());
903     IntExpr = S.ImpCastExprToType(IntExpr.take(), ComplexTy,
904                                   CK_IntegralComplexToFloatingComplex);
905   }
906   return false;
907 }
908 
909 /// \brief Takes two complex float types and converts them to the same type.
910 /// Helper function of UsualArithmeticConversions()
911 static QualType
912 handleComplexFloatToComplexFloatConverstion(Sema &S, ExprResult &LHS,
913                                             ExprResult &RHS, QualType LHSType,
914                                             QualType RHSType,
915                                             bool IsCompAssign) {
916   int order = S.Context.getFloatingTypeOrder(LHSType, RHSType);
917 
918   if (order < 0) {
919     // _Complex float -> _Complex double
920     if (!IsCompAssign)
921       LHS = S.ImpCastExprToType(LHS.take(), RHSType, CK_FloatingComplexCast);
922     return RHSType;
923   }
924   if (order > 0)
925     // _Complex float -> _Complex double
926     RHS = S.ImpCastExprToType(RHS.take(), LHSType, CK_FloatingComplexCast);
927   return LHSType;
928 }
929 
930 /// \brief Converts otherExpr to complex float and promotes complexExpr if
931 /// necessary.  Helper function of UsualArithmeticConversions()
932 static QualType handleOtherComplexFloatConversion(Sema &S,
933                                                   ExprResult &ComplexExpr,
934                                                   ExprResult &OtherExpr,
935                                                   QualType ComplexTy,
936                                                   QualType OtherTy,
937                                                   bool ConvertComplexExpr,
938                                                   bool ConvertOtherExpr) {
939   int order = S.Context.getFloatingTypeOrder(ComplexTy, OtherTy);
940 
941   // If just the complexExpr is complex, the otherExpr needs to be converted,
942   // and the complexExpr might need to be promoted.
943   if (order > 0) { // complexExpr is wider
944     // float -> _Complex double
945     if (ConvertOtherExpr) {
946       QualType fp = cast<ComplexType>(ComplexTy)->getElementType();
947       OtherExpr = S.ImpCastExprToType(OtherExpr.take(), fp, CK_FloatingCast);
948       OtherExpr = S.ImpCastExprToType(OtherExpr.take(), ComplexTy,
949                                       CK_FloatingRealToComplex);
950     }
951     return ComplexTy;
952   }
953 
954   // otherTy is at least as wide.  Find its corresponding complex type.
955   QualType result = (order == 0 ? ComplexTy :
956                                   S.Context.getComplexType(OtherTy));
957 
958   // double -> _Complex double
959   if (ConvertOtherExpr)
960     OtherExpr = S.ImpCastExprToType(OtherExpr.take(), result,
961                                     CK_FloatingRealToComplex);
962 
963   // _Complex float -> _Complex double
964   if (ConvertComplexExpr && order < 0)
965     ComplexExpr = S.ImpCastExprToType(ComplexExpr.take(), result,
966                                       CK_FloatingComplexCast);
967 
968   return result;
969 }
970 
971 /// \brief Handle arithmetic conversion with complex types.  Helper function of
972 /// UsualArithmeticConversions()
973 static QualType handleComplexFloatConversion(Sema &S, ExprResult &LHS,
974                                              ExprResult &RHS, QualType LHSType,
975                                              QualType RHSType,
976                                              bool IsCompAssign) {
977   // if we have an integer operand, the result is the complex type.
978   if (!handleIntegerToComplexFloatConversion(S, RHS, LHS, RHSType, LHSType,
979                                              /*skipCast*/false))
980     return LHSType;
981   if (!handleIntegerToComplexFloatConversion(S, LHS, RHS, LHSType, RHSType,
982                                              /*skipCast*/IsCompAssign))
983     return RHSType;
984 
985   // This handles complex/complex, complex/float, or float/complex.
986   // When both operands are complex, the shorter operand is converted to the
987   // type of the longer, and that is the type of the result. This corresponds
988   // to what is done when combining two real floating-point operands.
989   // The fun begins when size promotion occur across type domains.
990   // From H&S 6.3.4: When one operand is complex and the other is a real
991   // floating-point type, the less precise type is converted, within it's
992   // real or complex domain, to the precision of the other type. For example,
993   // when combining a "long double" with a "double _Complex", the
994   // "double _Complex" is promoted to "long double _Complex".
995 
996   bool LHSComplexFloat = LHSType->isComplexType();
997   bool RHSComplexFloat = RHSType->isComplexType();
998 
999   // If both are complex, just cast to the more precise type.
1000   if (LHSComplexFloat && RHSComplexFloat)
1001     return handleComplexFloatToComplexFloatConverstion(S, LHS, RHS,
1002                                                        LHSType, RHSType,
1003                                                        IsCompAssign);
1004 
1005   // If only one operand is complex, promote it if necessary and convert the
1006   // other operand to complex.
1007   if (LHSComplexFloat)
1008     return handleOtherComplexFloatConversion(
1009         S, LHS, RHS, LHSType, RHSType, /*convertComplexExpr*/!IsCompAssign,
1010         /*convertOtherExpr*/ true);
1011 
1012   assert(RHSComplexFloat);
1013   return handleOtherComplexFloatConversion(
1014       S, RHS, LHS, RHSType, LHSType, /*convertComplexExpr*/true,
1015       /*convertOtherExpr*/ !IsCompAssign);
1016 }
1017 
1018 /// \brief Hande arithmetic conversion from integer to float.  Helper function
1019 /// of UsualArithmeticConversions()
1020 static QualType handleIntToFloatConversion(Sema &S, ExprResult &FloatExpr,
1021                                            ExprResult &IntExpr,
1022                                            QualType FloatTy, QualType IntTy,
1023                                            bool ConvertFloat, bool ConvertInt) {
1024   if (IntTy->isIntegerType()) {
1025     if (ConvertInt)
1026       // Convert intExpr to the lhs floating point type.
1027       IntExpr = S.ImpCastExprToType(IntExpr.take(), FloatTy,
1028                                     CK_IntegralToFloating);
1029     return FloatTy;
1030   }
1031 
1032   // Convert both sides to the appropriate complex float.
1033   assert(IntTy->isComplexIntegerType());
1034   QualType result = S.Context.getComplexType(FloatTy);
1035 
1036   // _Complex int -> _Complex float
1037   if (ConvertInt)
1038     IntExpr = S.ImpCastExprToType(IntExpr.take(), result,
1039                                   CK_IntegralComplexToFloatingComplex);
1040 
1041   // float -> _Complex float
1042   if (ConvertFloat)
1043     FloatExpr = S.ImpCastExprToType(FloatExpr.take(), result,
1044                                     CK_FloatingRealToComplex);
1045 
1046   return result;
1047 }
1048 
1049 /// \brief Handle arithmethic conversion with floating point types.  Helper
1050 /// function of UsualArithmeticConversions()
1051 static QualType handleFloatConversion(Sema &S, ExprResult &LHS,
1052                                       ExprResult &RHS, QualType LHSType,
1053                                       QualType RHSType, bool IsCompAssign) {
1054   bool LHSFloat = LHSType->isRealFloatingType();
1055   bool RHSFloat = RHSType->isRealFloatingType();
1056 
1057   // If we have two real floating types, convert the smaller operand
1058   // to the bigger result.
1059   if (LHSFloat && RHSFloat) {
1060     int order = S.Context.getFloatingTypeOrder(LHSType, RHSType);
1061     if (order > 0) {
1062       RHS = S.ImpCastExprToType(RHS.take(), LHSType, CK_FloatingCast);
1063       return LHSType;
1064     }
1065 
1066     assert(order < 0 && "illegal float comparison");
1067     if (!IsCompAssign)
1068       LHS = S.ImpCastExprToType(LHS.take(), RHSType, CK_FloatingCast);
1069     return RHSType;
1070   }
1071 
1072   if (LHSFloat)
1073     return handleIntToFloatConversion(S, LHS, RHS, LHSType, RHSType,
1074                                       /*convertFloat=*/!IsCompAssign,
1075                                       /*convertInt=*/ true);
1076   assert(RHSFloat);
1077   return handleIntToFloatConversion(S, RHS, LHS, RHSType, LHSType,
1078                                     /*convertInt=*/ true,
1079                                     /*convertFloat=*/!IsCompAssign);
1080 }
1081 
1082 typedef ExprResult PerformCastFn(Sema &S, Expr *operand, QualType toType);
1083 
1084 namespace {
1085 /// These helper callbacks are placed in an anonymous namespace to
1086 /// permit their use as function template parameters.
1087 ExprResult doIntegralCast(Sema &S, Expr *op, QualType toType) {
1088   return S.ImpCastExprToType(op, toType, CK_IntegralCast);
1089 }
1090 
1091 ExprResult doComplexIntegralCast(Sema &S, Expr *op, QualType toType) {
1092   return S.ImpCastExprToType(op, S.Context.getComplexType(toType),
1093                              CK_IntegralComplexCast);
1094 }
1095 }
1096 
1097 /// \brief Handle integer arithmetic conversions.  Helper function of
1098 /// UsualArithmeticConversions()
1099 template <PerformCastFn doLHSCast, PerformCastFn doRHSCast>
1100 static QualType handleIntegerConversion(Sema &S, ExprResult &LHS,
1101                                         ExprResult &RHS, QualType LHSType,
1102                                         QualType RHSType, bool IsCompAssign) {
1103   // The rules for this case are in C99 6.3.1.8
1104   int order = S.Context.getIntegerTypeOrder(LHSType, RHSType);
1105   bool LHSSigned = LHSType->hasSignedIntegerRepresentation();
1106   bool RHSSigned = RHSType->hasSignedIntegerRepresentation();
1107   if (LHSSigned == RHSSigned) {
1108     // Same signedness; use the higher-ranked type
1109     if (order >= 0) {
1110       RHS = (*doRHSCast)(S, RHS.take(), LHSType);
1111       return LHSType;
1112     } else if (!IsCompAssign)
1113       LHS = (*doLHSCast)(S, LHS.take(), RHSType);
1114     return RHSType;
1115   } else if (order != (LHSSigned ? 1 : -1)) {
1116     // The unsigned type has greater than or equal rank to the
1117     // signed type, so use the unsigned type
1118     if (RHSSigned) {
1119       RHS = (*doRHSCast)(S, RHS.take(), LHSType);
1120       return LHSType;
1121     } else if (!IsCompAssign)
1122       LHS = (*doLHSCast)(S, LHS.take(), RHSType);
1123     return RHSType;
1124   } else if (S.Context.getIntWidth(LHSType) != S.Context.getIntWidth(RHSType)) {
1125     // The two types are different widths; if we are here, that
1126     // means the signed type is larger than the unsigned type, so
1127     // use the signed type.
1128     if (LHSSigned) {
1129       RHS = (*doRHSCast)(S, RHS.take(), LHSType);
1130       return LHSType;
1131     } else if (!IsCompAssign)
1132       LHS = (*doLHSCast)(S, LHS.take(), RHSType);
1133     return RHSType;
1134   } else {
1135     // The signed type is higher-ranked than the unsigned type,
1136     // but isn't actually any bigger (like unsigned int and long
1137     // on most 32-bit systems).  Use the unsigned type corresponding
1138     // to the signed type.
1139     QualType result =
1140       S.Context.getCorrespondingUnsignedType(LHSSigned ? LHSType : RHSType);
1141     RHS = (*doRHSCast)(S, RHS.take(), result);
1142     if (!IsCompAssign)
1143       LHS = (*doLHSCast)(S, LHS.take(), result);
1144     return result;
1145   }
1146 }
1147 
1148 /// \brief Handle conversions with GCC complex int extension.  Helper function
1149 /// of UsualArithmeticConversions()
1150 static QualType handleComplexIntConversion(Sema &S, ExprResult &LHS,
1151                                            ExprResult &RHS, QualType LHSType,
1152                                            QualType RHSType,
1153                                            bool IsCompAssign) {
1154   const ComplexType *LHSComplexInt = LHSType->getAsComplexIntegerType();
1155   const ComplexType *RHSComplexInt = RHSType->getAsComplexIntegerType();
1156 
1157   if (LHSComplexInt && RHSComplexInt) {
1158     QualType LHSEltType = LHSComplexInt->getElementType();
1159     QualType RHSEltType = RHSComplexInt->getElementType();
1160     QualType ScalarType =
1161       handleIntegerConversion<doComplexIntegralCast, doComplexIntegralCast>
1162         (S, LHS, RHS, LHSEltType, RHSEltType, IsCompAssign);
1163 
1164     return S.Context.getComplexType(ScalarType);
1165   }
1166 
1167   if (LHSComplexInt) {
1168     QualType LHSEltType = LHSComplexInt->getElementType();
1169     QualType ScalarType =
1170       handleIntegerConversion<doComplexIntegralCast, doIntegralCast>
1171         (S, LHS, RHS, LHSEltType, RHSType, IsCompAssign);
1172     QualType ComplexType = S.Context.getComplexType(ScalarType);
1173     RHS = S.ImpCastExprToType(RHS.take(), ComplexType,
1174                               CK_IntegralRealToComplex);
1175 
1176     return ComplexType;
1177   }
1178 
1179   assert(RHSComplexInt);
1180 
1181   QualType RHSEltType = RHSComplexInt->getElementType();
1182   QualType ScalarType =
1183     handleIntegerConversion<doIntegralCast, doComplexIntegralCast>
1184       (S, LHS, RHS, LHSType, RHSEltType, IsCompAssign);
1185   QualType ComplexType = S.Context.getComplexType(ScalarType);
1186 
1187   if (!IsCompAssign)
1188     LHS = S.ImpCastExprToType(LHS.take(), ComplexType,
1189                               CK_IntegralRealToComplex);
1190   return ComplexType;
1191 }
1192 
1193 /// UsualArithmeticConversions - Performs various conversions that are common to
1194 /// binary operators (C99 6.3.1.8). If both operands aren't arithmetic, this
1195 /// routine returns the first non-arithmetic type found. The client is
1196 /// responsible for emitting appropriate error diagnostics.
1197 QualType Sema::UsualArithmeticConversions(ExprResult &LHS, ExprResult &RHS,
1198                                           bool IsCompAssign) {
1199   if (!IsCompAssign) {
1200     LHS = UsualUnaryConversions(LHS.take());
1201     if (LHS.isInvalid())
1202       return QualType();
1203   }
1204 
1205   RHS = UsualUnaryConversions(RHS.take());
1206   if (RHS.isInvalid())
1207     return QualType();
1208 
1209   // For conversion purposes, we ignore any qualifiers.
1210   // For example, "const float" and "float" are equivalent.
1211   QualType LHSType =
1212     Context.getCanonicalType(LHS.get()->getType()).getUnqualifiedType();
1213   QualType RHSType =
1214     Context.getCanonicalType(RHS.get()->getType()).getUnqualifiedType();
1215 
1216   // For conversion purposes, we ignore any atomic qualifier on the LHS.
1217   if (const AtomicType *AtomicLHS = LHSType->getAs<AtomicType>())
1218     LHSType = AtomicLHS->getValueType();
1219 
1220   // If both types are identical, no conversion is needed.
1221   if (LHSType == RHSType)
1222     return LHSType;
1223 
1224   // If either side is a non-arithmetic type (e.g. a pointer), we are done.
1225   // The caller can deal with this (e.g. pointer + int).
1226   if (!LHSType->isArithmeticType() || !RHSType->isArithmeticType())
1227     return QualType();
1228 
1229   // Apply unary and bitfield promotions to the LHS's type.
1230   QualType LHSUnpromotedType = LHSType;
1231   if (LHSType->isPromotableIntegerType())
1232     LHSType = Context.getPromotedIntegerType(LHSType);
1233   QualType LHSBitfieldPromoteTy = Context.isPromotableBitField(LHS.get());
1234   if (!LHSBitfieldPromoteTy.isNull())
1235     LHSType = LHSBitfieldPromoteTy;
1236   if (LHSType != LHSUnpromotedType && !IsCompAssign)
1237     LHS = ImpCastExprToType(LHS.take(), LHSType, CK_IntegralCast);
1238 
1239   // If both types are identical, no conversion is needed.
1240   if (LHSType == RHSType)
1241     return LHSType;
1242 
1243   // At this point, we have two different arithmetic types.
1244 
1245   // Handle complex types first (C99 6.3.1.8p1).
1246   if (LHSType->isComplexType() || RHSType->isComplexType())
1247     return handleComplexFloatConversion(*this, LHS, RHS, LHSType, RHSType,
1248                                         IsCompAssign);
1249 
1250   // Now handle "real" floating types (i.e. float, double, long double).
1251   if (LHSType->isRealFloatingType() || RHSType->isRealFloatingType())
1252     return handleFloatConversion(*this, LHS, RHS, LHSType, RHSType,
1253                                  IsCompAssign);
1254 
1255   // Handle GCC complex int extension.
1256   if (LHSType->isComplexIntegerType() || RHSType->isComplexIntegerType())
1257     return handleComplexIntConversion(*this, LHS, RHS, LHSType, RHSType,
1258                                       IsCompAssign);
1259 
1260   // Finally, we have two differing integer types.
1261   return handleIntegerConversion<doIntegralCast, doIntegralCast>
1262            (*this, LHS, RHS, LHSType, RHSType, IsCompAssign);
1263 }
1264 
1265 
1266 //===----------------------------------------------------------------------===//
1267 //  Semantic Analysis for various Expression Types
1268 //===----------------------------------------------------------------------===//
1269 
1270 
1271 ExprResult
1272 Sema::ActOnGenericSelectionExpr(SourceLocation KeyLoc,
1273                                 SourceLocation DefaultLoc,
1274                                 SourceLocation RParenLoc,
1275                                 Expr *ControllingExpr,
1276                                 ArrayRef<ParsedType> ArgTypes,
1277                                 ArrayRef<Expr *> ArgExprs) {
1278   unsigned NumAssocs = ArgTypes.size();
1279   assert(NumAssocs == ArgExprs.size());
1280 
1281   TypeSourceInfo **Types = new TypeSourceInfo*[NumAssocs];
1282   for (unsigned i = 0; i < NumAssocs; ++i) {
1283     if (ArgTypes[i])
1284       (void) GetTypeFromParser(ArgTypes[i], &Types[i]);
1285     else
1286       Types[i] = 0;
1287   }
1288 
1289   ExprResult ER = CreateGenericSelectionExpr(KeyLoc, DefaultLoc, RParenLoc,
1290                                              ControllingExpr,
1291                                              llvm::makeArrayRef(Types, NumAssocs),
1292                                              ArgExprs);
1293   delete [] Types;
1294   return ER;
1295 }
1296 
1297 ExprResult
1298 Sema::CreateGenericSelectionExpr(SourceLocation KeyLoc,
1299                                  SourceLocation DefaultLoc,
1300                                  SourceLocation RParenLoc,
1301                                  Expr *ControllingExpr,
1302                                  ArrayRef<TypeSourceInfo *> Types,
1303                                  ArrayRef<Expr *> Exprs) {
1304   unsigned NumAssocs = Types.size();
1305   assert(NumAssocs == Exprs.size());
1306   if (ControllingExpr->getType()->isPlaceholderType()) {
1307     ExprResult result = CheckPlaceholderExpr(ControllingExpr);
1308     if (result.isInvalid()) return ExprError();
1309     ControllingExpr = result.take();
1310   }
1311 
1312   bool TypeErrorFound = false,
1313        IsResultDependent = ControllingExpr->isTypeDependent(),
1314        ContainsUnexpandedParameterPack
1315          = ControllingExpr->containsUnexpandedParameterPack();
1316 
1317   for (unsigned i = 0; i < NumAssocs; ++i) {
1318     if (Exprs[i]->containsUnexpandedParameterPack())
1319       ContainsUnexpandedParameterPack = true;
1320 
1321     if (Types[i]) {
1322       if (Types[i]->getType()->containsUnexpandedParameterPack())
1323         ContainsUnexpandedParameterPack = true;
1324 
1325       if (Types[i]->getType()->isDependentType()) {
1326         IsResultDependent = true;
1327       } else {
1328         // C11 6.5.1.1p2 "The type name in a generic association shall specify a
1329         // complete object type other than a variably modified type."
1330         unsigned D = 0;
1331         if (Types[i]->getType()->isIncompleteType())
1332           D = diag::err_assoc_type_incomplete;
1333         else if (!Types[i]->getType()->isObjectType())
1334           D = diag::err_assoc_type_nonobject;
1335         else if (Types[i]->getType()->isVariablyModifiedType())
1336           D = diag::err_assoc_type_variably_modified;
1337 
1338         if (D != 0) {
1339           Diag(Types[i]->getTypeLoc().getBeginLoc(), D)
1340             << Types[i]->getTypeLoc().getSourceRange()
1341             << Types[i]->getType();
1342           TypeErrorFound = true;
1343         }
1344 
1345         // C11 6.5.1.1p2 "No two generic associations in the same generic
1346         // selection shall specify compatible types."
1347         for (unsigned j = i+1; j < NumAssocs; ++j)
1348           if (Types[j] && !Types[j]->getType()->isDependentType() &&
1349               Context.typesAreCompatible(Types[i]->getType(),
1350                                          Types[j]->getType())) {
1351             Diag(Types[j]->getTypeLoc().getBeginLoc(),
1352                  diag::err_assoc_compatible_types)
1353               << Types[j]->getTypeLoc().getSourceRange()
1354               << Types[j]->getType()
1355               << Types[i]->getType();
1356             Diag(Types[i]->getTypeLoc().getBeginLoc(),
1357                  diag::note_compat_assoc)
1358               << Types[i]->getTypeLoc().getSourceRange()
1359               << Types[i]->getType();
1360             TypeErrorFound = true;
1361           }
1362       }
1363     }
1364   }
1365   if (TypeErrorFound)
1366     return ExprError();
1367 
1368   // If we determined that the generic selection is result-dependent, don't
1369   // try to compute the result expression.
1370   if (IsResultDependent)
1371     return Owned(new (Context) GenericSelectionExpr(
1372                    Context, KeyLoc, ControllingExpr,
1373                    Types, Exprs,
1374                    DefaultLoc, RParenLoc, ContainsUnexpandedParameterPack));
1375 
1376   SmallVector<unsigned, 1> CompatIndices;
1377   unsigned DefaultIndex = -1U;
1378   for (unsigned i = 0; i < NumAssocs; ++i) {
1379     if (!Types[i])
1380       DefaultIndex = i;
1381     else if (Context.typesAreCompatible(ControllingExpr->getType(),
1382                                         Types[i]->getType()))
1383       CompatIndices.push_back(i);
1384   }
1385 
1386   // C11 6.5.1.1p2 "The controlling expression of a generic selection shall have
1387   // type compatible with at most one of the types named in its generic
1388   // association list."
1389   if (CompatIndices.size() > 1) {
1390     // We strip parens here because the controlling expression is typically
1391     // parenthesized in macro definitions.
1392     ControllingExpr = ControllingExpr->IgnoreParens();
1393     Diag(ControllingExpr->getLocStart(), diag::err_generic_sel_multi_match)
1394       << ControllingExpr->getSourceRange() << ControllingExpr->getType()
1395       << (unsigned) CompatIndices.size();
1396     for (SmallVectorImpl<unsigned>::iterator I = CompatIndices.begin(),
1397          E = CompatIndices.end(); I != E; ++I) {
1398       Diag(Types[*I]->getTypeLoc().getBeginLoc(),
1399            diag::note_compat_assoc)
1400         << Types[*I]->getTypeLoc().getSourceRange()
1401         << Types[*I]->getType();
1402     }
1403     return ExprError();
1404   }
1405 
1406   // C11 6.5.1.1p2 "If a generic selection has no default generic association,
1407   // its controlling expression shall have type compatible with exactly one of
1408   // the types named in its generic association list."
1409   if (DefaultIndex == -1U && CompatIndices.size() == 0) {
1410     // We strip parens here because the controlling expression is typically
1411     // parenthesized in macro definitions.
1412     ControllingExpr = ControllingExpr->IgnoreParens();
1413     Diag(ControllingExpr->getLocStart(), diag::err_generic_sel_no_match)
1414       << ControllingExpr->getSourceRange() << ControllingExpr->getType();
1415     return ExprError();
1416   }
1417 
1418   // C11 6.5.1.1p3 "If a generic selection has a generic association with a
1419   // type name that is compatible with the type of the controlling expression,
1420   // then the result expression of the generic selection is the expression
1421   // in that generic association. Otherwise, the result expression of the
1422   // generic selection is the expression in the default generic association."
1423   unsigned ResultIndex =
1424     CompatIndices.size() ? CompatIndices[0] : DefaultIndex;
1425 
1426   return Owned(new (Context) GenericSelectionExpr(
1427                  Context, KeyLoc, ControllingExpr,
1428                  Types, Exprs,
1429                  DefaultLoc, RParenLoc, ContainsUnexpandedParameterPack,
1430                  ResultIndex));
1431 }
1432 
1433 /// getUDSuffixLoc - Create a SourceLocation for a ud-suffix, given the
1434 /// location of the token and the offset of the ud-suffix within it.
1435 static SourceLocation getUDSuffixLoc(Sema &S, SourceLocation TokLoc,
1436                                      unsigned Offset) {
1437   return Lexer::AdvanceToTokenCharacter(TokLoc, Offset, S.getSourceManager(),
1438                                         S.getLangOpts());
1439 }
1440 
1441 /// BuildCookedLiteralOperatorCall - A user-defined literal was found. Look up
1442 /// the corresponding cooked (non-raw) literal operator, and build a call to it.
1443 static ExprResult BuildCookedLiteralOperatorCall(Sema &S, Scope *Scope,
1444                                                  IdentifierInfo *UDSuffix,
1445                                                  SourceLocation UDSuffixLoc,
1446                                                  ArrayRef<Expr*> Args,
1447                                                  SourceLocation LitEndLoc) {
1448   assert(Args.size() <= 2 && "too many arguments for literal operator");
1449 
1450   QualType ArgTy[2];
1451   for (unsigned ArgIdx = 0; ArgIdx != Args.size(); ++ArgIdx) {
1452     ArgTy[ArgIdx] = Args[ArgIdx]->getType();
1453     if (ArgTy[ArgIdx]->isArrayType())
1454       ArgTy[ArgIdx] = S.Context.getArrayDecayedType(ArgTy[ArgIdx]);
1455   }
1456 
1457   DeclarationName OpName =
1458     S.Context.DeclarationNames.getCXXLiteralOperatorName(UDSuffix);
1459   DeclarationNameInfo OpNameInfo(OpName, UDSuffixLoc);
1460   OpNameInfo.setCXXLiteralOperatorNameLoc(UDSuffixLoc);
1461 
1462   LookupResult R(S, OpName, UDSuffixLoc, Sema::LookupOrdinaryName);
1463   if (S.LookupLiteralOperator(Scope, R, llvm::makeArrayRef(ArgTy, Args.size()),
1464                               /*AllowRaw*/false, /*AllowTemplate*/false,
1465                               /*AllowStringTemplate*/false) == Sema::LOLR_Error)
1466     return ExprError();
1467 
1468   return S.BuildLiteralOperatorCall(R, OpNameInfo, Args, LitEndLoc);
1469 }
1470 
1471 /// ActOnStringLiteral - The specified tokens were lexed as pasted string
1472 /// fragments (e.g. "foo" "bar" L"baz").  The result string has to handle string
1473 /// concatenation ([C99 5.1.1.2, translation phase #6]), so it may come from
1474 /// multiple tokens.  However, the common case is that StringToks points to one
1475 /// string.
1476 ///
1477 ExprResult
1478 Sema::ActOnStringLiteral(const Token *StringToks, unsigned NumStringToks,
1479                          Scope *UDLScope) {
1480   assert(NumStringToks && "Must have at least one string!");
1481 
1482   StringLiteralParser Literal(StringToks, NumStringToks, PP);
1483   if (Literal.hadError)
1484     return ExprError();
1485 
1486   SmallVector<SourceLocation, 4> StringTokLocs;
1487   for (unsigned i = 0; i != NumStringToks; ++i)
1488     StringTokLocs.push_back(StringToks[i].getLocation());
1489 
1490   QualType CharTy = Context.CharTy;
1491   StringLiteral::StringKind Kind = StringLiteral::Ascii;
1492   if (Literal.isWide()) {
1493     CharTy = Context.getWideCharType();
1494     Kind = StringLiteral::Wide;
1495   } else if (Literal.isUTF8()) {
1496     Kind = StringLiteral::UTF8;
1497   } else if (Literal.isUTF16()) {
1498     CharTy = Context.Char16Ty;
1499     Kind = StringLiteral::UTF16;
1500   } else if (Literal.isUTF32()) {
1501     CharTy = Context.Char32Ty;
1502     Kind = StringLiteral::UTF32;
1503   } else if (Literal.isPascal()) {
1504     CharTy = Context.UnsignedCharTy;
1505   }
1506 
1507   QualType CharTyConst = CharTy;
1508   // A C++ string literal has a const-qualified element type (C++ 2.13.4p1).
1509   if (getLangOpts().CPlusPlus || getLangOpts().ConstStrings)
1510     CharTyConst.addConst();
1511 
1512   // Get an array type for the string, according to C99 6.4.5.  This includes
1513   // the nul terminator character as well as the string length for pascal
1514   // strings.
1515   QualType StrTy = Context.getConstantArrayType(CharTyConst,
1516                                  llvm::APInt(32, Literal.GetNumStringChars()+1),
1517                                  ArrayType::Normal, 0);
1518 
1519   // Pass &StringTokLocs[0], StringTokLocs.size() to factory!
1520   StringLiteral *Lit = StringLiteral::Create(Context, Literal.GetString(),
1521                                              Kind, Literal.Pascal, StrTy,
1522                                              &StringTokLocs[0],
1523                                              StringTokLocs.size());
1524   if (Literal.getUDSuffix().empty())
1525     return Owned(Lit);
1526 
1527   // We're building a user-defined literal.
1528   IdentifierInfo *UDSuffix = &Context.Idents.get(Literal.getUDSuffix());
1529   SourceLocation UDSuffixLoc =
1530     getUDSuffixLoc(*this, StringTokLocs[Literal.getUDSuffixToken()],
1531                    Literal.getUDSuffixOffset());
1532 
1533   // Make sure we're allowed user-defined literals here.
1534   if (!UDLScope)
1535     return ExprError(Diag(UDSuffixLoc, diag::err_invalid_string_udl));
1536 
1537   // C++11 [lex.ext]p5: The literal L is treated as a call of the form
1538   //   operator "" X (str, len)
1539   QualType SizeType = Context.getSizeType();
1540 
1541   DeclarationName OpName =
1542     Context.DeclarationNames.getCXXLiteralOperatorName(UDSuffix);
1543   DeclarationNameInfo OpNameInfo(OpName, UDSuffixLoc);
1544   OpNameInfo.setCXXLiteralOperatorNameLoc(UDSuffixLoc);
1545 
1546   QualType ArgTy[] = {
1547     Context.getArrayDecayedType(StrTy), SizeType
1548   };
1549 
1550   LookupResult R(*this, OpName, UDSuffixLoc, LookupOrdinaryName);
1551   switch (LookupLiteralOperator(UDLScope, R, ArgTy,
1552                                 /*AllowRaw*/false, /*AllowTemplate*/false,
1553                                 /*AllowStringTemplate*/true)) {
1554 
1555   case LOLR_Cooked: {
1556     llvm::APInt Len(Context.getIntWidth(SizeType), Literal.GetNumStringChars());
1557     IntegerLiteral *LenArg = IntegerLiteral::Create(Context, Len, SizeType,
1558                                                     StringTokLocs[0]);
1559     Expr *Args[] = { Lit, LenArg };
1560 
1561     return BuildLiteralOperatorCall(R, OpNameInfo, Args, StringTokLocs.back());
1562   }
1563 
1564   case LOLR_StringTemplate: {
1565     TemplateArgumentListInfo ExplicitArgs;
1566 
1567     unsigned CharBits = Context.getIntWidth(CharTy);
1568     bool CharIsUnsigned = CharTy->isUnsignedIntegerType();
1569     llvm::APSInt Value(CharBits, CharIsUnsigned);
1570 
1571     TemplateArgument TypeArg(CharTy);
1572     TemplateArgumentLocInfo TypeArgInfo(Context.getTrivialTypeSourceInfo(CharTy));
1573     ExplicitArgs.addArgument(TemplateArgumentLoc(TypeArg, TypeArgInfo));
1574 
1575     for (unsigned I = 0, N = Lit->getLength(); I != N; ++I) {
1576       Value = Lit->getCodeUnit(I);
1577       TemplateArgument Arg(Context, Value, CharTy);
1578       TemplateArgumentLocInfo ArgInfo;
1579       ExplicitArgs.addArgument(TemplateArgumentLoc(Arg, ArgInfo));
1580     }
1581     return BuildLiteralOperatorCall(R, OpNameInfo, None, StringTokLocs.back(),
1582                                     &ExplicitArgs);
1583   }
1584   case LOLR_Raw:
1585   case LOLR_Template:
1586     llvm_unreachable("unexpected literal operator lookup result");
1587   case LOLR_Error:
1588     return ExprError();
1589   }
1590   llvm_unreachable("unexpected literal operator lookup result");
1591 }
1592 
1593 ExprResult
1594 Sema::BuildDeclRefExpr(ValueDecl *D, QualType Ty, ExprValueKind VK,
1595                        SourceLocation Loc,
1596                        const CXXScopeSpec *SS) {
1597   DeclarationNameInfo NameInfo(D->getDeclName(), Loc);
1598   return BuildDeclRefExpr(D, Ty, VK, NameInfo, SS);
1599 }
1600 
1601 /// BuildDeclRefExpr - Build an expression that references a
1602 /// declaration that does not require a closure capture.
1603 ExprResult
1604 Sema::BuildDeclRefExpr(ValueDecl *D, QualType Ty, ExprValueKind VK,
1605                        const DeclarationNameInfo &NameInfo,
1606                        const CXXScopeSpec *SS, NamedDecl *FoundD,
1607                        const TemplateArgumentListInfo *TemplateArgs) {
1608   if (getLangOpts().CUDA)
1609     if (const FunctionDecl *Caller = dyn_cast<FunctionDecl>(CurContext))
1610       if (const FunctionDecl *Callee = dyn_cast<FunctionDecl>(D)) {
1611         CUDAFunctionTarget CallerTarget = IdentifyCUDATarget(Caller),
1612                            CalleeTarget = IdentifyCUDATarget(Callee);
1613         if (CheckCUDATarget(CallerTarget, CalleeTarget)) {
1614           Diag(NameInfo.getLoc(), diag::err_ref_bad_target)
1615             << CalleeTarget << D->getIdentifier() << CallerTarget;
1616           Diag(D->getLocation(), diag::note_previous_decl)
1617             << D->getIdentifier();
1618           return ExprError();
1619         }
1620       }
1621 
1622   bool refersToEnclosingScope =
1623     (CurContext != D->getDeclContext() &&
1624      D->getDeclContext()->isFunctionOrMethod()) ||
1625     (isa<VarDecl>(D) &&
1626      cast<VarDecl>(D)->isInitCapture());
1627 
1628   DeclRefExpr *E;
1629   if (isa<VarTemplateSpecializationDecl>(D)) {
1630     VarTemplateSpecializationDecl *VarSpec =
1631         cast<VarTemplateSpecializationDecl>(D);
1632 
1633     E = DeclRefExpr::Create(
1634         Context,
1635         SS ? SS->getWithLocInContext(Context) : NestedNameSpecifierLoc(),
1636         VarSpec->getTemplateKeywordLoc(), D, refersToEnclosingScope,
1637         NameInfo.getLoc(), Ty, VK, FoundD, TemplateArgs);
1638   } else {
1639     assert(!TemplateArgs && "No template arguments for non-variable"
1640                             " template specialization referrences");
1641     E = DeclRefExpr::Create(
1642         Context,
1643         SS ? SS->getWithLocInContext(Context) : NestedNameSpecifierLoc(),
1644         SourceLocation(), D, refersToEnclosingScope, NameInfo, Ty, VK, FoundD);
1645   }
1646 
1647   MarkDeclRefReferenced(E);
1648 
1649   if (getLangOpts().ObjCARCWeak && isa<VarDecl>(D) &&
1650       Ty.getObjCLifetime() == Qualifiers::OCL_Weak) {
1651     DiagnosticsEngine::Level Level =
1652       Diags.getDiagnosticLevel(diag::warn_arc_repeated_use_of_weak,
1653                                E->getLocStart());
1654     if (Level != DiagnosticsEngine::Ignored)
1655       recordUseOfEvaluatedWeak(E);
1656   }
1657 
1658   // Just in case we're building an illegal pointer-to-member.
1659   FieldDecl *FD = dyn_cast<FieldDecl>(D);
1660   if (FD && FD->isBitField())
1661     E->setObjectKind(OK_BitField);
1662 
1663   return Owned(E);
1664 }
1665 
1666 /// Decomposes the given name into a DeclarationNameInfo, its location, and
1667 /// possibly a list of template arguments.
1668 ///
1669 /// If this produces template arguments, it is permitted to call
1670 /// DecomposeTemplateName.
1671 ///
1672 /// This actually loses a lot of source location information for
1673 /// non-standard name kinds; we should consider preserving that in
1674 /// some way.
1675 void
1676 Sema::DecomposeUnqualifiedId(const UnqualifiedId &Id,
1677                              TemplateArgumentListInfo &Buffer,
1678                              DeclarationNameInfo &NameInfo,
1679                              const TemplateArgumentListInfo *&TemplateArgs) {
1680   if (Id.getKind() == UnqualifiedId::IK_TemplateId) {
1681     Buffer.setLAngleLoc(Id.TemplateId->LAngleLoc);
1682     Buffer.setRAngleLoc(Id.TemplateId->RAngleLoc);
1683 
1684     ASTTemplateArgsPtr TemplateArgsPtr(Id.TemplateId->getTemplateArgs(),
1685                                        Id.TemplateId->NumArgs);
1686     translateTemplateArguments(TemplateArgsPtr, Buffer);
1687 
1688     TemplateName TName = Id.TemplateId->Template.get();
1689     SourceLocation TNameLoc = Id.TemplateId->TemplateNameLoc;
1690     NameInfo = Context.getNameForTemplate(TName, TNameLoc);
1691     TemplateArgs = &Buffer;
1692   } else {
1693     NameInfo = GetNameFromUnqualifiedId(Id);
1694     TemplateArgs = 0;
1695   }
1696 }
1697 
1698 /// Diagnose an empty lookup.
1699 ///
1700 /// \return false if new lookup candidates were found
1701 bool Sema::DiagnoseEmptyLookup(Scope *S, CXXScopeSpec &SS, LookupResult &R,
1702                                CorrectionCandidateCallback &CCC,
1703                                TemplateArgumentListInfo *ExplicitTemplateArgs,
1704                                ArrayRef<Expr *> Args) {
1705   DeclarationName Name = R.getLookupName();
1706 
1707   unsigned diagnostic = diag::err_undeclared_var_use;
1708   unsigned diagnostic_suggest = diag::err_undeclared_var_use_suggest;
1709   if (Name.getNameKind() == DeclarationName::CXXOperatorName ||
1710       Name.getNameKind() == DeclarationName::CXXLiteralOperatorName ||
1711       Name.getNameKind() == DeclarationName::CXXConversionFunctionName) {
1712     diagnostic = diag::err_undeclared_use;
1713     diagnostic_suggest = diag::err_undeclared_use_suggest;
1714   }
1715 
1716   // If the original lookup was an unqualified lookup, fake an
1717   // unqualified lookup.  This is useful when (for example) the
1718   // original lookup would not have found something because it was a
1719   // dependent name.
1720   DeclContext *DC = (SS.isEmpty() && !CallsUndergoingInstantiation.empty())
1721     ? CurContext : 0;
1722   while (DC) {
1723     if (isa<CXXRecordDecl>(DC)) {
1724       LookupQualifiedName(R, DC);
1725 
1726       if (!R.empty()) {
1727         // Don't give errors about ambiguities in this lookup.
1728         R.suppressDiagnostics();
1729 
1730         // During a default argument instantiation the CurContext points
1731         // to a CXXMethodDecl; but we can't apply a this-> fixit inside a
1732         // function parameter list, hence add an explicit check.
1733         bool isDefaultArgument = !ActiveTemplateInstantiations.empty() &&
1734                               ActiveTemplateInstantiations.back().Kind ==
1735             ActiveTemplateInstantiation::DefaultFunctionArgumentInstantiation;
1736         CXXMethodDecl *CurMethod = dyn_cast<CXXMethodDecl>(CurContext);
1737         bool isInstance = CurMethod &&
1738                           CurMethod->isInstance() &&
1739                           DC == CurMethod->getParent() && !isDefaultArgument;
1740 
1741 
1742         // Give a code modification hint to insert 'this->'.
1743         // TODO: fixit for inserting 'Base<T>::' in the other cases.
1744         // Actually quite difficult!
1745         if (getLangOpts().MicrosoftMode)
1746           diagnostic = diag::warn_found_via_dependent_bases_lookup;
1747         if (isInstance) {
1748           Diag(R.getNameLoc(), diagnostic) << Name
1749             << FixItHint::CreateInsertion(R.getNameLoc(), "this->");
1750           UnresolvedLookupExpr *ULE = cast<UnresolvedLookupExpr>(
1751               CallsUndergoingInstantiation.back()->getCallee());
1752 
1753           CXXMethodDecl *DepMethod;
1754           if (CurMethod->isDependentContext())
1755             DepMethod = CurMethod;
1756           else if (CurMethod->getTemplatedKind() ==
1757               FunctionDecl::TK_FunctionTemplateSpecialization)
1758             DepMethod = cast<CXXMethodDecl>(CurMethod->getPrimaryTemplate()->
1759                 getInstantiatedFromMemberTemplate()->getTemplatedDecl());
1760           else
1761             DepMethod = cast<CXXMethodDecl>(
1762                 CurMethod->getInstantiatedFromMemberFunction());
1763           assert(DepMethod && "No template pattern found");
1764 
1765           QualType DepThisType = DepMethod->getThisType(Context);
1766           CheckCXXThisCapture(R.getNameLoc());
1767           CXXThisExpr *DepThis = new (Context) CXXThisExpr(
1768                                      R.getNameLoc(), DepThisType, false);
1769           TemplateArgumentListInfo TList;
1770           if (ULE->hasExplicitTemplateArgs())
1771             ULE->copyTemplateArgumentsInto(TList);
1772 
1773           CXXScopeSpec SS;
1774           SS.Adopt(ULE->getQualifierLoc());
1775           CXXDependentScopeMemberExpr *DepExpr =
1776               CXXDependentScopeMemberExpr::Create(
1777                   Context, DepThis, DepThisType, true, SourceLocation(),
1778                   SS.getWithLocInContext(Context),
1779                   ULE->getTemplateKeywordLoc(), 0,
1780                   R.getLookupNameInfo(),
1781                   ULE->hasExplicitTemplateArgs() ? &TList : 0);
1782           CallsUndergoingInstantiation.back()->setCallee(DepExpr);
1783         } else {
1784           Diag(R.getNameLoc(), diagnostic) << Name;
1785         }
1786 
1787         // Do we really want to note all of these?
1788         for (LookupResult::iterator I = R.begin(), E = R.end(); I != E; ++I)
1789           Diag((*I)->getLocation(), diag::note_dependent_var_use);
1790 
1791         // Return true if we are inside a default argument instantiation
1792         // and the found name refers to an instance member function, otherwise
1793         // the function calling DiagnoseEmptyLookup will try to create an
1794         // implicit member call and this is wrong for default argument.
1795         if (isDefaultArgument && ((*R.begin())->isCXXInstanceMember())) {
1796           Diag(R.getNameLoc(), diag::err_member_call_without_object);
1797           return true;
1798         }
1799 
1800         // Tell the callee to try to recover.
1801         return false;
1802       }
1803 
1804       R.clear();
1805     }
1806 
1807     // In Microsoft mode, if we are performing lookup from within a friend
1808     // function definition declared at class scope then we must set
1809     // DC to the lexical parent to be able to search into the parent
1810     // class.
1811     if (getLangOpts().MicrosoftMode && isa<FunctionDecl>(DC) &&
1812         cast<FunctionDecl>(DC)->getFriendObjectKind() &&
1813         DC->getLexicalParent()->isRecord())
1814       DC = DC->getLexicalParent();
1815     else
1816       DC = DC->getParent();
1817   }
1818 
1819   // We didn't find anything, so try to correct for a typo.
1820   TypoCorrection Corrected;
1821   if (S && (Corrected = CorrectTypo(R.getLookupNameInfo(), R.getLookupKind(),
1822                                     S, &SS, CCC))) {
1823     std::string CorrectedStr(Corrected.getAsString(getLangOpts()));
1824     bool DroppedSpecifier =
1825         Corrected.WillReplaceSpecifier() && Name.getAsString() == CorrectedStr;
1826     R.setLookupName(Corrected.getCorrection());
1827 
1828     bool AcceptableWithRecovery = false;
1829     bool AcceptableWithoutRecovery = false;
1830     NamedDecl *ND = Corrected.getCorrectionDecl();
1831     if (ND) {
1832       if (Corrected.isOverloaded()) {
1833         OverloadCandidateSet OCS(R.getNameLoc());
1834         OverloadCandidateSet::iterator Best;
1835         for (TypoCorrection::decl_iterator CD = Corrected.begin(),
1836                                         CDEnd = Corrected.end();
1837              CD != CDEnd; ++CD) {
1838           if (FunctionTemplateDecl *FTD =
1839                    dyn_cast<FunctionTemplateDecl>(*CD))
1840             AddTemplateOverloadCandidate(
1841                 FTD, DeclAccessPair::make(FTD, AS_none), ExplicitTemplateArgs,
1842                 Args, OCS);
1843           else if (FunctionDecl *FD = dyn_cast<FunctionDecl>(*CD))
1844             if (!ExplicitTemplateArgs || ExplicitTemplateArgs->size() == 0)
1845               AddOverloadCandidate(FD, DeclAccessPair::make(FD, AS_none),
1846                                    Args, OCS);
1847         }
1848         switch (OCS.BestViableFunction(*this, R.getNameLoc(), Best)) {
1849         case OR_Success:
1850           ND = Best->Function;
1851           Corrected.setCorrectionDecl(ND);
1852           break;
1853         default:
1854           // FIXME: Arbitrarily pick the first declaration for the note.
1855           Corrected.setCorrectionDecl(ND);
1856           break;
1857         }
1858       }
1859       R.addDecl(ND);
1860 
1861       AcceptableWithRecovery =
1862           isa<ValueDecl>(ND) || isa<FunctionTemplateDecl>(ND);
1863       // FIXME: If we ended up with a typo for a type name or
1864       // Objective-C class name, we're in trouble because the parser
1865       // is in the wrong place to recover. Suggest the typo
1866       // correction, but don't make it a fix-it since we're not going
1867       // to recover well anyway.
1868       AcceptableWithoutRecovery =
1869           isa<TypeDecl>(ND) || isa<ObjCInterfaceDecl>(ND);
1870     } else {
1871       // FIXME: We found a keyword. Suggest it, but don't provide a fix-it
1872       // because we aren't able to recover.
1873       AcceptableWithoutRecovery = true;
1874     }
1875 
1876     if (AcceptableWithRecovery || AcceptableWithoutRecovery) {
1877       unsigned NoteID = (Corrected.getCorrectionDecl() &&
1878                          isa<ImplicitParamDecl>(Corrected.getCorrectionDecl()))
1879                             ? diag::note_implicit_param_decl
1880                             : diag::note_previous_decl;
1881       if (SS.isEmpty())
1882         diagnoseTypo(Corrected, PDiag(diagnostic_suggest) << Name,
1883                      PDiag(NoteID), AcceptableWithRecovery);
1884       else
1885         diagnoseTypo(Corrected, PDiag(diag::err_no_member_suggest)
1886                                   << Name << computeDeclContext(SS, false)
1887                                   << DroppedSpecifier << SS.getRange(),
1888                      PDiag(NoteID), AcceptableWithRecovery);
1889 
1890       // Tell the callee whether to try to recover.
1891       return !AcceptableWithRecovery;
1892     }
1893   }
1894   R.clear();
1895 
1896   // Emit a special diagnostic for failed member lookups.
1897   // FIXME: computing the declaration context might fail here (?)
1898   if (!SS.isEmpty()) {
1899     Diag(R.getNameLoc(), diag::err_no_member)
1900       << Name << computeDeclContext(SS, false)
1901       << SS.getRange();
1902     return true;
1903   }
1904 
1905   // Give up, we can't recover.
1906   Diag(R.getNameLoc(), diagnostic) << Name;
1907   return true;
1908 }
1909 
1910 ExprResult Sema::ActOnIdExpression(Scope *S,
1911                                    CXXScopeSpec &SS,
1912                                    SourceLocation TemplateKWLoc,
1913                                    UnqualifiedId &Id,
1914                                    bool HasTrailingLParen,
1915                                    bool IsAddressOfOperand,
1916                                    CorrectionCandidateCallback *CCC,
1917                                    bool IsInlineAsmIdentifier) {
1918   assert(!(IsAddressOfOperand && HasTrailingLParen) &&
1919          "cannot be direct & operand and have a trailing lparen");
1920   if (SS.isInvalid())
1921     return ExprError();
1922 
1923   TemplateArgumentListInfo TemplateArgsBuffer;
1924 
1925   // Decompose the UnqualifiedId into the following data.
1926   DeclarationNameInfo NameInfo;
1927   const TemplateArgumentListInfo *TemplateArgs;
1928   DecomposeUnqualifiedId(Id, TemplateArgsBuffer, NameInfo, TemplateArgs);
1929 
1930   DeclarationName Name = NameInfo.getName();
1931   IdentifierInfo *II = Name.getAsIdentifierInfo();
1932   SourceLocation NameLoc = NameInfo.getLoc();
1933 
1934   // C++ [temp.dep.expr]p3:
1935   //   An id-expression is type-dependent if it contains:
1936   //     -- an identifier that was declared with a dependent type,
1937   //        (note: handled after lookup)
1938   //     -- a template-id that is dependent,
1939   //        (note: handled in BuildTemplateIdExpr)
1940   //     -- a conversion-function-id that specifies a dependent type,
1941   //     -- a nested-name-specifier that contains a class-name that
1942   //        names a dependent type.
1943   // Determine whether this is a member of an unknown specialization;
1944   // we need to handle these differently.
1945   bool DependentID = false;
1946   if (Name.getNameKind() == DeclarationName::CXXConversionFunctionName &&
1947       Name.getCXXNameType()->isDependentType()) {
1948     DependentID = true;
1949   } else if (SS.isSet()) {
1950     if (DeclContext *DC = computeDeclContext(SS, false)) {
1951       if (RequireCompleteDeclContext(SS, DC))
1952         return ExprError();
1953     } else {
1954       DependentID = true;
1955     }
1956   }
1957 
1958   if (DependentID)
1959     return ActOnDependentIdExpression(SS, TemplateKWLoc, NameInfo,
1960                                       IsAddressOfOperand, TemplateArgs);
1961 
1962   // Perform the required lookup.
1963   LookupResult R(*this, NameInfo,
1964                  (Id.getKind() == UnqualifiedId::IK_ImplicitSelfParam)
1965                   ? LookupObjCImplicitSelfParam : LookupOrdinaryName);
1966   if (TemplateArgs) {
1967     // Lookup the template name again to correctly establish the context in
1968     // which it was found. This is really unfortunate as we already did the
1969     // lookup to determine that it was a template name in the first place. If
1970     // this becomes a performance hit, we can work harder to preserve those
1971     // results until we get here but it's likely not worth it.
1972     bool MemberOfUnknownSpecialization;
1973     LookupTemplateName(R, S, SS, QualType(), /*EnteringContext=*/false,
1974                        MemberOfUnknownSpecialization);
1975 
1976     if (MemberOfUnknownSpecialization ||
1977         (R.getResultKind() == LookupResult::NotFoundInCurrentInstantiation))
1978       return ActOnDependentIdExpression(SS, TemplateKWLoc, NameInfo,
1979                                         IsAddressOfOperand, TemplateArgs);
1980   } else {
1981     bool IvarLookupFollowUp = II && !SS.isSet() && getCurMethodDecl();
1982     LookupParsedName(R, S, &SS, !IvarLookupFollowUp);
1983 
1984     // If the result might be in a dependent base class, this is a dependent
1985     // id-expression.
1986     if (R.getResultKind() == LookupResult::NotFoundInCurrentInstantiation)
1987       return ActOnDependentIdExpression(SS, TemplateKWLoc, NameInfo,
1988                                         IsAddressOfOperand, TemplateArgs);
1989 
1990     // If this reference is in an Objective-C method, then we need to do
1991     // some special Objective-C lookup, too.
1992     if (IvarLookupFollowUp) {
1993       ExprResult E(LookupInObjCMethod(R, S, II, true));
1994       if (E.isInvalid())
1995         return ExprError();
1996 
1997       if (Expr *Ex = E.takeAs<Expr>())
1998         return Owned(Ex);
1999     }
2000   }
2001 
2002   if (R.isAmbiguous())
2003     return ExprError();
2004 
2005   // Determine whether this name might be a candidate for
2006   // argument-dependent lookup.
2007   bool ADL = UseArgumentDependentLookup(SS, R, HasTrailingLParen);
2008 
2009   if (R.empty() && !ADL) {
2010 
2011     // Otherwise, this could be an implicitly declared function reference (legal
2012     // in C90, extension in C99, forbidden in C++).
2013     if (HasTrailingLParen && II && !getLangOpts().CPlusPlus) {
2014       NamedDecl *D = ImplicitlyDefineFunction(NameLoc, *II, S);
2015       if (D) R.addDecl(D);
2016     }
2017 
2018     // If this name wasn't predeclared and if this is not a function
2019     // call, diagnose the problem.
2020     if (R.empty()) {
2021       // In Microsoft mode, if we are inside a template class member function
2022       // whose parent class has dependent base classes, and we can't resolve
2023       // an identifier, then assume the identifier is a member of a dependent
2024       // base class.  The goal is to postpone name lookup to instantiation time
2025       // to be able to search into the type dependent base classes.
2026       // FIXME: If we want 100% compatibility with MSVC, we will have delay all
2027       // unqualified name lookup.  Any name lookup during template parsing means
2028       // clang might find something that MSVC doesn't.  For now, we only handle
2029       // the common case of members of a dependent base class.
2030       if (getLangOpts().MicrosoftMode) {
2031         CXXMethodDecl *MD = dyn_cast<CXXMethodDecl>(CurContext);
2032         if (MD && MD->isInstance() && MD->getParent()->hasAnyDependentBases()) {
2033           assert(SS.isEmpty() && "qualifiers should be already handled");
2034           QualType ThisType = MD->getThisType(Context);
2035           // Since the 'this' expression is synthesized, we don't need to
2036           // perform the double-lookup check.
2037           NamedDecl *FirstQualifierInScope = 0;
2038           return Owned(CXXDependentScopeMemberExpr::Create(
2039               Context, /*This=*/0, ThisType, /*IsArrow=*/true,
2040               /*Op=*/SourceLocation(), SS.getWithLocInContext(Context),
2041               TemplateKWLoc, FirstQualifierInScope, NameInfo, TemplateArgs));
2042         }
2043       }
2044 
2045       // Don't diagnose an empty lookup for inline assmebly.
2046       if (IsInlineAsmIdentifier)
2047         return ExprError();
2048 
2049       CorrectionCandidateCallback DefaultValidator;
2050       if (DiagnoseEmptyLookup(S, SS, R, CCC ? *CCC : DefaultValidator))
2051         return ExprError();
2052 
2053       assert(!R.empty() &&
2054              "DiagnoseEmptyLookup returned false but added no results");
2055 
2056       // If we found an Objective-C instance variable, let
2057       // LookupInObjCMethod build the appropriate expression to
2058       // reference the ivar.
2059       if (ObjCIvarDecl *Ivar = R.getAsSingle<ObjCIvarDecl>()) {
2060         R.clear();
2061         ExprResult E(LookupInObjCMethod(R, S, Ivar->getIdentifier()));
2062         // In a hopelessly buggy code, Objective-C instance variable
2063         // lookup fails and no expression will be built to reference it.
2064         if (!E.isInvalid() && !E.get())
2065           return ExprError();
2066         return E;
2067       }
2068     }
2069   }
2070 
2071   // This is guaranteed from this point on.
2072   assert(!R.empty() || ADL);
2073 
2074   // Check whether this might be a C++ implicit instance member access.
2075   // C++ [class.mfct.non-static]p3:
2076   //   When an id-expression that is not part of a class member access
2077   //   syntax and not used to form a pointer to member is used in the
2078   //   body of a non-static member function of class X, if name lookup
2079   //   resolves the name in the id-expression to a non-static non-type
2080   //   member of some class C, the id-expression is transformed into a
2081   //   class member access expression using (*this) as the
2082   //   postfix-expression to the left of the . operator.
2083   //
2084   // But we don't actually need to do this for '&' operands if R
2085   // resolved to a function or overloaded function set, because the
2086   // expression is ill-formed if it actually works out to be a
2087   // non-static member function:
2088   //
2089   // C++ [expr.ref]p4:
2090   //   Otherwise, if E1.E2 refers to a non-static member function. . .
2091   //   [t]he expression can be used only as the left-hand operand of a
2092   //   member function call.
2093   //
2094   // There are other safeguards against such uses, but it's important
2095   // to get this right here so that we don't end up making a
2096   // spuriously dependent expression if we're inside a dependent
2097   // instance method.
2098   if (!R.empty() && (*R.begin())->isCXXClassMember()) {
2099     bool MightBeImplicitMember;
2100     if (!IsAddressOfOperand)
2101       MightBeImplicitMember = true;
2102     else if (!SS.isEmpty())
2103       MightBeImplicitMember = false;
2104     else if (R.isOverloadedResult())
2105       MightBeImplicitMember = false;
2106     else if (R.isUnresolvableResult())
2107       MightBeImplicitMember = true;
2108     else
2109       MightBeImplicitMember = isa<FieldDecl>(R.getFoundDecl()) ||
2110                               isa<IndirectFieldDecl>(R.getFoundDecl()) ||
2111                               isa<MSPropertyDecl>(R.getFoundDecl());
2112 
2113     if (MightBeImplicitMember)
2114       return BuildPossibleImplicitMemberExpr(SS, TemplateKWLoc,
2115                                              R, TemplateArgs);
2116   }
2117 
2118   if (TemplateArgs || TemplateKWLoc.isValid()) {
2119 
2120     // In C++1y, if this is a variable template id, then check it
2121     // in BuildTemplateIdExpr().
2122     // The single lookup result must be a variable template declaration.
2123     if (Id.getKind() == UnqualifiedId::IK_TemplateId && Id.TemplateId &&
2124         Id.TemplateId->Kind == TNK_Var_template) {
2125       assert(R.getAsSingle<VarTemplateDecl>() &&
2126              "There should only be one declaration found.");
2127     }
2128 
2129     return BuildTemplateIdExpr(SS, TemplateKWLoc, R, ADL, TemplateArgs);
2130   }
2131 
2132   return BuildDeclarationNameExpr(SS, R, ADL);
2133 }
2134 
2135 /// BuildQualifiedDeclarationNameExpr - Build a C++ qualified
2136 /// declaration name, generally during template instantiation.
2137 /// There's a large number of things which don't need to be done along
2138 /// this path.
2139 ExprResult
2140 Sema::BuildQualifiedDeclarationNameExpr(CXXScopeSpec &SS,
2141                                         const DeclarationNameInfo &NameInfo,
2142                                         bool IsAddressOfOperand) {
2143   DeclContext *DC = computeDeclContext(SS, false);
2144   if (!DC)
2145     return BuildDependentDeclRefExpr(SS, /*TemplateKWLoc=*/SourceLocation(),
2146                                      NameInfo, /*TemplateArgs=*/0);
2147 
2148   if (RequireCompleteDeclContext(SS, DC))
2149     return ExprError();
2150 
2151   LookupResult R(*this, NameInfo, LookupOrdinaryName);
2152   LookupQualifiedName(R, DC);
2153 
2154   if (R.isAmbiguous())
2155     return ExprError();
2156 
2157   if (R.getResultKind() == LookupResult::NotFoundInCurrentInstantiation)
2158     return BuildDependentDeclRefExpr(SS, /*TemplateKWLoc=*/SourceLocation(),
2159                                      NameInfo, /*TemplateArgs=*/0);
2160 
2161   if (R.empty()) {
2162     Diag(NameInfo.getLoc(), diag::err_no_member)
2163       << NameInfo.getName() << DC << SS.getRange();
2164     return ExprError();
2165   }
2166 
2167   // Defend against this resolving to an implicit member access. We usually
2168   // won't get here if this might be a legitimate a class member (we end up in
2169   // BuildMemberReferenceExpr instead), but this can be valid if we're forming
2170   // a pointer-to-member or in an unevaluated context in C++11.
2171   if (!R.empty() && (*R.begin())->isCXXClassMember() && !IsAddressOfOperand)
2172     return BuildPossibleImplicitMemberExpr(SS,
2173                                            /*TemplateKWLoc=*/SourceLocation(),
2174                                            R, /*TemplateArgs=*/0);
2175 
2176   return BuildDeclarationNameExpr(SS, R, /* ADL */ false);
2177 }
2178 
2179 /// LookupInObjCMethod - The parser has read a name in, and Sema has
2180 /// detected that we're currently inside an ObjC method.  Perform some
2181 /// additional lookup.
2182 ///
2183 /// Ideally, most of this would be done by lookup, but there's
2184 /// actually quite a lot of extra work involved.
2185 ///
2186 /// Returns a null sentinel to indicate trivial success.
2187 ExprResult
2188 Sema::LookupInObjCMethod(LookupResult &Lookup, Scope *S,
2189                          IdentifierInfo *II, bool AllowBuiltinCreation) {
2190   SourceLocation Loc = Lookup.getNameLoc();
2191   ObjCMethodDecl *CurMethod = getCurMethodDecl();
2192 
2193   // Check for error condition which is already reported.
2194   if (!CurMethod)
2195     return ExprError();
2196 
2197   // There are two cases to handle here.  1) scoped lookup could have failed,
2198   // in which case we should look for an ivar.  2) scoped lookup could have
2199   // found a decl, but that decl is outside the current instance method (i.e.
2200   // a global variable).  In these two cases, we do a lookup for an ivar with
2201   // this name, if the lookup sucedes, we replace it our current decl.
2202 
2203   // If we're in a class method, we don't normally want to look for
2204   // ivars.  But if we don't find anything else, and there's an
2205   // ivar, that's an error.
2206   bool IsClassMethod = CurMethod->isClassMethod();
2207 
2208   bool LookForIvars;
2209   if (Lookup.empty())
2210     LookForIvars = true;
2211   else if (IsClassMethod)
2212     LookForIvars = false;
2213   else
2214     LookForIvars = (Lookup.isSingleResult() &&
2215                     Lookup.getFoundDecl()->isDefinedOutsideFunctionOrMethod());
2216   ObjCInterfaceDecl *IFace = 0;
2217   if (LookForIvars) {
2218     IFace = CurMethod->getClassInterface();
2219     ObjCInterfaceDecl *ClassDeclared;
2220     ObjCIvarDecl *IV = 0;
2221     if (IFace && (IV = IFace->lookupInstanceVariable(II, ClassDeclared))) {
2222       // Diagnose using an ivar in a class method.
2223       if (IsClassMethod)
2224         return ExprError(Diag(Loc, diag::error_ivar_use_in_class_method)
2225                          << IV->getDeclName());
2226 
2227       // If we're referencing an invalid decl, just return this as a silent
2228       // error node.  The error diagnostic was already emitted on the decl.
2229       if (IV->isInvalidDecl())
2230         return ExprError();
2231 
2232       // Check if referencing a field with __attribute__((deprecated)).
2233       if (DiagnoseUseOfDecl(IV, Loc))
2234         return ExprError();
2235 
2236       // Diagnose the use of an ivar outside of the declaring class.
2237       if (IV->getAccessControl() == ObjCIvarDecl::Private &&
2238           !declaresSameEntity(ClassDeclared, IFace) &&
2239           !getLangOpts().DebuggerSupport)
2240         Diag(Loc, diag::error_private_ivar_access) << IV->getDeclName();
2241 
2242       // FIXME: This should use a new expr for a direct reference, don't
2243       // turn this into Self->ivar, just return a BareIVarExpr or something.
2244       IdentifierInfo &II = Context.Idents.get("self");
2245       UnqualifiedId SelfName;
2246       SelfName.setIdentifier(&II, SourceLocation());
2247       SelfName.setKind(UnqualifiedId::IK_ImplicitSelfParam);
2248       CXXScopeSpec SelfScopeSpec;
2249       SourceLocation TemplateKWLoc;
2250       ExprResult SelfExpr = ActOnIdExpression(S, SelfScopeSpec, TemplateKWLoc,
2251                                               SelfName, false, false);
2252       if (SelfExpr.isInvalid())
2253         return ExprError();
2254 
2255       SelfExpr = DefaultLvalueConversion(SelfExpr.take());
2256       if (SelfExpr.isInvalid())
2257         return ExprError();
2258 
2259       MarkAnyDeclReferenced(Loc, IV, true);
2260       if (!IV->getBackingIvarReferencedInAccessor()) {
2261         // Mark this ivar 'referenced' in this method, if it is a backing ivar
2262         // of a property and current method is one of its property accessor.
2263         const ObjCPropertyDecl *PDecl;
2264         const ObjCIvarDecl *BIV = GetIvarBackingPropertyAccessor(CurMethod, PDecl);
2265         if (BIV && BIV == IV)
2266           IV->setBackingIvarReferencedInAccessor(true);
2267       }
2268 
2269       ObjCMethodFamily MF = CurMethod->getMethodFamily();
2270       if (MF != OMF_init && MF != OMF_dealloc && MF != OMF_finalize &&
2271           !IvarBacksCurrentMethodAccessor(IFace, CurMethod, IV))
2272         Diag(Loc, diag::warn_direct_ivar_access) << IV->getDeclName();
2273 
2274       ObjCIvarRefExpr *Result = new (Context) ObjCIvarRefExpr(IV, IV->getType(),
2275                                                               Loc, IV->getLocation(),
2276                                                               SelfExpr.take(),
2277                                                               true, true);
2278 
2279       if (getLangOpts().ObjCAutoRefCount) {
2280         if (IV->getType().getObjCLifetime() == Qualifiers::OCL_Weak) {
2281           DiagnosticsEngine::Level Level =
2282             Diags.getDiagnosticLevel(diag::warn_arc_repeated_use_of_weak, Loc);
2283           if (Level != DiagnosticsEngine::Ignored)
2284             recordUseOfEvaluatedWeak(Result);
2285         }
2286         if (CurContext->isClosure())
2287           Diag(Loc, diag::warn_implicitly_retains_self)
2288             << FixItHint::CreateInsertion(Loc, "self->");
2289       }
2290 
2291       return Owned(Result);
2292     }
2293   } else if (CurMethod->isInstanceMethod()) {
2294     // We should warn if a local variable hides an ivar.
2295     if (ObjCInterfaceDecl *IFace = CurMethod->getClassInterface()) {
2296       ObjCInterfaceDecl *ClassDeclared;
2297       if (ObjCIvarDecl *IV = IFace->lookupInstanceVariable(II, ClassDeclared)) {
2298         if (IV->getAccessControl() != ObjCIvarDecl::Private ||
2299             declaresSameEntity(IFace, ClassDeclared))
2300           Diag(Loc, diag::warn_ivar_use_hidden) << IV->getDeclName();
2301       }
2302     }
2303   } else if (Lookup.isSingleResult() &&
2304              Lookup.getFoundDecl()->isDefinedOutsideFunctionOrMethod()) {
2305     // If accessing a stand-alone ivar in a class method, this is an error.
2306     if (const ObjCIvarDecl *IV = dyn_cast<ObjCIvarDecl>(Lookup.getFoundDecl()))
2307       return ExprError(Diag(Loc, diag::error_ivar_use_in_class_method)
2308                        << IV->getDeclName());
2309   }
2310 
2311   if (Lookup.empty() && II && AllowBuiltinCreation) {
2312     // FIXME. Consolidate this with similar code in LookupName.
2313     if (unsigned BuiltinID = II->getBuiltinID()) {
2314       if (!(getLangOpts().CPlusPlus &&
2315             Context.BuiltinInfo.isPredefinedLibFunction(BuiltinID))) {
2316         NamedDecl *D = LazilyCreateBuiltin((IdentifierInfo *)II, BuiltinID,
2317                                            S, Lookup.isForRedeclaration(),
2318                                            Lookup.getNameLoc());
2319         if (D) Lookup.addDecl(D);
2320       }
2321     }
2322   }
2323   // Sentinel value saying that we didn't do anything special.
2324   return Owned((Expr*) 0);
2325 }
2326 
2327 /// \brief Cast a base object to a member's actual type.
2328 ///
2329 /// Logically this happens in three phases:
2330 ///
2331 /// * First we cast from the base type to the naming class.
2332 ///   The naming class is the class into which we were looking
2333 ///   when we found the member;  it's the qualifier type if a
2334 ///   qualifier was provided, and otherwise it's the base type.
2335 ///
2336 /// * Next we cast from the naming class to the declaring class.
2337 ///   If the member we found was brought into a class's scope by
2338 ///   a using declaration, this is that class;  otherwise it's
2339 ///   the class declaring the member.
2340 ///
2341 /// * Finally we cast from the declaring class to the "true"
2342 ///   declaring class of the member.  This conversion does not
2343 ///   obey access control.
2344 ExprResult
2345 Sema::PerformObjectMemberConversion(Expr *From,
2346                                     NestedNameSpecifier *Qualifier,
2347                                     NamedDecl *FoundDecl,
2348                                     NamedDecl *Member) {
2349   CXXRecordDecl *RD = dyn_cast<CXXRecordDecl>(Member->getDeclContext());
2350   if (!RD)
2351     return Owned(From);
2352 
2353   QualType DestRecordType;
2354   QualType DestType;
2355   QualType FromRecordType;
2356   QualType FromType = From->getType();
2357   bool PointerConversions = false;
2358   if (isa<FieldDecl>(Member)) {
2359     DestRecordType = Context.getCanonicalType(Context.getTypeDeclType(RD));
2360 
2361     if (FromType->getAs<PointerType>()) {
2362       DestType = Context.getPointerType(DestRecordType);
2363       FromRecordType = FromType->getPointeeType();
2364       PointerConversions = true;
2365     } else {
2366       DestType = DestRecordType;
2367       FromRecordType = FromType;
2368     }
2369   } else if (CXXMethodDecl *Method = dyn_cast<CXXMethodDecl>(Member)) {
2370     if (Method->isStatic())
2371       return Owned(From);
2372 
2373     DestType = Method->getThisType(Context);
2374     DestRecordType = DestType->getPointeeType();
2375 
2376     if (FromType->getAs<PointerType>()) {
2377       FromRecordType = FromType->getPointeeType();
2378       PointerConversions = true;
2379     } else {
2380       FromRecordType = FromType;
2381       DestType = DestRecordType;
2382     }
2383   } else {
2384     // No conversion necessary.
2385     return Owned(From);
2386   }
2387 
2388   if (DestType->isDependentType() || FromType->isDependentType())
2389     return Owned(From);
2390 
2391   // If the unqualified types are the same, no conversion is necessary.
2392   if (Context.hasSameUnqualifiedType(FromRecordType, DestRecordType))
2393     return Owned(From);
2394 
2395   SourceRange FromRange = From->getSourceRange();
2396   SourceLocation FromLoc = FromRange.getBegin();
2397 
2398   ExprValueKind VK = From->getValueKind();
2399 
2400   // C++ [class.member.lookup]p8:
2401   //   [...] Ambiguities can often be resolved by qualifying a name with its
2402   //   class name.
2403   //
2404   // If the member was a qualified name and the qualified referred to a
2405   // specific base subobject type, we'll cast to that intermediate type
2406   // first and then to the object in which the member is declared. That allows
2407   // one to resolve ambiguities in, e.g., a diamond-shaped hierarchy such as:
2408   //
2409   //   class Base { public: int x; };
2410   //   class Derived1 : public Base { };
2411   //   class Derived2 : public Base { };
2412   //   class VeryDerived : public Derived1, public Derived2 { void f(); };
2413   //
2414   //   void VeryDerived::f() {
2415   //     x = 17; // error: ambiguous base subobjects
2416   //     Derived1::x = 17; // okay, pick the Base subobject of Derived1
2417   //   }
2418   if (Qualifier && Qualifier->getAsType()) {
2419     QualType QType = QualType(Qualifier->getAsType(), 0);
2420     assert(QType->isRecordType() && "lookup done with non-record type");
2421 
2422     QualType QRecordType = QualType(QType->getAs<RecordType>(), 0);
2423 
2424     // In C++98, the qualifier type doesn't actually have to be a base
2425     // type of the object type, in which case we just ignore it.
2426     // Otherwise build the appropriate casts.
2427     if (IsDerivedFrom(FromRecordType, QRecordType)) {
2428       CXXCastPath BasePath;
2429       if (CheckDerivedToBaseConversion(FromRecordType, QRecordType,
2430                                        FromLoc, FromRange, &BasePath))
2431         return ExprError();
2432 
2433       if (PointerConversions)
2434         QType = Context.getPointerType(QType);
2435       From = ImpCastExprToType(From, QType, CK_UncheckedDerivedToBase,
2436                                VK, &BasePath).take();
2437 
2438       FromType = QType;
2439       FromRecordType = QRecordType;
2440 
2441       // If the qualifier type was the same as the destination type,
2442       // we're done.
2443       if (Context.hasSameUnqualifiedType(FromRecordType, DestRecordType))
2444         return Owned(From);
2445     }
2446   }
2447 
2448   bool IgnoreAccess = false;
2449 
2450   // If we actually found the member through a using declaration, cast
2451   // down to the using declaration's type.
2452   //
2453   // Pointer equality is fine here because only one declaration of a
2454   // class ever has member declarations.
2455   if (FoundDecl->getDeclContext() != Member->getDeclContext()) {
2456     assert(isa<UsingShadowDecl>(FoundDecl));
2457     QualType URecordType = Context.getTypeDeclType(
2458                            cast<CXXRecordDecl>(FoundDecl->getDeclContext()));
2459 
2460     // We only need to do this if the naming-class to declaring-class
2461     // conversion is non-trivial.
2462     if (!Context.hasSameUnqualifiedType(FromRecordType, URecordType)) {
2463       assert(IsDerivedFrom(FromRecordType, URecordType));
2464       CXXCastPath BasePath;
2465       if (CheckDerivedToBaseConversion(FromRecordType, URecordType,
2466                                        FromLoc, FromRange, &BasePath))
2467         return ExprError();
2468 
2469       QualType UType = URecordType;
2470       if (PointerConversions)
2471         UType = Context.getPointerType(UType);
2472       From = ImpCastExprToType(From, UType, CK_UncheckedDerivedToBase,
2473                                VK, &BasePath).take();
2474       FromType = UType;
2475       FromRecordType = URecordType;
2476     }
2477 
2478     // We don't do access control for the conversion from the
2479     // declaring class to the true declaring class.
2480     IgnoreAccess = true;
2481   }
2482 
2483   CXXCastPath BasePath;
2484   if (CheckDerivedToBaseConversion(FromRecordType, DestRecordType,
2485                                    FromLoc, FromRange, &BasePath,
2486                                    IgnoreAccess))
2487     return ExprError();
2488 
2489   return ImpCastExprToType(From, DestType, CK_UncheckedDerivedToBase,
2490                            VK, &BasePath);
2491 }
2492 
2493 bool Sema::UseArgumentDependentLookup(const CXXScopeSpec &SS,
2494                                       const LookupResult &R,
2495                                       bool HasTrailingLParen) {
2496   // Only when used directly as the postfix-expression of a call.
2497   if (!HasTrailingLParen)
2498     return false;
2499 
2500   // Never if a scope specifier was provided.
2501   if (SS.isSet())
2502     return false;
2503 
2504   // Only in C++ or ObjC++.
2505   if (!getLangOpts().CPlusPlus)
2506     return false;
2507 
2508   // Turn off ADL when we find certain kinds of declarations during
2509   // normal lookup:
2510   for (LookupResult::iterator I = R.begin(), E = R.end(); I != E; ++I) {
2511     NamedDecl *D = *I;
2512 
2513     // C++0x [basic.lookup.argdep]p3:
2514     //     -- a declaration of a class member
2515     // Since using decls preserve this property, we check this on the
2516     // original decl.
2517     if (D->isCXXClassMember())
2518       return false;
2519 
2520     // C++0x [basic.lookup.argdep]p3:
2521     //     -- a block-scope function declaration that is not a
2522     //        using-declaration
2523     // NOTE: we also trigger this for function templates (in fact, we
2524     // don't check the decl type at all, since all other decl types
2525     // turn off ADL anyway).
2526     if (isa<UsingShadowDecl>(D))
2527       D = cast<UsingShadowDecl>(D)->getTargetDecl();
2528     else if (D->getLexicalDeclContext()->isFunctionOrMethod())
2529       return false;
2530 
2531     // C++0x [basic.lookup.argdep]p3:
2532     //     -- a declaration that is neither a function or a function
2533     //        template
2534     // And also for builtin functions.
2535     if (isa<FunctionDecl>(D)) {
2536       FunctionDecl *FDecl = cast<FunctionDecl>(D);
2537 
2538       // But also builtin functions.
2539       if (FDecl->getBuiltinID() && FDecl->isImplicit())
2540         return false;
2541     } else if (!isa<FunctionTemplateDecl>(D))
2542       return false;
2543   }
2544 
2545   return true;
2546 }
2547 
2548 
2549 /// Diagnoses obvious problems with the use of the given declaration
2550 /// as an expression.  This is only actually called for lookups that
2551 /// were not overloaded, and it doesn't promise that the declaration
2552 /// will in fact be used.
2553 static bool CheckDeclInExpr(Sema &S, SourceLocation Loc, NamedDecl *D) {
2554   if (isa<TypedefNameDecl>(D)) {
2555     S.Diag(Loc, diag::err_unexpected_typedef) << D->getDeclName();
2556     return true;
2557   }
2558 
2559   if (isa<ObjCInterfaceDecl>(D)) {
2560     S.Diag(Loc, diag::err_unexpected_interface) << D->getDeclName();
2561     return true;
2562   }
2563 
2564   if (isa<NamespaceDecl>(D)) {
2565     S.Diag(Loc, diag::err_unexpected_namespace) << D->getDeclName();
2566     return true;
2567   }
2568 
2569   return false;
2570 }
2571 
2572 ExprResult
2573 Sema::BuildDeclarationNameExpr(const CXXScopeSpec &SS,
2574                                LookupResult &R,
2575                                bool NeedsADL) {
2576   // If this is a single, fully-resolved result and we don't need ADL,
2577   // just build an ordinary singleton decl ref.
2578   if (!NeedsADL && R.isSingleResult() && !R.getAsSingle<FunctionTemplateDecl>())
2579     return BuildDeclarationNameExpr(SS, R.getLookupNameInfo(), R.getFoundDecl(),
2580                                     R.getRepresentativeDecl());
2581 
2582   // We only need to check the declaration if there's exactly one
2583   // result, because in the overloaded case the results can only be
2584   // functions and function templates.
2585   if (R.isSingleResult() &&
2586       CheckDeclInExpr(*this, R.getNameLoc(), R.getFoundDecl()))
2587     return ExprError();
2588 
2589   // Otherwise, just build an unresolved lookup expression.  Suppress
2590   // any lookup-related diagnostics; we'll hash these out later, when
2591   // we've picked a target.
2592   R.suppressDiagnostics();
2593 
2594   UnresolvedLookupExpr *ULE
2595     = UnresolvedLookupExpr::Create(Context, R.getNamingClass(),
2596                                    SS.getWithLocInContext(Context),
2597                                    R.getLookupNameInfo(),
2598                                    NeedsADL, R.isOverloadedResult(),
2599                                    R.begin(), R.end());
2600 
2601   return Owned(ULE);
2602 }
2603 
2604 /// \brief Complete semantic analysis for a reference to the given declaration.
2605 ExprResult Sema::BuildDeclarationNameExpr(
2606     const CXXScopeSpec &SS, const DeclarationNameInfo &NameInfo, NamedDecl *D,
2607     NamedDecl *FoundD, const TemplateArgumentListInfo *TemplateArgs) {
2608   assert(D && "Cannot refer to a NULL declaration");
2609   assert(!isa<FunctionTemplateDecl>(D) &&
2610          "Cannot refer unambiguously to a function template");
2611 
2612   SourceLocation Loc = NameInfo.getLoc();
2613   if (CheckDeclInExpr(*this, Loc, D))
2614     return ExprError();
2615 
2616   if (TemplateDecl *Template = dyn_cast<TemplateDecl>(D)) {
2617     // Specifically diagnose references to class templates that are missing
2618     // a template argument list.
2619     Diag(Loc, diag::err_template_decl_ref) << (isa<VarTemplateDecl>(D) ? 1 : 0)
2620                                            << Template << SS.getRange();
2621     Diag(Template->getLocation(), diag::note_template_decl_here);
2622     return ExprError();
2623   }
2624 
2625   // Make sure that we're referring to a value.
2626   ValueDecl *VD = dyn_cast<ValueDecl>(D);
2627   if (!VD) {
2628     Diag(Loc, diag::err_ref_non_value)
2629       << D << SS.getRange();
2630     Diag(D->getLocation(), diag::note_declared_at);
2631     return ExprError();
2632   }
2633 
2634   // Check whether this declaration can be used. Note that we suppress
2635   // this check when we're going to perform argument-dependent lookup
2636   // on this function name, because this might not be the function
2637   // that overload resolution actually selects.
2638   if (DiagnoseUseOfDecl(VD, Loc))
2639     return ExprError();
2640 
2641   // Only create DeclRefExpr's for valid Decl's.
2642   if (VD->isInvalidDecl())
2643     return ExprError();
2644 
2645   // Handle members of anonymous structs and unions.  If we got here,
2646   // and the reference is to a class member indirect field, then this
2647   // must be the subject of a pointer-to-member expression.
2648   if (IndirectFieldDecl *indirectField = dyn_cast<IndirectFieldDecl>(VD))
2649     if (!indirectField->isCXXClassMember())
2650       return BuildAnonymousStructUnionMemberReference(SS, NameInfo.getLoc(),
2651                                                       indirectField);
2652 
2653   {
2654     QualType type = VD->getType();
2655     ExprValueKind valueKind = VK_RValue;
2656 
2657     switch (D->getKind()) {
2658     // Ignore all the non-ValueDecl kinds.
2659 #define ABSTRACT_DECL(kind)
2660 #define VALUE(type, base)
2661 #define DECL(type, base) \
2662     case Decl::type:
2663 #include "clang/AST/DeclNodes.inc"
2664       llvm_unreachable("invalid value decl kind");
2665 
2666     // These shouldn't make it here.
2667     case Decl::ObjCAtDefsField:
2668     case Decl::ObjCIvar:
2669       llvm_unreachable("forming non-member reference to ivar?");
2670 
2671     // Enum constants are always r-values and never references.
2672     // Unresolved using declarations are dependent.
2673     case Decl::EnumConstant:
2674     case Decl::UnresolvedUsingValue:
2675       valueKind = VK_RValue;
2676       break;
2677 
2678     // Fields and indirect fields that got here must be for
2679     // pointer-to-member expressions; we just call them l-values for
2680     // internal consistency, because this subexpression doesn't really
2681     // exist in the high-level semantics.
2682     case Decl::Field:
2683     case Decl::IndirectField:
2684       assert(getLangOpts().CPlusPlus &&
2685              "building reference to field in C?");
2686 
2687       // These can't have reference type in well-formed programs, but
2688       // for internal consistency we do this anyway.
2689       type = type.getNonReferenceType();
2690       valueKind = VK_LValue;
2691       break;
2692 
2693     // Non-type template parameters are either l-values or r-values
2694     // depending on the type.
2695     case Decl::NonTypeTemplateParm: {
2696       if (const ReferenceType *reftype = type->getAs<ReferenceType>()) {
2697         type = reftype->getPointeeType();
2698         valueKind = VK_LValue; // even if the parameter is an r-value reference
2699         break;
2700       }
2701 
2702       // For non-references, we need to strip qualifiers just in case
2703       // the template parameter was declared as 'const int' or whatever.
2704       valueKind = VK_RValue;
2705       type = type.getUnqualifiedType();
2706       break;
2707     }
2708 
2709     case Decl::Var:
2710     case Decl::VarTemplateSpecialization:
2711     case Decl::VarTemplatePartialSpecialization:
2712       // In C, "extern void blah;" is valid and is an r-value.
2713       if (!getLangOpts().CPlusPlus &&
2714           !type.hasQualifiers() &&
2715           type->isVoidType()) {
2716         valueKind = VK_RValue;
2717         break;
2718       }
2719       // fallthrough
2720 
2721     case Decl::ImplicitParam:
2722     case Decl::ParmVar: {
2723       // These are always l-values.
2724       valueKind = VK_LValue;
2725       type = type.getNonReferenceType();
2726 
2727       // FIXME: Does the addition of const really only apply in
2728       // potentially-evaluated contexts? Since the variable isn't actually
2729       // captured in an unevaluated context, it seems that the answer is no.
2730       if (!isUnevaluatedContext()) {
2731         QualType CapturedType = getCapturedDeclRefType(cast<VarDecl>(VD), Loc);
2732         if (!CapturedType.isNull())
2733           type = CapturedType;
2734       }
2735 
2736       break;
2737     }
2738 
2739     case Decl::Function: {
2740       if (unsigned BID = cast<FunctionDecl>(VD)->getBuiltinID()) {
2741         if (!Context.BuiltinInfo.isPredefinedLibFunction(BID)) {
2742           type = Context.BuiltinFnTy;
2743           valueKind = VK_RValue;
2744           break;
2745         }
2746       }
2747 
2748       const FunctionType *fty = type->castAs<FunctionType>();
2749 
2750       // If we're referring to a function with an __unknown_anytype
2751       // result type, make the entire expression __unknown_anytype.
2752       if (fty->getResultType() == Context.UnknownAnyTy) {
2753         type = Context.UnknownAnyTy;
2754         valueKind = VK_RValue;
2755         break;
2756       }
2757 
2758       // Functions are l-values in C++.
2759       if (getLangOpts().CPlusPlus) {
2760         valueKind = VK_LValue;
2761         break;
2762       }
2763 
2764       // C99 DR 316 says that, if a function type comes from a
2765       // function definition (without a prototype), that type is only
2766       // used for checking compatibility. Therefore, when referencing
2767       // the function, we pretend that we don't have the full function
2768       // type.
2769       if (!cast<FunctionDecl>(VD)->hasPrototype() &&
2770           isa<FunctionProtoType>(fty))
2771         type = Context.getFunctionNoProtoType(fty->getResultType(),
2772                                               fty->getExtInfo());
2773 
2774       // Functions are r-values in C.
2775       valueKind = VK_RValue;
2776       break;
2777     }
2778 
2779     case Decl::MSProperty:
2780       valueKind = VK_LValue;
2781       break;
2782 
2783     case Decl::CXXMethod:
2784       // If we're referring to a method with an __unknown_anytype
2785       // result type, make the entire expression __unknown_anytype.
2786       // This should only be possible with a type written directly.
2787       if (const FunctionProtoType *proto
2788             = dyn_cast<FunctionProtoType>(VD->getType()))
2789         if (proto->getResultType() == Context.UnknownAnyTy) {
2790           type = Context.UnknownAnyTy;
2791           valueKind = VK_RValue;
2792           break;
2793         }
2794 
2795       // C++ methods are l-values if static, r-values if non-static.
2796       if (cast<CXXMethodDecl>(VD)->isStatic()) {
2797         valueKind = VK_LValue;
2798         break;
2799       }
2800       // fallthrough
2801 
2802     case Decl::CXXConversion:
2803     case Decl::CXXDestructor:
2804     case Decl::CXXConstructor:
2805       valueKind = VK_RValue;
2806       break;
2807     }
2808 
2809     return BuildDeclRefExpr(VD, type, valueKind, NameInfo, &SS, FoundD,
2810                             TemplateArgs);
2811   }
2812 }
2813 
2814 ExprResult Sema::BuildPredefinedExpr(SourceLocation Loc,
2815                                      PredefinedExpr::IdentType IT) {
2816   // Pick the current block, lambda, captured statement or function.
2817   Decl *currentDecl = 0;
2818   if (const BlockScopeInfo *BSI = getCurBlock())
2819     currentDecl = BSI->TheDecl;
2820   else if (const LambdaScopeInfo *LSI = getCurLambda())
2821     currentDecl = LSI->CallOperator;
2822   else if (const CapturedRegionScopeInfo *CSI = getCurCapturedRegion())
2823     currentDecl = CSI->TheCapturedDecl;
2824   else
2825     currentDecl = getCurFunctionOrMethodDecl();
2826 
2827   if (!currentDecl) {
2828     Diag(Loc, diag::ext_predef_outside_function);
2829     currentDecl = Context.getTranslationUnitDecl();
2830   }
2831 
2832   QualType ResTy;
2833   if (cast<DeclContext>(currentDecl)->isDependentContext())
2834     ResTy = Context.DependentTy;
2835   else {
2836     // Pre-defined identifiers are of type char[x], where x is the length of
2837     // the string.
2838     unsigned Length = PredefinedExpr::ComputeName(IT, currentDecl).length();
2839 
2840     llvm::APInt LengthI(32, Length + 1);
2841     if (IT == PredefinedExpr::LFunction)
2842       ResTy = Context.WideCharTy.withConst();
2843     else
2844       ResTy = Context.CharTy.withConst();
2845     ResTy = Context.getConstantArrayType(ResTy, LengthI, ArrayType::Normal, 0);
2846   }
2847 
2848   return Owned(new (Context) PredefinedExpr(Loc, ResTy, IT));
2849 }
2850 
2851 ExprResult Sema::ActOnPredefinedExpr(SourceLocation Loc, tok::TokenKind Kind) {
2852   PredefinedExpr::IdentType IT;
2853 
2854   switch (Kind) {
2855   default: llvm_unreachable("Unknown simple primary expr!");
2856   case tok::kw___func__: IT = PredefinedExpr::Func; break; // [C99 6.4.2.2]
2857   case tok::kw___FUNCTION__: IT = PredefinedExpr::Function; break;
2858   case tok::kw_L__FUNCTION__: IT = PredefinedExpr::LFunction; break;
2859   case tok::kw___PRETTY_FUNCTION__: IT = PredefinedExpr::PrettyFunction; break;
2860   }
2861 
2862   return BuildPredefinedExpr(Loc, IT);
2863 }
2864 
2865 ExprResult Sema::ActOnCharacterConstant(const Token &Tok, Scope *UDLScope) {
2866   SmallString<16> CharBuffer;
2867   bool Invalid = false;
2868   StringRef ThisTok = PP.getSpelling(Tok, CharBuffer, &Invalid);
2869   if (Invalid)
2870     return ExprError();
2871 
2872   CharLiteralParser Literal(ThisTok.begin(), ThisTok.end(), Tok.getLocation(),
2873                             PP, Tok.getKind());
2874   if (Literal.hadError())
2875     return ExprError();
2876 
2877   QualType Ty;
2878   if (Literal.isWide())
2879     Ty = Context.WideCharTy; // L'x' -> wchar_t in C and C++.
2880   else if (Literal.isUTF16())
2881     Ty = Context.Char16Ty; // u'x' -> char16_t in C11 and C++11.
2882   else if (Literal.isUTF32())
2883     Ty = Context.Char32Ty; // U'x' -> char32_t in C11 and C++11.
2884   else if (!getLangOpts().CPlusPlus || Literal.isMultiChar())
2885     Ty = Context.IntTy;   // 'x' -> int in C, 'wxyz' -> int in C++.
2886   else
2887     Ty = Context.CharTy;  // 'x' -> char in C++
2888 
2889   CharacterLiteral::CharacterKind Kind = CharacterLiteral::Ascii;
2890   if (Literal.isWide())
2891     Kind = CharacterLiteral::Wide;
2892   else if (Literal.isUTF16())
2893     Kind = CharacterLiteral::UTF16;
2894   else if (Literal.isUTF32())
2895     Kind = CharacterLiteral::UTF32;
2896 
2897   Expr *Lit = new (Context) CharacterLiteral(Literal.getValue(), Kind, Ty,
2898                                              Tok.getLocation());
2899 
2900   if (Literal.getUDSuffix().empty())
2901     return Owned(Lit);
2902 
2903   // We're building a user-defined literal.
2904   IdentifierInfo *UDSuffix = &Context.Idents.get(Literal.getUDSuffix());
2905   SourceLocation UDSuffixLoc =
2906     getUDSuffixLoc(*this, Tok.getLocation(), Literal.getUDSuffixOffset());
2907 
2908   // Make sure we're allowed user-defined literals here.
2909   if (!UDLScope)
2910     return ExprError(Diag(UDSuffixLoc, diag::err_invalid_character_udl));
2911 
2912   // C++11 [lex.ext]p6: The literal L is treated as a call of the form
2913   //   operator "" X (ch)
2914   return BuildCookedLiteralOperatorCall(*this, UDLScope, UDSuffix, UDSuffixLoc,
2915                                         Lit, Tok.getLocation());
2916 }
2917 
2918 ExprResult Sema::ActOnIntegerConstant(SourceLocation Loc, uint64_t Val) {
2919   unsigned IntSize = Context.getTargetInfo().getIntWidth();
2920   return Owned(IntegerLiteral::Create(Context, llvm::APInt(IntSize, Val),
2921                                       Context.IntTy, Loc));
2922 }
2923 
2924 static Expr *BuildFloatingLiteral(Sema &S, NumericLiteralParser &Literal,
2925                                   QualType Ty, SourceLocation Loc) {
2926   const llvm::fltSemantics &Format = S.Context.getFloatTypeSemantics(Ty);
2927 
2928   using llvm::APFloat;
2929   APFloat Val(Format);
2930 
2931   APFloat::opStatus result = Literal.GetFloatValue(Val);
2932 
2933   // Overflow is always an error, but underflow is only an error if
2934   // we underflowed to zero (APFloat reports denormals as underflow).
2935   if ((result & APFloat::opOverflow) ||
2936       ((result & APFloat::opUnderflow) && Val.isZero())) {
2937     unsigned diagnostic;
2938     SmallString<20> buffer;
2939     if (result & APFloat::opOverflow) {
2940       diagnostic = diag::warn_float_overflow;
2941       APFloat::getLargest(Format).toString(buffer);
2942     } else {
2943       diagnostic = diag::warn_float_underflow;
2944       APFloat::getSmallest(Format).toString(buffer);
2945     }
2946 
2947     S.Diag(Loc, diagnostic)
2948       << Ty
2949       << StringRef(buffer.data(), buffer.size());
2950   }
2951 
2952   bool isExact = (result == APFloat::opOK);
2953   return FloatingLiteral::Create(S.Context, Val, isExact, Ty, Loc);
2954 }
2955 
2956 ExprResult Sema::ActOnNumericConstant(const Token &Tok, Scope *UDLScope) {
2957   // Fast path for a single digit (which is quite common).  A single digit
2958   // cannot have a trigraph, escaped newline, radix prefix, or suffix.
2959   if (Tok.getLength() == 1) {
2960     const char Val = PP.getSpellingOfSingleCharacterNumericConstant(Tok);
2961     return ActOnIntegerConstant(Tok.getLocation(), Val-'0');
2962   }
2963 
2964   SmallString<128> SpellingBuffer;
2965   // NumericLiteralParser wants to overread by one character.  Add padding to
2966   // the buffer in case the token is copied to the buffer.  If getSpelling()
2967   // returns a StringRef to the memory buffer, it should have a null char at
2968   // the EOF, so it is also safe.
2969   SpellingBuffer.resize(Tok.getLength() + 1);
2970 
2971   // Get the spelling of the token, which eliminates trigraphs, etc.
2972   bool Invalid = false;
2973   StringRef TokSpelling = PP.getSpelling(Tok, SpellingBuffer, &Invalid);
2974   if (Invalid)
2975     return ExprError();
2976 
2977   NumericLiteralParser Literal(TokSpelling, Tok.getLocation(), PP);
2978   if (Literal.hadError)
2979     return ExprError();
2980 
2981   if (Literal.hasUDSuffix()) {
2982     // We're building a user-defined literal.
2983     IdentifierInfo *UDSuffix = &Context.Idents.get(Literal.getUDSuffix());
2984     SourceLocation UDSuffixLoc =
2985       getUDSuffixLoc(*this, Tok.getLocation(), Literal.getUDSuffixOffset());
2986 
2987     // Make sure we're allowed user-defined literals here.
2988     if (!UDLScope)
2989       return ExprError(Diag(UDSuffixLoc, diag::err_invalid_numeric_udl));
2990 
2991     QualType CookedTy;
2992     if (Literal.isFloatingLiteral()) {
2993       // C++11 [lex.ext]p4: If S contains a literal operator with parameter type
2994       // long double, the literal is treated as a call of the form
2995       //   operator "" X (f L)
2996       CookedTy = Context.LongDoubleTy;
2997     } else {
2998       // C++11 [lex.ext]p3: If S contains a literal operator with parameter type
2999       // unsigned long long, the literal is treated as a call of the form
3000       //   operator "" X (n ULL)
3001       CookedTy = Context.UnsignedLongLongTy;
3002     }
3003 
3004     DeclarationName OpName =
3005       Context.DeclarationNames.getCXXLiteralOperatorName(UDSuffix);
3006     DeclarationNameInfo OpNameInfo(OpName, UDSuffixLoc);
3007     OpNameInfo.setCXXLiteralOperatorNameLoc(UDSuffixLoc);
3008 
3009     SourceLocation TokLoc = Tok.getLocation();
3010 
3011     // Perform literal operator lookup to determine if we're building a raw
3012     // literal or a cooked one.
3013     LookupResult R(*this, OpName, UDSuffixLoc, LookupOrdinaryName);
3014     switch (LookupLiteralOperator(UDLScope, R, CookedTy,
3015                                   /*AllowRaw*/true, /*AllowTemplate*/true,
3016                                   /*AllowStringTemplate*/false)) {
3017     case LOLR_Error:
3018       return ExprError();
3019 
3020     case LOLR_Cooked: {
3021       Expr *Lit;
3022       if (Literal.isFloatingLiteral()) {
3023         Lit = BuildFloatingLiteral(*this, Literal, CookedTy, Tok.getLocation());
3024       } else {
3025         llvm::APInt ResultVal(Context.getTargetInfo().getLongLongWidth(), 0);
3026         if (Literal.GetIntegerValue(ResultVal))
3027           Diag(Tok.getLocation(), diag::err_integer_too_large);
3028         Lit = IntegerLiteral::Create(Context, ResultVal, CookedTy,
3029                                      Tok.getLocation());
3030       }
3031       return BuildLiteralOperatorCall(R, OpNameInfo, Lit, TokLoc);
3032     }
3033 
3034     case LOLR_Raw: {
3035       // C++11 [lit.ext]p3, p4: If S contains a raw literal operator, the
3036       // literal is treated as a call of the form
3037       //   operator "" X ("n")
3038       unsigned Length = Literal.getUDSuffixOffset();
3039       QualType StrTy = Context.getConstantArrayType(
3040           Context.CharTy.withConst(), llvm::APInt(32, Length + 1),
3041           ArrayType::Normal, 0);
3042       Expr *Lit = StringLiteral::Create(
3043           Context, StringRef(TokSpelling.data(), Length), StringLiteral::Ascii,
3044           /*Pascal*/false, StrTy, &TokLoc, 1);
3045       return BuildLiteralOperatorCall(R, OpNameInfo, Lit, TokLoc);
3046     }
3047 
3048     case LOLR_Template: {
3049       // C++11 [lit.ext]p3, p4: Otherwise (S contains a literal operator
3050       // template), L is treated as a call fo the form
3051       //   operator "" X <'c1', 'c2', ... 'ck'>()
3052       // where n is the source character sequence c1 c2 ... ck.
3053       TemplateArgumentListInfo ExplicitArgs;
3054       unsigned CharBits = Context.getIntWidth(Context.CharTy);
3055       bool CharIsUnsigned = Context.CharTy->isUnsignedIntegerType();
3056       llvm::APSInt Value(CharBits, CharIsUnsigned);
3057       for (unsigned I = 0, N = Literal.getUDSuffixOffset(); I != N; ++I) {
3058         Value = TokSpelling[I];
3059         TemplateArgument Arg(Context, Value, Context.CharTy);
3060         TemplateArgumentLocInfo ArgInfo;
3061         ExplicitArgs.addArgument(TemplateArgumentLoc(Arg, ArgInfo));
3062       }
3063       return BuildLiteralOperatorCall(R, OpNameInfo, None, TokLoc,
3064                                       &ExplicitArgs);
3065     }
3066     case LOLR_StringTemplate:
3067       llvm_unreachable("unexpected literal operator lookup result");
3068     }
3069   }
3070 
3071   Expr *Res;
3072 
3073   if (Literal.isFloatingLiteral()) {
3074     QualType Ty;
3075     if (Literal.isFloat)
3076       Ty = Context.FloatTy;
3077     else if (!Literal.isLong)
3078       Ty = Context.DoubleTy;
3079     else
3080       Ty = Context.LongDoubleTy;
3081 
3082     Res = BuildFloatingLiteral(*this, Literal, Ty, Tok.getLocation());
3083 
3084     if (Ty == Context.DoubleTy) {
3085       if (getLangOpts().SinglePrecisionConstants) {
3086         Res = ImpCastExprToType(Res, Context.FloatTy, CK_FloatingCast).take();
3087       } else if (getLangOpts().OpenCL && !getOpenCLOptions().cl_khr_fp64) {
3088         Diag(Tok.getLocation(), diag::warn_double_const_requires_fp64);
3089         Res = ImpCastExprToType(Res, Context.FloatTy, CK_FloatingCast).take();
3090       }
3091     }
3092   } else if (!Literal.isIntegerLiteral()) {
3093     return ExprError();
3094   } else {
3095     QualType Ty;
3096 
3097     // 'long long' is a C99 or C++11 feature.
3098     if (!getLangOpts().C99 && Literal.isLongLong) {
3099       if (getLangOpts().CPlusPlus)
3100         Diag(Tok.getLocation(),
3101              getLangOpts().CPlusPlus11 ?
3102              diag::warn_cxx98_compat_longlong : diag::ext_cxx11_longlong);
3103       else
3104         Diag(Tok.getLocation(), diag::ext_c99_longlong);
3105     }
3106 
3107     // Get the value in the widest-possible width.
3108     unsigned MaxWidth = Context.getTargetInfo().getIntMaxTWidth();
3109     // The microsoft literal suffix extensions support 128-bit literals, which
3110     // may be wider than [u]intmax_t.
3111     // FIXME: Actually, they don't. We seem to have accidentally invented the
3112     //        i128 suffix.
3113     if (Literal.isMicrosoftInteger && MaxWidth < 128 &&
3114         PP.getTargetInfo().hasInt128Type())
3115       MaxWidth = 128;
3116     llvm::APInt ResultVal(MaxWidth, 0);
3117 
3118     if (Literal.GetIntegerValue(ResultVal)) {
3119       // If this value didn't fit into uintmax_t, error and force to ull.
3120       Diag(Tok.getLocation(), diag::err_integer_too_large);
3121       Ty = Context.UnsignedLongLongTy;
3122       assert(Context.getTypeSize(Ty) == ResultVal.getBitWidth() &&
3123              "long long is not intmax_t?");
3124     } else {
3125       // If this value fits into a ULL, try to figure out what else it fits into
3126       // according to the rules of C99 6.4.4.1p5.
3127 
3128       // Octal, Hexadecimal, and integers with a U suffix are allowed to
3129       // be an unsigned int.
3130       bool AllowUnsigned = Literal.isUnsigned || Literal.getRadix() != 10;
3131 
3132       // Check from smallest to largest, picking the smallest type we can.
3133       unsigned Width = 0;
3134       if (!Literal.isLong && !Literal.isLongLong) {
3135         // Are int/unsigned possibilities?
3136         unsigned IntSize = Context.getTargetInfo().getIntWidth();
3137 
3138         // Does it fit in a unsigned int?
3139         if (ResultVal.isIntN(IntSize)) {
3140           // Does it fit in a signed int?
3141           if (!Literal.isUnsigned && ResultVal[IntSize-1] == 0)
3142             Ty = Context.IntTy;
3143           else if (AllowUnsigned)
3144             Ty = Context.UnsignedIntTy;
3145           Width = IntSize;
3146         }
3147       }
3148 
3149       // Are long/unsigned long possibilities?
3150       if (Ty.isNull() && !Literal.isLongLong) {
3151         unsigned LongSize = Context.getTargetInfo().getLongWidth();
3152 
3153         // Does it fit in a unsigned long?
3154         if (ResultVal.isIntN(LongSize)) {
3155           // Does it fit in a signed long?
3156           if (!Literal.isUnsigned && ResultVal[LongSize-1] == 0)
3157             Ty = Context.LongTy;
3158           else if (AllowUnsigned)
3159             Ty = Context.UnsignedLongTy;
3160           Width = LongSize;
3161         }
3162       }
3163 
3164       // Check long long if needed.
3165       if (Ty.isNull()) {
3166         unsigned LongLongSize = Context.getTargetInfo().getLongLongWidth();
3167 
3168         // Does it fit in a unsigned long long?
3169         if (ResultVal.isIntN(LongLongSize)) {
3170           // Does it fit in a signed long long?
3171           // To be compatible with MSVC, hex integer literals ending with the
3172           // LL or i64 suffix are always signed in Microsoft mode.
3173           if (!Literal.isUnsigned && (ResultVal[LongLongSize-1] == 0 ||
3174               (getLangOpts().MicrosoftExt && Literal.isLongLong)))
3175             Ty = Context.LongLongTy;
3176           else if (AllowUnsigned)
3177             Ty = Context.UnsignedLongLongTy;
3178           Width = LongLongSize;
3179         }
3180       }
3181 
3182       // If it doesn't fit in unsigned long long, and we're using Microsoft
3183       // extensions, then its a 128-bit integer literal.
3184       if (Ty.isNull() && Literal.isMicrosoftInteger &&
3185           PP.getTargetInfo().hasInt128Type()) {
3186         if (Literal.isUnsigned)
3187           Ty = Context.UnsignedInt128Ty;
3188         else
3189           Ty = Context.Int128Ty;
3190         Width = 128;
3191       }
3192 
3193       // If we still couldn't decide a type, we probably have something that
3194       // does not fit in a signed long long, but has no U suffix.
3195       if (Ty.isNull()) {
3196         Diag(Tok.getLocation(), diag::warn_integer_too_large_for_signed);
3197         Ty = Context.UnsignedLongLongTy;
3198         Width = Context.getTargetInfo().getLongLongWidth();
3199       }
3200 
3201       if (ResultVal.getBitWidth() != Width)
3202         ResultVal = ResultVal.trunc(Width);
3203     }
3204     Res = IntegerLiteral::Create(Context, ResultVal, Ty, Tok.getLocation());
3205   }
3206 
3207   // If this is an imaginary literal, create the ImaginaryLiteral wrapper.
3208   if (Literal.isImaginary)
3209     Res = new (Context) ImaginaryLiteral(Res,
3210                                         Context.getComplexType(Res->getType()));
3211 
3212   return Owned(Res);
3213 }
3214 
3215 ExprResult Sema::ActOnParenExpr(SourceLocation L, SourceLocation R, Expr *E) {
3216   assert((E != 0) && "ActOnParenExpr() missing expr");
3217   return Owned(new (Context) ParenExpr(L, R, E));
3218 }
3219 
3220 static bool CheckVecStepTraitOperandType(Sema &S, QualType T,
3221                                          SourceLocation Loc,
3222                                          SourceRange ArgRange) {
3223   // [OpenCL 1.1 6.11.12] "The vec_step built-in function takes a built-in
3224   // scalar or vector data type argument..."
3225   // Every built-in scalar type (OpenCL 1.1 6.1.1) is either an arithmetic
3226   // type (C99 6.2.5p18) or void.
3227   if (!(T->isArithmeticType() || T->isVoidType() || T->isVectorType())) {
3228     S.Diag(Loc, diag::err_vecstep_non_scalar_vector_type)
3229       << T << ArgRange;
3230     return true;
3231   }
3232 
3233   assert((T->isVoidType() || !T->isIncompleteType()) &&
3234          "Scalar types should always be complete");
3235   return false;
3236 }
3237 
3238 static bool CheckExtensionTraitOperandType(Sema &S, QualType T,
3239                                            SourceLocation Loc,
3240                                            SourceRange ArgRange,
3241                                            UnaryExprOrTypeTrait TraitKind) {
3242   // Invalid types must be hard errors for SFINAE in C++.
3243   if (S.LangOpts.CPlusPlus)
3244     return true;
3245 
3246   // C99 6.5.3.4p1:
3247   if (T->isFunctionType() &&
3248       (TraitKind == UETT_SizeOf || TraitKind == UETT_AlignOf)) {
3249     // sizeof(function)/alignof(function) is allowed as an extension.
3250     S.Diag(Loc, diag::ext_sizeof_alignof_function_type)
3251       << TraitKind << ArgRange;
3252     return false;
3253   }
3254 
3255   // Allow sizeof(void)/alignof(void) as an extension.
3256   if (T->isVoidType()) {
3257     S.Diag(Loc, diag::ext_sizeof_alignof_void_type) << TraitKind << ArgRange;
3258     return false;
3259   }
3260 
3261   return true;
3262 }
3263 
3264 static bool CheckObjCTraitOperandConstraints(Sema &S, QualType T,
3265                                              SourceLocation Loc,
3266                                              SourceRange ArgRange,
3267                                              UnaryExprOrTypeTrait TraitKind) {
3268   // Reject sizeof(interface) and sizeof(interface<proto>) if the
3269   // runtime doesn't allow it.
3270   if (!S.LangOpts.ObjCRuntime.allowsSizeofAlignof() && T->isObjCObjectType()) {
3271     S.Diag(Loc, diag::err_sizeof_nonfragile_interface)
3272       << T << (TraitKind == UETT_SizeOf)
3273       << ArgRange;
3274     return true;
3275   }
3276 
3277   return false;
3278 }
3279 
3280 /// \brief Check whether E is a pointer from a decayed array type (the decayed
3281 /// pointer type is equal to T) and emit a warning if it is.
3282 static void warnOnSizeofOnArrayDecay(Sema &S, SourceLocation Loc, QualType T,
3283                                      Expr *E) {
3284   // Don't warn if the operation changed the type.
3285   if (T != E->getType())
3286     return;
3287 
3288   // Now look for array decays.
3289   ImplicitCastExpr *ICE = dyn_cast<ImplicitCastExpr>(E);
3290   if (!ICE || ICE->getCastKind() != CK_ArrayToPointerDecay)
3291     return;
3292 
3293   S.Diag(Loc, diag::warn_sizeof_array_decay) << ICE->getSourceRange()
3294                                              << ICE->getType()
3295                                              << ICE->getSubExpr()->getType();
3296 }
3297 
3298 /// \brief Check the constrains on expression operands to unary type expression
3299 /// and type traits.
3300 ///
3301 /// Completes any types necessary and validates the constraints on the operand
3302 /// expression. The logic mostly mirrors the type-based overload, but may modify
3303 /// the expression as it completes the type for that expression through template
3304 /// instantiation, etc.
3305 bool Sema::CheckUnaryExprOrTypeTraitOperand(Expr *E,
3306                                             UnaryExprOrTypeTrait ExprKind) {
3307   QualType ExprTy = E->getType();
3308   assert(!ExprTy->isReferenceType());
3309 
3310   if (ExprKind == UETT_VecStep)
3311     return CheckVecStepTraitOperandType(*this, ExprTy, E->getExprLoc(),
3312                                         E->getSourceRange());
3313 
3314   // Whitelist some types as extensions
3315   if (!CheckExtensionTraitOperandType(*this, ExprTy, E->getExprLoc(),
3316                                       E->getSourceRange(), ExprKind))
3317     return false;
3318 
3319   if (RequireCompleteExprType(E,
3320                               diag::err_sizeof_alignof_incomplete_type,
3321                               ExprKind, E->getSourceRange()))
3322     return true;
3323 
3324   // Completing the expression's type may have changed it.
3325   ExprTy = E->getType();
3326   assert(!ExprTy->isReferenceType());
3327 
3328   if (ExprTy->isFunctionType()) {
3329     Diag(E->getExprLoc(), diag::err_sizeof_alignof_function_type)
3330       << ExprKind << E->getSourceRange();
3331     return true;
3332   }
3333 
3334   if (CheckObjCTraitOperandConstraints(*this, ExprTy, E->getExprLoc(),
3335                                        E->getSourceRange(), ExprKind))
3336     return true;
3337 
3338   if (ExprKind == UETT_SizeOf) {
3339     if (DeclRefExpr *DeclRef = dyn_cast<DeclRefExpr>(E->IgnoreParens())) {
3340       if (ParmVarDecl *PVD = dyn_cast<ParmVarDecl>(DeclRef->getFoundDecl())) {
3341         QualType OType = PVD->getOriginalType();
3342         QualType Type = PVD->getType();
3343         if (Type->isPointerType() && OType->isArrayType()) {
3344           Diag(E->getExprLoc(), diag::warn_sizeof_array_param)
3345             << Type << OType;
3346           Diag(PVD->getLocation(), diag::note_declared_at);
3347         }
3348       }
3349     }
3350 
3351     // Warn on "sizeof(array op x)" and "sizeof(x op array)", where the array
3352     // decays into a pointer and returns an unintended result. This is most
3353     // likely a typo for "sizeof(array) op x".
3354     if (BinaryOperator *BO = dyn_cast<BinaryOperator>(E->IgnoreParens())) {
3355       warnOnSizeofOnArrayDecay(*this, BO->getOperatorLoc(), BO->getType(),
3356                                BO->getLHS());
3357       warnOnSizeofOnArrayDecay(*this, BO->getOperatorLoc(), BO->getType(),
3358                                BO->getRHS());
3359     }
3360   }
3361 
3362   return false;
3363 }
3364 
3365 /// \brief Check the constraints on operands to unary expression and type
3366 /// traits.
3367 ///
3368 /// This will complete any types necessary, and validate the various constraints
3369 /// on those operands.
3370 ///
3371 /// The UsualUnaryConversions() function is *not* called by this routine.
3372 /// C99 6.3.2.1p[2-4] all state:
3373 ///   Except when it is the operand of the sizeof operator ...
3374 ///
3375 /// C++ [expr.sizeof]p4
3376 ///   The lvalue-to-rvalue, array-to-pointer, and function-to-pointer
3377 ///   standard conversions are not applied to the operand of sizeof.
3378 ///
3379 /// This policy is followed for all of the unary trait expressions.
3380 bool Sema::CheckUnaryExprOrTypeTraitOperand(QualType ExprType,
3381                                             SourceLocation OpLoc,
3382                                             SourceRange ExprRange,
3383                                             UnaryExprOrTypeTrait ExprKind) {
3384   if (ExprType->isDependentType())
3385     return false;
3386 
3387   // C++ [expr.sizeof]p2: "When applied to a reference or a reference type,
3388   //   the result is the size of the referenced type."
3389   // C++ [expr.alignof]p3: "When alignof is applied to a reference type, the
3390   //   result shall be the alignment of the referenced type."
3391   if (const ReferenceType *Ref = ExprType->getAs<ReferenceType>())
3392     ExprType = Ref->getPointeeType();
3393 
3394   if (ExprKind == UETT_VecStep)
3395     return CheckVecStepTraitOperandType(*this, ExprType, OpLoc, ExprRange);
3396 
3397   // Whitelist some types as extensions
3398   if (!CheckExtensionTraitOperandType(*this, ExprType, OpLoc, ExprRange,
3399                                       ExprKind))
3400     return false;
3401 
3402   if (RequireCompleteType(OpLoc, ExprType,
3403                           diag::err_sizeof_alignof_incomplete_type,
3404                           ExprKind, ExprRange))
3405     return true;
3406 
3407   if (ExprType->isFunctionType()) {
3408     Diag(OpLoc, diag::err_sizeof_alignof_function_type)
3409       << ExprKind << ExprRange;
3410     return true;
3411   }
3412 
3413   if (CheckObjCTraitOperandConstraints(*this, ExprType, OpLoc, ExprRange,
3414                                        ExprKind))
3415     return true;
3416 
3417   return false;
3418 }
3419 
3420 static bool CheckAlignOfExpr(Sema &S, Expr *E) {
3421   E = E->IgnoreParens();
3422 
3423   // Cannot know anything else if the expression is dependent.
3424   if (E->isTypeDependent())
3425     return false;
3426 
3427   if (E->getObjectKind() == OK_BitField) {
3428     S.Diag(E->getExprLoc(), diag::err_sizeof_alignof_bitfield)
3429        << 1 << E->getSourceRange();
3430     return true;
3431   }
3432 
3433   ValueDecl *D = 0;
3434   if (DeclRefExpr *DRE = dyn_cast<DeclRefExpr>(E)) {
3435     D = DRE->getDecl();
3436   } else if (MemberExpr *ME = dyn_cast<MemberExpr>(E)) {
3437     D = ME->getMemberDecl();
3438   }
3439 
3440   // If it's a field, require the containing struct to have a
3441   // complete definition so that we can compute the layout.
3442   //
3443   // This requires a very particular set of circumstances.  For a
3444   // field to be contained within an incomplete type, we must in the
3445   // process of parsing that type.  To have an expression refer to a
3446   // field, it must be an id-expression or a member-expression, but
3447   // the latter are always ill-formed when the base type is
3448   // incomplete, including only being partially complete.  An
3449   // id-expression can never refer to a field in C because fields
3450   // are not in the ordinary namespace.  In C++, an id-expression
3451   // can implicitly be a member access, but only if there's an
3452   // implicit 'this' value, and all such contexts are subject to
3453   // delayed parsing --- except for trailing return types in C++11.
3454   // And if an id-expression referring to a field occurs in a
3455   // context that lacks a 'this' value, it's ill-formed --- except,
3456   // agian, in C++11, where such references are allowed in an
3457   // unevaluated context.  So C++11 introduces some new complexity.
3458   //
3459   // For the record, since __alignof__ on expressions is a GCC
3460   // extension, GCC seems to permit this but always gives the
3461   // nonsensical answer 0.
3462   //
3463   // We don't really need the layout here --- we could instead just
3464   // directly check for all the appropriate alignment-lowing
3465   // attributes --- but that would require duplicating a lot of
3466   // logic that just isn't worth duplicating for such a marginal
3467   // use-case.
3468   if (FieldDecl *FD = dyn_cast_or_null<FieldDecl>(D)) {
3469     // Fast path this check, since we at least know the record has a
3470     // definition if we can find a member of it.
3471     if (!FD->getParent()->isCompleteDefinition()) {
3472       S.Diag(E->getExprLoc(), diag::err_alignof_member_of_incomplete_type)
3473         << E->getSourceRange();
3474       return true;
3475     }
3476 
3477     // Otherwise, if it's a field, and the field doesn't have
3478     // reference type, then it must have a complete type (or be a
3479     // flexible array member, which we explicitly want to
3480     // white-list anyway), which makes the following checks trivial.
3481     if (!FD->getType()->isReferenceType())
3482       return false;
3483   }
3484 
3485   return S.CheckUnaryExprOrTypeTraitOperand(E, UETT_AlignOf);
3486 }
3487 
3488 bool Sema::CheckVecStepExpr(Expr *E) {
3489   E = E->IgnoreParens();
3490 
3491   // Cannot know anything else if the expression is dependent.
3492   if (E->isTypeDependent())
3493     return false;
3494 
3495   return CheckUnaryExprOrTypeTraitOperand(E, UETT_VecStep);
3496 }
3497 
3498 /// \brief Build a sizeof or alignof expression given a type operand.
3499 ExprResult
3500 Sema::CreateUnaryExprOrTypeTraitExpr(TypeSourceInfo *TInfo,
3501                                      SourceLocation OpLoc,
3502                                      UnaryExprOrTypeTrait ExprKind,
3503                                      SourceRange R) {
3504   if (!TInfo)
3505     return ExprError();
3506 
3507   QualType T = TInfo->getType();
3508 
3509   if (!T->isDependentType() &&
3510       CheckUnaryExprOrTypeTraitOperand(T, OpLoc, R, ExprKind))
3511     return ExprError();
3512 
3513   // C99 6.5.3.4p4: the type (an unsigned integer type) is size_t.
3514   return Owned(new (Context) UnaryExprOrTypeTraitExpr(ExprKind, TInfo,
3515                                                       Context.getSizeType(),
3516                                                       OpLoc, R.getEnd()));
3517 }
3518 
3519 /// \brief Build a sizeof or alignof expression given an expression
3520 /// operand.
3521 ExprResult
3522 Sema::CreateUnaryExprOrTypeTraitExpr(Expr *E, SourceLocation OpLoc,
3523                                      UnaryExprOrTypeTrait ExprKind) {
3524   ExprResult PE = CheckPlaceholderExpr(E);
3525   if (PE.isInvalid())
3526     return ExprError();
3527 
3528   E = PE.get();
3529 
3530   // Verify that the operand is valid.
3531   bool isInvalid = false;
3532   if (E->isTypeDependent()) {
3533     // Delay type-checking for type-dependent expressions.
3534   } else if (ExprKind == UETT_AlignOf) {
3535     isInvalid = CheckAlignOfExpr(*this, E);
3536   } else if (ExprKind == UETT_VecStep) {
3537     isInvalid = CheckVecStepExpr(E);
3538   } else if (E->refersToBitField()) {  // C99 6.5.3.4p1.
3539     Diag(E->getExprLoc(), diag::err_sizeof_alignof_bitfield) << 0;
3540     isInvalid = true;
3541   } else {
3542     isInvalid = CheckUnaryExprOrTypeTraitOperand(E, UETT_SizeOf);
3543   }
3544 
3545   if (isInvalid)
3546     return ExprError();
3547 
3548   if (ExprKind == UETT_SizeOf && E->getType()->isVariableArrayType()) {
3549     PE = TransformToPotentiallyEvaluated(E);
3550     if (PE.isInvalid()) return ExprError();
3551     E = PE.take();
3552   }
3553 
3554   // C99 6.5.3.4p4: the type (an unsigned integer type) is size_t.
3555   return Owned(new (Context) UnaryExprOrTypeTraitExpr(
3556       ExprKind, E, Context.getSizeType(), OpLoc,
3557       E->getSourceRange().getEnd()));
3558 }
3559 
3560 /// ActOnUnaryExprOrTypeTraitExpr - Handle @c sizeof(type) and @c sizeof @c
3561 /// expr and the same for @c alignof and @c __alignof
3562 /// Note that the ArgRange is invalid if isType is false.
3563 ExprResult
3564 Sema::ActOnUnaryExprOrTypeTraitExpr(SourceLocation OpLoc,
3565                                     UnaryExprOrTypeTrait ExprKind, bool IsType,
3566                                     void *TyOrEx, const SourceRange &ArgRange) {
3567   // If error parsing type, ignore.
3568   if (TyOrEx == 0) return ExprError();
3569 
3570   if (IsType) {
3571     TypeSourceInfo *TInfo;
3572     (void) GetTypeFromParser(ParsedType::getFromOpaquePtr(TyOrEx), &TInfo);
3573     return CreateUnaryExprOrTypeTraitExpr(TInfo, OpLoc, ExprKind, ArgRange);
3574   }
3575 
3576   Expr *ArgEx = (Expr *)TyOrEx;
3577   ExprResult Result = CreateUnaryExprOrTypeTraitExpr(ArgEx, OpLoc, ExprKind);
3578   return Result;
3579 }
3580 
3581 static QualType CheckRealImagOperand(Sema &S, ExprResult &V, SourceLocation Loc,
3582                                      bool IsReal) {
3583   if (V.get()->isTypeDependent())
3584     return S.Context.DependentTy;
3585 
3586   // _Real and _Imag are only l-values for normal l-values.
3587   if (V.get()->getObjectKind() != OK_Ordinary) {
3588     V = S.DefaultLvalueConversion(V.take());
3589     if (V.isInvalid())
3590       return QualType();
3591   }
3592 
3593   // These operators return the element type of a complex type.
3594   if (const ComplexType *CT = V.get()->getType()->getAs<ComplexType>())
3595     return CT->getElementType();
3596 
3597   // Otherwise they pass through real integer and floating point types here.
3598   if (V.get()->getType()->isArithmeticType())
3599     return V.get()->getType();
3600 
3601   // Test for placeholders.
3602   ExprResult PR = S.CheckPlaceholderExpr(V.get());
3603   if (PR.isInvalid()) return QualType();
3604   if (PR.get() != V.get()) {
3605     V = PR;
3606     return CheckRealImagOperand(S, V, Loc, IsReal);
3607   }
3608 
3609   // Reject anything else.
3610   S.Diag(Loc, diag::err_realimag_invalid_type) << V.get()->getType()
3611     << (IsReal ? "__real" : "__imag");
3612   return QualType();
3613 }
3614 
3615 
3616 
3617 ExprResult
3618 Sema::ActOnPostfixUnaryOp(Scope *S, SourceLocation OpLoc,
3619                           tok::TokenKind Kind, Expr *Input) {
3620   UnaryOperatorKind Opc;
3621   switch (Kind) {
3622   default: llvm_unreachable("Unknown unary op!");
3623   case tok::plusplus:   Opc = UO_PostInc; break;
3624   case tok::minusminus: Opc = UO_PostDec; break;
3625   }
3626 
3627   // Since this might is a postfix expression, get rid of ParenListExprs.
3628   ExprResult Result = MaybeConvertParenListExprToParenExpr(S, Input);
3629   if (Result.isInvalid()) return ExprError();
3630   Input = Result.take();
3631 
3632   return BuildUnaryOp(S, OpLoc, Opc, Input);
3633 }
3634 
3635 /// \brief Diagnose if arithmetic on the given ObjC pointer is illegal.
3636 ///
3637 /// \return true on error
3638 static bool checkArithmeticOnObjCPointer(Sema &S,
3639                                          SourceLocation opLoc,
3640                                          Expr *op) {
3641   assert(op->getType()->isObjCObjectPointerType());
3642   if (S.LangOpts.ObjCRuntime.allowsPointerArithmetic())
3643     return false;
3644 
3645   S.Diag(opLoc, diag::err_arithmetic_nonfragile_interface)
3646     << op->getType()->castAs<ObjCObjectPointerType>()->getPointeeType()
3647     << op->getSourceRange();
3648   return true;
3649 }
3650 
3651 ExprResult
3652 Sema::ActOnArraySubscriptExpr(Scope *S, Expr *base, SourceLocation lbLoc,
3653                               Expr *idx, SourceLocation rbLoc) {
3654   // Since this might be a postfix expression, get rid of ParenListExprs.
3655   if (isa<ParenListExpr>(base)) {
3656     ExprResult result = MaybeConvertParenListExprToParenExpr(S, base);
3657     if (result.isInvalid()) return ExprError();
3658     base = result.take();
3659   }
3660 
3661   // Handle any non-overload placeholder types in the base and index
3662   // expressions.  We can't handle overloads here because the other
3663   // operand might be an overloadable type, in which case the overload
3664   // resolution for the operator overload should get the first crack
3665   // at the overload.
3666   if (base->getType()->isNonOverloadPlaceholderType()) {
3667     ExprResult result = CheckPlaceholderExpr(base);
3668     if (result.isInvalid()) return ExprError();
3669     base = result.take();
3670   }
3671   if (idx->getType()->isNonOverloadPlaceholderType()) {
3672     ExprResult result = CheckPlaceholderExpr(idx);
3673     if (result.isInvalid()) return ExprError();
3674     idx = result.take();
3675   }
3676 
3677   // Build an unanalyzed expression if either operand is type-dependent.
3678   if (getLangOpts().CPlusPlus &&
3679       (base->isTypeDependent() || idx->isTypeDependent())) {
3680     return Owned(new (Context) ArraySubscriptExpr(base, idx,
3681                                                   Context.DependentTy,
3682                                                   VK_LValue, OK_Ordinary,
3683                                                   rbLoc));
3684   }
3685 
3686   // Use C++ overloaded-operator rules if either operand has record
3687   // type.  The spec says to do this if either type is *overloadable*,
3688   // but enum types can't declare subscript operators or conversion
3689   // operators, so there's nothing interesting for overload resolution
3690   // to do if there aren't any record types involved.
3691   //
3692   // ObjC pointers have their own subscripting logic that is not tied
3693   // to overload resolution and so should not take this path.
3694   if (getLangOpts().CPlusPlus &&
3695       (base->getType()->isRecordType() ||
3696        (!base->getType()->isObjCObjectPointerType() &&
3697         idx->getType()->isRecordType()))) {
3698     return CreateOverloadedArraySubscriptExpr(lbLoc, rbLoc, base, idx);
3699   }
3700 
3701   return CreateBuiltinArraySubscriptExpr(base, lbLoc, idx, rbLoc);
3702 }
3703 
3704 ExprResult
3705 Sema::CreateBuiltinArraySubscriptExpr(Expr *Base, SourceLocation LLoc,
3706                                       Expr *Idx, SourceLocation RLoc) {
3707   Expr *LHSExp = Base;
3708   Expr *RHSExp = Idx;
3709 
3710   // Perform default conversions.
3711   if (!LHSExp->getType()->getAs<VectorType>()) {
3712     ExprResult Result = DefaultFunctionArrayLvalueConversion(LHSExp);
3713     if (Result.isInvalid())
3714       return ExprError();
3715     LHSExp = Result.take();
3716   }
3717   ExprResult Result = DefaultFunctionArrayLvalueConversion(RHSExp);
3718   if (Result.isInvalid())
3719     return ExprError();
3720   RHSExp = Result.take();
3721 
3722   QualType LHSTy = LHSExp->getType(), RHSTy = RHSExp->getType();
3723   ExprValueKind VK = VK_LValue;
3724   ExprObjectKind OK = OK_Ordinary;
3725 
3726   // C99 6.5.2.1p2: the expression e1[e2] is by definition precisely equivalent
3727   // to the expression *((e1)+(e2)). This means the array "Base" may actually be
3728   // in the subscript position. As a result, we need to derive the array base
3729   // and index from the expression types.
3730   Expr *BaseExpr, *IndexExpr;
3731   QualType ResultType;
3732   if (LHSTy->isDependentType() || RHSTy->isDependentType()) {
3733     BaseExpr = LHSExp;
3734     IndexExpr = RHSExp;
3735     ResultType = Context.DependentTy;
3736   } else if (const PointerType *PTy = LHSTy->getAs<PointerType>()) {
3737     BaseExpr = LHSExp;
3738     IndexExpr = RHSExp;
3739     ResultType = PTy->getPointeeType();
3740   } else if (const ObjCObjectPointerType *PTy =
3741                LHSTy->getAs<ObjCObjectPointerType>()) {
3742     BaseExpr = LHSExp;
3743     IndexExpr = RHSExp;
3744 
3745     // Use custom logic if this should be the pseudo-object subscript
3746     // expression.
3747     if (!LangOpts.ObjCRuntime.isSubscriptPointerArithmetic())
3748       return BuildObjCSubscriptExpression(RLoc, BaseExpr, IndexExpr, 0, 0);
3749 
3750     ResultType = PTy->getPointeeType();
3751     if (!LangOpts.ObjCRuntime.allowsPointerArithmetic()) {
3752       Diag(LLoc, diag::err_subscript_nonfragile_interface)
3753         << ResultType << BaseExpr->getSourceRange();
3754       return ExprError();
3755     }
3756   } else if (const PointerType *PTy = RHSTy->getAs<PointerType>()) {
3757      // Handle the uncommon case of "123[Ptr]".
3758     BaseExpr = RHSExp;
3759     IndexExpr = LHSExp;
3760     ResultType = PTy->getPointeeType();
3761   } else if (const ObjCObjectPointerType *PTy =
3762                RHSTy->getAs<ObjCObjectPointerType>()) {
3763      // Handle the uncommon case of "123[Ptr]".
3764     BaseExpr = RHSExp;
3765     IndexExpr = LHSExp;
3766     ResultType = PTy->getPointeeType();
3767     if (!LangOpts.ObjCRuntime.allowsPointerArithmetic()) {
3768       Diag(LLoc, diag::err_subscript_nonfragile_interface)
3769         << ResultType << BaseExpr->getSourceRange();
3770       return ExprError();
3771     }
3772   } else if (const VectorType *VTy = LHSTy->getAs<VectorType>()) {
3773     BaseExpr = LHSExp;    // vectors: V[123]
3774     IndexExpr = RHSExp;
3775     VK = LHSExp->getValueKind();
3776     if (VK != VK_RValue)
3777       OK = OK_VectorComponent;
3778 
3779     // FIXME: need to deal with const...
3780     ResultType = VTy->getElementType();
3781   } else if (LHSTy->isArrayType()) {
3782     // If we see an array that wasn't promoted by
3783     // DefaultFunctionArrayLvalueConversion, it must be an array that
3784     // wasn't promoted because of the C90 rule that doesn't
3785     // allow promoting non-lvalue arrays.  Warn, then
3786     // force the promotion here.
3787     Diag(LHSExp->getLocStart(), diag::ext_subscript_non_lvalue) <<
3788         LHSExp->getSourceRange();
3789     LHSExp = ImpCastExprToType(LHSExp, Context.getArrayDecayedType(LHSTy),
3790                                CK_ArrayToPointerDecay).take();
3791     LHSTy = LHSExp->getType();
3792 
3793     BaseExpr = LHSExp;
3794     IndexExpr = RHSExp;
3795     ResultType = LHSTy->getAs<PointerType>()->getPointeeType();
3796   } else if (RHSTy->isArrayType()) {
3797     // Same as previous, except for 123[f().a] case
3798     Diag(RHSExp->getLocStart(), diag::ext_subscript_non_lvalue) <<
3799         RHSExp->getSourceRange();
3800     RHSExp = ImpCastExprToType(RHSExp, Context.getArrayDecayedType(RHSTy),
3801                                CK_ArrayToPointerDecay).take();
3802     RHSTy = RHSExp->getType();
3803 
3804     BaseExpr = RHSExp;
3805     IndexExpr = LHSExp;
3806     ResultType = RHSTy->getAs<PointerType>()->getPointeeType();
3807   } else {
3808     return ExprError(Diag(LLoc, diag::err_typecheck_subscript_value)
3809        << LHSExp->getSourceRange() << RHSExp->getSourceRange());
3810   }
3811   // C99 6.5.2.1p1
3812   if (!IndexExpr->getType()->isIntegerType() && !IndexExpr->isTypeDependent())
3813     return ExprError(Diag(LLoc, diag::err_typecheck_subscript_not_integer)
3814                      << IndexExpr->getSourceRange());
3815 
3816   if ((IndexExpr->getType()->isSpecificBuiltinType(BuiltinType::Char_S) ||
3817        IndexExpr->getType()->isSpecificBuiltinType(BuiltinType::Char_U))
3818          && !IndexExpr->isTypeDependent())
3819     Diag(LLoc, diag::warn_subscript_is_char) << IndexExpr->getSourceRange();
3820 
3821   // C99 6.5.2.1p1: "shall have type "pointer to *object* type". Similarly,
3822   // C++ [expr.sub]p1: The type "T" shall be a completely-defined object
3823   // type. Note that Functions are not objects, and that (in C99 parlance)
3824   // incomplete types are not object types.
3825   if (ResultType->isFunctionType()) {
3826     Diag(BaseExpr->getLocStart(), diag::err_subscript_function_type)
3827       << ResultType << BaseExpr->getSourceRange();
3828     return ExprError();
3829   }
3830 
3831   if (ResultType->isVoidType() && !getLangOpts().CPlusPlus) {
3832     // GNU extension: subscripting on pointer to void
3833     Diag(LLoc, diag::ext_gnu_subscript_void_type)
3834       << BaseExpr->getSourceRange();
3835 
3836     // C forbids expressions of unqualified void type from being l-values.
3837     // See IsCForbiddenLValueType.
3838     if (!ResultType.hasQualifiers()) VK = VK_RValue;
3839   } else if (!ResultType->isDependentType() &&
3840       RequireCompleteType(LLoc, ResultType,
3841                           diag::err_subscript_incomplete_type, BaseExpr))
3842     return ExprError();
3843 
3844   assert(VK == VK_RValue || LangOpts.CPlusPlus ||
3845          !ResultType.isCForbiddenLValueType());
3846 
3847   return Owned(new (Context) ArraySubscriptExpr(LHSExp, RHSExp,
3848                                                 ResultType, VK, OK, RLoc));
3849 }
3850 
3851 ExprResult Sema::BuildCXXDefaultArgExpr(SourceLocation CallLoc,
3852                                         FunctionDecl *FD,
3853                                         ParmVarDecl *Param) {
3854   if (Param->hasUnparsedDefaultArg()) {
3855     Diag(CallLoc,
3856          diag::err_use_of_default_argument_to_function_declared_later) <<
3857       FD << cast<CXXRecordDecl>(FD->getDeclContext())->getDeclName();
3858     Diag(UnparsedDefaultArgLocs[Param],
3859          diag::note_default_argument_declared_here);
3860     return ExprError();
3861   }
3862 
3863   if (Param->hasUninstantiatedDefaultArg()) {
3864     Expr *UninstExpr = Param->getUninstantiatedDefaultArg();
3865 
3866     EnterExpressionEvaluationContext EvalContext(*this, PotentiallyEvaluated,
3867                                                  Param);
3868 
3869     // Instantiate the expression.
3870     MultiLevelTemplateArgumentList MutiLevelArgList
3871       = getTemplateInstantiationArgs(FD, 0, /*RelativeToPrimary=*/true);
3872 
3873     InstantiatingTemplate Inst(*this, CallLoc, Param,
3874                                MutiLevelArgList.getInnermost());
3875     if (Inst.isInvalid())
3876       return ExprError();
3877 
3878     ExprResult Result;
3879     {
3880       // C++ [dcl.fct.default]p5:
3881       //   The names in the [default argument] expression are bound, and
3882       //   the semantic constraints are checked, at the point where the
3883       //   default argument expression appears.
3884       ContextRAII SavedContext(*this, FD);
3885       LocalInstantiationScope Local(*this);
3886       Result = SubstExpr(UninstExpr, MutiLevelArgList);
3887     }
3888     if (Result.isInvalid())
3889       return ExprError();
3890 
3891     // Check the expression as an initializer for the parameter.
3892     InitializedEntity Entity
3893       = InitializedEntity::InitializeParameter(Context, Param);
3894     InitializationKind Kind
3895       = InitializationKind::CreateCopy(Param->getLocation(),
3896              /*FIXME:EqualLoc*/UninstExpr->getLocStart());
3897     Expr *ResultE = Result.takeAs<Expr>();
3898 
3899     InitializationSequence InitSeq(*this, Entity, Kind, ResultE);
3900     Result = InitSeq.Perform(*this, Entity, Kind, ResultE);
3901     if (Result.isInvalid())
3902       return ExprError();
3903 
3904     Expr *Arg = Result.takeAs<Expr>();
3905     CheckCompletedExpr(Arg, Param->getOuterLocStart());
3906     // Build the default argument expression.
3907     return Owned(CXXDefaultArgExpr::Create(Context, CallLoc, Param, Arg));
3908   }
3909 
3910   // If the default expression creates temporaries, we need to
3911   // push them to the current stack of expression temporaries so they'll
3912   // be properly destroyed.
3913   // FIXME: We should really be rebuilding the default argument with new
3914   // bound temporaries; see the comment in PR5810.
3915   // We don't need to do that with block decls, though, because
3916   // blocks in default argument expression can never capture anything.
3917   if (isa<ExprWithCleanups>(Param->getInit())) {
3918     // Set the "needs cleanups" bit regardless of whether there are
3919     // any explicit objects.
3920     ExprNeedsCleanups = true;
3921 
3922     // Append all the objects to the cleanup list.  Right now, this
3923     // should always be a no-op, because blocks in default argument
3924     // expressions should never be able to capture anything.
3925     assert(!cast<ExprWithCleanups>(Param->getInit())->getNumObjects() &&
3926            "default argument expression has capturing blocks?");
3927   }
3928 
3929   // We already type-checked the argument, so we know it works.
3930   // Just mark all of the declarations in this potentially-evaluated expression
3931   // as being "referenced".
3932   MarkDeclarationsReferencedInExpr(Param->getDefaultArg(),
3933                                    /*SkipLocalVariables=*/true);
3934   return Owned(CXXDefaultArgExpr::Create(Context, CallLoc, Param));
3935 }
3936 
3937 
3938 Sema::VariadicCallType
3939 Sema::getVariadicCallType(FunctionDecl *FDecl, const FunctionProtoType *Proto,
3940                           Expr *Fn) {
3941   if (Proto && Proto->isVariadic()) {
3942     if (dyn_cast_or_null<CXXConstructorDecl>(FDecl))
3943       return VariadicConstructor;
3944     else if (Fn && Fn->getType()->isBlockPointerType())
3945       return VariadicBlock;
3946     else if (FDecl) {
3947       if (CXXMethodDecl *Method = dyn_cast_or_null<CXXMethodDecl>(FDecl))
3948         if (Method->isInstance())
3949           return VariadicMethod;
3950     } else if (Fn && Fn->getType() == Context.BoundMemberTy)
3951       return VariadicMethod;
3952     return VariadicFunction;
3953   }
3954   return VariadicDoesNotApply;
3955 }
3956 
3957 namespace {
3958 class FunctionCallCCC : public FunctionCallFilterCCC {
3959 public:
3960   FunctionCallCCC(Sema &SemaRef, const IdentifierInfo *FuncName,
3961                   unsigned NumArgs, bool HasExplicitTemplateArgs)
3962       : FunctionCallFilterCCC(SemaRef, NumArgs, HasExplicitTemplateArgs),
3963         FunctionName(FuncName) {}
3964 
3965   virtual bool ValidateCandidate(const TypoCorrection &candidate) {
3966     if (!candidate.getCorrectionSpecifier() ||
3967         candidate.getCorrectionAsIdentifierInfo() != FunctionName) {
3968       return false;
3969     }
3970 
3971     return FunctionCallFilterCCC::ValidateCandidate(candidate);
3972   }
3973 
3974 private:
3975   const IdentifierInfo *const FunctionName;
3976 };
3977 }
3978 
3979 static TypoCorrection TryTypoCorrectionForCall(Sema &S,
3980                                                DeclarationNameInfo FuncName,
3981                                                ArrayRef<Expr *> Args) {
3982   FunctionCallCCC CCC(S, FuncName.getName().getAsIdentifierInfo(),
3983                       Args.size(), false);
3984   if (TypoCorrection Corrected =
3985           S.CorrectTypo(FuncName, Sema::LookupOrdinaryName,
3986                         S.getScopeForContext(S.CurContext), NULL, CCC)) {
3987     if (NamedDecl *ND = Corrected.getCorrectionDecl()) {
3988       if (Corrected.isOverloaded()) {
3989         OverloadCandidateSet OCS(FuncName.getLoc());
3990         OverloadCandidateSet::iterator Best;
3991         for (TypoCorrection::decl_iterator CD = Corrected.begin(),
3992                                            CDEnd = Corrected.end();
3993              CD != CDEnd; ++CD) {
3994           if (FunctionDecl *FD = dyn_cast<FunctionDecl>(*CD))
3995             S.AddOverloadCandidate(FD, DeclAccessPair::make(FD, AS_none), Args,
3996                                    OCS);
3997         }
3998         switch (OCS.BestViableFunction(S, FuncName.getLoc(), Best)) {
3999         case OR_Success:
4000           ND = Best->Function;
4001           Corrected.setCorrectionDecl(ND);
4002           break;
4003         default:
4004           break;
4005         }
4006       }
4007       if (isa<ValueDecl>(ND) || isa<FunctionTemplateDecl>(ND)) {
4008         return Corrected;
4009       }
4010     }
4011   }
4012   return TypoCorrection();
4013 }
4014 
4015 /// ConvertArgumentsForCall - Converts the arguments specified in
4016 /// Args/NumArgs to the parameter types of the function FDecl with
4017 /// function prototype Proto. Call is the call expression itself, and
4018 /// Fn is the function expression. For a C++ member function, this
4019 /// routine does not attempt to convert the object argument. Returns
4020 /// true if the call is ill-formed.
4021 bool
4022 Sema::ConvertArgumentsForCall(CallExpr *Call, Expr *Fn,
4023                               FunctionDecl *FDecl,
4024                               const FunctionProtoType *Proto,
4025                               ArrayRef<Expr *> Args,
4026                               SourceLocation RParenLoc,
4027                               bool IsExecConfig) {
4028   // Bail out early if calling a builtin with custom typechecking.
4029   // We don't need to do this in the
4030   if (FDecl)
4031     if (unsigned ID = FDecl->getBuiltinID())
4032       if (Context.BuiltinInfo.hasCustomTypechecking(ID))
4033         return false;
4034 
4035   // C99 6.5.2.2p7 - the arguments are implicitly converted, as if by
4036   // assignment, to the types of the corresponding parameter, ...
4037   unsigned NumArgsInProto = Proto->getNumArgs();
4038   bool Invalid = false;
4039   unsigned MinArgs = FDecl ? FDecl->getMinRequiredArguments() : NumArgsInProto;
4040   unsigned FnKind = Fn->getType()->isBlockPointerType()
4041                        ? 1 /* block */
4042                        : (IsExecConfig ? 3 /* kernel function (exec config) */
4043                                        : 0 /* function */);
4044 
4045   // If too few arguments are available (and we don't have default
4046   // arguments for the remaining parameters), don't make the call.
4047   if (Args.size() < NumArgsInProto) {
4048     if (Args.size() < MinArgs) {
4049       MemberExpr *ME = dyn_cast<MemberExpr>(Fn);
4050       TypoCorrection TC;
4051       if (FDecl && (TC = TryTypoCorrectionForCall(
4052                         *this, DeclarationNameInfo(FDecl->getDeclName(),
4053                                                    (ME ? ME->getMemberLoc()
4054                                                        : Fn->getLocStart())),
4055                         Args))) {
4056         unsigned diag_id =
4057             MinArgs == NumArgsInProto && !Proto->isVariadic()
4058                 ? diag::err_typecheck_call_too_few_args_suggest
4059                 : diag::err_typecheck_call_too_few_args_at_least_suggest;
4060         diagnoseTypo(TC, PDiag(diag_id) << FnKind << MinArgs
4061                                         << static_cast<unsigned>(Args.size())
4062                                         << Fn->getSourceRange());
4063       } else if (MinArgs == 1 && FDecl && FDecl->getParamDecl(0)->getDeclName())
4064         Diag(RParenLoc, MinArgs == NumArgsInProto && !Proto->isVariadic()
4065                           ? diag::err_typecheck_call_too_few_args_one
4066                           : diag::err_typecheck_call_too_few_args_at_least_one)
4067           << FnKind
4068           << FDecl->getParamDecl(0) << Fn->getSourceRange();
4069       else
4070         Diag(RParenLoc, MinArgs == NumArgsInProto && !Proto->isVariadic()
4071                           ? diag::err_typecheck_call_too_few_args
4072                           : diag::err_typecheck_call_too_few_args_at_least)
4073           << FnKind
4074           << MinArgs << static_cast<unsigned>(Args.size())
4075           << Fn->getSourceRange();
4076 
4077       // Emit the location of the prototype.
4078       if (!TC && FDecl && !FDecl->getBuiltinID() && !IsExecConfig)
4079         Diag(FDecl->getLocStart(), diag::note_callee_decl)
4080           << FDecl;
4081 
4082       return true;
4083     }
4084     Call->setNumArgs(Context, NumArgsInProto);
4085   }
4086 
4087   // If too many are passed and not variadic, error on the extras and drop
4088   // them.
4089   if (Args.size() > NumArgsInProto) {
4090     if (!Proto->isVariadic()) {
4091       TypoCorrection TC;
4092       if (FDecl && (TC = TryTypoCorrectionForCall(
4093                         *this, DeclarationNameInfo(FDecl->getDeclName(),
4094                                                    Fn->getLocStart()),
4095                         Args))) {
4096         unsigned diag_id =
4097             MinArgs == NumArgsInProto && !Proto->isVariadic()
4098                 ? diag::err_typecheck_call_too_many_args_suggest
4099                 : diag::err_typecheck_call_too_many_args_at_most_suggest;
4100         diagnoseTypo(TC, PDiag(diag_id) << FnKind << NumArgsInProto
4101                                         << static_cast<unsigned>(Args.size())
4102                                         << Fn->getSourceRange());
4103       } else if (NumArgsInProto == 1 && FDecl &&
4104                  FDecl->getParamDecl(0)->getDeclName())
4105         Diag(Args[NumArgsInProto]->getLocStart(),
4106              MinArgs == NumArgsInProto
4107                ? diag::err_typecheck_call_too_many_args_one
4108                : diag::err_typecheck_call_too_many_args_at_most_one)
4109           << FnKind
4110           << FDecl->getParamDecl(0) << static_cast<unsigned>(Args.size())
4111           << Fn->getSourceRange()
4112           << SourceRange(Args[NumArgsInProto]->getLocStart(),
4113                          Args.back()->getLocEnd());
4114       else
4115         Diag(Args[NumArgsInProto]->getLocStart(),
4116              MinArgs == NumArgsInProto
4117                ? diag::err_typecheck_call_too_many_args
4118                : diag::err_typecheck_call_too_many_args_at_most)
4119           << FnKind
4120           << NumArgsInProto << static_cast<unsigned>(Args.size())
4121           << Fn->getSourceRange()
4122           << SourceRange(Args[NumArgsInProto]->getLocStart(),
4123                          Args.back()->getLocEnd());
4124 
4125       // Emit the location of the prototype.
4126       if (!TC && FDecl && !FDecl->getBuiltinID() && !IsExecConfig)
4127         Diag(FDecl->getLocStart(), diag::note_callee_decl)
4128           << FDecl;
4129 
4130       // This deletes the extra arguments.
4131       Call->setNumArgs(Context, NumArgsInProto);
4132       return true;
4133     }
4134   }
4135   SmallVector<Expr *, 8> AllArgs;
4136   VariadicCallType CallType = getVariadicCallType(FDecl, Proto, Fn);
4137 
4138   Invalid = GatherArgumentsForCall(Call->getLocStart(), FDecl,
4139                                    Proto, 0, Args, AllArgs, CallType);
4140   if (Invalid)
4141     return true;
4142   unsigned TotalNumArgs = AllArgs.size();
4143   for (unsigned i = 0; i < TotalNumArgs; ++i)
4144     Call->setArg(i, AllArgs[i]);
4145 
4146   return false;
4147 }
4148 
4149 bool Sema::GatherArgumentsForCall(SourceLocation CallLoc,
4150                                   FunctionDecl *FDecl,
4151                                   const FunctionProtoType *Proto,
4152                                   unsigned FirstProtoArg,
4153                                   ArrayRef<Expr *> Args,
4154                                   SmallVectorImpl<Expr *> &AllArgs,
4155                                   VariadicCallType CallType,
4156                                   bool AllowExplicit,
4157                                   bool IsListInitialization) {
4158   unsigned NumArgsInProto = Proto->getNumArgs();
4159   unsigned NumArgsToCheck = Args.size();
4160   bool Invalid = false;
4161   if (Args.size() != NumArgsInProto)
4162     // Use default arguments for missing arguments
4163     NumArgsToCheck = NumArgsInProto;
4164   unsigned ArgIx = 0;
4165   // Continue to check argument types (even if we have too few/many args).
4166   for (unsigned i = FirstProtoArg; i != NumArgsToCheck; i++) {
4167     QualType ProtoArgType = Proto->getArgType(i);
4168 
4169     Expr *Arg;
4170     ParmVarDecl *Param;
4171     if (ArgIx < Args.size()) {
4172       Arg = Args[ArgIx++];
4173 
4174       if (RequireCompleteType(Arg->getLocStart(),
4175                               ProtoArgType,
4176                               diag::err_call_incomplete_argument, Arg))
4177         return true;
4178 
4179       // Pass the argument
4180       Param = 0;
4181       if (FDecl && i < FDecl->getNumParams())
4182         Param = FDecl->getParamDecl(i);
4183 
4184       // Strip the unbridged-cast placeholder expression off, if applicable.
4185       bool CFAudited = false;
4186       if (Arg->getType() == Context.ARCUnbridgedCastTy &&
4187           FDecl && FDecl->hasAttr<CFAuditedTransferAttr>() &&
4188           (!Param || !Param->hasAttr<CFConsumedAttr>()))
4189         Arg = stripARCUnbridgedCast(Arg);
4190       else if (getLangOpts().ObjCAutoRefCount &&
4191                FDecl && FDecl->hasAttr<CFAuditedTransferAttr>() &&
4192                (!Param || !Param->hasAttr<CFConsumedAttr>()))
4193         CFAudited = true;
4194 
4195       InitializedEntity Entity = Param ?
4196           InitializedEntity::InitializeParameter(Context, Param, ProtoArgType)
4197         : InitializedEntity::InitializeParameter(Context, ProtoArgType,
4198                                                  Proto->isArgConsumed(i));
4199 
4200       // Remember that parameter belongs to a CF audited API.
4201       if (CFAudited)
4202         Entity.setParameterCFAudited();
4203 
4204       ExprResult ArgE = PerformCopyInitialization(Entity,
4205                                                   SourceLocation(),
4206                                                   Owned(Arg),
4207                                                   IsListInitialization,
4208                                                   AllowExplicit);
4209       if (ArgE.isInvalid())
4210         return true;
4211 
4212       Arg = ArgE.takeAs<Expr>();
4213     } else {
4214       assert(FDecl && "can't use default arguments without a known callee");
4215       Param = FDecl->getParamDecl(i);
4216 
4217       ExprResult ArgExpr =
4218         BuildCXXDefaultArgExpr(CallLoc, FDecl, Param);
4219       if (ArgExpr.isInvalid())
4220         return true;
4221 
4222       Arg = ArgExpr.takeAs<Expr>();
4223     }
4224 
4225     // Check for array bounds violations for each argument to the call. This
4226     // check only triggers warnings when the argument isn't a more complex Expr
4227     // with its own checking, such as a BinaryOperator.
4228     CheckArrayAccess(Arg);
4229 
4230     // Check for violations of C99 static array rules (C99 6.7.5.3p7).
4231     CheckStaticArrayArgument(CallLoc, Param, Arg);
4232 
4233     AllArgs.push_back(Arg);
4234   }
4235 
4236   // If this is a variadic call, handle args passed through "...".
4237   if (CallType != VariadicDoesNotApply) {
4238     // Assume that extern "C" functions with variadic arguments that
4239     // return __unknown_anytype aren't *really* variadic.
4240     if (Proto->getResultType() == Context.UnknownAnyTy &&
4241         FDecl && FDecl->isExternC()) {
4242       for (unsigned i = ArgIx, e = Args.size(); i != e; ++i) {
4243         QualType paramType; // ignored
4244         ExprResult arg = checkUnknownAnyArg(CallLoc, Args[i], paramType);
4245         Invalid |= arg.isInvalid();
4246         AllArgs.push_back(arg.take());
4247       }
4248 
4249     // Otherwise do argument promotion, (C99 6.5.2.2p7).
4250     } else {
4251       for (unsigned i = ArgIx, e = Args.size(); i != e; ++i) {
4252         ExprResult Arg = DefaultVariadicArgumentPromotion(Args[i], CallType,
4253                                                           FDecl);
4254         Invalid |= Arg.isInvalid();
4255         AllArgs.push_back(Arg.take());
4256       }
4257     }
4258 
4259     // Check for array bounds violations.
4260     for (unsigned i = ArgIx, e = Args.size(); i != e; ++i)
4261       CheckArrayAccess(Args[i]);
4262   }
4263   return Invalid;
4264 }
4265 
4266 static void DiagnoseCalleeStaticArrayParam(Sema &S, ParmVarDecl *PVD) {
4267   TypeLoc TL = PVD->getTypeSourceInfo()->getTypeLoc();
4268   if (DecayedTypeLoc DTL = TL.getAs<DecayedTypeLoc>())
4269     TL = DTL.getOriginalLoc();
4270   if (ArrayTypeLoc ATL = TL.getAs<ArrayTypeLoc>())
4271     S.Diag(PVD->getLocation(), diag::note_callee_static_array)
4272       << ATL.getLocalSourceRange();
4273 }
4274 
4275 /// CheckStaticArrayArgument - If the given argument corresponds to a static
4276 /// array parameter, check that it is non-null, and that if it is formed by
4277 /// array-to-pointer decay, the underlying array is sufficiently large.
4278 ///
4279 /// C99 6.7.5.3p7: If the keyword static also appears within the [ and ] of the
4280 /// array type derivation, then for each call to the function, the value of the
4281 /// corresponding actual argument shall provide access to the first element of
4282 /// an array with at least as many elements as specified by the size expression.
4283 void
4284 Sema::CheckStaticArrayArgument(SourceLocation CallLoc,
4285                                ParmVarDecl *Param,
4286                                const Expr *ArgExpr) {
4287   // Static array parameters are not supported in C++.
4288   if (!Param || getLangOpts().CPlusPlus)
4289     return;
4290 
4291   QualType OrigTy = Param->getOriginalType();
4292 
4293   const ArrayType *AT = Context.getAsArrayType(OrigTy);
4294   if (!AT || AT->getSizeModifier() != ArrayType::Static)
4295     return;
4296 
4297   if (ArgExpr->isNullPointerConstant(Context,
4298                                      Expr::NPC_NeverValueDependent)) {
4299     Diag(CallLoc, diag::warn_null_arg) << ArgExpr->getSourceRange();
4300     DiagnoseCalleeStaticArrayParam(*this, Param);
4301     return;
4302   }
4303 
4304   const ConstantArrayType *CAT = dyn_cast<ConstantArrayType>(AT);
4305   if (!CAT)
4306     return;
4307 
4308   const ConstantArrayType *ArgCAT =
4309     Context.getAsConstantArrayType(ArgExpr->IgnoreParenImpCasts()->getType());
4310   if (!ArgCAT)
4311     return;
4312 
4313   if (ArgCAT->getSize().ult(CAT->getSize())) {
4314     Diag(CallLoc, diag::warn_static_array_too_small)
4315       << ArgExpr->getSourceRange()
4316       << (unsigned) ArgCAT->getSize().getZExtValue()
4317       << (unsigned) CAT->getSize().getZExtValue();
4318     DiagnoseCalleeStaticArrayParam(*this, Param);
4319   }
4320 }
4321 
4322 /// Given a function expression of unknown-any type, try to rebuild it
4323 /// to have a function type.
4324 static ExprResult rebuildUnknownAnyFunction(Sema &S, Expr *fn);
4325 
4326 /// Is the given type a placeholder that we need to lower out
4327 /// immediately during argument processing?
4328 static bool isPlaceholderToRemoveAsArg(QualType type) {
4329   // Placeholders are never sugared.
4330   const BuiltinType *placeholder = dyn_cast<BuiltinType>(type);
4331   if (!placeholder) return false;
4332 
4333   switch (placeholder->getKind()) {
4334   // Ignore all the non-placeholder types.
4335 #define PLACEHOLDER_TYPE(ID, SINGLETON_ID)
4336 #define BUILTIN_TYPE(ID, SINGLETON_ID) case BuiltinType::ID:
4337 #include "clang/AST/BuiltinTypes.def"
4338     return false;
4339 
4340   // We cannot lower out overload sets; they might validly be resolved
4341   // by the call machinery.
4342   case BuiltinType::Overload:
4343     return false;
4344 
4345   // Unbridged casts in ARC can be handled in some call positions and
4346   // should be left in place.
4347   case BuiltinType::ARCUnbridgedCast:
4348     return false;
4349 
4350   // Pseudo-objects should be converted as soon as possible.
4351   case BuiltinType::PseudoObject:
4352     return true;
4353 
4354   // The debugger mode could theoretically but currently does not try
4355   // to resolve unknown-typed arguments based on known parameter types.
4356   case BuiltinType::UnknownAny:
4357     return true;
4358 
4359   // These are always invalid as call arguments and should be reported.
4360   case BuiltinType::BoundMember:
4361   case BuiltinType::BuiltinFn:
4362     return true;
4363   }
4364   llvm_unreachable("bad builtin type kind");
4365 }
4366 
4367 /// Check an argument list for placeholders that we won't try to
4368 /// handle later.
4369 static bool checkArgsForPlaceholders(Sema &S, MultiExprArg args) {
4370   // Apply this processing to all the arguments at once instead of
4371   // dying at the first failure.
4372   bool hasInvalid = false;
4373   for (size_t i = 0, e = args.size(); i != e; i++) {
4374     if (isPlaceholderToRemoveAsArg(args[i]->getType())) {
4375       ExprResult result = S.CheckPlaceholderExpr(args[i]);
4376       if (result.isInvalid()) hasInvalid = true;
4377       else args[i] = result.take();
4378     }
4379   }
4380   return hasInvalid;
4381 }
4382 
4383 /// ActOnCallExpr - Handle a call to Fn with the specified array of arguments.
4384 /// This provides the location of the left/right parens and a list of comma
4385 /// locations.
4386 ExprResult
4387 Sema::ActOnCallExpr(Scope *S, Expr *Fn, SourceLocation LParenLoc,
4388                     MultiExprArg ArgExprs, SourceLocation RParenLoc,
4389                     Expr *ExecConfig, bool IsExecConfig) {
4390   // Since this might be a postfix expression, get rid of ParenListExprs.
4391   ExprResult Result = MaybeConvertParenListExprToParenExpr(S, Fn);
4392   if (Result.isInvalid()) return ExprError();
4393   Fn = Result.take();
4394 
4395   if (checkArgsForPlaceholders(*this, ArgExprs))
4396     return ExprError();
4397 
4398   if (getLangOpts().CPlusPlus) {
4399     // If this is a pseudo-destructor expression, build the call immediately.
4400     if (isa<CXXPseudoDestructorExpr>(Fn)) {
4401       if (!ArgExprs.empty()) {
4402         // Pseudo-destructor calls should not have any arguments.
4403         Diag(Fn->getLocStart(), diag::err_pseudo_dtor_call_with_args)
4404           << FixItHint::CreateRemoval(
4405                                     SourceRange(ArgExprs[0]->getLocStart(),
4406                                                 ArgExprs.back()->getLocEnd()));
4407       }
4408 
4409       return Owned(new (Context) CallExpr(Context, Fn, None,
4410                                           Context.VoidTy, VK_RValue,
4411                                           RParenLoc));
4412     }
4413     if (Fn->getType() == Context.PseudoObjectTy) {
4414       ExprResult result = CheckPlaceholderExpr(Fn);
4415       if (result.isInvalid()) return ExprError();
4416       Fn = result.take();
4417     }
4418 
4419     // Determine whether this is a dependent call inside a C++ template,
4420     // in which case we won't do any semantic analysis now.
4421     // FIXME: Will need to cache the results of name lookup (including ADL) in
4422     // Fn.
4423     bool Dependent = false;
4424     if (Fn->isTypeDependent())
4425       Dependent = true;
4426     else if (Expr::hasAnyTypeDependentArguments(ArgExprs))
4427       Dependent = true;
4428 
4429     if (Dependent) {
4430       if (ExecConfig) {
4431         return Owned(new (Context) CUDAKernelCallExpr(
4432             Context, Fn, cast<CallExpr>(ExecConfig), ArgExprs,
4433             Context.DependentTy, VK_RValue, RParenLoc));
4434       } else {
4435         return Owned(new (Context) CallExpr(Context, Fn, ArgExprs,
4436                                             Context.DependentTy, VK_RValue,
4437                                             RParenLoc));
4438       }
4439     }
4440 
4441     // Determine whether this is a call to an object (C++ [over.call.object]).
4442     if (Fn->getType()->isRecordType())
4443       return Owned(BuildCallToObjectOfClassType(S, Fn, LParenLoc,
4444                                                 ArgExprs, RParenLoc));
4445 
4446     if (Fn->getType() == Context.UnknownAnyTy) {
4447       ExprResult result = rebuildUnknownAnyFunction(*this, Fn);
4448       if (result.isInvalid()) return ExprError();
4449       Fn = result.take();
4450     }
4451 
4452     if (Fn->getType() == Context.BoundMemberTy) {
4453       return BuildCallToMemberFunction(S, Fn, LParenLoc, ArgExprs, RParenLoc);
4454     }
4455   }
4456 
4457   // Check for overloaded calls.  This can happen even in C due to extensions.
4458   if (Fn->getType() == Context.OverloadTy) {
4459     OverloadExpr::FindResult find = OverloadExpr::find(Fn);
4460 
4461     // We aren't supposed to apply this logic for if there's an '&' involved.
4462     if (!find.HasFormOfMemberPointer) {
4463       OverloadExpr *ovl = find.Expression;
4464       if (isa<UnresolvedLookupExpr>(ovl)) {
4465         UnresolvedLookupExpr *ULE = cast<UnresolvedLookupExpr>(ovl);
4466         return BuildOverloadedCallExpr(S, Fn, ULE, LParenLoc, ArgExprs,
4467                                        RParenLoc, ExecConfig);
4468       } else {
4469         return BuildCallToMemberFunction(S, Fn, LParenLoc, ArgExprs,
4470                                          RParenLoc);
4471       }
4472     }
4473   }
4474 
4475   // If we're directly calling a function, get the appropriate declaration.
4476   if (Fn->getType() == Context.UnknownAnyTy) {
4477     ExprResult result = rebuildUnknownAnyFunction(*this, Fn);
4478     if (result.isInvalid()) return ExprError();
4479     Fn = result.take();
4480   }
4481 
4482   Expr *NakedFn = Fn->IgnoreParens();
4483 
4484   NamedDecl *NDecl = 0;
4485   if (UnaryOperator *UnOp = dyn_cast<UnaryOperator>(NakedFn))
4486     if (UnOp->getOpcode() == UO_AddrOf)
4487       NakedFn = UnOp->getSubExpr()->IgnoreParens();
4488 
4489   if (isa<DeclRefExpr>(NakedFn))
4490     NDecl = cast<DeclRefExpr>(NakedFn)->getDecl();
4491   else if (isa<MemberExpr>(NakedFn))
4492     NDecl = cast<MemberExpr>(NakedFn)->getMemberDecl();
4493 
4494   return BuildResolvedCallExpr(Fn, NDecl, LParenLoc, ArgExprs, RParenLoc,
4495                                ExecConfig, IsExecConfig);
4496 }
4497 
4498 ExprResult
4499 Sema::ActOnCUDAExecConfigExpr(Scope *S, SourceLocation LLLLoc,
4500                               MultiExprArg ExecConfig, SourceLocation GGGLoc) {
4501   FunctionDecl *ConfigDecl = Context.getcudaConfigureCallDecl();
4502   if (!ConfigDecl)
4503     return ExprError(Diag(LLLLoc, diag::err_undeclared_var_use)
4504                           << "cudaConfigureCall");
4505   QualType ConfigQTy = ConfigDecl->getType();
4506 
4507   DeclRefExpr *ConfigDR = new (Context) DeclRefExpr(
4508       ConfigDecl, false, ConfigQTy, VK_LValue, LLLLoc);
4509   MarkFunctionReferenced(LLLLoc, ConfigDecl);
4510 
4511   return ActOnCallExpr(S, ConfigDR, LLLLoc, ExecConfig, GGGLoc, 0,
4512                        /*IsExecConfig=*/true);
4513 }
4514 
4515 /// ActOnAsTypeExpr - create a new asType (bitcast) from the arguments.
4516 ///
4517 /// __builtin_astype( value, dst type )
4518 ///
4519 ExprResult Sema::ActOnAsTypeExpr(Expr *E, ParsedType ParsedDestTy,
4520                                  SourceLocation BuiltinLoc,
4521                                  SourceLocation RParenLoc) {
4522   ExprValueKind VK = VK_RValue;
4523   ExprObjectKind OK = OK_Ordinary;
4524   QualType DstTy = GetTypeFromParser(ParsedDestTy);
4525   QualType SrcTy = E->getType();
4526   if (Context.getTypeSize(DstTy) != Context.getTypeSize(SrcTy))
4527     return ExprError(Diag(BuiltinLoc,
4528                           diag::err_invalid_astype_of_different_size)
4529                      << DstTy
4530                      << SrcTy
4531                      << E->getSourceRange());
4532   return Owned(new (Context) AsTypeExpr(E, DstTy, VK, OK, BuiltinLoc,
4533                RParenLoc));
4534 }
4535 
4536 /// ActOnConvertVectorExpr - create a new convert-vector expression from the
4537 /// provided arguments.
4538 ///
4539 /// __builtin_convertvector( value, dst type )
4540 ///
4541 ExprResult Sema::ActOnConvertVectorExpr(Expr *E, ParsedType ParsedDestTy,
4542                                         SourceLocation BuiltinLoc,
4543                                         SourceLocation RParenLoc) {
4544   TypeSourceInfo *TInfo;
4545   GetTypeFromParser(ParsedDestTy, &TInfo);
4546   return SemaConvertVectorExpr(E, TInfo, BuiltinLoc, RParenLoc);
4547 }
4548 
4549 /// BuildResolvedCallExpr - Build a call to a resolved expression,
4550 /// i.e. an expression not of \p OverloadTy.  The expression should
4551 /// unary-convert to an expression of function-pointer or
4552 /// block-pointer type.
4553 ///
4554 /// \param NDecl the declaration being called, if available
4555 ExprResult
4556 Sema::BuildResolvedCallExpr(Expr *Fn, NamedDecl *NDecl,
4557                             SourceLocation LParenLoc,
4558                             ArrayRef<Expr *> Args,
4559                             SourceLocation RParenLoc,
4560                             Expr *Config, bool IsExecConfig) {
4561   FunctionDecl *FDecl = dyn_cast_or_null<FunctionDecl>(NDecl);
4562   unsigned BuiltinID = (FDecl ? FDecl->getBuiltinID() : 0);
4563 
4564   // Promote the function operand.
4565   // We special-case function promotion here because we only allow promoting
4566   // builtin functions to function pointers in the callee of a call.
4567   ExprResult Result;
4568   if (BuiltinID &&
4569       Fn->getType()->isSpecificBuiltinType(BuiltinType::BuiltinFn)) {
4570     Result = ImpCastExprToType(Fn, Context.getPointerType(FDecl->getType()),
4571                                CK_BuiltinFnToFnPtr).take();
4572   } else {
4573     Result = UsualUnaryConversions(Fn);
4574   }
4575   if (Result.isInvalid())
4576     return ExprError();
4577   Fn = Result.take();
4578 
4579   // Make the call expr early, before semantic checks.  This guarantees cleanup
4580   // of arguments and function on error.
4581   CallExpr *TheCall;
4582   if (Config)
4583     TheCall = new (Context) CUDAKernelCallExpr(Context, Fn,
4584                                                cast<CallExpr>(Config), Args,
4585                                                Context.BoolTy, VK_RValue,
4586                                                RParenLoc);
4587   else
4588     TheCall = new (Context) CallExpr(Context, Fn, Args, Context.BoolTy,
4589                                      VK_RValue, RParenLoc);
4590 
4591   // Bail out early if calling a builtin with custom typechecking.
4592   if (BuiltinID && Context.BuiltinInfo.hasCustomTypechecking(BuiltinID))
4593     return CheckBuiltinFunctionCall(BuiltinID, TheCall);
4594 
4595  retry:
4596   const FunctionType *FuncT;
4597   if (const PointerType *PT = Fn->getType()->getAs<PointerType>()) {
4598     // C99 6.5.2.2p1 - "The expression that denotes the called function shall
4599     // have type pointer to function".
4600     FuncT = PT->getPointeeType()->getAs<FunctionType>();
4601     if (FuncT == 0)
4602       return ExprError(Diag(LParenLoc, diag::err_typecheck_call_not_function)
4603                          << Fn->getType() << Fn->getSourceRange());
4604   } else if (const BlockPointerType *BPT =
4605                Fn->getType()->getAs<BlockPointerType>()) {
4606     FuncT = BPT->getPointeeType()->castAs<FunctionType>();
4607   } else {
4608     // Handle calls to expressions of unknown-any type.
4609     if (Fn->getType() == Context.UnknownAnyTy) {
4610       ExprResult rewrite = rebuildUnknownAnyFunction(*this, Fn);
4611       if (rewrite.isInvalid()) return ExprError();
4612       Fn = rewrite.take();
4613       TheCall->setCallee(Fn);
4614       goto retry;
4615     }
4616 
4617     return ExprError(Diag(LParenLoc, diag::err_typecheck_call_not_function)
4618       << Fn->getType() << Fn->getSourceRange());
4619   }
4620 
4621   if (getLangOpts().CUDA) {
4622     if (Config) {
4623       // CUDA: Kernel calls must be to global functions
4624       if (FDecl && !FDecl->hasAttr<CUDAGlobalAttr>())
4625         return ExprError(Diag(LParenLoc,diag::err_kern_call_not_global_function)
4626             << FDecl->getName() << Fn->getSourceRange());
4627 
4628       // CUDA: Kernel function must have 'void' return type
4629       if (!FuncT->getResultType()->isVoidType())
4630         return ExprError(Diag(LParenLoc, diag::err_kern_type_not_void_return)
4631             << Fn->getType() << Fn->getSourceRange());
4632     } else {
4633       // CUDA: Calls to global functions must be configured
4634       if (FDecl && FDecl->hasAttr<CUDAGlobalAttr>())
4635         return ExprError(Diag(LParenLoc, diag::err_global_call_not_config)
4636             << FDecl->getName() << Fn->getSourceRange());
4637     }
4638   }
4639 
4640   // Check for a valid return type
4641   if (CheckCallReturnType(FuncT->getResultType(),
4642                           Fn->getLocStart(), TheCall,
4643                           FDecl))
4644     return ExprError();
4645 
4646   // We know the result type of the call, set it.
4647   TheCall->setType(FuncT->getCallResultType(Context));
4648   TheCall->setValueKind(Expr::getValueKindForType(FuncT->getResultType()));
4649 
4650   const FunctionProtoType *Proto = dyn_cast<FunctionProtoType>(FuncT);
4651   if (Proto) {
4652     if (ConvertArgumentsForCall(TheCall, Fn, FDecl, Proto, Args, RParenLoc,
4653                                 IsExecConfig))
4654       return ExprError();
4655   } else {
4656     assert(isa<FunctionNoProtoType>(FuncT) && "Unknown FunctionType!");
4657 
4658     if (FDecl) {
4659       // Check if we have too few/too many template arguments, based
4660       // on our knowledge of the function definition.
4661       const FunctionDecl *Def = 0;
4662       if (FDecl->hasBody(Def) && Args.size() != Def->param_size()) {
4663         Proto = Def->getType()->getAs<FunctionProtoType>();
4664        if (!Proto || !(Proto->isVariadic() && Args.size() >= Def->param_size()))
4665           Diag(RParenLoc, diag::warn_call_wrong_number_of_arguments)
4666           << (Args.size() > Def->param_size()) << FDecl << Fn->getSourceRange();
4667       }
4668 
4669       // If the function we're calling isn't a function prototype, but we have
4670       // a function prototype from a prior declaratiom, use that prototype.
4671       if (!FDecl->hasPrototype())
4672         Proto = FDecl->getType()->getAs<FunctionProtoType>();
4673     }
4674 
4675     // Promote the arguments (C99 6.5.2.2p6).
4676     for (unsigned i = 0, e = Args.size(); i != e; i++) {
4677       Expr *Arg = Args[i];
4678 
4679       if (Proto && i < Proto->getNumArgs()) {
4680         InitializedEntity Entity
4681           = InitializedEntity::InitializeParameter(Context,
4682                                                    Proto->getArgType(i),
4683                                                    Proto->isArgConsumed(i));
4684         ExprResult ArgE = PerformCopyInitialization(Entity,
4685                                                     SourceLocation(),
4686                                                     Owned(Arg));
4687         if (ArgE.isInvalid())
4688           return true;
4689 
4690         Arg = ArgE.takeAs<Expr>();
4691 
4692       } else {
4693         ExprResult ArgE = DefaultArgumentPromotion(Arg);
4694 
4695         if (ArgE.isInvalid())
4696           return true;
4697 
4698         Arg = ArgE.takeAs<Expr>();
4699       }
4700 
4701       if (RequireCompleteType(Arg->getLocStart(),
4702                               Arg->getType(),
4703                               diag::err_call_incomplete_argument, Arg))
4704         return ExprError();
4705 
4706       TheCall->setArg(i, Arg);
4707     }
4708   }
4709 
4710   if (CXXMethodDecl *Method = dyn_cast_or_null<CXXMethodDecl>(FDecl))
4711     if (!Method->isStatic())
4712       return ExprError(Diag(LParenLoc, diag::err_member_call_without_object)
4713         << Fn->getSourceRange());
4714 
4715   // Check for sentinels
4716   if (NDecl)
4717     DiagnoseSentinelCalls(NDecl, LParenLoc, Args);
4718 
4719   // Do special checking on direct calls to functions.
4720   if (FDecl) {
4721     if (CheckFunctionCall(FDecl, TheCall, Proto))
4722       return ExprError();
4723 
4724     if (BuiltinID)
4725       return CheckBuiltinFunctionCall(BuiltinID, TheCall);
4726   } else if (NDecl) {
4727     if (CheckPointerCall(NDecl, TheCall, Proto))
4728       return ExprError();
4729   } else {
4730     if (CheckOtherCall(TheCall, Proto))
4731       return ExprError();
4732   }
4733 
4734   return MaybeBindToTemporary(TheCall);
4735 }
4736 
4737 ExprResult
4738 Sema::ActOnCompoundLiteral(SourceLocation LParenLoc, ParsedType Ty,
4739                            SourceLocation RParenLoc, Expr *InitExpr) {
4740   assert(Ty && "ActOnCompoundLiteral(): missing type");
4741   // FIXME: put back this assert when initializers are worked out.
4742   //assert((InitExpr != 0) && "ActOnCompoundLiteral(): missing expression");
4743 
4744   TypeSourceInfo *TInfo;
4745   QualType literalType = GetTypeFromParser(Ty, &TInfo);
4746   if (!TInfo)
4747     TInfo = Context.getTrivialTypeSourceInfo(literalType);
4748 
4749   return BuildCompoundLiteralExpr(LParenLoc, TInfo, RParenLoc, InitExpr);
4750 }
4751 
4752 ExprResult
4753 Sema::BuildCompoundLiteralExpr(SourceLocation LParenLoc, TypeSourceInfo *TInfo,
4754                                SourceLocation RParenLoc, Expr *LiteralExpr) {
4755   QualType literalType = TInfo->getType();
4756 
4757   if (literalType->isArrayType()) {
4758     if (RequireCompleteType(LParenLoc, Context.getBaseElementType(literalType),
4759           diag::err_illegal_decl_array_incomplete_type,
4760           SourceRange(LParenLoc,
4761                       LiteralExpr->getSourceRange().getEnd())))
4762       return ExprError();
4763     if (literalType->isVariableArrayType())
4764       return ExprError(Diag(LParenLoc, diag::err_variable_object_no_init)
4765         << SourceRange(LParenLoc, LiteralExpr->getSourceRange().getEnd()));
4766   } else if (!literalType->isDependentType() &&
4767              RequireCompleteType(LParenLoc, literalType,
4768                diag::err_typecheck_decl_incomplete_type,
4769                SourceRange(LParenLoc, LiteralExpr->getSourceRange().getEnd())))
4770     return ExprError();
4771 
4772   InitializedEntity Entity
4773     = InitializedEntity::InitializeCompoundLiteralInit(TInfo);
4774   InitializationKind Kind
4775     = InitializationKind::CreateCStyleCast(LParenLoc,
4776                                            SourceRange(LParenLoc, RParenLoc),
4777                                            /*InitList=*/true);
4778   InitializationSequence InitSeq(*this, Entity, Kind, LiteralExpr);
4779   ExprResult Result = InitSeq.Perform(*this, Entity, Kind, LiteralExpr,
4780                                       &literalType);
4781   if (Result.isInvalid())
4782     return ExprError();
4783   LiteralExpr = Result.get();
4784 
4785   bool isFileScope = getCurFunctionOrMethodDecl() == 0;
4786   if (isFileScope &&
4787       !LiteralExpr->isTypeDependent() &&
4788       !LiteralExpr->isValueDependent() &&
4789       !literalType->isDependentType()) { // 6.5.2.5p3
4790     if (CheckForConstantInitializer(LiteralExpr, literalType))
4791       return ExprError();
4792   }
4793 
4794   // In C, compound literals are l-values for some reason.
4795   ExprValueKind VK = getLangOpts().CPlusPlus ? VK_RValue : VK_LValue;
4796 
4797   return MaybeBindToTemporary(
4798            new (Context) CompoundLiteralExpr(LParenLoc, TInfo, literalType,
4799                                              VK, LiteralExpr, isFileScope));
4800 }
4801 
4802 ExprResult
4803 Sema::ActOnInitList(SourceLocation LBraceLoc, MultiExprArg InitArgList,
4804                     SourceLocation RBraceLoc) {
4805   // Immediately handle non-overload placeholders.  Overloads can be
4806   // resolved contextually, but everything else here can't.
4807   for (unsigned I = 0, E = InitArgList.size(); I != E; ++I) {
4808     if (InitArgList[I]->getType()->isNonOverloadPlaceholderType()) {
4809       ExprResult result = CheckPlaceholderExpr(InitArgList[I]);
4810 
4811       // Ignore failures; dropping the entire initializer list because
4812       // of one failure would be terrible for indexing/etc.
4813       if (result.isInvalid()) continue;
4814 
4815       InitArgList[I] = result.take();
4816     }
4817   }
4818 
4819   // Semantic analysis for initializers is done by ActOnDeclarator() and
4820   // CheckInitializer() - it requires knowledge of the object being intialized.
4821 
4822   InitListExpr *E = new (Context) InitListExpr(Context, LBraceLoc, InitArgList,
4823                                                RBraceLoc);
4824   E->setType(Context.VoidTy); // FIXME: just a place holder for now.
4825   return Owned(E);
4826 }
4827 
4828 /// Do an explicit extend of the given block pointer if we're in ARC.
4829 static void maybeExtendBlockObject(Sema &S, ExprResult &E) {
4830   assert(E.get()->getType()->isBlockPointerType());
4831   assert(E.get()->isRValue());
4832 
4833   // Only do this in an r-value context.
4834   if (!S.getLangOpts().ObjCAutoRefCount) return;
4835 
4836   E = ImplicitCastExpr::Create(S.Context, E.get()->getType(),
4837                                CK_ARCExtendBlockObject, E.get(),
4838                                /*base path*/ 0, VK_RValue);
4839   S.ExprNeedsCleanups = true;
4840 }
4841 
4842 /// Prepare a conversion of the given expression to an ObjC object
4843 /// pointer type.
4844 CastKind Sema::PrepareCastToObjCObjectPointer(ExprResult &E) {
4845   QualType type = E.get()->getType();
4846   if (type->isObjCObjectPointerType()) {
4847     return CK_BitCast;
4848   } else if (type->isBlockPointerType()) {
4849     maybeExtendBlockObject(*this, E);
4850     return CK_BlockPointerToObjCPointerCast;
4851   } else {
4852     assert(type->isPointerType());
4853     return CK_CPointerToObjCPointerCast;
4854   }
4855 }
4856 
4857 /// Prepares for a scalar cast, performing all the necessary stages
4858 /// except the final cast and returning the kind required.
4859 CastKind Sema::PrepareScalarCast(ExprResult &Src, QualType DestTy) {
4860   // Both Src and Dest are scalar types, i.e. arithmetic or pointer.
4861   // Also, callers should have filtered out the invalid cases with
4862   // pointers.  Everything else should be possible.
4863 
4864   QualType SrcTy = Src.get()->getType();
4865   if (Context.hasSameUnqualifiedType(SrcTy, DestTy))
4866     return CK_NoOp;
4867 
4868   switch (Type::ScalarTypeKind SrcKind = SrcTy->getScalarTypeKind()) {
4869   case Type::STK_MemberPointer:
4870     llvm_unreachable("member pointer type in C");
4871 
4872   case Type::STK_CPointer:
4873   case Type::STK_BlockPointer:
4874   case Type::STK_ObjCObjectPointer:
4875     switch (DestTy->getScalarTypeKind()) {
4876     case Type::STK_CPointer:
4877       return CK_BitCast;
4878     case Type::STK_BlockPointer:
4879       return (SrcKind == Type::STK_BlockPointer
4880                 ? CK_BitCast : CK_AnyPointerToBlockPointerCast);
4881     case Type::STK_ObjCObjectPointer:
4882       if (SrcKind == Type::STK_ObjCObjectPointer)
4883         return CK_BitCast;
4884       if (SrcKind == Type::STK_CPointer)
4885         return CK_CPointerToObjCPointerCast;
4886       maybeExtendBlockObject(*this, Src);
4887       return CK_BlockPointerToObjCPointerCast;
4888     case Type::STK_Bool:
4889       return CK_PointerToBoolean;
4890     case Type::STK_Integral:
4891       return CK_PointerToIntegral;
4892     case Type::STK_Floating:
4893     case Type::STK_FloatingComplex:
4894     case Type::STK_IntegralComplex:
4895     case Type::STK_MemberPointer:
4896       llvm_unreachable("illegal cast from pointer");
4897     }
4898     llvm_unreachable("Should have returned before this");
4899 
4900   case Type::STK_Bool: // casting from bool is like casting from an integer
4901   case Type::STK_Integral:
4902     switch (DestTy->getScalarTypeKind()) {
4903     case Type::STK_CPointer:
4904     case Type::STK_ObjCObjectPointer:
4905     case Type::STK_BlockPointer:
4906       if (Src.get()->isNullPointerConstant(Context,
4907                                            Expr::NPC_ValueDependentIsNull))
4908         return CK_NullToPointer;
4909       return CK_IntegralToPointer;
4910     case Type::STK_Bool:
4911       return CK_IntegralToBoolean;
4912     case Type::STK_Integral:
4913       return CK_IntegralCast;
4914     case Type::STK_Floating:
4915       return CK_IntegralToFloating;
4916     case Type::STK_IntegralComplex:
4917       Src = ImpCastExprToType(Src.take(),
4918                               DestTy->castAs<ComplexType>()->getElementType(),
4919                               CK_IntegralCast);
4920       return CK_IntegralRealToComplex;
4921     case Type::STK_FloatingComplex:
4922       Src = ImpCastExprToType(Src.take(),
4923                               DestTy->castAs<ComplexType>()->getElementType(),
4924                               CK_IntegralToFloating);
4925       return CK_FloatingRealToComplex;
4926     case Type::STK_MemberPointer:
4927       llvm_unreachable("member pointer type in C");
4928     }
4929     llvm_unreachable("Should have returned before this");
4930 
4931   case Type::STK_Floating:
4932     switch (DestTy->getScalarTypeKind()) {
4933     case Type::STK_Floating:
4934       return CK_FloatingCast;
4935     case Type::STK_Bool:
4936       return CK_FloatingToBoolean;
4937     case Type::STK_Integral:
4938       return CK_FloatingToIntegral;
4939     case Type::STK_FloatingComplex:
4940       Src = ImpCastExprToType(Src.take(),
4941                               DestTy->castAs<ComplexType>()->getElementType(),
4942                               CK_FloatingCast);
4943       return CK_FloatingRealToComplex;
4944     case Type::STK_IntegralComplex:
4945       Src = ImpCastExprToType(Src.take(),
4946                               DestTy->castAs<ComplexType>()->getElementType(),
4947                               CK_FloatingToIntegral);
4948       return CK_IntegralRealToComplex;
4949     case Type::STK_CPointer:
4950     case Type::STK_ObjCObjectPointer:
4951     case Type::STK_BlockPointer:
4952       llvm_unreachable("valid float->pointer cast?");
4953     case Type::STK_MemberPointer:
4954       llvm_unreachable("member pointer type in C");
4955     }
4956     llvm_unreachable("Should have returned before this");
4957 
4958   case Type::STK_FloatingComplex:
4959     switch (DestTy->getScalarTypeKind()) {
4960     case Type::STK_FloatingComplex:
4961       return CK_FloatingComplexCast;
4962     case Type::STK_IntegralComplex:
4963       return CK_FloatingComplexToIntegralComplex;
4964     case Type::STK_Floating: {
4965       QualType ET = SrcTy->castAs<ComplexType>()->getElementType();
4966       if (Context.hasSameType(ET, DestTy))
4967         return CK_FloatingComplexToReal;
4968       Src = ImpCastExprToType(Src.take(), ET, CK_FloatingComplexToReal);
4969       return CK_FloatingCast;
4970     }
4971     case Type::STK_Bool:
4972       return CK_FloatingComplexToBoolean;
4973     case Type::STK_Integral:
4974       Src = ImpCastExprToType(Src.take(),
4975                               SrcTy->castAs<ComplexType>()->getElementType(),
4976                               CK_FloatingComplexToReal);
4977       return CK_FloatingToIntegral;
4978     case Type::STK_CPointer:
4979     case Type::STK_ObjCObjectPointer:
4980     case Type::STK_BlockPointer:
4981       llvm_unreachable("valid complex float->pointer cast?");
4982     case Type::STK_MemberPointer:
4983       llvm_unreachable("member pointer type in C");
4984     }
4985     llvm_unreachable("Should have returned before this");
4986 
4987   case Type::STK_IntegralComplex:
4988     switch (DestTy->getScalarTypeKind()) {
4989     case Type::STK_FloatingComplex:
4990       return CK_IntegralComplexToFloatingComplex;
4991     case Type::STK_IntegralComplex:
4992       return CK_IntegralComplexCast;
4993     case Type::STK_Integral: {
4994       QualType ET = SrcTy->castAs<ComplexType>()->getElementType();
4995       if (Context.hasSameType(ET, DestTy))
4996         return CK_IntegralComplexToReal;
4997       Src = ImpCastExprToType(Src.take(), ET, CK_IntegralComplexToReal);
4998       return CK_IntegralCast;
4999     }
5000     case Type::STK_Bool:
5001       return CK_IntegralComplexToBoolean;
5002     case Type::STK_Floating:
5003       Src = ImpCastExprToType(Src.take(),
5004                               SrcTy->castAs<ComplexType>()->getElementType(),
5005                               CK_IntegralComplexToReal);
5006       return CK_IntegralToFloating;
5007     case Type::STK_CPointer:
5008     case Type::STK_ObjCObjectPointer:
5009     case Type::STK_BlockPointer:
5010       llvm_unreachable("valid complex int->pointer cast?");
5011     case Type::STK_MemberPointer:
5012       llvm_unreachable("member pointer type in C");
5013     }
5014     llvm_unreachable("Should have returned before this");
5015   }
5016 
5017   llvm_unreachable("Unhandled scalar cast");
5018 }
5019 
5020 bool Sema::CheckVectorCast(SourceRange R, QualType VectorTy, QualType Ty,
5021                            CastKind &Kind) {
5022   assert(VectorTy->isVectorType() && "Not a vector type!");
5023 
5024   if (Ty->isVectorType() || Ty->isIntegerType()) {
5025     if (Context.getTypeSize(VectorTy) != Context.getTypeSize(Ty))
5026       return Diag(R.getBegin(),
5027                   Ty->isVectorType() ?
5028                   diag::err_invalid_conversion_between_vectors :
5029                   diag::err_invalid_conversion_between_vector_and_integer)
5030         << VectorTy << Ty << R;
5031   } else
5032     return Diag(R.getBegin(),
5033                 diag::err_invalid_conversion_between_vector_and_scalar)
5034       << VectorTy << Ty << R;
5035 
5036   Kind = CK_BitCast;
5037   return false;
5038 }
5039 
5040 ExprResult Sema::CheckExtVectorCast(SourceRange R, QualType DestTy,
5041                                     Expr *CastExpr, CastKind &Kind) {
5042   assert(DestTy->isExtVectorType() && "Not an extended vector type!");
5043 
5044   QualType SrcTy = CastExpr->getType();
5045 
5046   // If SrcTy is a VectorType, the total size must match to explicitly cast to
5047   // an ExtVectorType.
5048   // In OpenCL, casts between vectors of different types are not allowed.
5049   // (See OpenCL 6.2).
5050   if (SrcTy->isVectorType()) {
5051     if (Context.getTypeSize(DestTy) != Context.getTypeSize(SrcTy)
5052         || (getLangOpts().OpenCL &&
5053             (DestTy.getCanonicalType() != SrcTy.getCanonicalType()))) {
5054       Diag(R.getBegin(),diag::err_invalid_conversion_between_ext_vectors)
5055         << DestTy << SrcTy << R;
5056       return ExprError();
5057     }
5058     Kind = CK_BitCast;
5059     return Owned(CastExpr);
5060   }
5061 
5062   // All non-pointer scalars can be cast to ExtVector type.  The appropriate
5063   // conversion will take place first from scalar to elt type, and then
5064   // splat from elt type to vector.
5065   if (SrcTy->isPointerType())
5066     return Diag(R.getBegin(),
5067                 diag::err_invalid_conversion_between_vector_and_scalar)
5068       << DestTy << SrcTy << R;
5069 
5070   QualType DestElemTy = DestTy->getAs<ExtVectorType>()->getElementType();
5071   ExprResult CastExprRes = Owned(CastExpr);
5072   CastKind CK = PrepareScalarCast(CastExprRes, DestElemTy);
5073   if (CastExprRes.isInvalid())
5074     return ExprError();
5075   CastExpr = ImpCastExprToType(CastExprRes.take(), DestElemTy, CK).take();
5076 
5077   Kind = CK_VectorSplat;
5078   return Owned(CastExpr);
5079 }
5080 
5081 ExprResult
5082 Sema::ActOnCastExpr(Scope *S, SourceLocation LParenLoc,
5083                     Declarator &D, ParsedType &Ty,
5084                     SourceLocation RParenLoc, Expr *CastExpr) {
5085   assert(!D.isInvalidType() && (CastExpr != 0) &&
5086          "ActOnCastExpr(): missing type or expr");
5087 
5088   TypeSourceInfo *castTInfo = GetTypeForDeclaratorCast(D, CastExpr->getType());
5089   if (D.isInvalidType())
5090     return ExprError();
5091 
5092   if (getLangOpts().CPlusPlus) {
5093     // Check that there are no default arguments (C++ only).
5094     CheckExtraCXXDefaultArguments(D);
5095   }
5096 
5097   checkUnusedDeclAttributes(D);
5098 
5099   QualType castType = castTInfo->getType();
5100   Ty = CreateParsedType(castType, castTInfo);
5101 
5102   bool isVectorLiteral = false;
5103 
5104   // Check for an altivec or OpenCL literal,
5105   // i.e. all the elements are integer constants.
5106   ParenExpr *PE = dyn_cast<ParenExpr>(CastExpr);
5107   ParenListExpr *PLE = dyn_cast<ParenListExpr>(CastExpr);
5108   if ((getLangOpts().AltiVec || getLangOpts().OpenCL)
5109        && castType->isVectorType() && (PE || PLE)) {
5110     if (PLE && PLE->getNumExprs() == 0) {
5111       Diag(PLE->getExprLoc(), diag::err_altivec_empty_initializer);
5112       return ExprError();
5113     }
5114     if (PE || PLE->getNumExprs() == 1) {
5115       Expr *E = (PE ? PE->getSubExpr() : PLE->getExpr(0));
5116       if (!E->getType()->isVectorType())
5117         isVectorLiteral = true;
5118     }
5119     else
5120       isVectorLiteral = true;
5121   }
5122 
5123   // If this is a vector initializer, '(' type ')' '(' init, ..., init ')'
5124   // then handle it as such.
5125   if (isVectorLiteral)
5126     return BuildVectorLiteral(LParenLoc, RParenLoc, CastExpr, castTInfo);
5127 
5128   // If the Expr being casted is a ParenListExpr, handle it specially.
5129   // This is not an AltiVec-style cast, so turn the ParenListExpr into a
5130   // sequence of BinOp comma operators.
5131   if (isa<ParenListExpr>(CastExpr)) {
5132     ExprResult Result = MaybeConvertParenListExprToParenExpr(S, CastExpr);
5133     if (Result.isInvalid()) return ExprError();
5134     CastExpr = Result.take();
5135   }
5136 
5137   return BuildCStyleCastExpr(LParenLoc, castTInfo, RParenLoc, CastExpr);
5138 }
5139 
5140 ExprResult Sema::BuildVectorLiteral(SourceLocation LParenLoc,
5141                                     SourceLocation RParenLoc, Expr *E,
5142                                     TypeSourceInfo *TInfo) {
5143   assert((isa<ParenListExpr>(E) || isa<ParenExpr>(E)) &&
5144          "Expected paren or paren list expression");
5145 
5146   Expr **exprs;
5147   unsigned numExprs;
5148   Expr *subExpr;
5149   SourceLocation LiteralLParenLoc, LiteralRParenLoc;
5150   if (ParenListExpr *PE = dyn_cast<ParenListExpr>(E)) {
5151     LiteralLParenLoc = PE->getLParenLoc();
5152     LiteralRParenLoc = PE->getRParenLoc();
5153     exprs = PE->getExprs();
5154     numExprs = PE->getNumExprs();
5155   } else { // isa<ParenExpr> by assertion at function entrance
5156     LiteralLParenLoc = cast<ParenExpr>(E)->getLParen();
5157     LiteralRParenLoc = cast<ParenExpr>(E)->getRParen();
5158     subExpr = cast<ParenExpr>(E)->getSubExpr();
5159     exprs = &subExpr;
5160     numExprs = 1;
5161   }
5162 
5163   QualType Ty = TInfo->getType();
5164   assert(Ty->isVectorType() && "Expected vector type");
5165 
5166   SmallVector<Expr *, 8> initExprs;
5167   const VectorType *VTy = Ty->getAs<VectorType>();
5168   unsigned numElems = Ty->getAs<VectorType>()->getNumElements();
5169 
5170   // '(...)' form of vector initialization in AltiVec: the number of
5171   // initializers must be one or must match the size of the vector.
5172   // If a single value is specified in the initializer then it will be
5173   // replicated to all the components of the vector
5174   if (VTy->getVectorKind() == VectorType::AltiVecVector) {
5175     // The number of initializers must be one or must match the size of the
5176     // vector. If a single value is specified in the initializer then it will
5177     // be replicated to all the components of the vector
5178     if (numExprs == 1) {
5179       QualType ElemTy = Ty->getAs<VectorType>()->getElementType();
5180       ExprResult Literal = DefaultLvalueConversion(exprs[0]);
5181       if (Literal.isInvalid())
5182         return ExprError();
5183       Literal = ImpCastExprToType(Literal.take(), ElemTy,
5184                                   PrepareScalarCast(Literal, ElemTy));
5185       return BuildCStyleCastExpr(LParenLoc, TInfo, RParenLoc, Literal.take());
5186     }
5187     else if (numExprs < numElems) {
5188       Diag(E->getExprLoc(),
5189            diag::err_incorrect_number_of_vector_initializers);
5190       return ExprError();
5191     }
5192     else
5193       initExprs.append(exprs, exprs + numExprs);
5194   }
5195   else {
5196     // For OpenCL, when the number of initializers is a single value,
5197     // it will be replicated to all components of the vector.
5198     if (getLangOpts().OpenCL &&
5199         VTy->getVectorKind() == VectorType::GenericVector &&
5200         numExprs == 1) {
5201         QualType ElemTy = Ty->getAs<VectorType>()->getElementType();
5202         ExprResult Literal = DefaultLvalueConversion(exprs[0]);
5203         if (Literal.isInvalid())
5204           return ExprError();
5205         Literal = ImpCastExprToType(Literal.take(), ElemTy,
5206                                     PrepareScalarCast(Literal, ElemTy));
5207         return BuildCStyleCastExpr(LParenLoc, TInfo, RParenLoc, Literal.take());
5208     }
5209 
5210     initExprs.append(exprs, exprs + numExprs);
5211   }
5212   // FIXME: This means that pretty-printing the final AST will produce curly
5213   // braces instead of the original commas.
5214   InitListExpr *initE = new (Context) InitListExpr(Context, LiteralLParenLoc,
5215                                                    initExprs, LiteralRParenLoc);
5216   initE->setType(Ty);
5217   return BuildCompoundLiteralExpr(LParenLoc, TInfo, RParenLoc, initE);
5218 }
5219 
5220 /// This is not an AltiVec-style cast or or C++ direct-initialization, so turn
5221 /// the ParenListExpr into a sequence of comma binary operators.
5222 ExprResult
5223 Sema::MaybeConvertParenListExprToParenExpr(Scope *S, Expr *OrigExpr) {
5224   ParenListExpr *E = dyn_cast<ParenListExpr>(OrigExpr);
5225   if (!E)
5226     return Owned(OrigExpr);
5227 
5228   ExprResult Result(E->getExpr(0));
5229 
5230   for (unsigned i = 1, e = E->getNumExprs(); i != e && !Result.isInvalid(); ++i)
5231     Result = ActOnBinOp(S, E->getExprLoc(), tok::comma, Result.get(),
5232                         E->getExpr(i));
5233 
5234   if (Result.isInvalid()) return ExprError();
5235 
5236   return ActOnParenExpr(E->getLParenLoc(), E->getRParenLoc(), Result.get());
5237 }
5238 
5239 ExprResult Sema::ActOnParenListExpr(SourceLocation L,
5240                                     SourceLocation R,
5241                                     MultiExprArg Val) {
5242   Expr *expr = new (Context) ParenListExpr(Context, L, Val, R);
5243   return Owned(expr);
5244 }
5245 
5246 /// \brief Emit a specialized diagnostic when one expression is a null pointer
5247 /// constant and the other is not a pointer.  Returns true if a diagnostic is
5248 /// emitted.
5249 bool Sema::DiagnoseConditionalForNull(Expr *LHSExpr, Expr *RHSExpr,
5250                                       SourceLocation QuestionLoc) {
5251   Expr *NullExpr = LHSExpr;
5252   Expr *NonPointerExpr = RHSExpr;
5253   Expr::NullPointerConstantKind NullKind =
5254       NullExpr->isNullPointerConstant(Context,
5255                                       Expr::NPC_ValueDependentIsNotNull);
5256 
5257   if (NullKind == Expr::NPCK_NotNull) {
5258     NullExpr = RHSExpr;
5259     NonPointerExpr = LHSExpr;
5260     NullKind =
5261         NullExpr->isNullPointerConstant(Context,
5262                                         Expr::NPC_ValueDependentIsNotNull);
5263   }
5264 
5265   if (NullKind == Expr::NPCK_NotNull)
5266     return false;
5267 
5268   if (NullKind == Expr::NPCK_ZeroExpression)
5269     return false;
5270 
5271   if (NullKind == Expr::NPCK_ZeroLiteral) {
5272     // In this case, check to make sure that we got here from a "NULL"
5273     // string in the source code.
5274     NullExpr = NullExpr->IgnoreParenImpCasts();
5275     SourceLocation loc = NullExpr->getExprLoc();
5276     if (!findMacroSpelling(loc, "NULL"))
5277       return false;
5278   }
5279 
5280   int DiagType = (NullKind == Expr::NPCK_CXX11_nullptr);
5281   Diag(QuestionLoc, diag::err_typecheck_cond_incompatible_operands_null)
5282       << NonPointerExpr->getType() << DiagType
5283       << NonPointerExpr->getSourceRange();
5284   return true;
5285 }
5286 
5287 /// \brief Return false if the condition expression is valid, true otherwise.
5288 static bool checkCondition(Sema &S, Expr *Cond) {
5289   QualType CondTy = Cond->getType();
5290 
5291   // C99 6.5.15p2
5292   if (CondTy->isScalarType()) return false;
5293 
5294   // OpenCL v1.1 s6.3.i says the condition is allowed to be a vector or scalar.
5295   if (S.getLangOpts().OpenCL && CondTy->isVectorType())
5296     return false;
5297 
5298   // Emit the proper error message.
5299   S.Diag(Cond->getLocStart(), S.getLangOpts().OpenCL ?
5300                               diag::err_typecheck_cond_expect_scalar :
5301                               diag::err_typecheck_cond_expect_scalar_or_vector)
5302     << CondTy;
5303   return true;
5304 }
5305 
5306 /// \brief Return false if the two expressions can be converted to a vector,
5307 /// true otherwise
5308 static bool checkConditionalConvertScalarsToVectors(Sema &S, ExprResult &LHS,
5309                                                     ExprResult &RHS,
5310                                                     QualType CondTy) {
5311   // Both operands should be of scalar type.
5312   if (!LHS.get()->getType()->isScalarType()) {
5313     S.Diag(LHS.get()->getLocStart(), diag::err_typecheck_cond_expect_scalar)
5314       << CondTy;
5315     return true;
5316   }
5317   if (!RHS.get()->getType()->isScalarType()) {
5318     S.Diag(RHS.get()->getLocStart(), diag::err_typecheck_cond_expect_scalar)
5319       << CondTy;
5320     return true;
5321   }
5322 
5323   // Implicity convert these scalars to the type of the condition.
5324   LHS = S.ImpCastExprToType(LHS.take(), CondTy, CK_IntegralCast);
5325   RHS = S.ImpCastExprToType(RHS.take(), CondTy, CK_IntegralCast);
5326   return false;
5327 }
5328 
5329 /// \brief Handle when one or both operands are void type.
5330 static QualType checkConditionalVoidType(Sema &S, ExprResult &LHS,
5331                                          ExprResult &RHS) {
5332     Expr *LHSExpr = LHS.get();
5333     Expr *RHSExpr = RHS.get();
5334 
5335     if (!LHSExpr->getType()->isVoidType())
5336       S.Diag(RHSExpr->getLocStart(), diag::ext_typecheck_cond_one_void)
5337         << RHSExpr->getSourceRange();
5338     if (!RHSExpr->getType()->isVoidType())
5339       S.Diag(LHSExpr->getLocStart(), diag::ext_typecheck_cond_one_void)
5340         << LHSExpr->getSourceRange();
5341     LHS = S.ImpCastExprToType(LHS.take(), S.Context.VoidTy, CK_ToVoid);
5342     RHS = S.ImpCastExprToType(RHS.take(), S.Context.VoidTy, CK_ToVoid);
5343     return S.Context.VoidTy;
5344 }
5345 
5346 /// \brief Return false if the NullExpr can be promoted to PointerTy,
5347 /// true otherwise.
5348 static bool checkConditionalNullPointer(Sema &S, ExprResult &NullExpr,
5349                                         QualType PointerTy) {
5350   if ((!PointerTy->isAnyPointerType() && !PointerTy->isBlockPointerType()) ||
5351       !NullExpr.get()->isNullPointerConstant(S.Context,
5352                                             Expr::NPC_ValueDependentIsNull))
5353     return true;
5354 
5355   NullExpr = S.ImpCastExprToType(NullExpr.take(), PointerTy, CK_NullToPointer);
5356   return false;
5357 }
5358 
5359 /// \brief Checks compatibility between two pointers and return the resulting
5360 /// type.
5361 static QualType checkConditionalPointerCompatibility(Sema &S, ExprResult &LHS,
5362                                                      ExprResult &RHS,
5363                                                      SourceLocation Loc) {
5364   QualType LHSTy = LHS.get()->getType();
5365   QualType RHSTy = RHS.get()->getType();
5366 
5367   if (S.Context.hasSameType(LHSTy, RHSTy)) {
5368     // Two identical pointers types are always compatible.
5369     return LHSTy;
5370   }
5371 
5372   QualType lhptee, rhptee;
5373 
5374   // Get the pointee types.
5375   bool IsBlockPointer = false;
5376   if (const BlockPointerType *LHSBTy = LHSTy->getAs<BlockPointerType>()) {
5377     lhptee = LHSBTy->getPointeeType();
5378     rhptee = RHSTy->castAs<BlockPointerType>()->getPointeeType();
5379     IsBlockPointer = true;
5380   } else {
5381     lhptee = LHSTy->castAs<PointerType>()->getPointeeType();
5382     rhptee = RHSTy->castAs<PointerType>()->getPointeeType();
5383   }
5384 
5385   // C99 6.5.15p6: If both operands are pointers to compatible types or to
5386   // differently qualified versions of compatible types, the result type is
5387   // a pointer to an appropriately qualified version of the composite
5388   // type.
5389 
5390   // Only CVR-qualifiers exist in the standard, and the differently-qualified
5391   // clause doesn't make sense for our extensions. E.g. address space 2 should
5392   // be incompatible with address space 3: they may live on different devices or
5393   // anything.
5394   Qualifiers lhQual = lhptee.getQualifiers();
5395   Qualifiers rhQual = rhptee.getQualifiers();
5396 
5397   unsigned MergedCVRQual = lhQual.getCVRQualifiers() | rhQual.getCVRQualifiers();
5398   lhQual.removeCVRQualifiers();
5399   rhQual.removeCVRQualifiers();
5400 
5401   lhptee = S.Context.getQualifiedType(lhptee.getUnqualifiedType(), lhQual);
5402   rhptee = S.Context.getQualifiedType(rhptee.getUnqualifiedType(), rhQual);
5403 
5404   QualType CompositeTy = S.Context.mergeTypes(lhptee, rhptee);
5405 
5406   if (CompositeTy.isNull()) {
5407     S.Diag(Loc, diag::warn_typecheck_cond_incompatible_pointers)
5408       << LHSTy << RHSTy << LHS.get()->getSourceRange()
5409       << RHS.get()->getSourceRange();
5410     // In this situation, we assume void* type. No especially good
5411     // reason, but this is what gcc does, and we do have to pick
5412     // to get a consistent AST.
5413     QualType incompatTy = S.Context.getPointerType(S.Context.VoidTy);
5414     LHS = S.ImpCastExprToType(LHS.take(), incompatTy, CK_BitCast);
5415     RHS = S.ImpCastExprToType(RHS.take(), incompatTy, CK_BitCast);
5416     return incompatTy;
5417   }
5418 
5419   // The pointer types are compatible.
5420   QualType ResultTy = CompositeTy.withCVRQualifiers(MergedCVRQual);
5421   if (IsBlockPointer)
5422     ResultTy = S.Context.getBlockPointerType(ResultTy);
5423   else
5424     ResultTy = S.Context.getPointerType(ResultTy);
5425 
5426   LHS = S.ImpCastExprToType(LHS.take(), ResultTy, CK_BitCast);
5427   RHS = S.ImpCastExprToType(RHS.take(), ResultTy, CK_BitCast);
5428   return ResultTy;
5429 }
5430 
5431 /// \brief Return the resulting type when the operands are both block pointers.
5432 static QualType checkConditionalBlockPointerCompatibility(Sema &S,
5433                                                           ExprResult &LHS,
5434                                                           ExprResult &RHS,
5435                                                           SourceLocation Loc) {
5436   QualType LHSTy = LHS.get()->getType();
5437   QualType RHSTy = RHS.get()->getType();
5438 
5439   if (!LHSTy->isBlockPointerType() || !RHSTy->isBlockPointerType()) {
5440     if (LHSTy->isVoidPointerType() || RHSTy->isVoidPointerType()) {
5441       QualType destType = S.Context.getPointerType(S.Context.VoidTy);
5442       LHS = S.ImpCastExprToType(LHS.take(), destType, CK_BitCast);
5443       RHS = S.ImpCastExprToType(RHS.take(), destType, CK_BitCast);
5444       return destType;
5445     }
5446     S.Diag(Loc, diag::err_typecheck_cond_incompatible_operands)
5447       << LHSTy << RHSTy << LHS.get()->getSourceRange()
5448       << RHS.get()->getSourceRange();
5449     return QualType();
5450   }
5451 
5452   // We have 2 block pointer types.
5453   return checkConditionalPointerCompatibility(S, LHS, RHS, Loc);
5454 }
5455 
5456 /// \brief Return the resulting type when the operands are both pointers.
5457 static QualType
5458 checkConditionalObjectPointersCompatibility(Sema &S, ExprResult &LHS,
5459                                             ExprResult &RHS,
5460                                             SourceLocation Loc) {
5461   // get the pointer types
5462   QualType LHSTy = LHS.get()->getType();
5463   QualType RHSTy = RHS.get()->getType();
5464 
5465   // get the "pointed to" types
5466   QualType lhptee = LHSTy->getAs<PointerType>()->getPointeeType();
5467   QualType rhptee = RHSTy->getAs<PointerType>()->getPointeeType();
5468 
5469   // ignore qualifiers on void (C99 6.5.15p3, clause 6)
5470   if (lhptee->isVoidType() && rhptee->isIncompleteOrObjectType()) {
5471     // Figure out necessary qualifiers (C99 6.5.15p6)
5472     QualType destPointee
5473       = S.Context.getQualifiedType(lhptee, rhptee.getQualifiers());
5474     QualType destType = S.Context.getPointerType(destPointee);
5475     // Add qualifiers if necessary.
5476     LHS = S.ImpCastExprToType(LHS.take(), destType, CK_NoOp);
5477     // Promote to void*.
5478     RHS = S.ImpCastExprToType(RHS.take(), destType, CK_BitCast);
5479     return destType;
5480   }
5481   if (rhptee->isVoidType() && lhptee->isIncompleteOrObjectType()) {
5482     QualType destPointee
5483       = S.Context.getQualifiedType(rhptee, lhptee.getQualifiers());
5484     QualType destType = S.Context.getPointerType(destPointee);
5485     // Add qualifiers if necessary.
5486     RHS = S.ImpCastExprToType(RHS.take(), destType, CK_NoOp);
5487     // Promote to void*.
5488     LHS = S.ImpCastExprToType(LHS.take(), destType, CK_BitCast);
5489     return destType;
5490   }
5491 
5492   return checkConditionalPointerCompatibility(S, LHS, RHS, Loc);
5493 }
5494 
5495 /// \brief Return false if the first expression is not an integer and the second
5496 /// expression is not a pointer, true otherwise.
5497 static bool checkPointerIntegerMismatch(Sema &S, ExprResult &Int,
5498                                         Expr* PointerExpr, SourceLocation Loc,
5499                                         bool IsIntFirstExpr) {
5500   if (!PointerExpr->getType()->isPointerType() ||
5501       !Int.get()->getType()->isIntegerType())
5502     return false;
5503 
5504   Expr *Expr1 = IsIntFirstExpr ? Int.get() : PointerExpr;
5505   Expr *Expr2 = IsIntFirstExpr ? PointerExpr : Int.get();
5506 
5507   S.Diag(Loc, diag::warn_typecheck_cond_pointer_integer_mismatch)
5508     << Expr1->getType() << Expr2->getType()
5509     << Expr1->getSourceRange() << Expr2->getSourceRange();
5510   Int = S.ImpCastExprToType(Int.take(), PointerExpr->getType(),
5511                             CK_IntegralToPointer);
5512   return true;
5513 }
5514 
5515 /// Note that LHS is not null here, even if this is the gnu "x ?: y" extension.
5516 /// In that case, LHS = cond.
5517 /// C99 6.5.15
5518 QualType Sema::CheckConditionalOperands(ExprResult &Cond, ExprResult &LHS,
5519                                         ExprResult &RHS, ExprValueKind &VK,
5520                                         ExprObjectKind &OK,
5521                                         SourceLocation QuestionLoc) {
5522 
5523   ExprResult LHSResult = CheckPlaceholderExpr(LHS.get());
5524   if (!LHSResult.isUsable()) return QualType();
5525   LHS = LHSResult;
5526 
5527   ExprResult RHSResult = CheckPlaceholderExpr(RHS.get());
5528   if (!RHSResult.isUsable()) return QualType();
5529   RHS = RHSResult;
5530 
5531   // C++ is sufficiently different to merit its own checker.
5532   if (getLangOpts().CPlusPlus)
5533     return CXXCheckConditionalOperands(Cond, LHS, RHS, VK, OK, QuestionLoc);
5534 
5535   VK = VK_RValue;
5536   OK = OK_Ordinary;
5537 
5538   // First, check the condition.
5539   Cond = UsualUnaryConversions(Cond.take());
5540   if (Cond.isInvalid())
5541     return QualType();
5542   if (checkCondition(*this, Cond.get()))
5543     return QualType();
5544 
5545   // Now check the two expressions.
5546   if (LHS.get()->getType()->isVectorType() ||
5547       RHS.get()->getType()->isVectorType())
5548     return CheckVectorOperands(LHS, RHS, QuestionLoc, /*isCompAssign*/false);
5549 
5550   UsualArithmeticConversions(LHS, RHS);
5551   if (LHS.isInvalid() || RHS.isInvalid())
5552     return QualType();
5553 
5554   QualType CondTy = Cond.get()->getType();
5555   QualType LHSTy = LHS.get()->getType();
5556   QualType RHSTy = RHS.get()->getType();
5557 
5558   // If the condition is a vector, and both operands are scalar,
5559   // attempt to implicity convert them to the vector type to act like the
5560   // built in select. (OpenCL v1.1 s6.3.i)
5561   if (getLangOpts().OpenCL && CondTy->isVectorType())
5562     if (checkConditionalConvertScalarsToVectors(*this, LHS, RHS, CondTy))
5563       return QualType();
5564 
5565   // If both operands have arithmetic type, do the usual arithmetic conversions
5566   // to find a common type: C99 6.5.15p3,5.
5567   if (LHSTy->isArithmeticType() && RHSTy->isArithmeticType())
5568     return LHS.get()->getType();
5569 
5570   // If both operands are the same structure or union type, the result is that
5571   // type.
5572   if (const RecordType *LHSRT = LHSTy->getAs<RecordType>()) {    // C99 6.5.15p3
5573     if (const RecordType *RHSRT = RHSTy->getAs<RecordType>())
5574       if (LHSRT->getDecl() == RHSRT->getDecl())
5575         // "If both the operands have structure or union type, the result has
5576         // that type."  This implies that CV qualifiers are dropped.
5577         return LHSTy.getUnqualifiedType();
5578     // FIXME: Type of conditional expression must be complete in C mode.
5579   }
5580 
5581   // C99 6.5.15p5: "If both operands have void type, the result has void type."
5582   // The following || allows only one side to be void (a GCC-ism).
5583   if (LHSTy->isVoidType() || RHSTy->isVoidType()) {
5584     return checkConditionalVoidType(*this, LHS, RHS);
5585   }
5586 
5587   // C99 6.5.15p6 - "if one operand is a null pointer constant, the result has
5588   // the type of the other operand."
5589   if (!checkConditionalNullPointer(*this, RHS, LHSTy)) return LHSTy;
5590   if (!checkConditionalNullPointer(*this, LHS, RHSTy)) return RHSTy;
5591 
5592   // All objective-c pointer type analysis is done here.
5593   QualType compositeType = FindCompositeObjCPointerType(LHS, RHS,
5594                                                         QuestionLoc);
5595   if (LHS.isInvalid() || RHS.isInvalid())
5596     return QualType();
5597   if (!compositeType.isNull())
5598     return compositeType;
5599 
5600 
5601   // Handle block pointer types.
5602   if (LHSTy->isBlockPointerType() || RHSTy->isBlockPointerType())
5603     return checkConditionalBlockPointerCompatibility(*this, LHS, RHS,
5604                                                      QuestionLoc);
5605 
5606   // Check constraints for C object pointers types (C99 6.5.15p3,6).
5607   if (LHSTy->isPointerType() && RHSTy->isPointerType())
5608     return checkConditionalObjectPointersCompatibility(*this, LHS, RHS,
5609                                                        QuestionLoc);
5610 
5611   // GCC compatibility: soften pointer/integer mismatch.  Note that
5612   // null pointers have been filtered out by this point.
5613   if (checkPointerIntegerMismatch(*this, LHS, RHS.get(), QuestionLoc,
5614       /*isIntFirstExpr=*/true))
5615     return RHSTy;
5616   if (checkPointerIntegerMismatch(*this, RHS, LHS.get(), QuestionLoc,
5617       /*isIntFirstExpr=*/false))
5618     return LHSTy;
5619 
5620   // Emit a better diagnostic if one of the expressions is a null pointer
5621   // constant and the other is not a pointer type. In this case, the user most
5622   // likely forgot to take the address of the other expression.
5623   if (DiagnoseConditionalForNull(LHS.get(), RHS.get(), QuestionLoc))
5624     return QualType();
5625 
5626   // Otherwise, the operands are not compatible.
5627   Diag(QuestionLoc, diag::err_typecheck_cond_incompatible_operands)
5628     << LHSTy << RHSTy << LHS.get()->getSourceRange()
5629     << RHS.get()->getSourceRange();
5630   return QualType();
5631 }
5632 
5633 /// FindCompositeObjCPointerType - Helper method to find composite type of
5634 /// two objective-c pointer types of the two input expressions.
5635 QualType Sema::FindCompositeObjCPointerType(ExprResult &LHS, ExprResult &RHS,
5636                                             SourceLocation QuestionLoc) {
5637   QualType LHSTy = LHS.get()->getType();
5638   QualType RHSTy = RHS.get()->getType();
5639 
5640   // Handle things like Class and struct objc_class*.  Here we case the result
5641   // to the pseudo-builtin, because that will be implicitly cast back to the
5642   // redefinition type if an attempt is made to access its fields.
5643   if (LHSTy->isObjCClassType() &&
5644       (Context.hasSameType(RHSTy, Context.getObjCClassRedefinitionType()))) {
5645     RHS = ImpCastExprToType(RHS.take(), LHSTy, CK_CPointerToObjCPointerCast);
5646     return LHSTy;
5647   }
5648   if (RHSTy->isObjCClassType() &&
5649       (Context.hasSameType(LHSTy, Context.getObjCClassRedefinitionType()))) {
5650     LHS = ImpCastExprToType(LHS.take(), RHSTy, CK_CPointerToObjCPointerCast);
5651     return RHSTy;
5652   }
5653   // And the same for struct objc_object* / id
5654   if (LHSTy->isObjCIdType() &&
5655       (Context.hasSameType(RHSTy, Context.getObjCIdRedefinitionType()))) {
5656     RHS = ImpCastExprToType(RHS.take(), LHSTy, CK_CPointerToObjCPointerCast);
5657     return LHSTy;
5658   }
5659   if (RHSTy->isObjCIdType() &&
5660       (Context.hasSameType(LHSTy, Context.getObjCIdRedefinitionType()))) {
5661     LHS = ImpCastExprToType(LHS.take(), RHSTy, CK_CPointerToObjCPointerCast);
5662     return RHSTy;
5663   }
5664   // And the same for struct objc_selector* / SEL
5665   if (Context.isObjCSelType(LHSTy) &&
5666       (Context.hasSameType(RHSTy, Context.getObjCSelRedefinitionType()))) {
5667     RHS = ImpCastExprToType(RHS.take(), LHSTy, CK_BitCast);
5668     return LHSTy;
5669   }
5670   if (Context.isObjCSelType(RHSTy) &&
5671       (Context.hasSameType(LHSTy, Context.getObjCSelRedefinitionType()))) {
5672     LHS = ImpCastExprToType(LHS.take(), RHSTy, CK_BitCast);
5673     return RHSTy;
5674   }
5675   // Check constraints for Objective-C object pointers types.
5676   if (LHSTy->isObjCObjectPointerType() && RHSTy->isObjCObjectPointerType()) {
5677 
5678     if (Context.getCanonicalType(LHSTy) == Context.getCanonicalType(RHSTy)) {
5679       // Two identical object pointer types are always compatible.
5680       return LHSTy;
5681     }
5682     const ObjCObjectPointerType *LHSOPT = LHSTy->castAs<ObjCObjectPointerType>();
5683     const ObjCObjectPointerType *RHSOPT = RHSTy->castAs<ObjCObjectPointerType>();
5684     QualType compositeType = LHSTy;
5685 
5686     // If both operands are interfaces and either operand can be
5687     // assigned to the other, use that type as the composite
5688     // type. This allows
5689     //   xxx ? (A*) a : (B*) b
5690     // where B is a subclass of A.
5691     //
5692     // Additionally, as for assignment, if either type is 'id'
5693     // allow silent coercion. Finally, if the types are
5694     // incompatible then make sure to use 'id' as the composite
5695     // type so the result is acceptable for sending messages to.
5696 
5697     // FIXME: Consider unifying with 'areComparableObjCPointerTypes'.
5698     // It could return the composite type.
5699     if (Context.canAssignObjCInterfaces(LHSOPT, RHSOPT)) {
5700       compositeType = RHSOPT->isObjCBuiltinType() ? RHSTy : LHSTy;
5701     } else if (Context.canAssignObjCInterfaces(RHSOPT, LHSOPT)) {
5702       compositeType = LHSOPT->isObjCBuiltinType() ? LHSTy : RHSTy;
5703     } else if ((LHSTy->isObjCQualifiedIdType() ||
5704                 RHSTy->isObjCQualifiedIdType()) &&
5705                Context.ObjCQualifiedIdTypesAreCompatible(LHSTy, RHSTy, true)) {
5706       // Need to handle "id<xx>" explicitly.
5707       // GCC allows qualified id and any Objective-C type to devolve to
5708       // id. Currently localizing to here until clear this should be
5709       // part of ObjCQualifiedIdTypesAreCompatible.
5710       compositeType = Context.getObjCIdType();
5711     } else if (LHSTy->isObjCIdType() || RHSTy->isObjCIdType()) {
5712       compositeType = Context.getObjCIdType();
5713     } else if (!(compositeType =
5714                  Context.areCommonBaseCompatible(LHSOPT, RHSOPT)).isNull())
5715       ;
5716     else {
5717       Diag(QuestionLoc, diag::ext_typecheck_cond_incompatible_operands)
5718       << LHSTy << RHSTy
5719       << LHS.get()->getSourceRange() << RHS.get()->getSourceRange();
5720       QualType incompatTy = Context.getObjCIdType();
5721       LHS = ImpCastExprToType(LHS.take(), incompatTy, CK_BitCast);
5722       RHS = ImpCastExprToType(RHS.take(), incompatTy, CK_BitCast);
5723       return incompatTy;
5724     }
5725     // The object pointer types are compatible.
5726     LHS = ImpCastExprToType(LHS.take(), compositeType, CK_BitCast);
5727     RHS = ImpCastExprToType(RHS.take(), compositeType, CK_BitCast);
5728     return compositeType;
5729   }
5730   // Check Objective-C object pointer types and 'void *'
5731   if (LHSTy->isVoidPointerType() && RHSTy->isObjCObjectPointerType()) {
5732     if (getLangOpts().ObjCAutoRefCount) {
5733       // ARC forbids the implicit conversion of object pointers to 'void *',
5734       // so these types are not compatible.
5735       Diag(QuestionLoc, diag::err_cond_voidptr_arc) << LHSTy << RHSTy
5736           << LHS.get()->getSourceRange() << RHS.get()->getSourceRange();
5737       LHS = RHS = true;
5738       return QualType();
5739     }
5740     QualType lhptee = LHSTy->getAs<PointerType>()->getPointeeType();
5741     QualType rhptee = RHSTy->getAs<ObjCObjectPointerType>()->getPointeeType();
5742     QualType destPointee
5743     = Context.getQualifiedType(lhptee, rhptee.getQualifiers());
5744     QualType destType = Context.getPointerType(destPointee);
5745     // Add qualifiers if necessary.
5746     LHS = ImpCastExprToType(LHS.take(), destType, CK_NoOp);
5747     // Promote to void*.
5748     RHS = ImpCastExprToType(RHS.take(), destType, CK_BitCast);
5749     return destType;
5750   }
5751   if (LHSTy->isObjCObjectPointerType() && RHSTy->isVoidPointerType()) {
5752     if (getLangOpts().ObjCAutoRefCount) {
5753       // ARC forbids the implicit conversion of object pointers to 'void *',
5754       // so these types are not compatible.
5755       Diag(QuestionLoc, diag::err_cond_voidptr_arc) << LHSTy << RHSTy
5756           << LHS.get()->getSourceRange() << RHS.get()->getSourceRange();
5757       LHS = RHS = true;
5758       return QualType();
5759     }
5760     QualType lhptee = LHSTy->getAs<ObjCObjectPointerType>()->getPointeeType();
5761     QualType rhptee = RHSTy->getAs<PointerType>()->getPointeeType();
5762     QualType destPointee
5763     = Context.getQualifiedType(rhptee, lhptee.getQualifiers());
5764     QualType destType = Context.getPointerType(destPointee);
5765     // Add qualifiers if necessary.
5766     RHS = ImpCastExprToType(RHS.take(), destType, CK_NoOp);
5767     // Promote to void*.
5768     LHS = ImpCastExprToType(LHS.take(), destType, CK_BitCast);
5769     return destType;
5770   }
5771   return QualType();
5772 }
5773 
5774 /// SuggestParentheses - Emit a note with a fixit hint that wraps
5775 /// ParenRange in parentheses.
5776 static void SuggestParentheses(Sema &Self, SourceLocation Loc,
5777                                const PartialDiagnostic &Note,
5778                                SourceRange ParenRange) {
5779   SourceLocation EndLoc = Self.PP.getLocForEndOfToken(ParenRange.getEnd());
5780   if (ParenRange.getBegin().isFileID() && ParenRange.getEnd().isFileID() &&
5781       EndLoc.isValid()) {
5782     Self.Diag(Loc, Note)
5783       << FixItHint::CreateInsertion(ParenRange.getBegin(), "(")
5784       << FixItHint::CreateInsertion(EndLoc, ")");
5785   } else {
5786     // We can't display the parentheses, so just show the bare note.
5787     Self.Diag(Loc, Note) << ParenRange;
5788   }
5789 }
5790 
5791 static bool IsArithmeticOp(BinaryOperatorKind Opc) {
5792   return Opc >= BO_Mul && Opc <= BO_Shr;
5793 }
5794 
5795 /// IsArithmeticBinaryExpr - Returns true if E is an arithmetic binary
5796 /// expression, either using a built-in or overloaded operator,
5797 /// and sets *OpCode to the opcode and *RHSExprs to the right-hand side
5798 /// expression.
5799 static bool IsArithmeticBinaryExpr(Expr *E, BinaryOperatorKind *Opcode,
5800                                    Expr **RHSExprs) {
5801   // Don't strip parenthesis: we should not warn if E is in parenthesis.
5802   E = E->IgnoreImpCasts();
5803   E = E->IgnoreConversionOperator();
5804   E = E->IgnoreImpCasts();
5805 
5806   // Built-in binary operator.
5807   if (BinaryOperator *OP = dyn_cast<BinaryOperator>(E)) {
5808     if (IsArithmeticOp(OP->getOpcode())) {
5809       *Opcode = OP->getOpcode();
5810       *RHSExprs = OP->getRHS();
5811       return true;
5812     }
5813   }
5814 
5815   // Overloaded operator.
5816   if (CXXOperatorCallExpr *Call = dyn_cast<CXXOperatorCallExpr>(E)) {
5817     if (Call->getNumArgs() != 2)
5818       return false;
5819 
5820     // Make sure this is really a binary operator that is safe to pass into
5821     // BinaryOperator::getOverloadedOpcode(), e.g. it's not a subscript op.
5822     OverloadedOperatorKind OO = Call->getOperator();
5823     if (OO < OO_Plus || OO > OO_Arrow ||
5824         OO == OO_PlusPlus || OO == OO_MinusMinus)
5825       return false;
5826 
5827     BinaryOperatorKind OpKind = BinaryOperator::getOverloadedOpcode(OO);
5828     if (IsArithmeticOp(OpKind)) {
5829       *Opcode = OpKind;
5830       *RHSExprs = Call->getArg(1);
5831       return true;
5832     }
5833   }
5834 
5835   return false;
5836 }
5837 
5838 static bool IsLogicOp(BinaryOperatorKind Opc) {
5839   return (Opc >= BO_LT && Opc <= BO_NE) || (Opc >= BO_LAnd && Opc <= BO_LOr);
5840 }
5841 
5842 /// ExprLooksBoolean - Returns true if E looks boolean, i.e. it has boolean type
5843 /// or is a logical expression such as (x==y) which has int type, but is
5844 /// commonly interpreted as boolean.
5845 static bool ExprLooksBoolean(Expr *E) {
5846   E = E->IgnoreParenImpCasts();
5847 
5848   if (E->getType()->isBooleanType())
5849     return true;
5850   if (BinaryOperator *OP = dyn_cast<BinaryOperator>(E))
5851     return IsLogicOp(OP->getOpcode());
5852   if (UnaryOperator *OP = dyn_cast<UnaryOperator>(E))
5853     return OP->getOpcode() == UO_LNot;
5854 
5855   return false;
5856 }
5857 
5858 /// DiagnoseConditionalPrecedence - Emit a warning when a conditional operator
5859 /// and binary operator are mixed in a way that suggests the programmer assumed
5860 /// the conditional operator has higher precedence, for example:
5861 /// "int x = a + someBinaryCondition ? 1 : 2".
5862 static void DiagnoseConditionalPrecedence(Sema &Self,
5863                                           SourceLocation OpLoc,
5864                                           Expr *Condition,
5865                                           Expr *LHSExpr,
5866                                           Expr *RHSExpr) {
5867   BinaryOperatorKind CondOpcode;
5868   Expr *CondRHS;
5869 
5870   if (!IsArithmeticBinaryExpr(Condition, &CondOpcode, &CondRHS))
5871     return;
5872   if (!ExprLooksBoolean(CondRHS))
5873     return;
5874 
5875   // The condition is an arithmetic binary expression, with a right-
5876   // hand side that looks boolean, so warn.
5877 
5878   Self.Diag(OpLoc, diag::warn_precedence_conditional)
5879       << Condition->getSourceRange()
5880       << BinaryOperator::getOpcodeStr(CondOpcode);
5881 
5882   SuggestParentheses(Self, OpLoc,
5883     Self.PDiag(diag::note_precedence_silence)
5884       << BinaryOperator::getOpcodeStr(CondOpcode),
5885     SourceRange(Condition->getLocStart(), Condition->getLocEnd()));
5886 
5887   SuggestParentheses(Self, OpLoc,
5888     Self.PDiag(diag::note_precedence_conditional_first),
5889     SourceRange(CondRHS->getLocStart(), RHSExpr->getLocEnd()));
5890 }
5891 
5892 /// ActOnConditionalOp - Parse a ?: operation.  Note that 'LHS' may be null
5893 /// in the case of a the GNU conditional expr extension.
5894 ExprResult Sema::ActOnConditionalOp(SourceLocation QuestionLoc,
5895                                     SourceLocation ColonLoc,
5896                                     Expr *CondExpr, Expr *LHSExpr,
5897                                     Expr *RHSExpr) {
5898   // If this is the gnu "x ?: y" extension, analyze the types as though the LHS
5899   // was the condition.
5900   OpaqueValueExpr *opaqueValue = 0;
5901   Expr *commonExpr = 0;
5902   if (LHSExpr == 0) {
5903     commonExpr = CondExpr;
5904     // Lower out placeholder types first.  This is important so that we don't
5905     // try to capture a placeholder. This happens in few cases in C++; such
5906     // as Objective-C++'s dictionary subscripting syntax.
5907     if (commonExpr->hasPlaceholderType()) {
5908       ExprResult result = CheckPlaceholderExpr(commonExpr);
5909       if (!result.isUsable()) return ExprError();
5910       commonExpr = result.take();
5911     }
5912     // We usually want to apply unary conversions *before* saving, except
5913     // in the special case of a C++ l-value conditional.
5914     if (!(getLangOpts().CPlusPlus
5915           && !commonExpr->isTypeDependent()
5916           && commonExpr->getValueKind() == RHSExpr->getValueKind()
5917           && commonExpr->isGLValue()
5918           && commonExpr->isOrdinaryOrBitFieldObject()
5919           && RHSExpr->isOrdinaryOrBitFieldObject()
5920           && Context.hasSameType(commonExpr->getType(), RHSExpr->getType()))) {
5921       ExprResult commonRes = UsualUnaryConversions(commonExpr);
5922       if (commonRes.isInvalid())
5923         return ExprError();
5924       commonExpr = commonRes.take();
5925     }
5926 
5927     opaqueValue = new (Context) OpaqueValueExpr(commonExpr->getExprLoc(),
5928                                                 commonExpr->getType(),
5929                                                 commonExpr->getValueKind(),
5930                                                 commonExpr->getObjectKind(),
5931                                                 commonExpr);
5932     LHSExpr = CondExpr = opaqueValue;
5933   }
5934 
5935   ExprValueKind VK = VK_RValue;
5936   ExprObjectKind OK = OK_Ordinary;
5937   ExprResult Cond = Owned(CondExpr), LHS = Owned(LHSExpr), RHS = Owned(RHSExpr);
5938   QualType result = CheckConditionalOperands(Cond, LHS, RHS,
5939                                              VK, OK, QuestionLoc);
5940   if (result.isNull() || Cond.isInvalid() || LHS.isInvalid() ||
5941       RHS.isInvalid())
5942     return ExprError();
5943 
5944   DiagnoseConditionalPrecedence(*this, QuestionLoc, Cond.get(), LHS.get(),
5945                                 RHS.get());
5946 
5947   if (!commonExpr)
5948     return Owned(new (Context) ConditionalOperator(Cond.take(), QuestionLoc,
5949                                                    LHS.take(), ColonLoc,
5950                                                    RHS.take(), result, VK, OK));
5951 
5952   return Owned(new (Context)
5953     BinaryConditionalOperator(commonExpr, opaqueValue, Cond.take(), LHS.take(),
5954                               RHS.take(), QuestionLoc, ColonLoc, result, VK,
5955                               OK));
5956 }
5957 
5958 // checkPointerTypesForAssignment - This is a very tricky routine (despite
5959 // being closely modeled after the C99 spec:-). The odd characteristic of this
5960 // routine is it effectively iqnores the qualifiers on the top level pointee.
5961 // This circumvents the usual type rules specified in 6.2.7p1 & 6.7.5.[1-3].
5962 // FIXME: add a couple examples in this comment.
5963 static Sema::AssignConvertType
5964 checkPointerTypesForAssignment(Sema &S, QualType LHSType, QualType RHSType) {
5965   assert(LHSType.isCanonical() && "LHS not canonicalized!");
5966   assert(RHSType.isCanonical() && "RHS not canonicalized!");
5967 
5968   // get the "pointed to" type (ignoring qualifiers at the top level)
5969   const Type *lhptee, *rhptee;
5970   Qualifiers lhq, rhq;
5971   llvm::tie(lhptee, lhq) = cast<PointerType>(LHSType)->getPointeeType().split();
5972   llvm::tie(rhptee, rhq) = cast<PointerType>(RHSType)->getPointeeType().split();
5973 
5974   Sema::AssignConvertType ConvTy = Sema::Compatible;
5975 
5976   // C99 6.5.16.1p1: This following citation is common to constraints
5977   // 3 & 4 (below). ...and the type *pointed to* by the left has all the
5978   // qualifiers of the type *pointed to* by the right;
5979   Qualifiers lq;
5980 
5981   // As a special case, 'non-__weak A *' -> 'non-__weak const *' is okay.
5982   if (lhq.getObjCLifetime() != rhq.getObjCLifetime() &&
5983       lhq.compatiblyIncludesObjCLifetime(rhq)) {
5984     // Ignore lifetime for further calculation.
5985     lhq.removeObjCLifetime();
5986     rhq.removeObjCLifetime();
5987   }
5988 
5989   if (!lhq.compatiblyIncludes(rhq)) {
5990     // Treat address-space mismatches as fatal.  TODO: address subspaces
5991     if (lhq.getAddressSpace() != rhq.getAddressSpace())
5992       ConvTy = Sema::IncompatiblePointerDiscardsQualifiers;
5993 
5994     // It's okay to add or remove GC or lifetime qualifiers when converting to
5995     // and from void*.
5996     else if (lhq.withoutObjCGCAttr().withoutObjCLifetime()
5997                         .compatiblyIncludes(
5998                                 rhq.withoutObjCGCAttr().withoutObjCLifetime())
5999              && (lhptee->isVoidType() || rhptee->isVoidType()))
6000       ; // keep old
6001 
6002     // Treat lifetime mismatches as fatal.
6003     else if (lhq.getObjCLifetime() != rhq.getObjCLifetime())
6004       ConvTy = Sema::IncompatiblePointerDiscardsQualifiers;
6005 
6006     // For GCC compatibility, other qualifier mismatches are treated
6007     // as still compatible in C.
6008     else ConvTy = Sema::CompatiblePointerDiscardsQualifiers;
6009   }
6010 
6011   // C99 6.5.16.1p1 (constraint 4): If one operand is a pointer to an object or
6012   // incomplete type and the other is a pointer to a qualified or unqualified
6013   // version of void...
6014   if (lhptee->isVoidType()) {
6015     if (rhptee->isIncompleteOrObjectType())
6016       return ConvTy;
6017 
6018     // As an extension, we allow cast to/from void* to function pointer.
6019     assert(rhptee->isFunctionType());
6020     return Sema::FunctionVoidPointer;
6021   }
6022 
6023   if (rhptee->isVoidType()) {
6024     if (lhptee->isIncompleteOrObjectType())
6025       return ConvTy;
6026 
6027     // As an extension, we allow cast to/from void* to function pointer.
6028     assert(lhptee->isFunctionType());
6029     return Sema::FunctionVoidPointer;
6030   }
6031 
6032   // C99 6.5.16.1p1 (constraint 3): both operands are pointers to qualified or
6033   // unqualified versions of compatible types, ...
6034   QualType ltrans = QualType(lhptee, 0), rtrans = QualType(rhptee, 0);
6035   if (!S.Context.typesAreCompatible(ltrans, rtrans)) {
6036     // Check if the pointee types are compatible ignoring the sign.
6037     // We explicitly check for char so that we catch "char" vs
6038     // "unsigned char" on systems where "char" is unsigned.
6039     if (lhptee->isCharType())
6040       ltrans = S.Context.UnsignedCharTy;
6041     else if (lhptee->hasSignedIntegerRepresentation())
6042       ltrans = S.Context.getCorrespondingUnsignedType(ltrans);
6043 
6044     if (rhptee->isCharType())
6045       rtrans = S.Context.UnsignedCharTy;
6046     else if (rhptee->hasSignedIntegerRepresentation())
6047       rtrans = S.Context.getCorrespondingUnsignedType(rtrans);
6048 
6049     if (ltrans == rtrans) {
6050       // Types are compatible ignoring the sign. Qualifier incompatibility
6051       // takes priority over sign incompatibility because the sign
6052       // warning can be disabled.
6053       if (ConvTy != Sema::Compatible)
6054         return ConvTy;
6055 
6056       return Sema::IncompatiblePointerSign;
6057     }
6058 
6059     // If we are a multi-level pointer, it's possible that our issue is simply
6060     // one of qualification - e.g. char ** -> const char ** is not allowed. If
6061     // the eventual target type is the same and the pointers have the same
6062     // level of indirection, this must be the issue.
6063     if (isa<PointerType>(lhptee) && isa<PointerType>(rhptee)) {
6064       do {
6065         lhptee = cast<PointerType>(lhptee)->getPointeeType().getTypePtr();
6066         rhptee = cast<PointerType>(rhptee)->getPointeeType().getTypePtr();
6067       } while (isa<PointerType>(lhptee) && isa<PointerType>(rhptee));
6068 
6069       if (lhptee == rhptee)
6070         return Sema::IncompatibleNestedPointerQualifiers;
6071     }
6072 
6073     // General pointer incompatibility takes priority over qualifiers.
6074     return Sema::IncompatiblePointer;
6075   }
6076   if (!S.getLangOpts().CPlusPlus &&
6077       S.IsNoReturnConversion(ltrans, rtrans, ltrans))
6078     return Sema::IncompatiblePointer;
6079   return ConvTy;
6080 }
6081 
6082 /// checkBlockPointerTypesForAssignment - This routine determines whether two
6083 /// block pointer types are compatible or whether a block and normal pointer
6084 /// are compatible. It is more restrict than comparing two function pointer
6085 // types.
6086 static Sema::AssignConvertType
6087 checkBlockPointerTypesForAssignment(Sema &S, QualType LHSType,
6088                                     QualType RHSType) {
6089   assert(LHSType.isCanonical() && "LHS not canonicalized!");
6090   assert(RHSType.isCanonical() && "RHS not canonicalized!");
6091 
6092   QualType lhptee, rhptee;
6093 
6094   // get the "pointed to" type (ignoring qualifiers at the top level)
6095   lhptee = cast<BlockPointerType>(LHSType)->getPointeeType();
6096   rhptee = cast<BlockPointerType>(RHSType)->getPointeeType();
6097 
6098   // In C++, the types have to match exactly.
6099   if (S.getLangOpts().CPlusPlus)
6100     return Sema::IncompatibleBlockPointer;
6101 
6102   Sema::AssignConvertType ConvTy = Sema::Compatible;
6103 
6104   // For blocks we enforce that qualifiers are identical.
6105   if (lhptee.getLocalQualifiers() != rhptee.getLocalQualifiers())
6106     ConvTy = Sema::CompatiblePointerDiscardsQualifiers;
6107 
6108   if (!S.Context.typesAreBlockPointerCompatible(LHSType, RHSType))
6109     return Sema::IncompatibleBlockPointer;
6110 
6111   return ConvTy;
6112 }
6113 
6114 /// checkObjCPointerTypesForAssignment - Compares two objective-c pointer types
6115 /// for assignment compatibility.
6116 static Sema::AssignConvertType
6117 checkObjCPointerTypesForAssignment(Sema &S, QualType LHSType,
6118                                    QualType RHSType) {
6119   assert(LHSType.isCanonical() && "LHS was not canonicalized!");
6120   assert(RHSType.isCanonical() && "RHS was not canonicalized!");
6121 
6122   if (LHSType->isObjCBuiltinType()) {
6123     // Class is not compatible with ObjC object pointers.
6124     if (LHSType->isObjCClassType() && !RHSType->isObjCBuiltinType() &&
6125         !RHSType->isObjCQualifiedClassType())
6126       return Sema::IncompatiblePointer;
6127     return Sema::Compatible;
6128   }
6129   if (RHSType->isObjCBuiltinType()) {
6130     if (RHSType->isObjCClassType() && !LHSType->isObjCBuiltinType() &&
6131         !LHSType->isObjCQualifiedClassType())
6132       return Sema::IncompatiblePointer;
6133     return Sema::Compatible;
6134   }
6135   QualType lhptee = LHSType->getAs<ObjCObjectPointerType>()->getPointeeType();
6136   QualType rhptee = RHSType->getAs<ObjCObjectPointerType>()->getPointeeType();
6137 
6138   if (!lhptee.isAtLeastAsQualifiedAs(rhptee) &&
6139       // make an exception for id<P>
6140       !LHSType->isObjCQualifiedIdType())
6141     return Sema::CompatiblePointerDiscardsQualifiers;
6142 
6143   if (S.Context.typesAreCompatible(LHSType, RHSType))
6144     return Sema::Compatible;
6145   if (LHSType->isObjCQualifiedIdType() || RHSType->isObjCQualifiedIdType())
6146     return Sema::IncompatibleObjCQualifiedId;
6147   return Sema::IncompatiblePointer;
6148 }
6149 
6150 Sema::AssignConvertType
6151 Sema::CheckAssignmentConstraints(SourceLocation Loc,
6152                                  QualType LHSType, QualType RHSType) {
6153   // Fake up an opaque expression.  We don't actually care about what
6154   // cast operations are required, so if CheckAssignmentConstraints
6155   // adds casts to this they'll be wasted, but fortunately that doesn't
6156   // usually happen on valid code.
6157   OpaqueValueExpr RHSExpr(Loc, RHSType, VK_RValue);
6158   ExprResult RHSPtr = &RHSExpr;
6159   CastKind K = CK_Invalid;
6160 
6161   return CheckAssignmentConstraints(LHSType, RHSPtr, K);
6162 }
6163 
6164 /// CheckAssignmentConstraints (C99 6.5.16) - This routine currently
6165 /// has code to accommodate several GCC extensions when type checking
6166 /// pointers. Here are some objectionable examples that GCC considers warnings:
6167 ///
6168 ///  int a, *pint;
6169 ///  short *pshort;
6170 ///  struct foo *pfoo;
6171 ///
6172 ///  pint = pshort; // warning: assignment from incompatible pointer type
6173 ///  a = pint; // warning: assignment makes integer from pointer without a cast
6174 ///  pint = a; // warning: assignment makes pointer from integer without a cast
6175 ///  pint = pfoo; // warning: assignment from incompatible pointer type
6176 ///
6177 /// As a result, the code for dealing with pointers is more complex than the
6178 /// C99 spec dictates.
6179 ///
6180 /// Sets 'Kind' for any result kind except Incompatible.
6181 Sema::AssignConvertType
6182 Sema::CheckAssignmentConstraints(QualType LHSType, ExprResult &RHS,
6183                                  CastKind &Kind) {
6184   QualType RHSType = RHS.get()->getType();
6185   QualType OrigLHSType = LHSType;
6186 
6187   // Get canonical types.  We're not formatting these types, just comparing
6188   // them.
6189   LHSType = Context.getCanonicalType(LHSType).getUnqualifiedType();
6190   RHSType = Context.getCanonicalType(RHSType).getUnqualifiedType();
6191 
6192   // Common case: no conversion required.
6193   if (LHSType == RHSType) {
6194     Kind = CK_NoOp;
6195     return Compatible;
6196   }
6197 
6198   // If we have an atomic type, try a non-atomic assignment, then just add an
6199   // atomic qualification step.
6200   if (const AtomicType *AtomicTy = dyn_cast<AtomicType>(LHSType)) {
6201     Sema::AssignConvertType result =
6202       CheckAssignmentConstraints(AtomicTy->getValueType(), RHS, Kind);
6203     if (result != Compatible)
6204       return result;
6205     if (Kind != CK_NoOp)
6206       RHS = ImpCastExprToType(RHS.take(), AtomicTy->getValueType(), Kind);
6207     Kind = CK_NonAtomicToAtomic;
6208     return Compatible;
6209   }
6210 
6211   // If the left-hand side is a reference type, then we are in a
6212   // (rare!) case where we've allowed the use of references in C,
6213   // e.g., as a parameter type in a built-in function. In this case,
6214   // just make sure that the type referenced is compatible with the
6215   // right-hand side type. The caller is responsible for adjusting
6216   // LHSType so that the resulting expression does not have reference
6217   // type.
6218   if (const ReferenceType *LHSTypeRef = LHSType->getAs<ReferenceType>()) {
6219     if (Context.typesAreCompatible(LHSTypeRef->getPointeeType(), RHSType)) {
6220       Kind = CK_LValueBitCast;
6221       return Compatible;
6222     }
6223     return Incompatible;
6224   }
6225 
6226   // Allow scalar to ExtVector assignments, and assignments of an ExtVector type
6227   // to the same ExtVector type.
6228   if (LHSType->isExtVectorType()) {
6229     if (RHSType->isExtVectorType())
6230       return Incompatible;
6231     if (RHSType->isArithmeticType()) {
6232       // CK_VectorSplat does T -> vector T, so first cast to the
6233       // element type.
6234       QualType elType = cast<ExtVectorType>(LHSType)->getElementType();
6235       if (elType != RHSType) {
6236         Kind = PrepareScalarCast(RHS, elType);
6237         RHS = ImpCastExprToType(RHS.take(), elType, Kind);
6238       }
6239       Kind = CK_VectorSplat;
6240       return Compatible;
6241     }
6242   }
6243 
6244   // Conversions to or from vector type.
6245   if (LHSType->isVectorType() || RHSType->isVectorType()) {
6246     if (LHSType->isVectorType() && RHSType->isVectorType()) {
6247       // Allow assignments of an AltiVec vector type to an equivalent GCC
6248       // vector type and vice versa
6249       if (Context.areCompatibleVectorTypes(LHSType, RHSType)) {
6250         Kind = CK_BitCast;
6251         return Compatible;
6252       }
6253 
6254       // If we are allowing lax vector conversions, and LHS and RHS are both
6255       // vectors, the total size only needs to be the same. This is a bitcast;
6256       // no bits are changed but the result type is different.
6257       if (getLangOpts().LaxVectorConversions &&
6258           (Context.getTypeSize(LHSType) == Context.getTypeSize(RHSType))) {
6259         Kind = CK_BitCast;
6260         return IncompatibleVectors;
6261       }
6262     }
6263     return Incompatible;
6264   }
6265 
6266   // Arithmetic conversions.
6267   if (LHSType->isArithmeticType() && RHSType->isArithmeticType() &&
6268       !(getLangOpts().CPlusPlus && LHSType->isEnumeralType())) {
6269     Kind = PrepareScalarCast(RHS, LHSType);
6270     return Compatible;
6271   }
6272 
6273   // Conversions to normal pointers.
6274   if (const PointerType *LHSPointer = dyn_cast<PointerType>(LHSType)) {
6275     // U* -> T*
6276     if (isa<PointerType>(RHSType)) {
6277       Kind = CK_BitCast;
6278       return checkPointerTypesForAssignment(*this, LHSType, RHSType);
6279     }
6280 
6281     // int -> T*
6282     if (RHSType->isIntegerType()) {
6283       Kind = CK_IntegralToPointer; // FIXME: null?
6284       return IntToPointer;
6285     }
6286 
6287     // C pointers are not compatible with ObjC object pointers,
6288     // with two exceptions:
6289     if (isa<ObjCObjectPointerType>(RHSType)) {
6290       //  - conversions to void*
6291       if (LHSPointer->getPointeeType()->isVoidType()) {
6292         Kind = CK_BitCast;
6293         return Compatible;
6294       }
6295 
6296       //  - conversions from 'Class' to the redefinition type
6297       if (RHSType->isObjCClassType() &&
6298           Context.hasSameType(LHSType,
6299                               Context.getObjCClassRedefinitionType())) {
6300         Kind = CK_BitCast;
6301         return Compatible;
6302       }
6303 
6304       Kind = CK_BitCast;
6305       return IncompatiblePointer;
6306     }
6307 
6308     // U^ -> void*
6309     if (RHSType->getAs<BlockPointerType>()) {
6310       if (LHSPointer->getPointeeType()->isVoidType()) {
6311         Kind = CK_BitCast;
6312         return Compatible;
6313       }
6314     }
6315 
6316     return Incompatible;
6317   }
6318 
6319   // Conversions to block pointers.
6320   if (isa<BlockPointerType>(LHSType)) {
6321     // U^ -> T^
6322     if (RHSType->isBlockPointerType()) {
6323       Kind = CK_BitCast;
6324       return checkBlockPointerTypesForAssignment(*this, LHSType, RHSType);
6325     }
6326 
6327     // int or null -> T^
6328     if (RHSType->isIntegerType()) {
6329       Kind = CK_IntegralToPointer; // FIXME: null
6330       return IntToBlockPointer;
6331     }
6332 
6333     // id -> T^
6334     if (getLangOpts().ObjC1 && RHSType->isObjCIdType()) {
6335       Kind = CK_AnyPointerToBlockPointerCast;
6336       return Compatible;
6337     }
6338 
6339     // void* -> T^
6340     if (const PointerType *RHSPT = RHSType->getAs<PointerType>())
6341       if (RHSPT->getPointeeType()->isVoidType()) {
6342         Kind = CK_AnyPointerToBlockPointerCast;
6343         return Compatible;
6344       }
6345 
6346     return Incompatible;
6347   }
6348 
6349   // Conversions to Objective-C pointers.
6350   if (isa<ObjCObjectPointerType>(LHSType)) {
6351     // A* -> B*
6352     if (RHSType->isObjCObjectPointerType()) {
6353       Kind = CK_BitCast;
6354       Sema::AssignConvertType result =
6355         checkObjCPointerTypesForAssignment(*this, LHSType, RHSType);
6356       if (getLangOpts().ObjCAutoRefCount &&
6357           result == Compatible &&
6358           !CheckObjCARCUnavailableWeakConversion(OrigLHSType, RHSType))
6359         result = IncompatibleObjCWeakRef;
6360       return result;
6361     }
6362 
6363     // int or null -> A*
6364     if (RHSType->isIntegerType()) {
6365       Kind = CK_IntegralToPointer; // FIXME: null
6366       return IntToPointer;
6367     }
6368 
6369     // In general, C pointers are not compatible with ObjC object pointers,
6370     // with two exceptions:
6371     if (isa<PointerType>(RHSType)) {
6372       Kind = CK_CPointerToObjCPointerCast;
6373 
6374       //  - conversions from 'void*'
6375       if (RHSType->isVoidPointerType()) {
6376         return Compatible;
6377       }
6378 
6379       //  - conversions to 'Class' from its redefinition type
6380       if (LHSType->isObjCClassType() &&
6381           Context.hasSameType(RHSType,
6382                               Context.getObjCClassRedefinitionType())) {
6383         return Compatible;
6384       }
6385 
6386       return IncompatiblePointer;
6387     }
6388 
6389     // T^ -> A*
6390     if (RHSType->isBlockPointerType()) {
6391       maybeExtendBlockObject(*this, RHS);
6392       Kind = CK_BlockPointerToObjCPointerCast;
6393       return Compatible;
6394     }
6395 
6396     return Incompatible;
6397   }
6398 
6399   // Conversions from pointers that are not covered by the above.
6400   if (isa<PointerType>(RHSType)) {
6401     // T* -> _Bool
6402     if (LHSType == Context.BoolTy) {
6403       Kind = CK_PointerToBoolean;
6404       return Compatible;
6405     }
6406 
6407     // T* -> int
6408     if (LHSType->isIntegerType()) {
6409       Kind = CK_PointerToIntegral;
6410       return PointerToInt;
6411     }
6412 
6413     return Incompatible;
6414   }
6415 
6416   // Conversions from Objective-C pointers that are not covered by the above.
6417   if (isa<ObjCObjectPointerType>(RHSType)) {
6418     // T* -> _Bool
6419     if (LHSType == Context.BoolTy) {
6420       Kind = CK_PointerToBoolean;
6421       return Compatible;
6422     }
6423 
6424     // T* -> int
6425     if (LHSType->isIntegerType()) {
6426       Kind = CK_PointerToIntegral;
6427       return PointerToInt;
6428     }
6429 
6430     return Incompatible;
6431   }
6432 
6433   // struct A -> struct B
6434   if (isa<TagType>(LHSType) && isa<TagType>(RHSType)) {
6435     if (Context.typesAreCompatible(LHSType, RHSType)) {
6436       Kind = CK_NoOp;
6437       return Compatible;
6438     }
6439   }
6440 
6441   return Incompatible;
6442 }
6443 
6444 /// \brief Constructs a transparent union from an expression that is
6445 /// used to initialize the transparent union.
6446 static void ConstructTransparentUnion(Sema &S, ASTContext &C,
6447                                       ExprResult &EResult, QualType UnionType,
6448                                       FieldDecl *Field) {
6449   // Build an initializer list that designates the appropriate member
6450   // of the transparent union.
6451   Expr *E = EResult.take();
6452   InitListExpr *Initializer = new (C) InitListExpr(C, SourceLocation(),
6453                                                    E, SourceLocation());
6454   Initializer->setType(UnionType);
6455   Initializer->setInitializedFieldInUnion(Field);
6456 
6457   // Build a compound literal constructing a value of the transparent
6458   // union type from this initializer list.
6459   TypeSourceInfo *unionTInfo = C.getTrivialTypeSourceInfo(UnionType);
6460   EResult = S.Owned(
6461     new (C) CompoundLiteralExpr(SourceLocation(), unionTInfo, UnionType,
6462                                 VK_RValue, Initializer, false));
6463 }
6464 
6465 Sema::AssignConvertType
6466 Sema::CheckTransparentUnionArgumentConstraints(QualType ArgType,
6467                                                ExprResult &RHS) {
6468   QualType RHSType = RHS.get()->getType();
6469 
6470   // If the ArgType is a Union type, we want to handle a potential
6471   // transparent_union GCC extension.
6472   const RecordType *UT = ArgType->getAsUnionType();
6473   if (!UT || !UT->getDecl()->hasAttr<TransparentUnionAttr>())
6474     return Incompatible;
6475 
6476   // The field to initialize within the transparent union.
6477   RecordDecl *UD = UT->getDecl();
6478   FieldDecl *InitField = 0;
6479   // It's compatible if the expression matches any of the fields.
6480   for (RecordDecl::field_iterator it = UD->field_begin(),
6481          itend = UD->field_end();
6482        it != itend; ++it) {
6483     if (it->getType()->isPointerType()) {
6484       // If the transparent union contains a pointer type, we allow:
6485       // 1) void pointer
6486       // 2) null pointer constant
6487       if (RHSType->isPointerType())
6488         if (RHSType->castAs<PointerType>()->getPointeeType()->isVoidType()) {
6489           RHS = ImpCastExprToType(RHS.take(), it->getType(), CK_BitCast);
6490           InitField = *it;
6491           break;
6492         }
6493 
6494       if (RHS.get()->isNullPointerConstant(Context,
6495                                            Expr::NPC_ValueDependentIsNull)) {
6496         RHS = ImpCastExprToType(RHS.take(), it->getType(),
6497                                 CK_NullToPointer);
6498         InitField = *it;
6499         break;
6500       }
6501     }
6502 
6503     CastKind Kind = CK_Invalid;
6504     if (CheckAssignmentConstraints(it->getType(), RHS, Kind)
6505           == Compatible) {
6506       RHS = ImpCastExprToType(RHS.take(), it->getType(), Kind);
6507       InitField = *it;
6508       break;
6509     }
6510   }
6511 
6512   if (!InitField)
6513     return Incompatible;
6514 
6515   ConstructTransparentUnion(*this, Context, RHS, ArgType, InitField);
6516   return Compatible;
6517 }
6518 
6519 Sema::AssignConvertType
6520 Sema::CheckSingleAssignmentConstraints(QualType LHSType, ExprResult &RHS,
6521                                        bool Diagnose,
6522                                        bool DiagnoseCFAudited) {
6523   if (getLangOpts().CPlusPlus) {
6524     if (!LHSType->isRecordType() && !LHSType->isAtomicType()) {
6525       // C++ 5.17p3: If the left operand is not of class type, the
6526       // expression is implicitly converted (C++ 4) to the
6527       // cv-unqualified type of the left operand.
6528       ExprResult Res;
6529       if (Diagnose) {
6530         Res = PerformImplicitConversion(RHS.get(), LHSType.getUnqualifiedType(),
6531                                         AA_Assigning);
6532       } else {
6533         ImplicitConversionSequence ICS =
6534             TryImplicitConversion(RHS.get(), LHSType.getUnqualifiedType(),
6535                                   /*SuppressUserConversions=*/false,
6536                                   /*AllowExplicit=*/false,
6537                                   /*InOverloadResolution=*/false,
6538                                   /*CStyle=*/false,
6539                                   /*AllowObjCWritebackConversion=*/false);
6540         if (ICS.isFailure())
6541           return Incompatible;
6542         Res = PerformImplicitConversion(RHS.get(), LHSType.getUnqualifiedType(),
6543                                         ICS, AA_Assigning);
6544       }
6545       if (Res.isInvalid())
6546         return Incompatible;
6547       Sema::AssignConvertType result = Compatible;
6548       if (getLangOpts().ObjCAutoRefCount &&
6549           !CheckObjCARCUnavailableWeakConversion(LHSType,
6550                                                  RHS.get()->getType()))
6551         result = IncompatibleObjCWeakRef;
6552       RHS = Res;
6553       return result;
6554     }
6555 
6556     // FIXME: Currently, we fall through and treat C++ classes like C
6557     // structures.
6558     // FIXME: We also fall through for atomics; not sure what should
6559     // happen there, though.
6560   }
6561 
6562   // C99 6.5.16.1p1: the left operand is a pointer and the right is
6563   // a null pointer constant.
6564   if ((LHSType->isPointerType() ||
6565        LHSType->isObjCObjectPointerType() ||
6566        LHSType->isBlockPointerType())
6567       && RHS.get()->isNullPointerConstant(Context,
6568                                           Expr::NPC_ValueDependentIsNull)) {
6569     RHS = ImpCastExprToType(RHS.take(), LHSType, CK_NullToPointer);
6570     return Compatible;
6571   }
6572 
6573   // This check seems unnatural, however it is necessary to ensure the proper
6574   // conversion of functions/arrays. If the conversion were done for all
6575   // DeclExpr's (created by ActOnIdExpression), it would mess up the unary
6576   // expressions that suppress this implicit conversion (&, sizeof).
6577   //
6578   // Suppress this for references: C++ 8.5.3p5.
6579   if (!LHSType->isReferenceType()) {
6580     RHS = DefaultFunctionArrayLvalueConversion(RHS.take());
6581     if (RHS.isInvalid())
6582       return Incompatible;
6583   }
6584 
6585   CastKind Kind = CK_Invalid;
6586   Sema::AssignConvertType result =
6587     CheckAssignmentConstraints(LHSType, RHS, Kind);
6588 
6589   // C99 6.5.16.1p2: The value of the right operand is converted to the
6590   // type of the assignment expression.
6591   // CheckAssignmentConstraints allows the left-hand side to be a reference,
6592   // so that we can use references in built-in functions even in C.
6593   // The getNonReferenceType() call makes sure that the resulting expression
6594   // does not have reference type.
6595   if (result != Incompatible && RHS.get()->getType() != LHSType) {
6596     QualType Ty = LHSType.getNonLValueExprType(Context);
6597     Expr *E = RHS.take();
6598     if (getLangOpts().ObjCAutoRefCount)
6599       CheckObjCARCConversion(SourceRange(), Ty, E, CCK_ImplicitConversion,
6600                              DiagnoseCFAudited);
6601     RHS = ImpCastExprToType(E, Ty, Kind);
6602   }
6603   return result;
6604 }
6605 
6606 QualType Sema::InvalidOperands(SourceLocation Loc, ExprResult &LHS,
6607                                ExprResult &RHS) {
6608   Diag(Loc, diag::err_typecheck_invalid_operands)
6609     << LHS.get()->getType() << RHS.get()->getType()
6610     << LHS.get()->getSourceRange() << RHS.get()->getSourceRange();
6611   return QualType();
6612 }
6613 
6614 QualType Sema::CheckVectorOperands(ExprResult &LHS, ExprResult &RHS,
6615                                    SourceLocation Loc, bool IsCompAssign) {
6616   if (!IsCompAssign) {
6617     LHS = DefaultFunctionArrayLvalueConversion(LHS.take());
6618     if (LHS.isInvalid())
6619       return QualType();
6620   }
6621   RHS = DefaultFunctionArrayLvalueConversion(RHS.take());
6622   if (RHS.isInvalid())
6623     return QualType();
6624 
6625   // For conversion purposes, we ignore any qualifiers.
6626   // For example, "const float" and "float" are equivalent.
6627   QualType LHSType =
6628     Context.getCanonicalType(LHS.get()->getType()).getUnqualifiedType();
6629   QualType RHSType =
6630     Context.getCanonicalType(RHS.get()->getType()).getUnqualifiedType();
6631 
6632   // If the vector types are identical, return.
6633   if (LHSType == RHSType)
6634     return LHSType;
6635 
6636   // Handle the case of equivalent AltiVec and GCC vector types
6637   if (LHSType->isVectorType() && RHSType->isVectorType() &&
6638       Context.areCompatibleVectorTypes(LHSType, RHSType)) {
6639     if (LHSType->isExtVectorType()) {
6640       RHS = ImpCastExprToType(RHS.take(), LHSType, CK_BitCast);
6641       return LHSType;
6642     }
6643 
6644     if (!IsCompAssign)
6645       LHS = ImpCastExprToType(LHS.take(), RHSType, CK_BitCast);
6646     return RHSType;
6647   }
6648 
6649   if (getLangOpts().LaxVectorConversions &&
6650       Context.getTypeSize(LHSType) == Context.getTypeSize(RHSType)) {
6651     // If we are allowing lax vector conversions, and LHS and RHS are both
6652     // vectors, the total size only needs to be the same. This is a
6653     // bitcast; no bits are changed but the result type is different.
6654     // FIXME: Should we really be allowing this?
6655     RHS = ImpCastExprToType(RHS.take(), LHSType, CK_BitCast);
6656     return LHSType;
6657   }
6658 
6659   // Canonicalize the ExtVector to the LHS, remember if we swapped so we can
6660   // swap back (so that we don't reverse the inputs to a subtract, for instance.
6661   bool swapped = false;
6662   if (RHSType->isExtVectorType() && !IsCompAssign) {
6663     swapped = true;
6664     std::swap(RHS, LHS);
6665     std::swap(RHSType, LHSType);
6666   }
6667 
6668   // Handle the case of an ext vector and scalar.
6669   if (const ExtVectorType *LV = LHSType->getAs<ExtVectorType>()) {
6670     QualType EltTy = LV->getElementType();
6671     if (EltTy->isIntegralType(Context) && RHSType->isIntegralType(Context)) {
6672       int order = Context.getIntegerTypeOrder(EltTy, RHSType);
6673       if (order > 0)
6674         RHS = ImpCastExprToType(RHS.take(), EltTy, CK_IntegralCast);
6675       if (order >= 0) {
6676         RHS = ImpCastExprToType(RHS.take(), LHSType, CK_VectorSplat);
6677         if (swapped) std::swap(RHS, LHS);
6678         return LHSType;
6679       }
6680     }
6681     if (EltTy->isRealFloatingType() && RHSType->isScalarType()) {
6682       if (RHSType->isRealFloatingType()) {
6683         int order = Context.getFloatingTypeOrder(EltTy, RHSType);
6684         if (order > 0)
6685           RHS = ImpCastExprToType(RHS.take(), EltTy, CK_FloatingCast);
6686         if (order >= 0) {
6687           RHS = ImpCastExprToType(RHS.take(), LHSType, CK_VectorSplat);
6688           if (swapped) std::swap(RHS, LHS);
6689           return LHSType;
6690         }
6691       }
6692       if (RHSType->isIntegralType(Context)) {
6693         RHS = ImpCastExprToType(RHS.take(), EltTy, CK_IntegralToFloating);
6694         RHS = ImpCastExprToType(RHS.take(), LHSType, CK_VectorSplat);
6695         if (swapped) std::swap(RHS, LHS);
6696         return LHSType;
6697       }
6698     }
6699   }
6700 
6701   // Vectors of different size or scalar and non-ext-vector are errors.
6702   if (swapped) std::swap(RHS, LHS);
6703   Diag(Loc, diag::err_typecheck_vector_not_convertable)
6704     << LHS.get()->getType() << RHS.get()->getType()
6705     << LHS.get()->getSourceRange() << RHS.get()->getSourceRange();
6706   return QualType();
6707 }
6708 
6709 // checkArithmeticNull - Detect when a NULL constant is used improperly in an
6710 // expression.  These are mainly cases where the null pointer is used as an
6711 // integer instead of a pointer.
6712 static void checkArithmeticNull(Sema &S, ExprResult &LHS, ExprResult &RHS,
6713                                 SourceLocation Loc, bool IsCompare) {
6714   // The canonical way to check for a GNU null is with isNullPointerConstant,
6715   // but we use a bit of a hack here for speed; this is a relatively
6716   // hot path, and isNullPointerConstant is slow.
6717   bool LHSNull = isa<GNUNullExpr>(LHS.get()->IgnoreParenImpCasts());
6718   bool RHSNull = isa<GNUNullExpr>(RHS.get()->IgnoreParenImpCasts());
6719 
6720   QualType NonNullType = LHSNull ? RHS.get()->getType() : LHS.get()->getType();
6721 
6722   // Avoid analyzing cases where the result will either be invalid (and
6723   // diagnosed as such) or entirely valid and not something to warn about.
6724   if ((!LHSNull && !RHSNull) || NonNullType->isBlockPointerType() ||
6725       NonNullType->isMemberPointerType() || NonNullType->isFunctionType())
6726     return;
6727 
6728   // Comparison operations would not make sense with a null pointer no matter
6729   // what the other expression is.
6730   if (!IsCompare) {
6731     S.Diag(Loc, diag::warn_null_in_arithmetic_operation)
6732         << (LHSNull ? LHS.get()->getSourceRange() : SourceRange())
6733         << (RHSNull ? RHS.get()->getSourceRange() : SourceRange());
6734     return;
6735   }
6736 
6737   // The rest of the operations only make sense with a null pointer
6738   // if the other expression is a pointer.
6739   if (LHSNull == RHSNull || NonNullType->isAnyPointerType() ||
6740       NonNullType->canDecayToPointerType())
6741     return;
6742 
6743   S.Diag(Loc, diag::warn_null_in_comparison_operation)
6744       << LHSNull /* LHS is NULL */ << NonNullType
6745       << LHS.get()->getSourceRange() << RHS.get()->getSourceRange();
6746 }
6747 
6748 QualType Sema::CheckMultiplyDivideOperands(ExprResult &LHS, ExprResult &RHS,
6749                                            SourceLocation Loc,
6750                                            bool IsCompAssign, bool IsDiv) {
6751   checkArithmeticNull(*this, LHS, RHS, Loc, /*isCompare=*/false);
6752 
6753   if (LHS.get()->getType()->isVectorType() ||
6754       RHS.get()->getType()->isVectorType())
6755     return CheckVectorOperands(LHS, RHS, Loc, IsCompAssign);
6756 
6757   QualType compType = UsualArithmeticConversions(LHS, RHS, IsCompAssign);
6758   if (LHS.isInvalid() || RHS.isInvalid())
6759     return QualType();
6760 
6761 
6762   if (compType.isNull() || !compType->isArithmeticType())
6763     return InvalidOperands(Loc, LHS, RHS);
6764 
6765   // Check for division by zero.
6766   llvm::APSInt RHSValue;
6767   if (IsDiv && !RHS.get()->isValueDependent() &&
6768       RHS.get()->EvaluateAsInt(RHSValue, Context) && RHSValue == 0)
6769     DiagRuntimeBehavior(Loc, RHS.get(),
6770                         PDiag(diag::warn_division_by_zero)
6771                           << RHS.get()->getSourceRange());
6772 
6773   return compType;
6774 }
6775 
6776 QualType Sema::CheckRemainderOperands(
6777   ExprResult &LHS, ExprResult &RHS, SourceLocation Loc, bool IsCompAssign) {
6778   checkArithmeticNull(*this, LHS, RHS, Loc, /*isCompare=*/false);
6779 
6780   if (LHS.get()->getType()->isVectorType() ||
6781       RHS.get()->getType()->isVectorType()) {
6782     if (LHS.get()->getType()->hasIntegerRepresentation() &&
6783         RHS.get()->getType()->hasIntegerRepresentation())
6784       return CheckVectorOperands(LHS, RHS, Loc, IsCompAssign);
6785     return InvalidOperands(Loc, LHS, RHS);
6786   }
6787 
6788   QualType compType = UsualArithmeticConversions(LHS, RHS, IsCompAssign);
6789   if (LHS.isInvalid() || RHS.isInvalid())
6790     return QualType();
6791 
6792   if (compType.isNull() || !compType->isIntegerType())
6793     return InvalidOperands(Loc, LHS, RHS);
6794 
6795   // Check for remainder by zero.
6796   llvm::APSInt RHSValue;
6797   if (!RHS.get()->isValueDependent() &&
6798       RHS.get()->EvaluateAsInt(RHSValue, Context) && RHSValue == 0)
6799     DiagRuntimeBehavior(Loc, RHS.get(),
6800                         PDiag(diag::warn_remainder_by_zero)
6801                           << RHS.get()->getSourceRange());
6802 
6803   return compType;
6804 }
6805 
6806 /// \brief Diagnose invalid arithmetic on two void pointers.
6807 static void diagnoseArithmeticOnTwoVoidPointers(Sema &S, SourceLocation Loc,
6808                                                 Expr *LHSExpr, Expr *RHSExpr) {
6809   S.Diag(Loc, S.getLangOpts().CPlusPlus
6810                 ? diag::err_typecheck_pointer_arith_void_type
6811                 : diag::ext_gnu_void_ptr)
6812     << 1 /* two pointers */ << LHSExpr->getSourceRange()
6813                             << RHSExpr->getSourceRange();
6814 }
6815 
6816 /// \brief Diagnose invalid arithmetic on a void pointer.
6817 static void diagnoseArithmeticOnVoidPointer(Sema &S, SourceLocation Loc,
6818                                             Expr *Pointer) {
6819   S.Diag(Loc, S.getLangOpts().CPlusPlus
6820                 ? diag::err_typecheck_pointer_arith_void_type
6821                 : diag::ext_gnu_void_ptr)
6822     << 0 /* one pointer */ << Pointer->getSourceRange();
6823 }
6824 
6825 /// \brief Diagnose invalid arithmetic on two function pointers.
6826 static void diagnoseArithmeticOnTwoFunctionPointers(Sema &S, SourceLocation Loc,
6827                                                     Expr *LHS, Expr *RHS) {
6828   assert(LHS->getType()->isAnyPointerType());
6829   assert(RHS->getType()->isAnyPointerType());
6830   S.Diag(Loc, S.getLangOpts().CPlusPlus
6831                 ? diag::err_typecheck_pointer_arith_function_type
6832                 : diag::ext_gnu_ptr_func_arith)
6833     << 1 /* two pointers */ << LHS->getType()->getPointeeType()
6834     // We only show the second type if it differs from the first.
6835     << (unsigned)!S.Context.hasSameUnqualifiedType(LHS->getType(),
6836                                                    RHS->getType())
6837     << RHS->getType()->getPointeeType()
6838     << LHS->getSourceRange() << RHS->getSourceRange();
6839 }
6840 
6841 /// \brief Diagnose invalid arithmetic on a function pointer.
6842 static void diagnoseArithmeticOnFunctionPointer(Sema &S, SourceLocation Loc,
6843                                                 Expr *Pointer) {
6844   assert(Pointer->getType()->isAnyPointerType());
6845   S.Diag(Loc, S.getLangOpts().CPlusPlus
6846                 ? diag::err_typecheck_pointer_arith_function_type
6847                 : diag::ext_gnu_ptr_func_arith)
6848     << 0 /* one pointer */ << Pointer->getType()->getPointeeType()
6849     << 0 /* one pointer, so only one type */
6850     << Pointer->getSourceRange();
6851 }
6852 
6853 /// \brief Emit error if Operand is incomplete pointer type
6854 ///
6855 /// \returns True if pointer has incomplete type
6856 static bool checkArithmeticIncompletePointerType(Sema &S, SourceLocation Loc,
6857                                                  Expr *Operand) {
6858   assert(Operand->getType()->isAnyPointerType() &&
6859          !Operand->getType()->isDependentType());
6860   QualType PointeeTy = Operand->getType()->getPointeeType();
6861   return S.RequireCompleteType(Loc, PointeeTy,
6862                                diag::err_typecheck_arithmetic_incomplete_type,
6863                                PointeeTy, Operand->getSourceRange());
6864 }
6865 
6866 /// \brief Check the validity of an arithmetic pointer operand.
6867 ///
6868 /// If the operand has pointer type, this code will check for pointer types
6869 /// which are invalid in arithmetic operations. These will be diagnosed
6870 /// appropriately, including whether or not the use is supported as an
6871 /// extension.
6872 ///
6873 /// \returns True when the operand is valid to use (even if as an extension).
6874 static bool checkArithmeticOpPointerOperand(Sema &S, SourceLocation Loc,
6875                                             Expr *Operand) {
6876   if (!Operand->getType()->isAnyPointerType()) return true;
6877 
6878   QualType PointeeTy = Operand->getType()->getPointeeType();
6879   if (PointeeTy->isVoidType()) {
6880     diagnoseArithmeticOnVoidPointer(S, Loc, Operand);
6881     return !S.getLangOpts().CPlusPlus;
6882   }
6883   if (PointeeTy->isFunctionType()) {
6884     diagnoseArithmeticOnFunctionPointer(S, Loc, Operand);
6885     return !S.getLangOpts().CPlusPlus;
6886   }
6887 
6888   if (checkArithmeticIncompletePointerType(S, Loc, Operand)) return false;
6889 
6890   return true;
6891 }
6892 
6893 /// \brief Check the validity of a binary arithmetic operation w.r.t. pointer
6894 /// operands.
6895 ///
6896 /// This routine will diagnose any invalid arithmetic on pointer operands much
6897 /// like \see checkArithmeticOpPointerOperand. However, it has special logic
6898 /// for emitting a single diagnostic even for operations where both LHS and RHS
6899 /// are (potentially problematic) pointers.
6900 ///
6901 /// \returns True when the operand is valid to use (even if as an extension).
6902 static bool checkArithmeticBinOpPointerOperands(Sema &S, SourceLocation Loc,
6903                                                 Expr *LHSExpr, Expr *RHSExpr) {
6904   bool isLHSPointer = LHSExpr->getType()->isAnyPointerType();
6905   bool isRHSPointer = RHSExpr->getType()->isAnyPointerType();
6906   if (!isLHSPointer && !isRHSPointer) return true;
6907 
6908   QualType LHSPointeeTy, RHSPointeeTy;
6909   if (isLHSPointer) LHSPointeeTy = LHSExpr->getType()->getPointeeType();
6910   if (isRHSPointer) RHSPointeeTy = RHSExpr->getType()->getPointeeType();
6911 
6912   // Check for arithmetic on pointers to incomplete types.
6913   bool isLHSVoidPtr = isLHSPointer && LHSPointeeTy->isVoidType();
6914   bool isRHSVoidPtr = isRHSPointer && RHSPointeeTy->isVoidType();
6915   if (isLHSVoidPtr || isRHSVoidPtr) {
6916     if (!isRHSVoidPtr) diagnoseArithmeticOnVoidPointer(S, Loc, LHSExpr);
6917     else if (!isLHSVoidPtr) diagnoseArithmeticOnVoidPointer(S, Loc, RHSExpr);
6918     else diagnoseArithmeticOnTwoVoidPointers(S, Loc, LHSExpr, RHSExpr);
6919 
6920     return !S.getLangOpts().CPlusPlus;
6921   }
6922 
6923   bool isLHSFuncPtr = isLHSPointer && LHSPointeeTy->isFunctionType();
6924   bool isRHSFuncPtr = isRHSPointer && RHSPointeeTy->isFunctionType();
6925   if (isLHSFuncPtr || isRHSFuncPtr) {
6926     if (!isRHSFuncPtr) diagnoseArithmeticOnFunctionPointer(S, Loc, LHSExpr);
6927     else if (!isLHSFuncPtr) diagnoseArithmeticOnFunctionPointer(S, Loc,
6928                                                                 RHSExpr);
6929     else diagnoseArithmeticOnTwoFunctionPointers(S, Loc, LHSExpr, RHSExpr);
6930 
6931     return !S.getLangOpts().CPlusPlus;
6932   }
6933 
6934   if (isLHSPointer && checkArithmeticIncompletePointerType(S, Loc, LHSExpr))
6935     return false;
6936   if (isRHSPointer && checkArithmeticIncompletePointerType(S, Loc, RHSExpr))
6937     return false;
6938 
6939   return true;
6940 }
6941 
6942 /// diagnoseStringPlusInt - Emit a warning when adding an integer to a string
6943 /// literal.
6944 static void diagnoseStringPlusInt(Sema &Self, SourceLocation OpLoc,
6945                                   Expr *LHSExpr, Expr *RHSExpr) {
6946   StringLiteral* StrExpr = dyn_cast<StringLiteral>(LHSExpr->IgnoreImpCasts());
6947   Expr* IndexExpr = RHSExpr;
6948   if (!StrExpr) {
6949     StrExpr = dyn_cast<StringLiteral>(RHSExpr->IgnoreImpCasts());
6950     IndexExpr = LHSExpr;
6951   }
6952 
6953   bool IsStringPlusInt = StrExpr &&
6954       IndexExpr->getType()->isIntegralOrUnscopedEnumerationType();
6955   if (!IsStringPlusInt)
6956     return;
6957 
6958   llvm::APSInt index;
6959   if (IndexExpr->EvaluateAsInt(index, Self.getASTContext())) {
6960     unsigned StrLenWithNull = StrExpr->getLength() + 1;
6961     if (index.isNonNegative() &&
6962         index <= llvm::APSInt(llvm::APInt(index.getBitWidth(), StrLenWithNull),
6963                               index.isUnsigned()))
6964       return;
6965   }
6966 
6967   SourceRange DiagRange(LHSExpr->getLocStart(), RHSExpr->getLocEnd());
6968   Self.Diag(OpLoc, diag::warn_string_plus_int)
6969       << DiagRange << IndexExpr->IgnoreImpCasts()->getType();
6970 
6971   // Only print a fixit for "str" + int, not for int + "str".
6972   if (IndexExpr == RHSExpr) {
6973     SourceLocation EndLoc = Self.PP.getLocForEndOfToken(RHSExpr->getLocEnd());
6974     Self.Diag(OpLoc, diag::note_string_plus_scalar_silence)
6975         << FixItHint::CreateInsertion(LHSExpr->getLocStart(), "&")
6976         << FixItHint::CreateReplacement(SourceRange(OpLoc), "[")
6977         << FixItHint::CreateInsertion(EndLoc, "]");
6978   } else
6979     Self.Diag(OpLoc, diag::note_string_plus_scalar_silence);
6980 }
6981 
6982 /// \brief Emit a warning when adding a char literal to a string.
6983 static void diagnoseStringPlusChar(Sema &Self, SourceLocation OpLoc,
6984                                    Expr *LHSExpr, Expr *RHSExpr) {
6985   const DeclRefExpr *StringRefExpr =
6986       dyn_cast<DeclRefExpr>(LHSExpr->IgnoreImpCasts());
6987   const CharacterLiteral *CharExpr =
6988       dyn_cast<CharacterLiteral>(RHSExpr->IgnoreImpCasts());
6989   if (!StringRefExpr) {
6990     StringRefExpr = dyn_cast<DeclRefExpr>(RHSExpr->IgnoreImpCasts());
6991     CharExpr = dyn_cast<CharacterLiteral>(LHSExpr->IgnoreImpCasts());
6992   }
6993 
6994   if (!CharExpr || !StringRefExpr)
6995     return;
6996 
6997   const QualType StringType = StringRefExpr->getType();
6998 
6999   // Return if not a PointerType.
7000   if (!StringType->isAnyPointerType())
7001     return;
7002 
7003   // Return if not a CharacterType.
7004   if (!StringType->getPointeeType()->isAnyCharacterType())
7005     return;
7006 
7007   ASTContext &Ctx = Self.getASTContext();
7008   SourceRange DiagRange(LHSExpr->getLocStart(), RHSExpr->getLocEnd());
7009 
7010   const QualType CharType = CharExpr->getType();
7011   if (!CharType->isAnyCharacterType() &&
7012       CharType->isIntegerType() &&
7013       llvm::isUIntN(Ctx.getCharWidth(), CharExpr->getValue())) {
7014     Self.Diag(OpLoc, diag::warn_string_plus_char)
7015         << DiagRange << Ctx.CharTy;
7016   } else {
7017     Self.Diag(OpLoc, diag::warn_string_plus_char)
7018         << DiagRange << CharExpr->getType();
7019   }
7020 
7021   // Only print a fixit for str + char, not for char + str.
7022   if (isa<CharacterLiteral>(RHSExpr->IgnoreImpCasts())) {
7023     SourceLocation EndLoc = Self.PP.getLocForEndOfToken(RHSExpr->getLocEnd());
7024     Self.Diag(OpLoc, diag::note_string_plus_scalar_silence)
7025         << FixItHint::CreateInsertion(LHSExpr->getLocStart(), "&")
7026         << FixItHint::CreateReplacement(SourceRange(OpLoc), "[")
7027         << FixItHint::CreateInsertion(EndLoc, "]");
7028   } else {
7029     Self.Diag(OpLoc, diag::note_string_plus_scalar_silence);
7030   }
7031 }
7032 
7033 /// \brief Emit error when two pointers are incompatible.
7034 static void diagnosePointerIncompatibility(Sema &S, SourceLocation Loc,
7035                                            Expr *LHSExpr, Expr *RHSExpr) {
7036   assert(LHSExpr->getType()->isAnyPointerType());
7037   assert(RHSExpr->getType()->isAnyPointerType());
7038   S.Diag(Loc, diag::err_typecheck_sub_ptr_compatible)
7039     << LHSExpr->getType() << RHSExpr->getType() << LHSExpr->getSourceRange()
7040     << RHSExpr->getSourceRange();
7041 }
7042 
7043 QualType Sema::CheckAdditionOperands( // C99 6.5.6
7044     ExprResult &LHS, ExprResult &RHS, SourceLocation Loc, unsigned Opc,
7045     QualType* CompLHSTy) {
7046   checkArithmeticNull(*this, LHS, RHS, Loc, /*isCompare=*/false);
7047 
7048   if (LHS.get()->getType()->isVectorType() ||
7049       RHS.get()->getType()->isVectorType()) {
7050     QualType compType = CheckVectorOperands(LHS, RHS, Loc, CompLHSTy);
7051     if (CompLHSTy) *CompLHSTy = compType;
7052     return compType;
7053   }
7054 
7055   QualType compType = UsualArithmeticConversions(LHS, RHS, CompLHSTy);
7056   if (LHS.isInvalid() || RHS.isInvalid())
7057     return QualType();
7058 
7059   // Diagnose "string literal" '+' int and string '+' "char literal".
7060   if (Opc == BO_Add) {
7061     diagnoseStringPlusInt(*this, Loc, LHS.get(), RHS.get());
7062     diagnoseStringPlusChar(*this, Loc, LHS.get(), RHS.get());
7063   }
7064 
7065   // handle the common case first (both operands are arithmetic).
7066   if (!compType.isNull() && compType->isArithmeticType()) {
7067     if (CompLHSTy) *CompLHSTy = compType;
7068     return compType;
7069   }
7070 
7071   // Type-checking.  Ultimately the pointer's going to be in PExp;
7072   // note that we bias towards the LHS being the pointer.
7073   Expr *PExp = LHS.get(), *IExp = RHS.get();
7074 
7075   bool isObjCPointer;
7076   if (PExp->getType()->isPointerType()) {
7077     isObjCPointer = false;
7078   } else if (PExp->getType()->isObjCObjectPointerType()) {
7079     isObjCPointer = true;
7080   } else {
7081     std::swap(PExp, IExp);
7082     if (PExp->getType()->isPointerType()) {
7083       isObjCPointer = false;
7084     } else if (PExp->getType()->isObjCObjectPointerType()) {
7085       isObjCPointer = true;
7086     } else {
7087       return InvalidOperands(Loc, LHS, RHS);
7088     }
7089   }
7090   assert(PExp->getType()->isAnyPointerType());
7091 
7092   if (!IExp->getType()->isIntegerType())
7093     return InvalidOperands(Loc, LHS, RHS);
7094 
7095   if (!checkArithmeticOpPointerOperand(*this, Loc, PExp))
7096     return QualType();
7097 
7098   if (isObjCPointer && checkArithmeticOnObjCPointer(*this, Loc, PExp))
7099     return QualType();
7100 
7101   // Check array bounds for pointer arithemtic
7102   CheckArrayAccess(PExp, IExp);
7103 
7104   if (CompLHSTy) {
7105     QualType LHSTy = Context.isPromotableBitField(LHS.get());
7106     if (LHSTy.isNull()) {
7107       LHSTy = LHS.get()->getType();
7108       if (LHSTy->isPromotableIntegerType())
7109         LHSTy = Context.getPromotedIntegerType(LHSTy);
7110     }
7111     *CompLHSTy = LHSTy;
7112   }
7113 
7114   return PExp->getType();
7115 }
7116 
7117 // C99 6.5.6
7118 QualType Sema::CheckSubtractionOperands(ExprResult &LHS, ExprResult &RHS,
7119                                         SourceLocation Loc,
7120                                         QualType* CompLHSTy) {
7121   checkArithmeticNull(*this, LHS, RHS, Loc, /*isCompare=*/false);
7122 
7123   if (LHS.get()->getType()->isVectorType() ||
7124       RHS.get()->getType()->isVectorType()) {
7125     QualType compType = CheckVectorOperands(LHS, RHS, Loc, CompLHSTy);
7126     if (CompLHSTy) *CompLHSTy = compType;
7127     return compType;
7128   }
7129 
7130   QualType compType = UsualArithmeticConversions(LHS, RHS, CompLHSTy);
7131   if (LHS.isInvalid() || RHS.isInvalid())
7132     return QualType();
7133 
7134   // Enforce type constraints: C99 6.5.6p3.
7135 
7136   // Handle the common case first (both operands are arithmetic).
7137   if (!compType.isNull() && compType->isArithmeticType()) {
7138     if (CompLHSTy) *CompLHSTy = compType;
7139     return compType;
7140   }
7141 
7142   // Either ptr - int   or   ptr - ptr.
7143   if (LHS.get()->getType()->isAnyPointerType()) {
7144     QualType lpointee = LHS.get()->getType()->getPointeeType();
7145 
7146     // Diagnose bad cases where we step over interface counts.
7147     if (LHS.get()->getType()->isObjCObjectPointerType() &&
7148         checkArithmeticOnObjCPointer(*this, Loc, LHS.get()))
7149       return QualType();
7150 
7151     // The result type of a pointer-int computation is the pointer type.
7152     if (RHS.get()->getType()->isIntegerType()) {
7153       if (!checkArithmeticOpPointerOperand(*this, Loc, LHS.get()))
7154         return QualType();
7155 
7156       // Check array bounds for pointer arithemtic
7157       CheckArrayAccess(LHS.get(), RHS.get(), /*ArraySubscriptExpr*/0,
7158                        /*AllowOnePastEnd*/true, /*IndexNegated*/true);
7159 
7160       if (CompLHSTy) *CompLHSTy = LHS.get()->getType();
7161       return LHS.get()->getType();
7162     }
7163 
7164     // Handle pointer-pointer subtractions.
7165     if (const PointerType *RHSPTy
7166           = RHS.get()->getType()->getAs<PointerType>()) {
7167       QualType rpointee = RHSPTy->getPointeeType();
7168 
7169       if (getLangOpts().CPlusPlus) {
7170         // Pointee types must be the same: C++ [expr.add]
7171         if (!Context.hasSameUnqualifiedType(lpointee, rpointee)) {
7172           diagnosePointerIncompatibility(*this, Loc, LHS.get(), RHS.get());
7173         }
7174       } else {
7175         // Pointee types must be compatible C99 6.5.6p3
7176         if (!Context.typesAreCompatible(
7177                 Context.getCanonicalType(lpointee).getUnqualifiedType(),
7178                 Context.getCanonicalType(rpointee).getUnqualifiedType())) {
7179           diagnosePointerIncompatibility(*this, Loc, LHS.get(), RHS.get());
7180           return QualType();
7181         }
7182       }
7183 
7184       if (!checkArithmeticBinOpPointerOperands(*this, Loc,
7185                                                LHS.get(), RHS.get()))
7186         return QualType();
7187 
7188       // The pointee type may have zero size.  As an extension, a structure or
7189       // union may have zero size or an array may have zero length.  In this
7190       // case subtraction does not make sense.
7191       if (!rpointee->isVoidType() && !rpointee->isFunctionType()) {
7192         CharUnits ElementSize = Context.getTypeSizeInChars(rpointee);
7193         if (ElementSize.isZero()) {
7194           Diag(Loc,diag::warn_sub_ptr_zero_size_types)
7195             << rpointee.getUnqualifiedType()
7196             << LHS.get()->getSourceRange() << RHS.get()->getSourceRange();
7197         }
7198       }
7199 
7200       if (CompLHSTy) *CompLHSTy = LHS.get()->getType();
7201       return Context.getPointerDiffType();
7202     }
7203   }
7204 
7205   return InvalidOperands(Loc, LHS, RHS);
7206 }
7207 
7208 static bool isScopedEnumerationType(QualType T) {
7209   if (const EnumType *ET = dyn_cast<EnumType>(T))
7210     return ET->getDecl()->isScoped();
7211   return false;
7212 }
7213 
7214 static void DiagnoseBadShiftValues(Sema& S, ExprResult &LHS, ExprResult &RHS,
7215                                    SourceLocation Loc, unsigned Opc,
7216                                    QualType LHSType) {
7217   // OpenCL 6.3j: shift values are effectively % word size of LHS (more defined),
7218   // so skip remaining warnings as we don't want to modify values within Sema.
7219   if (S.getLangOpts().OpenCL)
7220     return;
7221 
7222   llvm::APSInt Right;
7223   // Check right/shifter operand
7224   if (RHS.get()->isValueDependent() ||
7225       !RHS.get()->isIntegerConstantExpr(Right, S.Context))
7226     return;
7227 
7228   if (Right.isNegative()) {
7229     S.DiagRuntimeBehavior(Loc, RHS.get(),
7230                           S.PDiag(diag::warn_shift_negative)
7231                             << RHS.get()->getSourceRange());
7232     return;
7233   }
7234   llvm::APInt LeftBits(Right.getBitWidth(),
7235                        S.Context.getTypeSize(LHS.get()->getType()));
7236   if (Right.uge(LeftBits)) {
7237     S.DiagRuntimeBehavior(Loc, RHS.get(),
7238                           S.PDiag(diag::warn_shift_gt_typewidth)
7239                             << RHS.get()->getSourceRange());
7240     return;
7241   }
7242   if (Opc != BO_Shl)
7243     return;
7244 
7245   // When left shifting an ICE which is signed, we can check for overflow which
7246   // according to C++ has undefined behavior ([expr.shift] 5.8/2). Unsigned
7247   // integers have defined behavior modulo one more than the maximum value
7248   // representable in the result type, so never warn for those.
7249   llvm::APSInt Left;
7250   if (LHS.get()->isValueDependent() ||
7251       !LHS.get()->isIntegerConstantExpr(Left, S.Context) ||
7252       LHSType->hasUnsignedIntegerRepresentation())
7253     return;
7254   llvm::APInt ResultBits =
7255       static_cast<llvm::APInt&>(Right) + Left.getMinSignedBits();
7256   if (LeftBits.uge(ResultBits))
7257     return;
7258   llvm::APSInt Result = Left.extend(ResultBits.getLimitedValue());
7259   Result = Result.shl(Right);
7260 
7261   // Print the bit representation of the signed integer as an unsigned
7262   // hexadecimal number.
7263   SmallString<40> HexResult;
7264   Result.toString(HexResult, 16, /*Signed =*/false, /*Literal =*/true);
7265 
7266   // If we are only missing a sign bit, this is less likely to result in actual
7267   // bugs -- if the result is cast back to an unsigned type, it will have the
7268   // expected value. Thus we place this behind a different warning that can be
7269   // turned off separately if needed.
7270   if (LeftBits == ResultBits - 1) {
7271     S.Diag(Loc, diag::warn_shift_result_sets_sign_bit)
7272         << HexResult.str() << LHSType
7273         << LHS.get()->getSourceRange() << RHS.get()->getSourceRange();
7274     return;
7275   }
7276 
7277   S.Diag(Loc, diag::warn_shift_result_gt_typewidth)
7278     << HexResult.str() << Result.getMinSignedBits() << LHSType
7279     << Left.getBitWidth() << LHS.get()->getSourceRange()
7280     << RHS.get()->getSourceRange();
7281 }
7282 
7283 // C99 6.5.7
7284 QualType Sema::CheckShiftOperands(ExprResult &LHS, ExprResult &RHS,
7285                                   SourceLocation Loc, unsigned Opc,
7286                                   bool IsCompAssign) {
7287   checkArithmeticNull(*this, LHS, RHS, Loc, /*isCompare=*/false);
7288 
7289   // Vector shifts promote their scalar inputs to vector type.
7290   if (LHS.get()->getType()->isVectorType() ||
7291       RHS.get()->getType()->isVectorType())
7292     return CheckVectorOperands(LHS, RHS, Loc, IsCompAssign);
7293 
7294   // Shifts don't perform usual arithmetic conversions, they just do integer
7295   // promotions on each operand. C99 6.5.7p3
7296 
7297   // For the LHS, do usual unary conversions, but then reset them away
7298   // if this is a compound assignment.
7299   ExprResult OldLHS = LHS;
7300   LHS = UsualUnaryConversions(LHS.take());
7301   if (LHS.isInvalid())
7302     return QualType();
7303   QualType LHSType = LHS.get()->getType();
7304   if (IsCompAssign) LHS = OldLHS;
7305 
7306   // The RHS is simpler.
7307   RHS = UsualUnaryConversions(RHS.take());
7308   if (RHS.isInvalid())
7309     return QualType();
7310   QualType RHSType = RHS.get()->getType();
7311 
7312   // C99 6.5.7p2: Each of the operands shall have integer type.
7313   if (!LHSType->hasIntegerRepresentation() ||
7314       !RHSType->hasIntegerRepresentation())
7315     return InvalidOperands(Loc, LHS, RHS);
7316 
7317   // C++0x: Don't allow scoped enums. FIXME: Use something better than
7318   // hasIntegerRepresentation() above instead of this.
7319   if (isScopedEnumerationType(LHSType) ||
7320       isScopedEnumerationType(RHSType)) {
7321     return InvalidOperands(Loc, LHS, RHS);
7322   }
7323   // Sanity-check shift operands
7324   DiagnoseBadShiftValues(*this, LHS, RHS, Loc, Opc, LHSType);
7325 
7326   // "The type of the result is that of the promoted left operand."
7327   return LHSType;
7328 }
7329 
7330 static bool IsWithinTemplateSpecialization(Decl *D) {
7331   if (DeclContext *DC = D->getDeclContext()) {
7332     if (isa<ClassTemplateSpecializationDecl>(DC))
7333       return true;
7334     if (FunctionDecl *FD = dyn_cast<FunctionDecl>(DC))
7335       return FD->isFunctionTemplateSpecialization();
7336   }
7337   return false;
7338 }
7339 
7340 /// If two different enums are compared, raise a warning.
7341 static void checkEnumComparison(Sema &S, SourceLocation Loc, Expr *LHS,
7342                                 Expr *RHS) {
7343   QualType LHSStrippedType = LHS->IgnoreParenImpCasts()->getType();
7344   QualType RHSStrippedType = RHS->IgnoreParenImpCasts()->getType();
7345 
7346   const EnumType *LHSEnumType = LHSStrippedType->getAs<EnumType>();
7347   if (!LHSEnumType)
7348     return;
7349   const EnumType *RHSEnumType = RHSStrippedType->getAs<EnumType>();
7350   if (!RHSEnumType)
7351     return;
7352 
7353   // Ignore anonymous enums.
7354   if (!LHSEnumType->getDecl()->getIdentifier())
7355     return;
7356   if (!RHSEnumType->getDecl()->getIdentifier())
7357     return;
7358 
7359   if (S.Context.hasSameUnqualifiedType(LHSStrippedType, RHSStrippedType))
7360     return;
7361 
7362   S.Diag(Loc, diag::warn_comparison_of_mixed_enum_types)
7363       << LHSStrippedType << RHSStrippedType
7364       << LHS->getSourceRange() << RHS->getSourceRange();
7365 }
7366 
7367 /// \brief Diagnose bad pointer comparisons.
7368 static void diagnoseDistinctPointerComparison(Sema &S, SourceLocation Loc,
7369                                               ExprResult &LHS, ExprResult &RHS,
7370                                               bool IsError) {
7371   S.Diag(Loc, IsError ? diag::err_typecheck_comparison_of_distinct_pointers
7372                       : diag::ext_typecheck_comparison_of_distinct_pointers)
7373     << LHS.get()->getType() << RHS.get()->getType()
7374     << LHS.get()->getSourceRange() << RHS.get()->getSourceRange();
7375 }
7376 
7377 /// \brief Returns false if the pointers are converted to a composite type,
7378 /// true otherwise.
7379 static bool convertPointersToCompositeType(Sema &S, SourceLocation Loc,
7380                                            ExprResult &LHS, ExprResult &RHS) {
7381   // C++ [expr.rel]p2:
7382   //   [...] Pointer conversions (4.10) and qualification
7383   //   conversions (4.4) are performed on pointer operands (or on
7384   //   a pointer operand and a null pointer constant) to bring
7385   //   them to their composite pointer type. [...]
7386   //
7387   // C++ [expr.eq]p1 uses the same notion for (in)equality
7388   // comparisons of pointers.
7389 
7390   // C++ [expr.eq]p2:
7391   //   In addition, pointers to members can be compared, or a pointer to
7392   //   member and a null pointer constant. Pointer to member conversions
7393   //   (4.11) and qualification conversions (4.4) are performed to bring
7394   //   them to a common type. If one operand is a null pointer constant,
7395   //   the common type is the type of the other operand. Otherwise, the
7396   //   common type is a pointer to member type similar (4.4) to the type
7397   //   of one of the operands, with a cv-qualification signature (4.4)
7398   //   that is the union of the cv-qualification signatures of the operand
7399   //   types.
7400 
7401   QualType LHSType = LHS.get()->getType();
7402   QualType RHSType = RHS.get()->getType();
7403   assert((LHSType->isPointerType() && RHSType->isPointerType()) ||
7404          (LHSType->isMemberPointerType() && RHSType->isMemberPointerType()));
7405 
7406   bool NonStandardCompositeType = false;
7407   bool *BoolPtr = S.isSFINAEContext() ? 0 : &NonStandardCompositeType;
7408   QualType T = S.FindCompositePointerType(Loc, LHS, RHS, BoolPtr);
7409   if (T.isNull()) {
7410     diagnoseDistinctPointerComparison(S, Loc, LHS, RHS, /*isError*/true);
7411     return true;
7412   }
7413 
7414   if (NonStandardCompositeType)
7415     S.Diag(Loc, diag::ext_typecheck_comparison_of_distinct_pointers_nonstandard)
7416       << LHSType << RHSType << T << LHS.get()->getSourceRange()
7417       << RHS.get()->getSourceRange();
7418 
7419   LHS = S.ImpCastExprToType(LHS.take(), T, CK_BitCast);
7420   RHS = S.ImpCastExprToType(RHS.take(), T, CK_BitCast);
7421   return false;
7422 }
7423 
7424 static void diagnoseFunctionPointerToVoidComparison(Sema &S, SourceLocation Loc,
7425                                                     ExprResult &LHS,
7426                                                     ExprResult &RHS,
7427                                                     bool IsError) {
7428   S.Diag(Loc, IsError ? diag::err_typecheck_comparison_of_fptr_to_void
7429                       : diag::ext_typecheck_comparison_of_fptr_to_void)
7430     << LHS.get()->getType() << RHS.get()->getType()
7431     << LHS.get()->getSourceRange() << RHS.get()->getSourceRange();
7432 }
7433 
7434 static bool isObjCObjectLiteral(ExprResult &E) {
7435   switch (E.get()->IgnoreParenImpCasts()->getStmtClass()) {
7436   case Stmt::ObjCArrayLiteralClass:
7437   case Stmt::ObjCDictionaryLiteralClass:
7438   case Stmt::ObjCStringLiteralClass:
7439   case Stmt::ObjCBoxedExprClass:
7440     return true;
7441   default:
7442     // Note that ObjCBoolLiteral is NOT an object literal!
7443     return false;
7444   }
7445 }
7446 
7447 static bool hasIsEqualMethod(Sema &S, const Expr *LHS, const Expr *RHS) {
7448   const ObjCObjectPointerType *Type =
7449     LHS->getType()->getAs<ObjCObjectPointerType>();
7450 
7451   // If this is not actually an Objective-C object, bail out.
7452   if (!Type)
7453     return false;
7454 
7455   // Get the LHS object's interface type.
7456   QualType InterfaceType = Type->getPointeeType();
7457   if (const ObjCObjectType *iQFaceTy =
7458       InterfaceType->getAsObjCQualifiedInterfaceType())
7459     InterfaceType = iQFaceTy->getBaseType();
7460 
7461   // If the RHS isn't an Objective-C object, bail out.
7462   if (!RHS->getType()->isObjCObjectPointerType())
7463     return false;
7464 
7465   // Try to find the -isEqual: method.
7466   Selector IsEqualSel = S.NSAPIObj->getIsEqualSelector();
7467   ObjCMethodDecl *Method = S.LookupMethodInObjectType(IsEqualSel,
7468                                                       InterfaceType,
7469                                                       /*instance=*/true);
7470   if (!Method) {
7471     if (Type->isObjCIdType()) {
7472       // For 'id', just check the global pool.
7473       Method = S.LookupInstanceMethodInGlobalPool(IsEqualSel, SourceRange(),
7474                                                   /*receiverId=*/true,
7475                                                   /*warn=*/false);
7476     } else {
7477       // Check protocols.
7478       Method = S.LookupMethodInQualifiedType(IsEqualSel, Type,
7479                                              /*instance=*/true);
7480     }
7481   }
7482 
7483   if (!Method)
7484     return false;
7485 
7486   QualType T = Method->param_begin()[0]->getType();
7487   if (!T->isObjCObjectPointerType())
7488     return false;
7489 
7490   QualType R = Method->getResultType();
7491   if (!R->isScalarType())
7492     return false;
7493 
7494   return true;
7495 }
7496 
7497 Sema::ObjCLiteralKind Sema::CheckLiteralKind(Expr *FromE) {
7498   FromE = FromE->IgnoreParenImpCasts();
7499   switch (FromE->getStmtClass()) {
7500     default:
7501       break;
7502     case Stmt::ObjCStringLiteralClass:
7503       // "string literal"
7504       return LK_String;
7505     case Stmt::ObjCArrayLiteralClass:
7506       // "array literal"
7507       return LK_Array;
7508     case Stmt::ObjCDictionaryLiteralClass:
7509       // "dictionary literal"
7510       return LK_Dictionary;
7511     case Stmt::BlockExprClass:
7512       return LK_Block;
7513     case Stmt::ObjCBoxedExprClass: {
7514       Expr *Inner = cast<ObjCBoxedExpr>(FromE)->getSubExpr()->IgnoreParens();
7515       switch (Inner->getStmtClass()) {
7516         case Stmt::IntegerLiteralClass:
7517         case Stmt::FloatingLiteralClass:
7518         case Stmt::CharacterLiteralClass:
7519         case Stmt::ObjCBoolLiteralExprClass:
7520         case Stmt::CXXBoolLiteralExprClass:
7521           // "numeric literal"
7522           return LK_Numeric;
7523         case Stmt::ImplicitCastExprClass: {
7524           CastKind CK = cast<CastExpr>(Inner)->getCastKind();
7525           // Boolean literals can be represented by implicit casts.
7526           if (CK == CK_IntegralToBoolean || CK == CK_IntegralCast)
7527             return LK_Numeric;
7528           break;
7529         }
7530         default:
7531           break;
7532       }
7533       return LK_Boxed;
7534     }
7535   }
7536   return LK_None;
7537 }
7538 
7539 static void diagnoseObjCLiteralComparison(Sema &S, SourceLocation Loc,
7540                                           ExprResult &LHS, ExprResult &RHS,
7541                                           BinaryOperator::Opcode Opc){
7542   Expr *Literal;
7543   Expr *Other;
7544   if (isObjCObjectLiteral(LHS)) {
7545     Literal = LHS.get();
7546     Other = RHS.get();
7547   } else {
7548     Literal = RHS.get();
7549     Other = LHS.get();
7550   }
7551 
7552   // Don't warn on comparisons against nil.
7553   Other = Other->IgnoreParenCasts();
7554   if (Other->isNullPointerConstant(S.getASTContext(),
7555                                    Expr::NPC_ValueDependentIsNotNull))
7556     return;
7557 
7558   // This should be kept in sync with warn_objc_literal_comparison.
7559   // LK_String should always be after the other literals, since it has its own
7560   // warning flag.
7561   Sema::ObjCLiteralKind LiteralKind = S.CheckLiteralKind(Literal);
7562   assert(LiteralKind != Sema::LK_Block);
7563   if (LiteralKind == Sema::LK_None) {
7564     llvm_unreachable("Unknown Objective-C object literal kind");
7565   }
7566 
7567   if (LiteralKind == Sema::LK_String)
7568     S.Diag(Loc, diag::warn_objc_string_literal_comparison)
7569       << Literal->getSourceRange();
7570   else
7571     S.Diag(Loc, diag::warn_objc_literal_comparison)
7572       << LiteralKind << Literal->getSourceRange();
7573 
7574   if (BinaryOperator::isEqualityOp(Opc) &&
7575       hasIsEqualMethod(S, LHS.get(), RHS.get())) {
7576     SourceLocation Start = LHS.get()->getLocStart();
7577     SourceLocation End = S.PP.getLocForEndOfToken(RHS.get()->getLocEnd());
7578     CharSourceRange OpRange =
7579       CharSourceRange::getCharRange(Loc, S.PP.getLocForEndOfToken(Loc));
7580 
7581     S.Diag(Loc, diag::note_objc_literal_comparison_isequal)
7582       << FixItHint::CreateInsertion(Start, Opc == BO_EQ ? "[" : "![")
7583       << FixItHint::CreateReplacement(OpRange, " isEqual:")
7584       << FixItHint::CreateInsertion(End, "]");
7585   }
7586 }
7587 
7588 static void diagnoseLogicalNotOnLHSofComparison(Sema &S, ExprResult &LHS,
7589                                                 ExprResult &RHS,
7590                                                 SourceLocation Loc,
7591                                                 unsigned OpaqueOpc) {
7592   // This checking requires bools.
7593   if (!S.getLangOpts().Bool) return;
7594 
7595   // Check that left hand side is !something.
7596   UnaryOperator *UO = dyn_cast<UnaryOperator>(LHS.get()->IgnoreImpCasts());
7597   if (!UO || UO->getOpcode() != UO_LNot) return;
7598 
7599   // Only check if the right hand side is non-bool arithmetic type.
7600   if (RHS.get()->getType()->isBooleanType()) return;
7601 
7602   // Make sure that the something in !something is not bool.
7603   Expr *SubExpr = UO->getSubExpr()->IgnoreImpCasts();
7604   if (SubExpr->getType()->isBooleanType()) return;
7605 
7606   // Emit warning.
7607   S.Diag(UO->getOperatorLoc(), diag::warn_logical_not_on_lhs_of_comparison)
7608       << Loc;
7609 
7610   // First note suggest !(x < y)
7611   SourceLocation FirstOpen = SubExpr->getLocStart();
7612   SourceLocation FirstClose = RHS.get()->getLocEnd();
7613   FirstClose = S.getPreprocessor().getLocForEndOfToken(FirstClose);
7614   if (FirstClose.isInvalid())
7615     FirstOpen = SourceLocation();
7616   S.Diag(UO->getOperatorLoc(), diag::note_logical_not_fix)
7617       << FixItHint::CreateInsertion(FirstOpen, "(")
7618       << FixItHint::CreateInsertion(FirstClose, ")");
7619 
7620   // Second note suggests (!x) < y
7621   SourceLocation SecondOpen = LHS.get()->getLocStart();
7622   SourceLocation SecondClose = LHS.get()->getLocEnd();
7623   SecondClose = S.getPreprocessor().getLocForEndOfToken(SecondClose);
7624   if (SecondClose.isInvalid())
7625     SecondOpen = SourceLocation();
7626   S.Diag(UO->getOperatorLoc(), diag::note_logical_not_silence_with_parens)
7627       << FixItHint::CreateInsertion(SecondOpen, "(")
7628       << FixItHint::CreateInsertion(SecondClose, ")");
7629 }
7630 
7631 // Get the decl for a simple expression: a reference to a variable,
7632 // an implicit C++ field reference, or an implicit ObjC ivar reference.
7633 static ValueDecl *getCompareDecl(Expr *E) {
7634   if (DeclRefExpr* DR = dyn_cast<DeclRefExpr>(E))
7635     return DR->getDecl();
7636   if (ObjCIvarRefExpr* Ivar = dyn_cast<ObjCIvarRefExpr>(E)) {
7637     if (Ivar->isFreeIvar())
7638       return Ivar->getDecl();
7639   }
7640   if (MemberExpr* Mem = dyn_cast<MemberExpr>(E)) {
7641     if (Mem->isImplicitAccess())
7642       return Mem->getMemberDecl();
7643   }
7644   return 0;
7645 }
7646 
7647 // C99 6.5.8, C++ [expr.rel]
7648 QualType Sema::CheckCompareOperands(ExprResult &LHS, ExprResult &RHS,
7649                                     SourceLocation Loc, unsigned OpaqueOpc,
7650                                     bool IsRelational) {
7651   checkArithmeticNull(*this, LHS, RHS, Loc, /*isCompare=*/true);
7652 
7653   BinaryOperatorKind Opc = (BinaryOperatorKind) OpaqueOpc;
7654 
7655   // Handle vector comparisons separately.
7656   if (LHS.get()->getType()->isVectorType() ||
7657       RHS.get()->getType()->isVectorType())
7658     return CheckVectorCompareOperands(LHS, RHS, Loc, IsRelational);
7659 
7660   QualType LHSType = LHS.get()->getType();
7661   QualType RHSType = RHS.get()->getType();
7662 
7663   Expr *LHSStripped = LHS.get()->IgnoreParenImpCasts();
7664   Expr *RHSStripped = RHS.get()->IgnoreParenImpCasts();
7665 
7666   checkEnumComparison(*this, Loc, LHS.get(), RHS.get());
7667   diagnoseLogicalNotOnLHSofComparison(*this, LHS, RHS, Loc, OpaqueOpc);
7668 
7669   if (!LHSType->hasFloatingRepresentation() &&
7670       !(LHSType->isBlockPointerType() && IsRelational) &&
7671       !LHS.get()->getLocStart().isMacroID() &&
7672       !RHS.get()->getLocStart().isMacroID()) {
7673     // For non-floating point types, check for self-comparisons of the form
7674     // x == x, x != x, x < x, etc.  These always evaluate to a constant, and
7675     // often indicate logic errors in the program.
7676     //
7677     // NOTE: Don't warn about comparison expressions resulting from macro
7678     // expansion. Also don't warn about comparisons which are only self
7679     // comparisons within a template specialization. The warnings should catch
7680     // obvious cases in the definition of the template anyways. The idea is to
7681     // warn when the typed comparison operator will always evaluate to the same
7682     // result.
7683     ValueDecl *DL = getCompareDecl(LHSStripped);
7684     ValueDecl *DR = getCompareDecl(RHSStripped);
7685     if (DL && DR && DL == DR && !IsWithinTemplateSpecialization(DL)) {
7686       DiagRuntimeBehavior(Loc, 0, PDiag(diag::warn_comparison_always)
7687                           << 0 // self-
7688                           << (Opc == BO_EQ
7689                               || Opc == BO_LE
7690                               || Opc == BO_GE));
7691     } else if (DL && DR && LHSType->isArrayType() && RHSType->isArrayType() &&
7692                !DL->getType()->isReferenceType() &&
7693                !DR->getType()->isReferenceType()) {
7694         // what is it always going to eval to?
7695         char always_evals_to;
7696         switch(Opc) {
7697         case BO_EQ: // e.g. array1 == array2
7698           always_evals_to = 0; // false
7699           break;
7700         case BO_NE: // e.g. array1 != array2
7701           always_evals_to = 1; // true
7702           break;
7703         default:
7704           // best we can say is 'a constant'
7705           always_evals_to = 2; // e.g. array1 <= array2
7706           break;
7707         }
7708         DiagRuntimeBehavior(Loc, 0, PDiag(diag::warn_comparison_always)
7709                             << 1 // array
7710                             << always_evals_to);
7711     }
7712 
7713     if (isa<CastExpr>(LHSStripped))
7714       LHSStripped = LHSStripped->IgnoreParenCasts();
7715     if (isa<CastExpr>(RHSStripped))
7716       RHSStripped = RHSStripped->IgnoreParenCasts();
7717 
7718     // Warn about comparisons against a string constant (unless the other
7719     // operand is null), the user probably wants strcmp.
7720     Expr *literalString = 0;
7721     Expr *literalStringStripped = 0;
7722     if ((isa<StringLiteral>(LHSStripped) || isa<ObjCEncodeExpr>(LHSStripped)) &&
7723         !RHSStripped->isNullPointerConstant(Context,
7724                                             Expr::NPC_ValueDependentIsNull)) {
7725       literalString = LHS.get();
7726       literalStringStripped = LHSStripped;
7727     } else if ((isa<StringLiteral>(RHSStripped) ||
7728                 isa<ObjCEncodeExpr>(RHSStripped)) &&
7729                !LHSStripped->isNullPointerConstant(Context,
7730                                             Expr::NPC_ValueDependentIsNull)) {
7731       literalString = RHS.get();
7732       literalStringStripped = RHSStripped;
7733     }
7734 
7735     if (literalString) {
7736       DiagRuntimeBehavior(Loc, 0,
7737         PDiag(diag::warn_stringcompare)
7738           << isa<ObjCEncodeExpr>(literalStringStripped)
7739           << literalString->getSourceRange());
7740     }
7741   }
7742 
7743   // C99 6.5.8p3 / C99 6.5.9p4
7744   UsualArithmeticConversions(LHS, RHS);
7745   if (LHS.isInvalid() || RHS.isInvalid())
7746     return QualType();
7747 
7748   LHSType = LHS.get()->getType();
7749   RHSType = RHS.get()->getType();
7750 
7751   // The result of comparisons is 'bool' in C++, 'int' in C.
7752   QualType ResultTy = Context.getLogicalOperationType();
7753 
7754   if (IsRelational) {
7755     if (LHSType->isRealType() && RHSType->isRealType())
7756       return ResultTy;
7757   } else {
7758     // Check for comparisons of floating point operands using != and ==.
7759     if (LHSType->hasFloatingRepresentation())
7760       CheckFloatComparison(Loc, LHS.get(), RHS.get());
7761 
7762     if (LHSType->isArithmeticType() && RHSType->isArithmeticType())
7763       return ResultTy;
7764   }
7765 
7766   bool LHSIsNull = LHS.get()->isNullPointerConstant(Context,
7767                                               Expr::NPC_ValueDependentIsNull);
7768   bool RHSIsNull = RHS.get()->isNullPointerConstant(Context,
7769                                               Expr::NPC_ValueDependentIsNull);
7770 
7771   // All of the following pointer-related warnings are GCC extensions, except
7772   // when handling null pointer constants.
7773   if (LHSType->isPointerType() && RHSType->isPointerType()) { // C99 6.5.8p2
7774     QualType LCanPointeeTy =
7775       LHSType->castAs<PointerType>()->getPointeeType().getCanonicalType();
7776     QualType RCanPointeeTy =
7777       RHSType->castAs<PointerType>()->getPointeeType().getCanonicalType();
7778 
7779     if (getLangOpts().CPlusPlus) {
7780       if (LCanPointeeTy == RCanPointeeTy)
7781         return ResultTy;
7782       if (!IsRelational &&
7783           (LCanPointeeTy->isVoidType() || RCanPointeeTy->isVoidType())) {
7784         // Valid unless comparison between non-null pointer and function pointer
7785         // This is a gcc extension compatibility comparison.
7786         // In a SFINAE context, we treat this as a hard error to maintain
7787         // conformance with the C++ standard.
7788         if ((LCanPointeeTy->isFunctionType() || RCanPointeeTy->isFunctionType())
7789             && !LHSIsNull && !RHSIsNull) {
7790           diagnoseFunctionPointerToVoidComparison(
7791               *this, Loc, LHS, RHS, /*isError*/ (bool)isSFINAEContext());
7792 
7793           if (isSFINAEContext())
7794             return QualType();
7795 
7796           RHS = ImpCastExprToType(RHS.take(), LHSType, CK_BitCast);
7797           return ResultTy;
7798         }
7799       }
7800 
7801       if (convertPointersToCompositeType(*this, Loc, LHS, RHS))
7802         return QualType();
7803       else
7804         return ResultTy;
7805     }
7806     // C99 6.5.9p2 and C99 6.5.8p2
7807     if (Context.typesAreCompatible(LCanPointeeTy.getUnqualifiedType(),
7808                                    RCanPointeeTy.getUnqualifiedType())) {
7809       // Valid unless a relational comparison of function pointers
7810       if (IsRelational && LCanPointeeTy->isFunctionType()) {
7811         Diag(Loc, diag::ext_typecheck_ordered_comparison_of_function_pointers)
7812           << LHSType << RHSType << LHS.get()->getSourceRange()
7813           << RHS.get()->getSourceRange();
7814       }
7815     } else if (!IsRelational &&
7816                (LCanPointeeTy->isVoidType() || RCanPointeeTy->isVoidType())) {
7817       // Valid unless comparison between non-null pointer and function pointer
7818       if ((LCanPointeeTy->isFunctionType() || RCanPointeeTy->isFunctionType())
7819           && !LHSIsNull && !RHSIsNull)
7820         diagnoseFunctionPointerToVoidComparison(*this, Loc, LHS, RHS,
7821                                                 /*isError*/false);
7822     } else {
7823       // Invalid
7824       diagnoseDistinctPointerComparison(*this, Loc, LHS, RHS, /*isError*/false);
7825     }
7826     if (LCanPointeeTy != RCanPointeeTy) {
7827       if (LHSIsNull && !RHSIsNull)
7828         LHS = ImpCastExprToType(LHS.take(), RHSType, CK_BitCast);
7829       else
7830         RHS = ImpCastExprToType(RHS.take(), LHSType, CK_BitCast);
7831     }
7832     return ResultTy;
7833   }
7834 
7835   if (getLangOpts().CPlusPlus) {
7836     // Comparison of nullptr_t with itself.
7837     if (LHSType->isNullPtrType() && RHSType->isNullPtrType())
7838       return ResultTy;
7839 
7840     // Comparison of pointers with null pointer constants and equality
7841     // comparisons of member pointers to null pointer constants.
7842     if (RHSIsNull &&
7843         ((LHSType->isAnyPointerType() || LHSType->isNullPtrType()) ||
7844          (!IsRelational &&
7845           (LHSType->isMemberPointerType() || LHSType->isBlockPointerType())))) {
7846       RHS = ImpCastExprToType(RHS.take(), LHSType,
7847                         LHSType->isMemberPointerType()
7848                           ? CK_NullToMemberPointer
7849                           : CK_NullToPointer);
7850       return ResultTy;
7851     }
7852     if (LHSIsNull &&
7853         ((RHSType->isAnyPointerType() || RHSType->isNullPtrType()) ||
7854          (!IsRelational &&
7855           (RHSType->isMemberPointerType() || RHSType->isBlockPointerType())))) {
7856       LHS = ImpCastExprToType(LHS.take(), RHSType,
7857                         RHSType->isMemberPointerType()
7858                           ? CK_NullToMemberPointer
7859                           : CK_NullToPointer);
7860       return ResultTy;
7861     }
7862 
7863     // Comparison of member pointers.
7864     if (!IsRelational &&
7865         LHSType->isMemberPointerType() && RHSType->isMemberPointerType()) {
7866       if (convertPointersToCompositeType(*this, Loc, LHS, RHS))
7867         return QualType();
7868       else
7869         return ResultTy;
7870     }
7871 
7872     // Handle scoped enumeration types specifically, since they don't promote
7873     // to integers.
7874     if (LHS.get()->getType()->isEnumeralType() &&
7875         Context.hasSameUnqualifiedType(LHS.get()->getType(),
7876                                        RHS.get()->getType()))
7877       return ResultTy;
7878   }
7879 
7880   // Handle block pointer types.
7881   if (!IsRelational && LHSType->isBlockPointerType() &&
7882       RHSType->isBlockPointerType()) {
7883     QualType lpointee = LHSType->castAs<BlockPointerType>()->getPointeeType();
7884     QualType rpointee = RHSType->castAs<BlockPointerType>()->getPointeeType();
7885 
7886     if (!LHSIsNull && !RHSIsNull &&
7887         !Context.typesAreCompatible(lpointee, rpointee)) {
7888       Diag(Loc, diag::err_typecheck_comparison_of_distinct_blocks)
7889         << LHSType << RHSType << LHS.get()->getSourceRange()
7890         << RHS.get()->getSourceRange();
7891     }
7892     RHS = ImpCastExprToType(RHS.take(), LHSType, CK_BitCast);
7893     return ResultTy;
7894   }
7895 
7896   // Allow block pointers to be compared with null pointer constants.
7897   if (!IsRelational
7898       && ((LHSType->isBlockPointerType() && RHSType->isPointerType())
7899           || (LHSType->isPointerType() && RHSType->isBlockPointerType()))) {
7900     if (!LHSIsNull && !RHSIsNull) {
7901       if (!((RHSType->isPointerType() && RHSType->castAs<PointerType>()
7902              ->getPointeeType()->isVoidType())
7903             || (LHSType->isPointerType() && LHSType->castAs<PointerType>()
7904                 ->getPointeeType()->isVoidType())))
7905         Diag(Loc, diag::err_typecheck_comparison_of_distinct_blocks)
7906           << LHSType << RHSType << LHS.get()->getSourceRange()
7907           << RHS.get()->getSourceRange();
7908     }
7909     if (LHSIsNull && !RHSIsNull)
7910       LHS = ImpCastExprToType(LHS.take(), RHSType,
7911                               RHSType->isPointerType() ? CK_BitCast
7912                                 : CK_AnyPointerToBlockPointerCast);
7913     else
7914       RHS = ImpCastExprToType(RHS.take(), LHSType,
7915                               LHSType->isPointerType() ? CK_BitCast
7916                                 : CK_AnyPointerToBlockPointerCast);
7917     return ResultTy;
7918   }
7919 
7920   if (LHSType->isObjCObjectPointerType() ||
7921       RHSType->isObjCObjectPointerType()) {
7922     const PointerType *LPT = LHSType->getAs<PointerType>();
7923     const PointerType *RPT = RHSType->getAs<PointerType>();
7924     if (LPT || RPT) {
7925       bool LPtrToVoid = LPT ? LPT->getPointeeType()->isVoidType() : false;
7926       bool RPtrToVoid = RPT ? RPT->getPointeeType()->isVoidType() : false;
7927 
7928       if (!LPtrToVoid && !RPtrToVoid &&
7929           !Context.typesAreCompatible(LHSType, RHSType)) {
7930         diagnoseDistinctPointerComparison(*this, Loc, LHS, RHS,
7931                                           /*isError*/false);
7932       }
7933       if (LHSIsNull && !RHSIsNull) {
7934         Expr *E = LHS.take();
7935         if (getLangOpts().ObjCAutoRefCount)
7936           CheckObjCARCConversion(SourceRange(), RHSType, E, CCK_ImplicitConversion);
7937         LHS = ImpCastExprToType(E, RHSType,
7938                                 RPT ? CK_BitCast :CK_CPointerToObjCPointerCast);
7939       }
7940       else {
7941         Expr *E = RHS.take();
7942         if (getLangOpts().ObjCAutoRefCount)
7943           CheckObjCARCConversion(SourceRange(), LHSType, E, CCK_ImplicitConversion);
7944         RHS = ImpCastExprToType(E, LHSType,
7945                                 LPT ? CK_BitCast :CK_CPointerToObjCPointerCast);
7946       }
7947       return ResultTy;
7948     }
7949     if (LHSType->isObjCObjectPointerType() &&
7950         RHSType->isObjCObjectPointerType()) {
7951       if (!Context.areComparableObjCPointerTypes(LHSType, RHSType))
7952         diagnoseDistinctPointerComparison(*this, Loc, LHS, RHS,
7953                                           /*isError*/false);
7954       if (isObjCObjectLiteral(LHS) || isObjCObjectLiteral(RHS))
7955         diagnoseObjCLiteralComparison(*this, Loc, LHS, RHS, Opc);
7956 
7957       if (LHSIsNull && !RHSIsNull)
7958         LHS = ImpCastExprToType(LHS.take(), RHSType, CK_BitCast);
7959       else
7960         RHS = ImpCastExprToType(RHS.take(), LHSType, CK_BitCast);
7961       return ResultTy;
7962     }
7963   }
7964   if ((LHSType->isAnyPointerType() && RHSType->isIntegerType()) ||
7965       (LHSType->isIntegerType() && RHSType->isAnyPointerType())) {
7966     unsigned DiagID = 0;
7967     bool isError = false;
7968     if (LangOpts.DebuggerSupport) {
7969       // Under a debugger, allow the comparison of pointers to integers,
7970       // since users tend to want to compare addresses.
7971     } else if ((LHSIsNull && LHSType->isIntegerType()) ||
7972         (RHSIsNull && RHSType->isIntegerType())) {
7973       if (IsRelational && !getLangOpts().CPlusPlus)
7974         DiagID = diag::ext_typecheck_ordered_comparison_of_pointer_and_zero;
7975     } else if (IsRelational && !getLangOpts().CPlusPlus)
7976       DiagID = diag::ext_typecheck_ordered_comparison_of_pointer_integer;
7977     else if (getLangOpts().CPlusPlus) {
7978       DiagID = diag::err_typecheck_comparison_of_pointer_integer;
7979       isError = true;
7980     } else
7981       DiagID = diag::ext_typecheck_comparison_of_pointer_integer;
7982 
7983     if (DiagID) {
7984       Diag(Loc, DiagID)
7985         << LHSType << RHSType << LHS.get()->getSourceRange()
7986         << RHS.get()->getSourceRange();
7987       if (isError)
7988         return QualType();
7989     }
7990 
7991     if (LHSType->isIntegerType())
7992       LHS = ImpCastExprToType(LHS.take(), RHSType,
7993                         LHSIsNull ? CK_NullToPointer : CK_IntegralToPointer);
7994     else
7995       RHS = ImpCastExprToType(RHS.take(), LHSType,
7996                         RHSIsNull ? CK_NullToPointer : CK_IntegralToPointer);
7997     return ResultTy;
7998   }
7999 
8000   // Handle block pointers.
8001   if (!IsRelational && RHSIsNull
8002       && LHSType->isBlockPointerType() && RHSType->isIntegerType()) {
8003     RHS = ImpCastExprToType(RHS.take(), LHSType, CK_NullToPointer);
8004     return ResultTy;
8005   }
8006   if (!IsRelational && LHSIsNull
8007       && LHSType->isIntegerType() && RHSType->isBlockPointerType()) {
8008     LHS = ImpCastExprToType(LHS.take(), RHSType, CK_NullToPointer);
8009     return ResultTy;
8010   }
8011 
8012   return InvalidOperands(Loc, LHS, RHS);
8013 }
8014 
8015 
8016 // Return a signed type that is of identical size and number of elements.
8017 // For floating point vectors, return an integer type of identical size
8018 // and number of elements.
8019 QualType Sema::GetSignedVectorType(QualType V) {
8020   const VectorType *VTy = V->getAs<VectorType>();
8021   unsigned TypeSize = Context.getTypeSize(VTy->getElementType());
8022   if (TypeSize == Context.getTypeSize(Context.CharTy))
8023     return Context.getExtVectorType(Context.CharTy, VTy->getNumElements());
8024   else if (TypeSize == Context.getTypeSize(Context.ShortTy))
8025     return Context.getExtVectorType(Context.ShortTy, VTy->getNumElements());
8026   else if (TypeSize == Context.getTypeSize(Context.IntTy))
8027     return Context.getExtVectorType(Context.IntTy, VTy->getNumElements());
8028   else if (TypeSize == Context.getTypeSize(Context.LongTy))
8029     return Context.getExtVectorType(Context.LongTy, VTy->getNumElements());
8030   assert(TypeSize == Context.getTypeSize(Context.LongLongTy) &&
8031          "Unhandled vector element size in vector compare");
8032   return Context.getExtVectorType(Context.LongLongTy, VTy->getNumElements());
8033 }
8034 
8035 /// CheckVectorCompareOperands - vector comparisons are a clang extension that
8036 /// operates on extended vector types.  Instead of producing an IntTy result,
8037 /// like a scalar comparison, a vector comparison produces a vector of integer
8038 /// types.
8039 QualType Sema::CheckVectorCompareOperands(ExprResult &LHS, ExprResult &RHS,
8040                                           SourceLocation Loc,
8041                                           bool IsRelational) {
8042   // Check to make sure we're operating on vectors of the same type and width,
8043   // Allowing one side to be a scalar of element type.
8044   QualType vType = CheckVectorOperands(LHS, RHS, Loc, /*isCompAssign*/false);
8045   if (vType.isNull())
8046     return vType;
8047 
8048   QualType LHSType = LHS.get()->getType();
8049 
8050   // If AltiVec, the comparison results in a numeric type, i.e.
8051   // bool for C++, int for C
8052   if (vType->getAs<VectorType>()->getVectorKind() == VectorType::AltiVecVector)
8053     return Context.getLogicalOperationType();
8054 
8055   // For non-floating point types, check for self-comparisons of the form
8056   // x == x, x != x, x < x, etc.  These always evaluate to a constant, and
8057   // often indicate logic errors in the program.
8058   if (!LHSType->hasFloatingRepresentation()) {
8059     if (DeclRefExpr* DRL
8060           = dyn_cast<DeclRefExpr>(LHS.get()->IgnoreParenImpCasts()))
8061       if (DeclRefExpr* DRR
8062             = dyn_cast<DeclRefExpr>(RHS.get()->IgnoreParenImpCasts()))
8063         if (DRL->getDecl() == DRR->getDecl())
8064           DiagRuntimeBehavior(Loc, 0,
8065                               PDiag(diag::warn_comparison_always)
8066                                 << 0 // self-
8067                                 << 2 // "a constant"
8068                               );
8069   }
8070 
8071   // Check for comparisons of floating point operands using != and ==.
8072   if (!IsRelational && LHSType->hasFloatingRepresentation()) {
8073     assert (RHS.get()->getType()->hasFloatingRepresentation());
8074     CheckFloatComparison(Loc, LHS.get(), RHS.get());
8075   }
8076 
8077   // Return a signed type for the vector.
8078   return GetSignedVectorType(LHSType);
8079 }
8080 
8081 QualType Sema::CheckVectorLogicalOperands(ExprResult &LHS, ExprResult &RHS,
8082                                           SourceLocation Loc) {
8083   // Ensure that either both operands are of the same vector type, or
8084   // one operand is of a vector type and the other is of its element type.
8085   QualType vType = CheckVectorOperands(LHS, RHS, Loc, false);
8086   if (vType.isNull())
8087     return InvalidOperands(Loc, LHS, RHS);
8088   if (getLangOpts().OpenCL && getLangOpts().OpenCLVersion < 120 &&
8089       vType->hasFloatingRepresentation())
8090     return InvalidOperands(Loc, LHS, RHS);
8091 
8092   return GetSignedVectorType(LHS.get()->getType());
8093 }
8094 
8095 inline QualType Sema::CheckBitwiseOperands(
8096   ExprResult &LHS, ExprResult &RHS, SourceLocation Loc, bool IsCompAssign) {
8097   checkArithmeticNull(*this, LHS, RHS, Loc, /*isCompare=*/false);
8098 
8099   if (LHS.get()->getType()->isVectorType() ||
8100       RHS.get()->getType()->isVectorType()) {
8101     if (LHS.get()->getType()->hasIntegerRepresentation() &&
8102         RHS.get()->getType()->hasIntegerRepresentation())
8103       return CheckVectorOperands(LHS, RHS, Loc, IsCompAssign);
8104 
8105     return InvalidOperands(Loc, LHS, RHS);
8106   }
8107 
8108   ExprResult LHSResult = Owned(LHS), RHSResult = Owned(RHS);
8109   QualType compType = UsualArithmeticConversions(LHSResult, RHSResult,
8110                                                  IsCompAssign);
8111   if (LHSResult.isInvalid() || RHSResult.isInvalid())
8112     return QualType();
8113   LHS = LHSResult.take();
8114   RHS = RHSResult.take();
8115 
8116   if (!compType.isNull() && compType->isIntegralOrUnscopedEnumerationType())
8117     return compType;
8118   return InvalidOperands(Loc, LHS, RHS);
8119 }
8120 
8121 inline QualType Sema::CheckLogicalOperands( // C99 6.5.[13,14]
8122   ExprResult &LHS, ExprResult &RHS, SourceLocation Loc, unsigned Opc) {
8123 
8124   // Check vector operands differently.
8125   if (LHS.get()->getType()->isVectorType() || RHS.get()->getType()->isVectorType())
8126     return CheckVectorLogicalOperands(LHS, RHS, Loc);
8127 
8128   // Diagnose cases where the user write a logical and/or but probably meant a
8129   // bitwise one.  We do this when the LHS is a non-bool integer and the RHS
8130   // is a constant.
8131   if (LHS.get()->getType()->isIntegerType() &&
8132       !LHS.get()->getType()->isBooleanType() &&
8133       RHS.get()->getType()->isIntegerType() && !RHS.get()->isValueDependent() &&
8134       // Don't warn in macros or template instantiations.
8135       !Loc.isMacroID() && ActiveTemplateInstantiations.empty()) {
8136     // If the RHS can be constant folded, and if it constant folds to something
8137     // that isn't 0 or 1 (which indicate a potential logical operation that
8138     // happened to fold to true/false) then warn.
8139     // Parens on the RHS are ignored.
8140     llvm::APSInt Result;
8141     if (RHS.get()->EvaluateAsInt(Result, Context))
8142       if ((getLangOpts().Bool && !RHS.get()->getType()->isBooleanType()) ||
8143           (Result != 0 && Result != 1)) {
8144         Diag(Loc, diag::warn_logical_instead_of_bitwise)
8145           << RHS.get()->getSourceRange()
8146           << (Opc == BO_LAnd ? "&&" : "||");
8147         // Suggest replacing the logical operator with the bitwise version
8148         Diag(Loc, diag::note_logical_instead_of_bitwise_change_operator)
8149             << (Opc == BO_LAnd ? "&" : "|")
8150             << FixItHint::CreateReplacement(SourceRange(
8151                 Loc, Lexer::getLocForEndOfToken(Loc, 0, getSourceManager(),
8152                                                 getLangOpts())),
8153                                             Opc == BO_LAnd ? "&" : "|");
8154         if (Opc == BO_LAnd)
8155           // Suggest replacing "Foo() && kNonZero" with "Foo()"
8156           Diag(Loc, diag::note_logical_instead_of_bitwise_remove_constant)
8157               << FixItHint::CreateRemoval(
8158                   SourceRange(
8159                       Lexer::getLocForEndOfToken(LHS.get()->getLocEnd(),
8160                                                  0, getSourceManager(),
8161                                                  getLangOpts()),
8162                       RHS.get()->getLocEnd()));
8163       }
8164   }
8165 
8166   if (!Context.getLangOpts().CPlusPlus) {
8167     // OpenCL v1.1 s6.3.g: The logical operators and (&&), or (||) do
8168     // not operate on the built-in scalar and vector float types.
8169     if (Context.getLangOpts().OpenCL &&
8170         Context.getLangOpts().OpenCLVersion < 120) {
8171       if (LHS.get()->getType()->isFloatingType() ||
8172           RHS.get()->getType()->isFloatingType())
8173         return InvalidOperands(Loc, LHS, RHS);
8174     }
8175 
8176     LHS = UsualUnaryConversions(LHS.take());
8177     if (LHS.isInvalid())
8178       return QualType();
8179 
8180     RHS = UsualUnaryConversions(RHS.take());
8181     if (RHS.isInvalid())
8182       return QualType();
8183 
8184     if (!LHS.get()->getType()->isScalarType() ||
8185         !RHS.get()->getType()->isScalarType())
8186       return InvalidOperands(Loc, LHS, RHS);
8187 
8188     return Context.IntTy;
8189   }
8190 
8191   // The following is safe because we only use this method for
8192   // non-overloadable operands.
8193 
8194   // C++ [expr.log.and]p1
8195   // C++ [expr.log.or]p1
8196   // The operands are both contextually converted to type bool.
8197   ExprResult LHSRes = PerformContextuallyConvertToBool(LHS.get());
8198   if (LHSRes.isInvalid())
8199     return InvalidOperands(Loc, LHS, RHS);
8200   LHS = LHSRes;
8201 
8202   ExprResult RHSRes = PerformContextuallyConvertToBool(RHS.get());
8203   if (RHSRes.isInvalid())
8204     return InvalidOperands(Loc, LHS, RHS);
8205   RHS = RHSRes;
8206 
8207   // C++ [expr.log.and]p2
8208   // C++ [expr.log.or]p2
8209   // The result is a bool.
8210   return Context.BoolTy;
8211 }
8212 
8213 static bool IsReadonlyMessage(Expr *E, Sema &S) {
8214   const MemberExpr *ME = dyn_cast<MemberExpr>(E);
8215   if (!ME) return false;
8216   if (!isa<FieldDecl>(ME->getMemberDecl())) return false;
8217   ObjCMessageExpr *Base =
8218     dyn_cast<ObjCMessageExpr>(ME->getBase()->IgnoreParenImpCasts());
8219   if (!Base) return false;
8220   return Base->getMethodDecl() != 0;
8221 }
8222 
8223 /// Is the given expression (which must be 'const') a reference to a
8224 /// variable which was originally non-const, but which has become
8225 /// 'const' due to being captured within a block?
8226 enum NonConstCaptureKind { NCCK_None, NCCK_Block, NCCK_Lambda };
8227 static NonConstCaptureKind isReferenceToNonConstCapture(Sema &S, Expr *E) {
8228   assert(E->isLValue() && E->getType().isConstQualified());
8229   E = E->IgnoreParens();
8230 
8231   // Must be a reference to a declaration from an enclosing scope.
8232   DeclRefExpr *DRE = dyn_cast<DeclRefExpr>(E);
8233   if (!DRE) return NCCK_None;
8234   if (!DRE->refersToEnclosingLocal()) return NCCK_None;
8235 
8236   // The declaration must be a variable which is not declared 'const'.
8237   VarDecl *var = dyn_cast<VarDecl>(DRE->getDecl());
8238   if (!var) return NCCK_None;
8239   if (var->getType().isConstQualified()) return NCCK_None;
8240   assert(var->hasLocalStorage() && "capture added 'const' to non-local?");
8241 
8242   // Decide whether the first capture was for a block or a lambda.
8243   DeclContext *DC = S.CurContext, *Prev = 0;
8244   while (DC != var->getDeclContext()) {
8245     Prev = DC;
8246     DC = DC->getParent();
8247   }
8248   // Unless we have an init-capture, we've gone one step too far.
8249   if (!var->isInitCapture())
8250     DC = Prev;
8251   return (isa<BlockDecl>(DC) ? NCCK_Block : NCCK_Lambda);
8252 }
8253 
8254 /// CheckForModifiableLvalue - Verify that E is a modifiable lvalue.  If not,
8255 /// emit an error and return true.  If so, return false.
8256 static bool CheckForModifiableLvalue(Expr *E, SourceLocation Loc, Sema &S) {
8257   assert(!E->hasPlaceholderType(BuiltinType::PseudoObject));
8258   SourceLocation OrigLoc = Loc;
8259   Expr::isModifiableLvalueResult IsLV = E->isModifiableLvalue(S.Context,
8260                                                               &Loc);
8261   if (IsLV == Expr::MLV_ClassTemporary && IsReadonlyMessage(E, S))
8262     IsLV = Expr::MLV_InvalidMessageExpression;
8263   if (IsLV == Expr::MLV_Valid)
8264     return false;
8265 
8266   unsigned Diag = 0;
8267   bool NeedType = false;
8268   switch (IsLV) { // C99 6.5.16p2
8269   case Expr::MLV_ConstQualified:
8270     Diag = diag::err_typecheck_assign_const;
8271 
8272     // Use a specialized diagnostic when we're assigning to an object
8273     // from an enclosing function or block.
8274     if (NonConstCaptureKind NCCK = isReferenceToNonConstCapture(S, E)) {
8275       if (NCCK == NCCK_Block)
8276         Diag = diag::err_block_decl_ref_not_modifiable_lvalue;
8277       else
8278         Diag = diag::err_lambda_decl_ref_not_modifiable_lvalue;
8279       break;
8280     }
8281 
8282     // In ARC, use some specialized diagnostics for occasions where we
8283     // infer 'const'.  These are always pseudo-strong variables.
8284     if (S.getLangOpts().ObjCAutoRefCount) {
8285       DeclRefExpr *declRef = dyn_cast<DeclRefExpr>(E->IgnoreParenCasts());
8286       if (declRef && isa<VarDecl>(declRef->getDecl())) {
8287         VarDecl *var = cast<VarDecl>(declRef->getDecl());
8288 
8289         // Use the normal diagnostic if it's pseudo-__strong but the
8290         // user actually wrote 'const'.
8291         if (var->isARCPseudoStrong() &&
8292             (!var->getTypeSourceInfo() ||
8293              !var->getTypeSourceInfo()->getType().isConstQualified())) {
8294           // There are two pseudo-strong cases:
8295           //  - self
8296           ObjCMethodDecl *method = S.getCurMethodDecl();
8297           if (method && var == method->getSelfDecl())
8298             Diag = method->isClassMethod()
8299               ? diag::err_typecheck_arc_assign_self_class_method
8300               : diag::err_typecheck_arc_assign_self;
8301 
8302           //  - fast enumeration variables
8303           else
8304             Diag = diag::err_typecheck_arr_assign_enumeration;
8305 
8306           SourceRange Assign;
8307           if (Loc != OrigLoc)
8308             Assign = SourceRange(OrigLoc, OrigLoc);
8309           S.Diag(Loc, Diag) << E->getSourceRange() << Assign;
8310           // We need to preserve the AST regardless, so migration tool
8311           // can do its job.
8312           return false;
8313         }
8314       }
8315     }
8316 
8317     break;
8318   case Expr::MLV_ArrayType:
8319   case Expr::MLV_ArrayTemporary:
8320     Diag = diag::err_typecheck_array_not_modifiable_lvalue;
8321     NeedType = true;
8322     break;
8323   case Expr::MLV_NotObjectType:
8324     Diag = diag::err_typecheck_non_object_not_modifiable_lvalue;
8325     NeedType = true;
8326     break;
8327   case Expr::MLV_LValueCast:
8328     Diag = diag::err_typecheck_lvalue_casts_not_supported;
8329     break;
8330   case Expr::MLV_Valid:
8331     llvm_unreachable("did not take early return for MLV_Valid");
8332   case Expr::MLV_InvalidExpression:
8333   case Expr::MLV_MemberFunction:
8334   case Expr::MLV_ClassTemporary:
8335     Diag = diag::err_typecheck_expression_not_modifiable_lvalue;
8336     break;
8337   case Expr::MLV_IncompleteType:
8338   case Expr::MLV_IncompleteVoidType:
8339     return S.RequireCompleteType(Loc, E->getType(),
8340              diag::err_typecheck_incomplete_type_not_modifiable_lvalue, E);
8341   case Expr::MLV_DuplicateVectorComponents:
8342     Diag = diag::err_typecheck_duplicate_vector_components_not_mlvalue;
8343     break;
8344   case Expr::MLV_NoSetterProperty:
8345     llvm_unreachable("readonly properties should be processed differently");
8346   case Expr::MLV_InvalidMessageExpression:
8347     Diag = diag::error_readonly_message_assignment;
8348     break;
8349   case Expr::MLV_SubObjCPropertySetting:
8350     Diag = diag::error_no_subobject_property_setting;
8351     break;
8352   }
8353 
8354   SourceRange Assign;
8355   if (Loc != OrigLoc)
8356     Assign = SourceRange(OrigLoc, OrigLoc);
8357   if (NeedType)
8358     S.Diag(Loc, Diag) << E->getType() << E->getSourceRange() << Assign;
8359   else
8360     S.Diag(Loc, Diag) << E->getSourceRange() << Assign;
8361   return true;
8362 }
8363 
8364 static void CheckIdentityFieldAssignment(Expr *LHSExpr, Expr *RHSExpr,
8365                                          SourceLocation Loc,
8366                                          Sema &Sema) {
8367   // C / C++ fields
8368   MemberExpr *ML = dyn_cast<MemberExpr>(LHSExpr);
8369   MemberExpr *MR = dyn_cast<MemberExpr>(RHSExpr);
8370   if (ML && MR && ML->getMemberDecl() == MR->getMemberDecl()) {
8371     if (isa<CXXThisExpr>(ML->getBase()) && isa<CXXThisExpr>(MR->getBase()))
8372       Sema.Diag(Loc, diag::warn_identity_field_assign) << 0;
8373   }
8374 
8375   // Objective-C instance variables
8376   ObjCIvarRefExpr *OL = dyn_cast<ObjCIvarRefExpr>(LHSExpr);
8377   ObjCIvarRefExpr *OR = dyn_cast<ObjCIvarRefExpr>(RHSExpr);
8378   if (OL && OR && OL->getDecl() == OR->getDecl()) {
8379     DeclRefExpr *RL = dyn_cast<DeclRefExpr>(OL->getBase()->IgnoreImpCasts());
8380     DeclRefExpr *RR = dyn_cast<DeclRefExpr>(OR->getBase()->IgnoreImpCasts());
8381     if (RL && RR && RL->getDecl() == RR->getDecl())
8382       Sema.Diag(Loc, diag::warn_identity_field_assign) << 1;
8383   }
8384 }
8385 
8386 // C99 6.5.16.1
8387 QualType Sema::CheckAssignmentOperands(Expr *LHSExpr, ExprResult &RHS,
8388                                        SourceLocation Loc,
8389                                        QualType CompoundType) {
8390   assert(!LHSExpr->hasPlaceholderType(BuiltinType::PseudoObject));
8391 
8392   // Verify that LHS is a modifiable lvalue, and emit error if not.
8393   if (CheckForModifiableLvalue(LHSExpr, Loc, *this))
8394     return QualType();
8395 
8396   QualType LHSType = LHSExpr->getType();
8397   QualType RHSType = CompoundType.isNull() ? RHS.get()->getType() :
8398                                              CompoundType;
8399   AssignConvertType ConvTy;
8400   if (CompoundType.isNull()) {
8401     Expr *RHSCheck = RHS.get();
8402 
8403     CheckIdentityFieldAssignment(LHSExpr, RHSCheck, Loc, *this);
8404 
8405     QualType LHSTy(LHSType);
8406     ConvTy = CheckSingleAssignmentConstraints(LHSTy, RHS);
8407     if (RHS.isInvalid())
8408       return QualType();
8409     // Special case of NSObject attributes on c-style pointer types.
8410     if (ConvTy == IncompatiblePointer &&
8411         ((Context.isObjCNSObjectType(LHSType) &&
8412           RHSType->isObjCObjectPointerType()) ||
8413          (Context.isObjCNSObjectType(RHSType) &&
8414           LHSType->isObjCObjectPointerType())))
8415       ConvTy = Compatible;
8416 
8417     if (ConvTy == Compatible &&
8418         LHSType->isObjCObjectType())
8419         Diag(Loc, diag::err_objc_object_assignment)
8420           << LHSType;
8421 
8422     // If the RHS is a unary plus or minus, check to see if they = and + are
8423     // right next to each other.  If so, the user may have typo'd "x =+ 4"
8424     // instead of "x += 4".
8425     if (ImplicitCastExpr *ICE = dyn_cast<ImplicitCastExpr>(RHSCheck))
8426       RHSCheck = ICE->getSubExpr();
8427     if (UnaryOperator *UO = dyn_cast<UnaryOperator>(RHSCheck)) {
8428       if ((UO->getOpcode() == UO_Plus ||
8429            UO->getOpcode() == UO_Minus) &&
8430           Loc.isFileID() && UO->getOperatorLoc().isFileID() &&
8431           // Only if the two operators are exactly adjacent.
8432           Loc.getLocWithOffset(1) == UO->getOperatorLoc() &&
8433           // And there is a space or other character before the subexpr of the
8434           // unary +/-.  We don't want to warn on "x=-1".
8435           Loc.getLocWithOffset(2) != UO->getSubExpr()->getLocStart() &&
8436           UO->getSubExpr()->getLocStart().isFileID()) {
8437         Diag(Loc, diag::warn_not_compound_assign)
8438           << (UO->getOpcode() == UO_Plus ? "+" : "-")
8439           << SourceRange(UO->getOperatorLoc(), UO->getOperatorLoc());
8440       }
8441     }
8442 
8443     if (ConvTy == Compatible) {
8444       if (LHSType.getObjCLifetime() == Qualifiers::OCL_Strong) {
8445         // Warn about retain cycles where a block captures the LHS, but
8446         // not if the LHS is a simple variable into which the block is
8447         // being stored...unless that variable can be captured by reference!
8448         const Expr *InnerLHS = LHSExpr->IgnoreParenCasts();
8449         const DeclRefExpr *DRE = dyn_cast<DeclRefExpr>(InnerLHS);
8450         if (!DRE || DRE->getDecl()->hasAttr<BlocksAttr>())
8451           checkRetainCycles(LHSExpr, RHS.get());
8452 
8453         // It is safe to assign a weak reference into a strong variable.
8454         // Although this code can still have problems:
8455         //   id x = self.weakProp;
8456         //   id y = self.weakProp;
8457         // we do not warn to warn spuriously when 'x' and 'y' are on separate
8458         // paths through the function. This should be revisited if
8459         // -Wrepeated-use-of-weak is made flow-sensitive.
8460         DiagnosticsEngine::Level Level =
8461           Diags.getDiagnosticLevel(diag::warn_arc_repeated_use_of_weak,
8462                                    RHS.get()->getLocStart());
8463         if (Level != DiagnosticsEngine::Ignored)
8464           getCurFunction()->markSafeWeakUse(RHS.get());
8465 
8466       } else if (getLangOpts().ObjCAutoRefCount) {
8467         checkUnsafeExprAssigns(Loc, LHSExpr, RHS.get());
8468       }
8469     }
8470   } else {
8471     // Compound assignment "x += y"
8472     ConvTy = CheckAssignmentConstraints(Loc, LHSType, RHSType);
8473   }
8474 
8475   if (DiagnoseAssignmentResult(ConvTy, Loc, LHSType, RHSType,
8476                                RHS.get(), AA_Assigning))
8477     return QualType();
8478 
8479   CheckForNullPointerDereference(*this, LHSExpr);
8480 
8481   // C99 6.5.16p3: The type of an assignment expression is the type of the
8482   // left operand unless the left operand has qualified type, in which case
8483   // it is the unqualified version of the type of the left operand.
8484   // C99 6.5.16.1p2: In simple assignment, the value of the right operand
8485   // is converted to the type of the assignment expression (above).
8486   // C++ 5.17p1: the type of the assignment expression is that of its left
8487   // operand.
8488   return (getLangOpts().CPlusPlus
8489           ? LHSType : LHSType.getUnqualifiedType());
8490 }
8491 
8492 // C99 6.5.17
8493 static QualType CheckCommaOperands(Sema &S, ExprResult &LHS, ExprResult &RHS,
8494                                    SourceLocation Loc) {
8495   LHS = S.CheckPlaceholderExpr(LHS.take());
8496   RHS = S.CheckPlaceholderExpr(RHS.take());
8497   if (LHS.isInvalid() || RHS.isInvalid())
8498     return QualType();
8499 
8500   // C's comma performs lvalue conversion (C99 6.3.2.1) on both its
8501   // operands, but not unary promotions.
8502   // C++'s comma does not do any conversions at all (C++ [expr.comma]p1).
8503 
8504   // So we treat the LHS as a ignored value, and in C++ we allow the
8505   // containing site to determine what should be done with the RHS.
8506   LHS = S.IgnoredValueConversions(LHS.take());
8507   if (LHS.isInvalid())
8508     return QualType();
8509 
8510   S.DiagnoseUnusedExprResult(LHS.get());
8511 
8512   if (!S.getLangOpts().CPlusPlus) {
8513     RHS = S.DefaultFunctionArrayLvalueConversion(RHS.take());
8514     if (RHS.isInvalid())
8515       return QualType();
8516     if (!RHS.get()->getType()->isVoidType())
8517       S.RequireCompleteType(Loc, RHS.get()->getType(),
8518                             diag::err_incomplete_type);
8519   }
8520 
8521   return RHS.get()->getType();
8522 }
8523 
8524 /// CheckIncrementDecrementOperand - unlike most "Check" methods, this routine
8525 /// doesn't need to call UsualUnaryConversions or UsualArithmeticConversions.
8526 static QualType CheckIncrementDecrementOperand(Sema &S, Expr *Op,
8527                                                ExprValueKind &VK,
8528                                                SourceLocation OpLoc,
8529                                                bool IsInc, bool IsPrefix) {
8530   if (Op->isTypeDependent())
8531     return S.Context.DependentTy;
8532 
8533   QualType ResType = Op->getType();
8534   // Atomic types can be used for increment / decrement where the non-atomic
8535   // versions can, so ignore the _Atomic() specifier for the purpose of
8536   // checking.
8537   if (const AtomicType *ResAtomicType = ResType->getAs<AtomicType>())
8538     ResType = ResAtomicType->getValueType();
8539 
8540   assert(!ResType.isNull() && "no type for increment/decrement expression");
8541 
8542   if (S.getLangOpts().CPlusPlus && ResType->isBooleanType()) {
8543     // Decrement of bool is not allowed.
8544     if (!IsInc) {
8545       S.Diag(OpLoc, diag::err_decrement_bool) << Op->getSourceRange();
8546       return QualType();
8547     }
8548     // Increment of bool sets it to true, but is deprecated.
8549     S.Diag(OpLoc, diag::warn_increment_bool) << Op->getSourceRange();
8550   } else if (S.getLangOpts().CPlusPlus && ResType->isEnumeralType()) {
8551     // Error on enum increments and decrements in C++ mode
8552     S.Diag(OpLoc, diag::err_increment_decrement_enum) << IsInc << ResType;
8553     return QualType();
8554   } else if (ResType->isRealType()) {
8555     // OK!
8556   } else if (ResType->isPointerType()) {
8557     // C99 6.5.2.4p2, 6.5.6p2
8558     if (!checkArithmeticOpPointerOperand(S, OpLoc, Op))
8559       return QualType();
8560   } else if (ResType->isObjCObjectPointerType()) {
8561     // On modern runtimes, ObjC pointer arithmetic is forbidden.
8562     // Otherwise, we just need a complete type.
8563     if (checkArithmeticIncompletePointerType(S, OpLoc, Op) ||
8564         checkArithmeticOnObjCPointer(S, OpLoc, Op))
8565       return QualType();
8566   } else if (ResType->isAnyComplexType()) {
8567     // C99 does not support ++/-- on complex types, we allow as an extension.
8568     S.Diag(OpLoc, diag::ext_integer_increment_complex)
8569       << ResType << Op->getSourceRange();
8570   } else if (ResType->isPlaceholderType()) {
8571     ExprResult PR = S.CheckPlaceholderExpr(Op);
8572     if (PR.isInvalid()) return QualType();
8573     return CheckIncrementDecrementOperand(S, PR.take(), VK, OpLoc,
8574                                           IsInc, IsPrefix);
8575   } else if (S.getLangOpts().AltiVec && ResType->isVectorType()) {
8576     // OK! ( C/C++ Language Extensions for CBEA(Version 2.6) 10.3 )
8577   } else if(S.getLangOpts().OpenCL && ResType->isVectorType() &&
8578             ResType->getAs<VectorType>()->getElementType()->isIntegerType()) {
8579     // OpenCL V1.2 6.3 says dec/inc ops operate on integer vector types.
8580   } else {
8581     S.Diag(OpLoc, diag::err_typecheck_illegal_increment_decrement)
8582       << ResType << int(IsInc) << Op->getSourceRange();
8583     return QualType();
8584   }
8585   // At this point, we know we have a real, complex or pointer type.
8586   // Now make sure the operand is a modifiable lvalue.
8587   if (CheckForModifiableLvalue(Op, OpLoc, S))
8588     return QualType();
8589   // In C++, a prefix increment is the same type as the operand. Otherwise
8590   // (in C or with postfix), the increment is the unqualified type of the
8591   // operand.
8592   if (IsPrefix && S.getLangOpts().CPlusPlus) {
8593     VK = VK_LValue;
8594     return ResType;
8595   } else {
8596     VK = VK_RValue;
8597     return ResType.getUnqualifiedType();
8598   }
8599 }
8600 
8601 
8602 /// getPrimaryDecl - Helper function for CheckAddressOfOperand().
8603 /// This routine allows us to typecheck complex/recursive expressions
8604 /// where the declaration is needed for type checking. We only need to
8605 /// handle cases when the expression references a function designator
8606 /// or is an lvalue. Here are some examples:
8607 ///  - &(x) => x
8608 ///  - &*****f => f for f a function designator.
8609 ///  - &s.xx => s
8610 ///  - &s.zz[1].yy -> s, if zz is an array
8611 ///  - *(x + 1) -> x, if x is an array
8612 ///  - &"123"[2] -> 0
8613 ///  - & __real__ x -> x
8614 static ValueDecl *getPrimaryDecl(Expr *E) {
8615   switch (E->getStmtClass()) {
8616   case Stmt::DeclRefExprClass:
8617     return cast<DeclRefExpr>(E)->getDecl();
8618   case Stmt::MemberExprClass:
8619     // If this is an arrow operator, the address is an offset from
8620     // the base's value, so the object the base refers to is
8621     // irrelevant.
8622     if (cast<MemberExpr>(E)->isArrow())
8623       return 0;
8624     // Otherwise, the expression refers to a part of the base
8625     return getPrimaryDecl(cast<MemberExpr>(E)->getBase());
8626   case Stmt::ArraySubscriptExprClass: {
8627     // FIXME: This code shouldn't be necessary!  We should catch the implicit
8628     // promotion of register arrays earlier.
8629     Expr* Base = cast<ArraySubscriptExpr>(E)->getBase();
8630     if (ImplicitCastExpr* ICE = dyn_cast<ImplicitCastExpr>(Base)) {
8631       if (ICE->getSubExpr()->getType()->isArrayType())
8632         return getPrimaryDecl(ICE->getSubExpr());
8633     }
8634     return 0;
8635   }
8636   case Stmt::UnaryOperatorClass: {
8637     UnaryOperator *UO = cast<UnaryOperator>(E);
8638 
8639     switch(UO->getOpcode()) {
8640     case UO_Real:
8641     case UO_Imag:
8642     case UO_Extension:
8643       return getPrimaryDecl(UO->getSubExpr());
8644     default:
8645       return 0;
8646     }
8647   }
8648   case Stmt::ParenExprClass:
8649     return getPrimaryDecl(cast<ParenExpr>(E)->getSubExpr());
8650   case Stmt::ImplicitCastExprClass:
8651     // If the result of an implicit cast is an l-value, we care about
8652     // the sub-expression; otherwise, the result here doesn't matter.
8653     return getPrimaryDecl(cast<ImplicitCastExpr>(E)->getSubExpr());
8654   default:
8655     return 0;
8656   }
8657 }
8658 
8659 namespace {
8660   enum {
8661     AO_Bit_Field = 0,
8662     AO_Vector_Element = 1,
8663     AO_Property_Expansion = 2,
8664     AO_Register_Variable = 3,
8665     AO_No_Error = 4
8666   };
8667 }
8668 /// \brief Diagnose invalid operand for address of operations.
8669 ///
8670 /// \param Type The type of operand which cannot have its address taken.
8671 static void diagnoseAddressOfInvalidType(Sema &S, SourceLocation Loc,
8672                                          Expr *E, unsigned Type) {
8673   S.Diag(Loc, diag::err_typecheck_address_of) << Type << E->getSourceRange();
8674 }
8675 
8676 /// CheckAddressOfOperand - The operand of & must be either a function
8677 /// designator or an lvalue designating an object. If it is an lvalue, the
8678 /// object cannot be declared with storage class register or be a bit field.
8679 /// Note: The usual conversions are *not* applied to the operand of the &
8680 /// operator (C99 6.3.2.1p[2-4]), and its result is never an lvalue.
8681 /// In C++, the operand might be an overloaded function name, in which case
8682 /// we allow the '&' but retain the overloaded-function type.
8683 QualType Sema::CheckAddressOfOperand(ExprResult &OrigOp, SourceLocation OpLoc) {
8684   if (const BuiltinType *PTy = OrigOp.get()->getType()->getAsPlaceholderType()){
8685     if (PTy->getKind() == BuiltinType::Overload) {
8686       Expr *E = OrigOp.get()->IgnoreParens();
8687       if (!isa<OverloadExpr>(E)) {
8688         assert(cast<UnaryOperator>(E)->getOpcode() == UO_AddrOf);
8689         Diag(OpLoc, diag::err_typecheck_invalid_lvalue_addrof_addrof_function)
8690           << OrigOp.get()->getSourceRange();
8691         return QualType();
8692       }
8693 
8694       OverloadExpr *Ovl = cast<OverloadExpr>(E);
8695       if (isa<UnresolvedMemberExpr>(Ovl))
8696         if (!ResolveSingleFunctionTemplateSpecialization(Ovl)) {
8697           Diag(OpLoc, diag::err_invalid_form_pointer_member_function)
8698             << OrigOp.get()->getSourceRange();
8699           return QualType();
8700         }
8701 
8702       return Context.OverloadTy;
8703     }
8704 
8705     if (PTy->getKind() == BuiltinType::UnknownAny)
8706       return Context.UnknownAnyTy;
8707 
8708     if (PTy->getKind() == BuiltinType::BoundMember) {
8709       Diag(OpLoc, diag::err_invalid_form_pointer_member_function)
8710         << OrigOp.get()->getSourceRange();
8711       return QualType();
8712     }
8713 
8714     OrigOp = CheckPlaceholderExpr(OrigOp.take());
8715     if (OrigOp.isInvalid()) return QualType();
8716   }
8717 
8718   if (OrigOp.get()->isTypeDependent())
8719     return Context.DependentTy;
8720 
8721   assert(!OrigOp.get()->getType()->isPlaceholderType());
8722 
8723   // Make sure to ignore parentheses in subsequent checks
8724   Expr *op = OrigOp.get()->IgnoreParens();
8725 
8726   if (getLangOpts().C99) {
8727     // Implement C99-only parts of addressof rules.
8728     if (UnaryOperator* uOp = dyn_cast<UnaryOperator>(op)) {
8729       if (uOp->getOpcode() == UO_Deref)
8730         // Per C99 6.5.3.2, the address of a deref always returns a valid result
8731         // (assuming the deref expression is valid).
8732         return uOp->getSubExpr()->getType();
8733     }
8734     // Technically, there should be a check for array subscript
8735     // expressions here, but the result of one is always an lvalue anyway.
8736   }
8737   ValueDecl *dcl = getPrimaryDecl(op);
8738   Expr::LValueClassification lval = op->ClassifyLValue(Context);
8739   unsigned AddressOfError = AO_No_Error;
8740 
8741   if (lval == Expr::LV_ClassTemporary || lval == Expr::LV_ArrayTemporary) {
8742     bool sfinae = (bool)isSFINAEContext();
8743     Diag(OpLoc, isSFINAEContext() ? diag::err_typecheck_addrof_temporary
8744                                   : diag::ext_typecheck_addrof_temporary)
8745       << op->getType() << op->getSourceRange();
8746     if (sfinae)
8747       return QualType();
8748     // Materialize the temporary as an lvalue so that we can take its address.
8749     OrigOp = op = new (Context)
8750         MaterializeTemporaryExpr(op->getType(), OrigOp.take(), true, 0);
8751   } else if (isa<ObjCSelectorExpr>(op)) {
8752     return Context.getPointerType(op->getType());
8753   } else if (lval == Expr::LV_MemberFunction) {
8754     // If it's an instance method, make a member pointer.
8755     // The expression must have exactly the form &A::foo.
8756 
8757     // If the underlying expression isn't a decl ref, give up.
8758     if (!isa<DeclRefExpr>(op)) {
8759       Diag(OpLoc, diag::err_invalid_form_pointer_member_function)
8760         << OrigOp.get()->getSourceRange();
8761       return QualType();
8762     }
8763     DeclRefExpr *DRE = cast<DeclRefExpr>(op);
8764     CXXMethodDecl *MD = cast<CXXMethodDecl>(DRE->getDecl());
8765 
8766     // The id-expression was parenthesized.
8767     if (OrigOp.get() != DRE) {
8768       Diag(OpLoc, diag::err_parens_pointer_member_function)
8769         << OrigOp.get()->getSourceRange();
8770 
8771     // The method was named without a qualifier.
8772     } else if (!DRE->getQualifier()) {
8773       if (MD->getParent()->getName().empty())
8774         Diag(OpLoc, diag::err_unqualified_pointer_member_function)
8775           << op->getSourceRange();
8776       else {
8777         SmallString<32> Str;
8778         StringRef Qual = (MD->getParent()->getName() + "::").toStringRef(Str);
8779         Diag(OpLoc, diag::err_unqualified_pointer_member_function)
8780           << op->getSourceRange()
8781           << FixItHint::CreateInsertion(op->getSourceRange().getBegin(), Qual);
8782       }
8783     }
8784 
8785     // Taking the address of a dtor is illegal per C++ [class.dtor]p2.
8786     if (isa<CXXDestructorDecl>(MD))
8787       Diag(OpLoc, diag::err_typecheck_addrof_dtor) << op->getSourceRange();
8788 
8789     return Context.getMemberPointerType(op->getType(),
8790               Context.getTypeDeclType(MD->getParent()).getTypePtr());
8791   } else if (lval != Expr::LV_Valid && lval != Expr::LV_IncompleteVoidType) {
8792     // C99 6.5.3.2p1
8793     // The operand must be either an l-value or a function designator
8794     if (!op->getType()->isFunctionType()) {
8795       // Use a special diagnostic for loads from property references.
8796       if (isa<PseudoObjectExpr>(op)) {
8797         AddressOfError = AO_Property_Expansion;
8798       } else {
8799         Diag(OpLoc, diag::err_typecheck_invalid_lvalue_addrof)
8800           << op->getType() << op->getSourceRange();
8801         return QualType();
8802       }
8803     }
8804   } else if (op->getObjectKind() == OK_BitField) { // C99 6.5.3.2p1
8805     // The operand cannot be a bit-field
8806     AddressOfError = AO_Bit_Field;
8807   } else if (op->getObjectKind() == OK_VectorComponent) {
8808     // The operand cannot be an element of a vector
8809     AddressOfError = AO_Vector_Element;
8810   } else if (dcl) { // C99 6.5.3.2p1
8811     // We have an lvalue with a decl. Make sure the decl is not declared
8812     // with the register storage-class specifier.
8813     if (const VarDecl *vd = dyn_cast<VarDecl>(dcl)) {
8814       // in C++ it is not error to take address of a register
8815       // variable (c++03 7.1.1P3)
8816       if (vd->getStorageClass() == SC_Register &&
8817           !getLangOpts().CPlusPlus) {
8818         AddressOfError = AO_Register_Variable;
8819       }
8820     } else if (isa<FunctionTemplateDecl>(dcl)) {
8821       return Context.OverloadTy;
8822     } else if (isa<FieldDecl>(dcl) || isa<IndirectFieldDecl>(dcl)) {
8823       // Okay: we can take the address of a field.
8824       // Could be a pointer to member, though, if there is an explicit
8825       // scope qualifier for the class.
8826       if (isa<DeclRefExpr>(op) && cast<DeclRefExpr>(op)->getQualifier()) {
8827         DeclContext *Ctx = dcl->getDeclContext();
8828         if (Ctx && Ctx->isRecord()) {
8829           if (dcl->getType()->isReferenceType()) {
8830             Diag(OpLoc,
8831                  diag::err_cannot_form_pointer_to_member_of_reference_type)
8832               << dcl->getDeclName() << dcl->getType();
8833             return QualType();
8834           }
8835 
8836           while (cast<RecordDecl>(Ctx)->isAnonymousStructOrUnion())
8837             Ctx = Ctx->getParent();
8838           return Context.getMemberPointerType(op->getType(),
8839                 Context.getTypeDeclType(cast<RecordDecl>(Ctx)).getTypePtr());
8840         }
8841       }
8842     } else if (!isa<FunctionDecl>(dcl) && !isa<NonTypeTemplateParmDecl>(dcl))
8843       llvm_unreachable("Unknown/unexpected decl type");
8844   }
8845 
8846   if (AddressOfError != AO_No_Error) {
8847     diagnoseAddressOfInvalidType(*this, OpLoc, op, AddressOfError);
8848     return QualType();
8849   }
8850 
8851   if (lval == Expr::LV_IncompleteVoidType) {
8852     // Taking the address of a void variable is technically illegal, but we
8853     // allow it in cases which are otherwise valid.
8854     // Example: "extern void x; void* y = &x;".
8855     Diag(OpLoc, diag::ext_typecheck_addrof_void) << op->getSourceRange();
8856   }
8857 
8858   // If the operand has type "type", the result has type "pointer to type".
8859   if (op->getType()->isObjCObjectType())
8860     return Context.getObjCObjectPointerType(op->getType());
8861   return Context.getPointerType(op->getType());
8862 }
8863 
8864 /// CheckIndirectionOperand - Type check unary indirection (prefix '*').
8865 static QualType CheckIndirectionOperand(Sema &S, Expr *Op, ExprValueKind &VK,
8866                                         SourceLocation OpLoc) {
8867   if (Op->isTypeDependent())
8868     return S.Context.DependentTy;
8869 
8870   ExprResult ConvResult = S.UsualUnaryConversions(Op);
8871   if (ConvResult.isInvalid())
8872     return QualType();
8873   Op = ConvResult.take();
8874   QualType OpTy = Op->getType();
8875   QualType Result;
8876 
8877   if (isa<CXXReinterpretCastExpr>(Op)) {
8878     QualType OpOrigType = Op->IgnoreParenCasts()->getType();
8879     S.CheckCompatibleReinterpretCast(OpOrigType, OpTy, /*IsDereference*/true,
8880                                      Op->getSourceRange());
8881   }
8882 
8883   // Note that per both C89 and C99, indirection is always legal, even if OpTy
8884   // is an incomplete type or void.  It would be possible to warn about
8885   // dereferencing a void pointer, but it's completely well-defined, and such a
8886   // warning is unlikely to catch any mistakes.
8887   if (const PointerType *PT = OpTy->getAs<PointerType>())
8888     Result = PT->getPointeeType();
8889   else if (const ObjCObjectPointerType *OPT =
8890              OpTy->getAs<ObjCObjectPointerType>())
8891     Result = OPT->getPointeeType();
8892   else {
8893     ExprResult PR = S.CheckPlaceholderExpr(Op);
8894     if (PR.isInvalid()) return QualType();
8895     if (PR.take() != Op)
8896       return CheckIndirectionOperand(S, PR.take(), VK, OpLoc);
8897   }
8898 
8899   if (Result.isNull()) {
8900     S.Diag(OpLoc, diag::err_typecheck_indirection_requires_pointer)
8901       << OpTy << Op->getSourceRange();
8902     return QualType();
8903   }
8904 
8905   // Dereferences are usually l-values...
8906   VK = VK_LValue;
8907 
8908   // ...except that certain expressions are never l-values in C.
8909   if (!S.getLangOpts().CPlusPlus && Result.isCForbiddenLValueType())
8910     VK = VK_RValue;
8911 
8912   return Result;
8913 }
8914 
8915 static inline BinaryOperatorKind ConvertTokenKindToBinaryOpcode(
8916   tok::TokenKind Kind) {
8917   BinaryOperatorKind Opc;
8918   switch (Kind) {
8919   default: llvm_unreachable("Unknown binop!");
8920   case tok::periodstar:           Opc = BO_PtrMemD; break;
8921   case tok::arrowstar:            Opc = BO_PtrMemI; break;
8922   case tok::star:                 Opc = BO_Mul; break;
8923   case tok::slash:                Opc = BO_Div; break;
8924   case tok::percent:              Opc = BO_Rem; break;
8925   case tok::plus:                 Opc = BO_Add; break;
8926   case tok::minus:                Opc = BO_Sub; break;
8927   case tok::lessless:             Opc = BO_Shl; break;
8928   case tok::greatergreater:       Opc = BO_Shr; break;
8929   case tok::lessequal:            Opc = BO_LE; break;
8930   case tok::less:                 Opc = BO_LT; break;
8931   case tok::greaterequal:         Opc = BO_GE; break;
8932   case tok::greater:              Opc = BO_GT; break;
8933   case tok::exclaimequal:         Opc = BO_NE; break;
8934   case tok::equalequal:           Opc = BO_EQ; break;
8935   case tok::amp:                  Opc = BO_And; break;
8936   case tok::caret:                Opc = BO_Xor; break;
8937   case tok::pipe:                 Opc = BO_Or; break;
8938   case tok::ampamp:               Opc = BO_LAnd; break;
8939   case tok::pipepipe:             Opc = BO_LOr; break;
8940   case tok::equal:                Opc = BO_Assign; break;
8941   case tok::starequal:            Opc = BO_MulAssign; break;
8942   case tok::slashequal:           Opc = BO_DivAssign; break;
8943   case tok::percentequal:         Opc = BO_RemAssign; break;
8944   case tok::plusequal:            Opc = BO_AddAssign; break;
8945   case tok::minusequal:           Opc = BO_SubAssign; break;
8946   case tok::lesslessequal:        Opc = BO_ShlAssign; break;
8947   case tok::greatergreaterequal:  Opc = BO_ShrAssign; break;
8948   case tok::ampequal:             Opc = BO_AndAssign; break;
8949   case tok::caretequal:           Opc = BO_XorAssign; break;
8950   case tok::pipeequal:            Opc = BO_OrAssign; break;
8951   case tok::comma:                Opc = BO_Comma; break;
8952   }
8953   return Opc;
8954 }
8955 
8956 static inline UnaryOperatorKind ConvertTokenKindToUnaryOpcode(
8957   tok::TokenKind Kind) {
8958   UnaryOperatorKind Opc;
8959   switch (Kind) {
8960   default: llvm_unreachable("Unknown unary op!");
8961   case tok::plusplus:     Opc = UO_PreInc; break;
8962   case tok::minusminus:   Opc = UO_PreDec; break;
8963   case tok::amp:          Opc = UO_AddrOf; break;
8964   case tok::star:         Opc = UO_Deref; break;
8965   case tok::plus:         Opc = UO_Plus; break;
8966   case tok::minus:        Opc = UO_Minus; break;
8967   case tok::tilde:        Opc = UO_Not; break;
8968   case tok::exclaim:      Opc = UO_LNot; break;
8969   case tok::kw___real:    Opc = UO_Real; break;
8970   case tok::kw___imag:    Opc = UO_Imag; break;
8971   case tok::kw___extension__: Opc = UO_Extension; break;
8972   }
8973   return Opc;
8974 }
8975 
8976 /// DiagnoseSelfAssignment - Emits a warning if a value is assigned to itself.
8977 /// This warning is only emitted for builtin assignment operations. It is also
8978 /// suppressed in the event of macro expansions.
8979 static void DiagnoseSelfAssignment(Sema &S, Expr *LHSExpr, Expr *RHSExpr,
8980                                    SourceLocation OpLoc) {
8981   if (!S.ActiveTemplateInstantiations.empty())
8982     return;
8983   if (OpLoc.isInvalid() || OpLoc.isMacroID())
8984     return;
8985   LHSExpr = LHSExpr->IgnoreParenImpCasts();
8986   RHSExpr = RHSExpr->IgnoreParenImpCasts();
8987   const DeclRefExpr *LHSDeclRef = dyn_cast<DeclRefExpr>(LHSExpr);
8988   const DeclRefExpr *RHSDeclRef = dyn_cast<DeclRefExpr>(RHSExpr);
8989   if (!LHSDeclRef || !RHSDeclRef ||
8990       LHSDeclRef->getLocation().isMacroID() ||
8991       RHSDeclRef->getLocation().isMacroID())
8992     return;
8993   const ValueDecl *LHSDecl =
8994     cast<ValueDecl>(LHSDeclRef->getDecl()->getCanonicalDecl());
8995   const ValueDecl *RHSDecl =
8996     cast<ValueDecl>(RHSDeclRef->getDecl()->getCanonicalDecl());
8997   if (LHSDecl != RHSDecl)
8998     return;
8999   if (LHSDecl->getType().isVolatileQualified())
9000     return;
9001   if (const ReferenceType *RefTy = LHSDecl->getType()->getAs<ReferenceType>())
9002     if (RefTy->getPointeeType().isVolatileQualified())
9003       return;
9004 
9005   S.Diag(OpLoc, diag::warn_self_assignment)
9006       << LHSDeclRef->getType()
9007       << LHSExpr->getSourceRange() << RHSExpr->getSourceRange();
9008 }
9009 
9010 /// Check if a bitwise-& is performed on an Objective-C pointer.  This
9011 /// is usually indicative of introspection within the Objective-C pointer.
9012 static void checkObjCPointerIntrospection(Sema &S, ExprResult &L, ExprResult &R,
9013                                           SourceLocation OpLoc) {
9014   if (!S.getLangOpts().ObjC1)
9015     return;
9016 
9017   const Expr *ObjCPointerExpr = 0, *OtherExpr = 0;
9018   const Expr *LHS = L.get();
9019   const Expr *RHS = R.get();
9020 
9021   if (LHS->IgnoreParenCasts()->getType()->isObjCObjectPointerType()) {
9022     ObjCPointerExpr = LHS;
9023     OtherExpr = RHS;
9024   }
9025   else if (RHS->IgnoreParenCasts()->getType()->isObjCObjectPointerType()) {
9026     ObjCPointerExpr = RHS;
9027     OtherExpr = LHS;
9028   }
9029 
9030   // This warning is deliberately made very specific to reduce false
9031   // positives with logic that uses '&' for hashing.  This logic mainly
9032   // looks for code trying to introspect into tagged pointers, which
9033   // code should generally never do.
9034   if (ObjCPointerExpr && isa<IntegerLiteral>(OtherExpr->IgnoreParenCasts())) {
9035     unsigned Diag = diag::warn_objc_pointer_masking;
9036     // Determine if we are introspecting the result of performSelectorXXX.
9037     const Expr *Ex = ObjCPointerExpr->IgnoreParenCasts();
9038     // Special case messages to -performSelector and friends, which
9039     // can return non-pointer values boxed in a pointer value.
9040     // Some clients may wish to silence warnings in this subcase.
9041     if (const ObjCMessageExpr *ME = dyn_cast<ObjCMessageExpr>(Ex)) {
9042       Selector S = ME->getSelector();
9043       StringRef SelArg0 = S.getNameForSlot(0);
9044       if (SelArg0.startswith("performSelector"))
9045         Diag = diag::warn_objc_pointer_masking_performSelector;
9046     }
9047 
9048     S.Diag(OpLoc, Diag)
9049       << ObjCPointerExpr->getSourceRange();
9050   }
9051 }
9052 
9053 /// CreateBuiltinBinOp - Creates a new built-in binary operation with
9054 /// operator @p Opc at location @c TokLoc. This routine only supports
9055 /// built-in operations; ActOnBinOp handles overloaded operators.
9056 ExprResult Sema::CreateBuiltinBinOp(SourceLocation OpLoc,
9057                                     BinaryOperatorKind Opc,
9058                                     Expr *LHSExpr, Expr *RHSExpr) {
9059   if (getLangOpts().CPlusPlus11 && isa<InitListExpr>(RHSExpr)) {
9060     // The syntax only allows initializer lists on the RHS of assignment,
9061     // so we don't need to worry about accepting invalid code for
9062     // non-assignment operators.
9063     // C++11 5.17p9:
9064     //   The meaning of x = {v} [...] is that of x = T(v) [...]. The meaning
9065     //   of x = {} is x = T().
9066     InitializationKind Kind =
9067         InitializationKind::CreateDirectList(RHSExpr->getLocStart());
9068     InitializedEntity Entity =
9069         InitializedEntity::InitializeTemporary(LHSExpr->getType());
9070     InitializationSequence InitSeq(*this, Entity, Kind, RHSExpr);
9071     ExprResult Init = InitSeq.Perform(*this, Entity, Kind, RHSExpr);
9072     if (Init.isInvalid())
9073       return Init;
9074     RHSExpr = Init.take();
9075   }
9076 
9077   ExprResult LHS = Owned(LHSExpr), RHS = Owned(RHSExpr);
9078   QualType ResultTy;     // Result type of the binary operator.
9079   // The following two variables are used for compound assignment operators
9080   QualType CompLHSTy;    // Type of LHS after promotions for computation
9081   QualType CompResultTy; // Type of computation result
9082   ExprValueKind VK = VK_RValue;
9083   ExprObjectKind OK = OK_Ordinary;
9084 
9085   switch (Opc) {
9086   case BO_Assign:
9087     ResultTy = CheckAssignmentOperands(LHS.get(), RHS, OpLoc, QualType());
9088     if (getLangOpts().CPlusPlus &&
9089         LHS.get()->getObjectKind() != OK_ObjCProperty) {
9090       VK = LHS.get()->getValueKind();
9091       OK = LHS.get()->getObjectKind();
9092     }
9093     if (!ResultTy.isNull())
9094       DiagnoseSelfAssignment(*this, LHS.get(), RHS.get(), OpLoc);
9095     break;
9096   case BO_PtrMemD:
9097   case BO_PtrMemI:
9098     ResultTy = CheckPointerToMemberOperands(LHS, RHS, VK, OpLoc,
9099                                             Opc == BO_PtrMemI);
9100     break;
9101   case BO_Mul:
9102   case BO_Div:
9103     ResultTy = CheckMultiplyDivideOperands(LHS, RHS, OpLoc, false,
9104                                            Opc == BO_Div);
9105     break;
9106   case BO_Rem:
9107     ResultTy = CheckRemainderOperands(LHS, RHS, OpLoc);
9108     break;
9109   case BO_Add:
9110     ResultTy = CheckAdditionOperands(LHS, RHS, OpLoc, Opc);
9111     break;
9112   case BO_Sub:
9113     ResultTy = CheckSubtractionOperands(LHS, RHS, OpLoc);
9114     break;
9115   case BO_Shl:
9116   case BO_Shr:
9117     ResultTy = CheckShiftOperands(LHS, RHS, OpLoc, Opc);
9118     break;
9119   case BO_LE:
9120   case BO_LT:
9121   case BO_GE:
9122   case BO_GT:
9123     ResultTy = CheckCompareOperands(LHS, RHS, OpLoc, Opc, true);
9124     break;
9125   case BO_EQ:
9126   case BO_NE:
9127     ResultTy = CheckCompareOperands(LHS, RHS, OpLoc, Opc, false);
9128     break;
9129   case BO_And:
9130     checkObjCPointerIntrospection(*this, LHS, RHS, OpLoc);
9131   case BO_Xor:
9132   case BO_Or:
9133     ResultTy = CheckBitwiseOperands(LHS, RHS, OpLoc);
9134     break;
9135   case BO_LAnd:
9136   case BO_LOr:
9137     ResultTy = CheckLogicalOperands(LHS, RHS, OpLoc, Opc);
9138     break;
9139   case BO_MulAssign:
9140   case BO_DivAssign:
9141     CompResultTy = CheckMultiplyDivideOperands(LHS, RHS, OpLoc, true,
9142                                                Opc == BO_DivAssign);
9143     CompLHSTy = CompResultTy;
9144     if (!CompResultTy.isNull() && !LHS.isInvalid() && !RHS.isInvalid())
9145       ResultTy = CheckAssignmentOperands(LHS.get(), RHS, OpLoc, CompResultTy);
9146     break;
9147   case BO_RemAssign:
9148     CompResultTy = CheckRemainderOperands(LHS, RHS, OpLoc, true);
9149     CompLHSTy = CompResultTy;
9150     if (!CompResultTy.isNull() && !LHS.isInvalid() && !RHS.isInvalid())
9151       ResultTy = CheckAssignmentOperands(LHS.get(), RHS, OpLoc, CompResultTy);
9152     break;
9153   case BO_AddAssign:
9154     CompResultTy = CheckAdditionOperands(LHS, RHS, OpLoc, Opc, &CompLHSTy);
9155     if (!CompResultTy.isNull() && !LHS.isInvalid() && !RHS.isInvalid())
9156       ResultTy = CheckAssignmentOperands(LHS.get(), RHS, OpLoc, CompResultTy);
9157     break;
9158   case BO_SubAssign:
9159     CompResultTy = CheckSubtractionOperands(LHS, RHS, OpLoc, &CompLHSTy);
9160     if (!CompResultTy.isNull() && !LHS.isInvalid() && !RHS.isInvalid())
9161       ResultTy = CheckAssignmentOperands(LHS.get(), RHS, OpLoc, CompResultTy);
9162     break;
9163   case BO_ShlAssign:
9164   case BO_ShrAssign:
9165     CompResultTy = CheckShiftOperands(LHS, RHS, OpLoc, Opc, true);
9166     CompLHSTy = CompResultTy;
9167     if (!CompResultTy.isNull() && !LHS.isInvalid() && !RHS.isInvalid())
9168       ResultTy = CheckAssignmentOperands(LHS.get(), RHS, OpLoc, CompResultTy);
9169     break;
9170   case BO_AndAssign:
9171   case BO_XorAssign:
9172   case BO_OrAssign:
9173     CompResultTy = CheckBitwiseOperands(LHS, RHS, OpLoc, true);
9174     CompLHSTy = CompResultTy;
9175     if (!CompResultTy.isNull() && !LHS.isInvalid() && !RHS.isInvalid())
9176       ResultTy = CheckAssignmentOperands(LHS.get(), RHS, OpLoc, CompResultTy);
9177     break;
9178   case BO_Comma:
9179     ResultTy = CheckCommaOperands(*this, LHS, RHS, OpLoc);
9180     if (getLangOpts().CPlusPlus && !RHS.isInvalid()) {
9181       VK = RHS.get()->getValueKind();
9182       OK = RHS.get()->getObjectKind();
9183     }
9184     break;
9185   }
9186   if (ResultTy.isNull() || LHS.isInvalid() || RHS.isInvalid())
9187     return ExprError();
9188 
9189   // Check for array bounds violations for both sides of the BinaryOperator
9190   CheckArrayAccess(LHS.get());
9191   CheckArrayAccess(RHS.get());
9192 
9193   if (const ObjCIsaExpr *OISA = dyn_cast<ObjCIsaExpr>(LHS.get()->IgnoreParenCasts())) {
9194     NamedDecl *ObjectSetClass = LookupSingleName(TUScope,
9195                                                  &Context.Idents.get("object_setClass"),
9196                                                  SourceLocation(), LookupOrdinaryName);
9197     if (ObjectSetClass && isa<ObjCIsaExpr>(LHS.get())) {
9198       SourceLocation RHSLocEnd = PP.getLocForEndOfToken(RHS.get()->getLocEnd());
9199       Diag(LHS.get()->getExprLoc(), diag::warn_objc_isa_assign) <<
9200       FixItHint::CreateInsertion(LHS.get()->getLocStart(), "object_setClass(") <<
9201       FixItHint::CreateReplacement(SourceRange(OISA->getOpLoc(), OpLoc), ",") <<
9202       FixItHint::CreateInsertion(RHSLocEnd, ")");
9203     }
9204     else
9205       Diag(LHS.get()->getExprLoc(), diag::warn_objc_isa_assign);
9206   }
9207   else if (const ObjCIvarRefExpr *OIRE =
9208            dyn_cast<ObjCIvarRefExpr>(LHS.get()->IgnoreParenCasts()))
9209     DiagnoseDirectIsaAccess(*this, OIRE, OpLoc, RHS.get());
9210 
9211   if (CompResultTy.isNull())
9212     return Owned(new (Context) BinaryOperator(LHS.take(), RHS.take(), Opc,
9213                                               ResultTy, VK, OK, OpLoc,
9214                                               FPFeatures.fp_contract));
9215   if (getLangOpts().CPlusPlus && LHS.get()->getObjectKind() !=
9216       OK_ObjCProperty) {
9217     VK = VK_LValue;
9218     OK = LHS.get()->getObjectKind();
9219   }
9220   return Owned(new (Context) CompoundAssignOperator(LHS.take(), RHS.take(), Opc,
9221                                                     ResultTy, VK, OK, CompLHSTy,
9222                                                     CompResultTy, OpLoc,
9223                                                     FPFeatures.fp_contract));
9224 }
9225 
9226 /// DiagnoseBitwisePrecedence - Emit a warning when bitwise and comparison
9227 /// operators are mixed in a way that suggests that the programmer forgot that
9228 /// comparison operators have higher precedence. The most typical example of
9229 /// such code is "flags & 0x0020 != 0", which is equivalent to "flags & 1".
9230 static void DiagnoseBitwisePrecedence(Sema &Self, BinaryOperatorKind Opc,
9231                                       SourceLocation OpLoc, Expr *LHSExpr,
9232                                       Expr *RHSExpr) {
9233   BinaryOperator *LHSBO = dyn_cast<BinaryOperator>(LHSExpr);
9234   BinaryOperator *RHSBO = dyn_cast<BinaryOperator>(RHSExpr);
9235 
9236   // Check that one of the sides is a comparison operator.
9237   bool isLeftComp = LHSBO && LHSBO->isComparisonOp();
9238   bool isRightComp = RHSBO && RHSBO->isComparisonOp();
9239   if (!isLeftComp && !isRightComp)
9240     return;
9241 
9242   // Bitwise operations are sometimes used as eager logical ops.
9243   // Don't diagnose this.
9244   bool isLeftBitwise = LHSBO && LHSBO->isBitwiseOp();
9245   bool isRightBitwise = RHSBO && RHSBO->isBitwiseOp();
9246   if ((isLeftComp || isLeftBitwise) && (isRightComp || isRightBitwise))
9247     return;
9248 
9249   SourceRange DiagRange = isLeftComp ? SourceRange(LHSExpr->getLocStart(),
9250                                                    OpLoc)
9251                                      : SourceRange(OpLoc, RHSExpr->getLocEnd());
9252   StringRef OpStr = isLeftComp ? LHSBO->getOpcodeStr() : RHSBO->getOpcodeStr();
9253   SourceRange ParensRange = isLeftComp ?
9254       SourceRange(LHSBO->getRHS()->getLocStart(), RHSExpr->getLocEnd())
9255     : SourceRange(LHSExpr->getLocStart(), RHSBO->getLHS()->getLocStart());
9256 
9257   Self.Diag(OpLoc, diag::warn_precedence_bitwise_rel)
9258     << DiagRange << BinaryOperator::getOpcodeStr(Opc) << OpStr;
9259   SuggestParentheses(Self, OpLoc,
9260     Self.PDiag(diag::note_precedence_silence) << OpStr,
9261     (isLeftComp ? LHSExpr : RHSExpr)->getSourceRange());
9262   SuggestParentheses(Self, OpLoc,
9263     Self.PDiag(diag::note_precedence_bitwise_first)
9264       << BinaryOperator::getOpcodeStr(Opc),
9265     ParensRange);
9266 }
9267 
9268 /// \brief It accepts a '&' expr that is inside a '|' one.
9269 /// Emit a diagnostic together with a fixit hint that wraps the '&' expression
9270 /// in parentheses.
9271 static void
9272 EmitDiagnosticForBitwiseAndInBitwiseOr(Sema &Self, SourceLocation OpLoc,
9273                                        BinaryOperator *Bop) {
9274   assert(Bop->getOpcode() == BO_And);
9275   Self.Diag(Bop->getOperatorLoc(), diag::warn_bitwise_and_in_bitwise_or)
9276       << Bop->getSourceRange() << OpLoc;
9277   SuggestParentheses(Self, Bop->getOperatorLoc(),
9278     Self.PDiag(diag::note_precedence_silence)
9279       << Bop->getOpcodeStr(),
9280     Bop->getSourceRange());
9281 }
9282 
9283 /// \brief It accepts a '&&' expr that is inside a '||' one.
9284 /// Emit a diagnostic together with a fixit hint that wraps the '&&' expression
9285 /// in parentheses.
9286 static void
9287 EmitDiagnosticForLogicalAndInLogicalOr(Sema &Self, SourceLocation OpLoc,
9288                                        BinaryOperator *Bop) {
9289   assert(Bop->getOpcode() == BO_LAnd);
9290   Self.Diag(Bop->getOperatorLoc(), diag::warn_logical_and_in_logical_or)
9291       << Bop->getSourceRange() << OpLoc;
9292   SuggestParentheses(Self, Bop->getOperatorLoc(),
9293     Self.PDiag(diag::note_precedence_silence)
9294       << Bop->getOpcodeStr(),
9295     Bop->getSourceRange());
9296 }
9297 
9298 /// \brief Returns true if the given expression can be evaluated as a constant
9299 /// 'true'.
9300 static bool EvaluatesAsTrue(Sema &S, Expr *E) {
9301   bool Res;
9302   return !E->isValueDependent() &&
9303          E->EvaluateAsBooleanCondition(Res, S.getASTContext()) && Res;
9304 }
9305 
9306 /// \brief Returns true if the given expression can be evaluated as a constant
9307 /// 'false'.
9308 static bool EvaluatesAsFalse(Sema &S, Expr *E) {
9309   bool Res;
9310   return !E->isValueDependent() &&
9311          E->EvaluateAsBooleanCondition(Res, S.getASTContext()) && !Res;
9312 }
9313 
9314 /// \brief Look for '&&' in the left hand of a '||' expr.
9315 static void DiagnoseLogicalAndInLogicalOrLHS(Sema &S, SourceLocation OpLoc,
9316                                              Expr *LHSExpr, Expr *RHSExpr) {
9317   if (BinaryOperator *Bop = dyn_cast<BinaryOperator>(LHSExpr)) {
9318     if (Bop->getOpcode() == BO_LAnd) {
9319       // If it's "a && b || 0" don't warn since the precedence doesn't matter.
9320       if (EvaluatesAsFalse(S, RHSExpr))
9321         return;
9322       // If it's "1 && a || b" don't warn since the precedence doesn't matter.
9323       if (!EvaluatesAsTrue(S, Bop->getLHS()))
9324         return EmitDiagnosticForLogicalAndInLogicalOr(S, OpLoc, Bop);
9325     } else if (Bop->getOpcode() == BO_LOr) {
9326       if (BinaryOperator *RBop = dyn_cast<BinaryOperator>(Bop->getRHS())) {
9327         // If it's "a || b && 1 || c" we didn't warn earlier for
9328         // "a || b && 1", but warn now.
9329         if (RBop->getOpcode() == BO_LAnd && EvaluatesAsTrue(S, RBop->getRHS()))
9330           return EmitDiagnosticForLogicalAndInLogicalOr(S, OpLoc, RBop);
9331       }
9332     }
9333   }
9334 }
9335 
9336 /// \brief Look for '&&' in the right hand of a '||' expr.
9337 static void DiagnoseLogicalAndInLogicalOrRHS(Sema &S, SourceLocation OpLoc,
9338                                              Expr *LHSExpr, Expr *RHSExpr) {
9339   if (BinaryOperator *Bop = dyn_cast<BinaryOperator>(RHSExpr)) {
9340     if (Bop->getOpcode() == BO_LAnd) {
9341       // If it's "0 || a && b" don't warn since the precedence doesn't matter.
9342       if (EvaluatesAsFalse(S, LHSExpr))
9343         return;
9344       // If it's "a || b && 1" don't warn since the precedence doesn't matter.
9345       if (!EvaluatesAsTrue(S, Bop->getRHS()))
9346         return EmitDiagnosticForLogicalAndInLogicalOr(S, OpLoc, Bop);
9347     }
9348   }
9349 }
9350 
9351 /// \brief Look for '&' in the left or right hand of a '|' expr.
9352 static void DiagnoseBitwiseAndInBitwiseOr(Sema &S, SourceLocation OpLoc,
9353                                              Expr *OrArg) {
9354   if (BinaryOperator *Bop = dyn_cast<BinaryOperator>(OrArg)) {
9355     if (Bop->getOpcode() == BO_And)
9356       return EmitDiagnosticForBitwiseAndInBitwiseOr(S, OpLoc, Bop);
9357   }
9358 }
9359 
9360 static void DiagnoseAdditionInShift(Sema &S, SourceLocation OpLoc,
9361                                     Expr *SubExpr, StringRef Shift) {
9362   if (BinaryOperator *Bop = dyn_cast<BinaryOperator>(SubExpr)) {
9363     if (Bop->getOpcode() == BO_Add || Bop->getOpcode() == BO_Sub) {
9364       StringRef Op = Bop->getOpcodeStr();
9365       S.Diag(Bop->getOperatorLoc(), diag::warn_addition_in_bitshift)
9366           << Bop->getSourceRange() << OpLoc << Shift << Op;
9367       SuggestParentheses(S, Bop->getOperatorLoc(),
9368           S.PDiag(diag::note_precedence_silence) << Op,
9369           Bop->getSourceRange());
9370     }
9371   }
9372 }
9373 
9374 static void DiagnoseShiftCompare(Sema &S, SourceLocation OpLoc,
9375                                  Expr *LHSExpr, Expr *RHSExpr) {
9376   CXXOperatorCallExpr *OCE = dyn_cast<CXXOperatorCallExpr>(LHSExpr);
9377   if (!OCE)
9378     return;
9379 
9380   FunctionDecl *FD = OCE->getDirectCallee();
9381   if (!FD || !FD->isOverloadedOperator())
9382     return;
9383 
9384   OverloadedOperatorKind Kind = FD->getOverloadedOperator();
9385   if (Kind != OO_LessLess && Kind != OO_GreaterGreater)
9386     return;
9387 
9388   S.Diag(OpLoc, diag::warn_overloaded_shift_in_comparison)
9389       << LHSExpr->getSourceRange() << RHSExpr->getSourceRange()
9390       << (Kind == OO_LessLess);
9391   SuggestParentheses(S, OCE->getOperatorLoc(),
9392                      S.PDiag(diag::note_precedence_silence)
9393                          << (Kind == OO_LessLess ? "<<" : ">>"),
9394                      OCE->getSourceRange());
9395   SuggestParentheses(S, OpLoc,
9396                      S.PDiag(diag::note_evaluate_comparison_first),
9397                      SourceRange(OCE->getArg(1)->getLocStart(),
9398                                  RHSExpr->getLocEnd()));
9399 }
9400 
9401 /// DiagnoseBinOpPrecedence - Emit warnings for expressions with tricky
9402 /// precedence.
9403 static void DiagnoseBinOpPrecedence(Sema &Self, BinaryOperatorKind Opc,
9404                                     SourceLocation OpLoc, Expr *LHSExpr,
9405                                     Expr *RHSExpr){
9406   // Diagnose "arg1 'bitwise' arg2 'eq' arg3".
9407   if (BinaryOperator::isBitwiseOp(Opc))
9408     DiagnoseBitwisePrecedence(Self, Opc, OpLoc, LHSExpr, RHSExpr);
9409 
9410   // Diagnose "arg1 & arg2 | arg3"
9411   if (Opc == BO_Or && !OpLoc.isMacroID()/* Don't warn in macros. */) {
9412     DiagnoseBitwiseAndInBitwiseOr(Self, OpLoc, LHSExpr);
9413     DiagnoseBitwiseAndInBitwiseOr(Self, OpLoc, RHSExpr);
9414   }
9415 
9416   // Warn about arg1 || arg2 && arg3, as GCC 4.3+ does.
9417   // We don't warn for 'assert(a || b && "bad")' since this is safe.
9418   if (Opc == BO_LOr && !OpLoc.isMacroID()/* Don't warn in macros. */) {
9419     DiagnoseLogicalAndInLogicalOrLHS(Self, OpLoc, LHSExpr, RHSExpr);
9420     DiagnoseLogicalAndInLogicalOrRHS(Self, OpLoc, LHSExpr, RHSExpr);
9421   }
9422 
9423   if ((Opc == BO_Shl && LHSExpr->getType()->isIntegralType(Self.getASTContext()))
9424       || Opc == BO_Shr) {
9425     StringRef Shift = BinaryOperator::getOpcodeStr(Opc);
9426     DiagnoseAdditionInShift(Self, OpLoc, LHSExpr, Shift);
9427     DiagnoseAdditionInShift(Self, OpLoc, RHSExpr, Shift);
9428   }
9429 
9430   // Warn on overloaded shift operators and comparisons, such as:
9431   // cout << 5 == 4;
9432   if (BinaryOperator::isComparisonOp(Opc))
9433     DiagnoseShiftCompare(Self, OpLoc, LHSExpr, RHSExpr);
9434 }
9435 
9436 // Binary Operators.  'Tok' is the token for the operator.
9437 ExprResult Sema::ActOnBinOp(Scope *S, SourceLocation TokLoc,
9438                             tok::TokenKind Kind,
9439                             Expr *LHSExpr, Expr *RHSExpr) {
9440   BinaryOperatorKind Opc = ConvertTokenKindToBinaryOpcode(Kind);
9441   assert((LHSExpr != 0) && "ActOnBinOp(): missing left expression");
9442   assert((RHSExpr != 0) && "ActOnBinOp(): missing right expression");
9443 
9444   // Emit warnings for tricky precedence issues, e.g. "bitfield & 0x4 == 0"
9445   DiagnoseBinOpPrecedence(*this, Opc, TokLoc, LHSExpr, RHSExpr);
9446 
9447   return BuildBinOp(S, TokLoc, Opc, LHSExpr, RHSExpr);
9448 }
9449 
9450 /// Build an overloaded binary operator expression in the given scope.
9451 static ExprResult BuildOverloadedBinOp(Sema &S, Scope *Sc, SourceLocation OpLoc,
9452                                        BinaryOperatorKind Opc,
9453                                        Expr *LHS, Expr *RHS) {
9454   // Find all of the overloaded operators visible from this
9455   // point. We perform both an operator-name lookup from the local
9456   // scope and an argument-dependent lookup based on the types of
9457   // the arguments.
9458   UnresolvedSet<16> Functions;
9459   OverloadedOperatorKind OverOp
9460     = BinaryOperator::getOverloadedOperator(Opc);
9461   if (Sc && OverOp != OO_None)
9462     S.LookupOverloadedOperatorName(OverOp, Sc, LHS->getType(),
9463                                    RHS->getType(), Functions);
9464 
9465   // Build the (potentially-overloaded, potentially-dependent)
9466   // binary operation.
9467   return S.CreateOverloadedBinOp(OpLoc, Opc, Functions, LHS, RHS);
9468 }
9469 
9470 ExprResult Sema::BuildBinOp(Scope *S, SourceLocation OpLoc,
9471                             BinaryOperatorKind Opc,
9472                             Expr *LHSExpr, Expr *RHSExpr) {
9473   // We want to end up calling one of checkPseudoObjectAssignment
9474   // (if the LHS is a pseudo-object), BuildOverloadedBinOp (if
9475   // both expressions are overloadable or either is type-dependent),
9476   // or CreateBuiltinBinOp (in any other case).  We also want to get
9477   // any placeholder types out of the way.
9478 
9479   // Handle pseudo-objects in the LHS.
9480   if (const BuiltinType *pty = LHSExpr->getType()->getAsPlaceholderType()) {
9481     // Assignments with a pseudo-object l-value need special analysis.
9482     if (pty->getKind() == BuiltinType::PseudoObject &&
9483         BinaryOperator::isAssignmentOp(Opc))
9484       return checkPseudoObjectAssignment(S, OpLoc, Opc, LHSExpr, RHSExpr);
9485 
9486     // Don't resolve overloads if the other type is overloadable.
9487     if (pty->getKind() == BuiltinType::Overload) {
9488       // We can't actually test that if we still have a placeholder,
9489       // though.  Fortunately, none of the exceptions we see in that
9490       // code below are valid when the LHS is an overload set.  Note
9491       // that an overload set can be dependently-typed, but it never
9492       // instantiates to having an overloadable type.
9493       ExprResult resolvedRHS = CheckPlaceholderExpr(RHSExpr);
9494       if (resolvedRHS.isInvalid()) return ExprError();
9495       RHSExpr = resolvedRHS.take();
9496 
9497       if (RHSExpr->isTypeDependent() ||
9498           RHSExpr->getType()->isOverloadableType())
9499         return BuildOverloadedBinOp(*this, S, OpLoc, Opc, LHSExpr, RHSExpr);
9500     }
9501 
9502     ExprResult LHS = CheckPlaceholderExpr(LHSExpr);
9503     if (LHS.isInvalid()) return ExprError();
9504     LHSExpr = LHS.take();
9505   }
9506 
9507   // Handle pseudo-objects in the RHS.
9508   if (const BuiltinType *pty = RHSExpr->getType()->getAsPlaceholderType()) {
9509     // An overload in the RHS can potentially be resolved by the type
9510     // being assigned to.
9511     if (Opc == BO_Assign && pty->getKind() == BuiltinType::Overload) {
9512       if (LHSExpr->isTypeDependent() || RHSExpr->isTypeDependent())
9513         return BuildOverloadedBinOp(*this, S, OpLoc, Opc, LHSExpr, RHSExpr);
9514 
9515       if (LHSExpr->getType()->isOverloadableType())
9516         return BuildOverloadedBinOp(*this, S, OpLoc, Opc, LHSExpr, RHSExpr);
9517 
9518       return CreateBuiltinBinOp(OpLoc, Opc, LHSExpr, RHSExpr);
9519     }
9520 
9521     // Don't resolve overloads if the other type is overloadable.
9522     if (pty->getKind() == BuiltinType::Overload &&
9523         LHSExpr->getType()->isOverloadableType())
9524       return BuildOverloadedBinOp(*this, S, OpLoc, Opc, LHSExpr, RHSExpr);
9525 
9526     ExprResult resolvedRHS = CheckPlaceholderExpr(RHSExpr);
9527     if (!resolvedRHS.isUsable()) return ExprError();
9528     RHSExpr = resolvedRHS.take();
9529   }
9530 
9531   if (getLangOpts().CPlusPlus) {
9532     // If either expression is type-dependent, always build an
9533     // overloaded op.
9534     if (LHSExpr->isTypeDependent() || RHSExpr->isTypeDependent())
9535       return BuildOverloadedBinOp(*this, S, OpLoc, Opc, LHSExpr, RHSExpr);
9536 
9537     // Otherwise, build an overloaded op if either expression has an
9538     // overloadable type.
9539     if (LHSExpr->getType()->isOverloadableType() ||
9540         RHSExpr->getType()->isOverloadableType())
9541       return BuildOverloadedBinOp(*this, S, OpLoc, Opc, LHSExpr, RHSExpr);
9542   }
9543 
9544   // Build a built-in binary operation.
9545   return CreateBuiltinBinOp(OpLoc, Opc, LHSExpr, RHSExpr);
9546 }
9547 
9548 ExprResult Sema::CreateBuiltinUnaryOp(SourceLocation OpLoc,
9549                                       UnaryOperatorKind Opc,
9550                                       Expr *InputExpr) {
9551   ExprResult Input = Owned(InputExpr);
9552   ExprValueKind VK = VK_RValue;
9553   ExprObjectKind OK = OK_Ordinary;
9554   QualType resultType;
9555   switch (Opc) {
9556   case UO_PreInc:
9557   case UO_PreDec:
9558   case UO_PostInc:
9559   case UO_PostDec:
9560     resultType = CheckIncrementDecrementOperand(*this, Input.get(), VK, OpLoc,
9561                                                 Opc == UO_PreInc ||
9562                                                 Opc == UO_PostInc,
9563                                                 Opc == UO_PreInc ||
9564                                                 Opc == UO_PreDec);
9565     break;
9566   case UO_AddrOf:
9567     resultType = CheckAddressOfOperand(Input, OpLoc);
9568     break;
9569   case UO_Deref: {
9570     Input = DefaultFunctionArrayLvalueConversion(Input.take());
9571     if (Input.isInvalid()) return ExprError();
9572     resultType = CheckIndirectionOperand(*this, Input.get(), VK, OpLoc);
9573     break;
9574   }
9575   case UO_Plus:
9576   case UO_Minus:
9577     Input = UsualUnaryConversions(Input.take());
9578     if (Input.isInvalid()) return ExprError();
9579     resultType = Input.get()->getType();
9580     if (resultType->isDependentType())
9581       break;
9582     if (resultType->isArithmeticType() || // C99 6.5.3.3p1
9583         resultType->isVectorType())
9584       break;
9585     else if (getLangOpts().CPlusPlus && // C++ [expr.unary.op]p6
9586              Opc == UO_Plus &&
9587              resultType->isPointerType())
9588       break;
9589 
9590     return ExprError(Diag(OpLoc, diag::err_typecheck_unary_expr)
9591       << resultType << Input.get()->getSourceRange());
9592 
9593   case UO_Not: // bitwise complement
9594     Input = UsualUnaryConversions(Input.take());
9595     if (Input.isInvalid())
9596       return ExprError();
9597     resultType = Input.get()->getType();
9598     if (resultType->isDependentType())
9599       break;
9600     // C99 6.5.3.3p1. We allow complex int and float as a GCC extension.
9601     if (resultType->isComplexType() || resultType->isComplexIntegerType())
9602       // C99 does not support '~' for complex conjugation.
9603       Diag(OpLoc, diag::ext_integer_complement_complex)
9604           << resultType << Input.get()->getSourceRange();
9605     else if (resultType->hasIntegerRepresentation())
9606       break;
9607     else if (resultType->isExtVectorType()) {
9608       if (Context.getLangOpts().OpenCL) {
9609         // OpenCL v1.1 s6.3.f: The bitwise operator not (~) does not operate
9610         // on vector float types.
9611         QualType T = resultType->getAs<ExtVectorType>()->getElementType();
9612         if (!T->isIntegerType())
9613           return ExprError(Diag(OpLoc, diag::err_typecheck_unary_expr)
9614                            << resultType << Input.get()->getSourceRange());
9615       }
9616       break;
9617     } else {
9618       return ExprError(Diag(OpLoc, diag::err_typecheck_unary_expr)
9619                        << resultType << Input.get()->getSourceRange());
9620     }
9621     break;
9622 
9623   case UO_LNot: // logical negation
9624     // Unlike +/-/~, integer promotions aren't done here (C99 6.5.3.3p5).
9625     Input = DefaultFunctionArrayLvalueConversion(Input.take());
9626     if (Input.isInvalid()) return ExprError();
9627     resultType = Input.get()->getType();
9628 
9629     // Though we still have to promote half FP to float...
9630     if (resultType->isHalfType() && !Context.getLangOpts().NativeHalfType) {
9631       Input = ImpCastExprToType(Input.take(), Context.FloatTy, CK_FloatingCast).take();
9632       resultType = Context.FloatTy;
9633     }
9634 
9635     if (resultType->isDependentType())
9636       break;
9637     if (resultType->isScalarType()) {
9638       // C99 6.5.3.3p1: ok, fallthrough;
9639       if (Context.getLangOpts().CPlusPlus) {
9640         // C++03 [expr.unary.op]p8, C++0x [expr.unary.op]p9:
9641         // operand contextually converted to bool.
9642         Input = ImpCastExprToType(Input.take(), Context.BoolTy,
9643                                   ScalarTypeToBooleanCastKind(resultType));
9644       } else if (Context.getLangOpts().OpenCL &&
9645                  Context.getLangOpts().OpenCLVersion < 120) {
9646         // OpenCL v1.1 6.3.h: The logical operator not (!) does not
9647         // operate on scalar float types.
9648         if (!resultType->isIntegerType())
9649           return ExprError(Diag(OpLoc, diag::err_typecheck_unary_expr)
9650                            << resultType << Input.get()->getSourceRange());
9651       }
9652     } else if (resultType->isExtVectorType()) {
9653       if (Context.getLangOpts().OpenCL &&
9654           Context.getLangOpts().OpenCLVersion < 120) {
9655         // OpenCL v1.1 6.3.h: The logical operator not (!) does not
9656         // operate on vector float types.
9657         QualType T = resultType->getAs<ExtVectorType>()->getElementType();
9658         if (!T->isIntegerType())
9659           return ExprError(Diag(OpLoc, diag::err_typecheck_unary_expr)
9660                            << resultType << Input.get()->getSourceRange());
9661       }
9662       // Vector logical not returns the signed variant of the operand type.
9663       resultType = GetSignedVectorType(resultType);
9664       break;
9665     } else {
9666       return ExprError(Diag(OpLoc, diag::err_typecheck_unary_expr)
9667         << resultType << Input.get()->getSourceRange());
9668     }
9669 
9670     // LNot always has type int. C99 6.5.3.3p5.
9671     // In C++, it's bool. C++ 5.3.1p8
9672     resultType = Context.getLogicalOperationType();
9673     break;
9674   case UO_Real:
9675   case UO_Imag:
9676     resultType = CheckRealImagOperand(*this, Input, OpLoc, Opc == UO_Real);
9677     // _Real maps ordinary l-values into ordinary l-values. _Imag maps ordinary
9678     // complex l-values to ordinary l-values and all other values to r-values.
9679     if (Input.isInvalid()) return ExprError();
9680     if (Opc == UO_Real || Input.get()->getType()->isAnyComplexType()) {
9681       if (Input.get()->getValueKind() != VK_RValue &&
9682           Input.get()->getObjectKind() == OK_Ordinary)
9683         VK = Input.get()->getValueKind();
9684     } else if (!getLangOpts().CPlusPlus) {
9685       // In C, a volatile scalar is read by __imag. In C++, it is not.
9686       Input = DefaultLvalueConversion(Input.take());
9687     }
9688     break;
9689   case UO_Extension:
9690     resultType = Input.get()->getType();
9691     VK = Input.get()->getValueKind();
9692     OK = Input.get()->getObjectKind();
9693     break;
9694   }
9695   if (resultType.isNull() || Input.isInvalid())
9696     return ExprError();
9697 
9698   // Check for array bounds violations in the operand of the UnaryOperator,
9699   // except for the '*' and '&' operators that have to be handled specially
9700   // by CheckArrayAccess (as there are special cases like &array[arraysize]
9701   // that are explicitly defined as valid by the standard).
9702   if (Opc != UO_AddrOf && Opc != UO_Deref)
9703     CheckArrayAccess(Input.get());
9704 
9705   return Owned(new (Context) UnaryOperator(Input.take(), Opc, resultType,
9706                                            VK, OK, OpLoc));
9707 }
9708 
9709 /// \brief Determine whether the given expression is a qualified member
9710 /// access expression, of a form that could be turned into a pointer to member
9711 /// with the address-of operator.
9712 static bool isQualifiedMemberAccess(Expr *E) {
9713   if (DeclRefExpr *DRE = dyn_cast<DeclRefExpr>(E)) {
9714     if (!DRE->getQualifier())
9715       return false;
9716 
9717     ValueDecl *VD = DRE->getDecl();
9718     if (!VD->isCXXClassMember())
9719       return false;
9720 
9721     if (isa<FieldDecl>(VD) || isa<IndirectFieldDecl>(VD))
9722       return true;
9723     if (CXXMethodDecl *Method = dyn_cast<CXXMethodDecl>(VD))
9724       return Method->isInstance();
9725 
9726     return false;
9727   }
9728 
9729   if (UnresolvedLookupExpr *ULE = dyn_cast<UnresolvedLookupExpr>(E)) {
9730     if (!ULE->getQualifier())
9731       return false;
9732 
9733     for (UnresolvedLookupExpr::decls_iterator D = ULE->decls_begin(),
9734                                            DEnd = ULE->decls_end();
9735          D != DEnd; ++D) {
9736       if (CXXMethodDecl *Method = dyn_cast<CXXMethodDecl>(*D)) {
9737         if (Method->isInstance())
9738           return true;
9739       } else {
9740         // Overload set does not contain methods.
9741         break;
9742       }
9743     }
9744 
9745     return false;
9746   }
9747 
9748   return false;
9749 }
9750 
9751 ExprResult Sema::BuildUnaryOp(Scope *S, SourceLocation OpLoc,
9752                               UnaryOperatorKind Opc, Expr *Input) {
9753   // First things first: handle placeholders so that the
9754   // overloaded-operator check considers the right type.
9755   if (const BuiltinType *pty = Input->getType()->getAsPlaceholderType()) {
9756     // Increment and decrement of pseudo-object references.
9757     if (pty->getKind() == BuiltinType::PseudoObject &&
9758         UnaryOperator::isIncrementDecrementOp(Opc))
9759       return checkPseudoObjectIncDec(S, OpLoc, Opc, Input);
9760 
9761     // extension is always a builtin operator.
9762     if (Opc == UO_Extension)
9763       return CreateBuiltinUnaryOp(OpLoc, Opc, Input);
9764 
9765     // & gets special logic for several kinds of placeholder.
9766     // The builtin code knows what to do.
9767     if (Opc == UO_AddrOf &&
9768         (pty->getKind() == BuiltinType::Overload ||
9769          pty->getKind() == BuiltinType::UnknownAny ||
9770          pty->getKind() == BuiltinType::BoundMember))
9771       return CreateBuiltinUnaryOp(OpLoc, Opc, Input);
9772 
9773     // Anything else needs to be handled now.
9774     ExprResult Result = CheckPlaceholderExpr(Input);
9775     if (Result.isInvalid()) return ExprError();
9776     Input = Result.take();
9777   }
9778 
9779   if (getLangOpts().CPlusPlus && Input->getType()->isOverloadableType() &&
9780       UnaryOperator::getOverloadedOperator(Opc) != OO_None &&
9781       !(Opc == UO_AddrOf && isQualifiedMemberAccess(Input))) {
9782     // Find all of the overloaded operators visible from this
9783     // point. We perform both an operator-name lookup from the local
9784     // scope and an argument-dependent lookup based on the types of
9785     // the arguments.
9786     UnresolvedSet<16> Functions;
9787     OverloadedOperatorKind OverOp = UnaryOperator::getOverloadedOperator(Opc);
9788     if (S && OverOp != OO_None)
9789       LookupOverloadedOperatorName(OverOp, S, Input->getType(), QualType(),
9790                                    Functions);
9791 
9792     return CreateOverloadedUnaryOp(OpLoc, Opc, Functions, Input);
9793   }
9794 
9795   return CreateBuiltinUnaryOp(OpLoc, Opc, Input);
9796 }
9797 
9798 // Unary Operators.  'Tok' is the token for the operator.
9799 ExprResult Sema::ActOnUnaryOp(Scope *S, SourceLocation OpLoc,
9800                               tok::TokenKind Op, Expr *Input) {
9801   return BuildUnaryOp(S, OpLoc, ConvertTokenKindToUnaryOpcode(Op), Input);
9802 }
9803 
9804 /// ActOnAddrLabel - Parse the GNU address of label extension: "&&foo".
9805 ExprResult Sema::ActOnAddrLabel(SourceLocation OpLoc, SourceLocation LabLoc,
9806                                 LabelDecl *TheDecl) {
9807   TheDecl->markUsed(Context);
9808   // Create the AST node.  The address of a label always has type 'void*'.
9809   return Owned(new (Context) AddrLabelExpr(OpLoc, LabLoc, TheDecl,
9810                                        Context.getPointerType(Context.VoidTy)));
9811 }
9812 
9813 /// Given the last statement in a statement-expression, check whether
9814 /// the result is a producing expression (like a call to an
9815 /// ns_returns_retained function) and, if so, rebuild it to hoist the
9816 /// release out of the full-expression.  Otherwise, return null.
9817 /// Cannot fail.
9818 static Expr *maybeRebuildARCConsumingStmt(Stmt *Statement) {
9819   // Should always be wrapped with one of these.
9820   ExprWithCleanups *cleanups = dyn_cast<ExprWithCleanups>(Statement);
9821   if (!cleanups) return 0;
9822 
9823   ImplicitCastExpr *cast = dyn_cast<ImplicitCastExpr>(cleanups->getSubExpr());
9824   if (!cast || cast->getCastKind() != CK_ARCConsumeObject)
9825     return 0;
9826 
9827   // Splice out the cast.  This shouldn't modify any interesting
9828   // features of the statement.
9829   Expr *producer = cast->getSubExpr();
9830   assert(producer->getType() == cast->getType());
9831   assert(producer->getValueKind() == cast->getValueKind());
9832   cleanups->setSubExpr(producer);
9833   return cleanups;
9834 }
9835 
9836 void Sema::ActOnStartStmtExpr() {
9837   PushExpressionEvaluationContext(ExprEvalContexts.back().Context);
9838 }
9839 
9840 void Sema::ActOnStmtExprError() {
9841   // Note that function is also called by TreeTransform when leaving a
9842   // StmtExpr scope without rebuilding anything.
9843 
9844   DiscardCleanupsInEvaluationContext();
9845   PopExpressionEvaluationContext();
9846 }
9847 
9848 ExprResult
9849 Sema::ActOnStmtExpr(SourceLocation LPLoc, Stmt *SubStmt,
9850                     SourceLocation RPLoc) { // "({..})"
9851   assert(SubStmt && isa<CompoundStmt>(SubStmt) && "Invalid action invocation!");
9852   CompoundStmt *Compound = cast<CompoundStmt>(SubStmt);
9853 
9854   if (hasAnyUnrecoverableErrorsInThisFunction())
9855     DiscardCleanupsInEvaluationContext();
9856   assert(!ExprNeedsCleanups && "cleanups within StmtExpr not correctly bound!");
9857   PopExpressionEvaluationContext();
9858 
9859   bool isFileScope
9860     = (getCurFunctionOrMethodDecl() == 0) && (getCurBlock() == 0);
9861   if (isFileScope)
9862     return ExprError(Diag(LPLoc, diag::err_stmtexpr_file_scope));
9863 
9864   // FIXME: there are a variety of strange constraints to enforce here, for
9865   // example, it is not possible to goto into a stmt expression apparently.
9866   // More semantic analysis is needed.
9867 
9868   // If there are sub stmts in the compound stmt, take the type of the last one
9869   // as the type of the stmtexpr.
9870   QualType Ty = Context.VoidTy;
9871   bool StmtExprMayBindToTemp = false;
9872   if (!Compound->body_empty()) {
9873     Stmt *LastStmt = Compound->body_back();
9874     LabelStmt *LastLabelStmt = 0;
9875     // If LastStmt is a label, skip down through into the body.
9876     while (LabelStmt *Label = dyn_cast<LabelStmt>(LastStmt)) {
9877       LastLabelStmt = Label;
9878       LastStmt = Label->getSubStmt();
9879     }
9880 
9881     if (Expr *LastE = dyn_cast<Expr>(LastStmt)) {
9882       // Do function/array conversion on the last expression, but not
9883       // lvalue-to-rvalue.  However, initialize an unqualified type.
9884       ExprResult LastExpr = DefaultFunctionArrayConversion(LastE);
9885       if (LastExpr.isInvalid())
9886         return ExprError();
9887       Ty = LastExpr.get()->getType().getUnqualifiedType();
9888 
9889       if (!Ty->isDependentType() && !LastExpr.get()->isTypeDependent()) {
9890         // In ARC, if the final expression ends in a consume, splice
9891         // the consume out and bind it later.  In the alternate case
9892         // (when dealing with a retainable type), the result
9893         // initialization will create a produce.  In both cases the
9894         // result will be +1, and we'll need to balance that out with
9895         // a bind.
9896         if (Expr *rebuiltLastStmt
9897               = maybeRebuildARCConsumingStmt(LastExpr.get())) {
9898           LastExpr = rebuiltLastStmt;
9899         } else {
9900           LastExpr = PerformCopyInitialization(
9901                             InitializedEntity::InitializeResult(LPLoc,
9902                                                                 Ty,
9903                                                                 false),
9904                                                    SourceLocation(),
9905                                                LastExpr);
9906         }
9907 
9908         if (LastExpr.isInvalid())
9909           return ExprError();
9910         if (LastExpr.get() != 0) {
9911           if (!LastLabelStmt)
9912             Compound->setLastStmt(LastExpr.take());
9913           else
9914             LastLabelStmt->setSubStmt(LastExpr.take());
9915           StmtExprMayBindToTemp = true;
9916         }
9917       }
9918     }
9919   }
9920 
9921   // FIXME: Check that expression type is complete/non-abstract; statement
9922   // expressions are not lvalues.
9923   Expr *ResStmtExpr = new (Context) StmtExpr(Compound, Ty, LPLoc, RPLoc);
9924   if (StmtExprMayBindToTemp)
9925     return MaybeBindToTemporary(ResStmtExpr);
9926   return Owned(ResStmtExpr);
9927 }
9928 
9929 ExprResult Sema::BuildBuiltinOffsetOf(SourceLocation BuiltinLoc,
9930                                       TypeSourceInfo *TInfo,
9931                                       OffsetOfComponent *CompPtr,
9932                                       unsigned NumComponents,
9933                                       SourceLocation RParenLoc) {
9934   QualType ArgTy = TInfo->getType();
9935   bool Dependent = ArgTy->isDependentType();
9936   SourceRange TypeRange = TInfo->getTypeLoc().getLocalSourceRange();
9937 
9938   // We must have at least one component that refers to the type, and the first
9939   // one is known to be a field designator.  Verify that the ArgTy represents
9940   // a struct/union/class.
9941   if (!Dependent && !ArgTy->isRecordType())
9942     return ExprError(Diag(BuiltinLoc, diag::err_offsetof_record_type)
9943                        << ArgTy << TypeRange);
9944 
9945   // Type must be complete per C99 7.17p3 because a declaring a variable
9946   // with an incomplete type would be ill-formed.
9947   if (!Dependent
9948       && RequireCompleteType(BuiltinLoc, ArgTy,
9949                              diag::err_offsetof_incomplete_type, TypeRange))
9950     return ExprError();
9951 
9952   // offsetof with non-identifier designators (e.g. "offsetof(x, a.b[c])") are a
9953   // GCC extension, diagnose them.
9954   // FIXME: This diagnostic isn't actually visible because the location is in
9955   // a system header!
9956   if (NumComponents != 1)
9957     Diag(BuiltinLoc, diag::ext_offsetof_extended_field_designator)
9958       << SourceRange(CompPtr[1].LocStart, CompPtr[NumComponents-1].LocEnd);
9959 
9960   bool DidWarnAboutNonPOD = false;
9961   QualType CurrentType = ArgTy;
9962   typedef OffsetOfExpr::OffsetOfNode OffsetOfNode;
9963   SmallVector<OffsetOfNode, 4> Comps;
9964   SmallVector<Expr*, 4> Exprs;
9965   for (unsigned i = 0; i != NumComponents; ++i) {
9966     const OffsetOfComponent &OC = CompPtr[i];
9967     if (OC.isBrackets) {
9968       // Offset of an array sub-field.  TODO: Should we allow vector elements?
9969       if (!CurrentType->isDependentType()) {
9970         const ArrayType *AT = Context.getAsArrayType(CurrentType);
9971         if(!AT)
9972           return ExprError(Diag(OC.LocEnd, diag::err_offsetof_array_type)
9973                            << CurrentType);
9974         CurrentType = AT->getElementType();
9975       } else
9976         CurrentType = Context.DependentTy;
9977 
9978       ExprResult IdxRval = DefaultLvalueConversion(static_cast<Expr*>(OC.U.E));
9979       if (IdxRval.isInvalid())
9980         return ExprError();
9981       Expr *Idx = IdxRval.take();
9982 
9983       // The expression must be an integral expression.
9984       // FIXME: An integral constant expression?
9985       if (!Idx->isTypeDependent() && !Idx->isValueDependent() &&
9986           !Idx->getType()->isIntegerType())
9987         return ExprError(Diag(Idx->getLocStart(),
9988                               diag::err_typecheck_subscript_not_integer)
9989                          << Idx->getSourceRange());
9990 
9991       // Record this array index.
9992       Comps.push_back(OffsetOfNode(OC.LocStart, Exprs.size(), OC.LocEnd));
9993       Exprs.push_back(Idx);
9994       continue;
9995     }
9996 
9997     // Offset of a field.
9998     if (CurrentType->isDependentType()) {
9999       // We have the offset of a field, but we can't look into the dependent
10000       // type. Just record the identifier of the field.
10001       Comps.push_back(OffsetOfNode(OC.LocStart, OC.U.IdentInfo, OC.LocEnd));
10002       CurrentType = Context.DependentTy;
10003       continue;
10004     }
10005 
10006     // We need to have a complete type to look into.
10007     if (RequireCompleteType(OC.LocStart, CurrentType,
10008                             diag::err_offsetof_incomplete_type))
10009       return ExprError();
10010 
10011     // Look for the designated field.
10012     const RecordType *RC = CurrentType->getAs<RecordType>();
10013     if (!RC)
10014       return ExprError(Diag(OC.LocEnd, diag::err_offsetof_record_type)
10015                        << CurrentType);
10016     RecordDecl *RD = RC->getDecl();
10017 
10018     // C++ [lib.support.types]p5:
10019     //   The macro offsetof accepts a restricted set of type arguments in this
10020     //   International Standard. type shall be a POD structure or a POD union
10021     //   (clause 9).
10022     // C++11 [support.types]p4:
10023     //   If type is not a standard-layout class (Clause 9), the results are
10024     //   undefined.
10025     if (CXXRecordDecl *CRD = dyn_cast<CXXRecordDecl>(RD)) {
10026       bool IsSafe = LangOpts.CPlusPlus11? CRD->isStandardLayout() : CRD->isPOD();
10027       unsigned DiagID =
10028         LangOpts.CPlusPlus11? diag::warn_offsetof_non_standardlayout_type
10029                             : diag::warn_offsetof_non_pod_type;
10030 
10031       if (!IsSafe && !DidWarnAboutNonPOD &&
10032           DiagRuntimeBehavior(BuiltinLoc, 0,
10033                               PDiag(DiagID)
10034                               << SourceRange(CompPtr[0].LocStart, OC.LocEnd)
10035                               << CurrentType))
10036         DidWarnAboutNonPOD = true;
10037     }
10038 
10039     // Look for the field.
10040     LookupResult R(*this, OC.U.IdentInfo, OC.LocStart, LookupMemberName);
10041     LookupQualifiedName(R, RD);
10042     FieldDecl *MemberDecl = R.getAsSingle<FieldDecl>();
10043     IndirectFieldDecl *IndirectMemberDecl = 0;
10044     if (!MemberDecl) {
10045       if ((IndirectMemberDecl = R.getAsSingle<IndirectFieldDecl>()))
10046         MemberDecl = IndirectMemberDecl->getAnonField();
10047     }
10048 
10049     if (!MemberDecl)
10050       return ExprError(Diag(BuiltinLoc, diag::err_no_member)
10051                        << OC.U.IdentInfo << RD << SourceRange(OC.LocStart,
10052                                                               OC.LocEnd));
10053 
10054     // C99 7.17p3:
10055     //   (If the specified member is a bit-field, the behavior is undefined.)
10056     //
10057     // We diagnose this as an error.
10058     if (MemberDecl->isBitField()) {
10059       Diag(OC.LocEnd, diag::err_offsetof_bitfield)
10060         << MemberDecl->getDeclName()
10061         << SourceRange(BuiltinLoc, RParenLoc);
10062       Diag(MemberDecl->getLocation(), diag::note_bitfield_decl);
10063       return ExprError();
10064     }
10065 
10066     RecordDecl *Parent = MemberDecl->getParent();
10067     if (IndirectMemberDecl)
10068       Parent = cast<RecordDecl>(IndirectMemberDecl->getDeclContext());
10069 
10070     // If the member was found in a base class, introduce OffsetOfNodes for
10071     // the base class indirections.
10072     CXXBasePaths Paths;
10073     if (IsDerivedFrom(CurrentType, Context.getTypeDeclType(Parent), Paths)) {
10074       if (Paths.getDetectedVirtual()) {
10075         Diag(OC.LocEnd, diag::err_offsetof_field_of_virtual_base)
10076           << MemberDecl->getDeclName()
10077           << SourceRange(BuiltinLoc, RParenLoc);
10078         return ExprError();
10079       }
10080 
10081       CXXBasePath &Path = Paths.front();
10082       for (CXXBasePath::iterator B = Path.begin(), BEnd = Path.end();
10083            B != BEnd; ++B)
10084         Comps.push_back(OffsetOfNode(B->Base));
10085     }
10086 
10087     if (IndirectMemberDecl) {
10088       for (IndirectFieldDecl::chain_iterator FI =
10089            IndirectMemberDecl->chain_begin(),
10090            FEnd = IndirectMemberDecl->chain_end(); FI != FEnd; FI++) {
10091         assert(isa<FieldDecl>(*FI));
10092         Comps.push_back(OffsetOfNode(OC.LocStart,
10093                                      cast<FieldDecl>(*FI), OC.LocEnd));
10094       }
10095     } else
10096       Comps.push_back(OffsetOfNode(OC.LocStart, MemberDecl, OC.LocEnd));
10097 
10098     CurrentType = MemberDecl->getType().getNonReferenceType();
10099   }
10100 
10101   return Owned(OffsetOfExpr::Create(Context, Context.getSizeType(), BuiltinLoc,
10102                                     TInfo, Comps, Exprs, RParenLoc));
10103 }
10104 
10105 ExprResult Sema::ActOnBuiltinOffsetOf(Scope *S,
10106                                       SourceLocation BuiltinLoc,
10107                                       SourceLocation TypeLoc,
10108                                       ParsedType ParsedArgTy,
10109                                       OffsetOfComponent *CompPtr,
10110                                       unsigned NumComponents,
10111                                       SourceLocation RParenLoc) {
10112 
10113   TypeSourceInfo *ArgTInfo;
10114   QualType ArgTy = GetTypeFromParser(ParsedArgTy, &ArgTInfo);
10115   if (ArgTy.isNull())
10116     return ExprError();
10117 
10118   if (!ArgTInfo)
10119     ArgTInfo = Context.getTrivialTypeSourceInfo(ArgTy, TypeLoc);
10120 
10121   return BuildBuiltinOffsetOf(BuiltinLoc, ArgTInfo, CompPtr, NumComponents,
10122                               RParenLoc);
10123 }
10124 
10125 
10126 ExprResult Sema::ActOnChooseExpr(SourceLocation BuiltinLoc,
10127                                  Expr *CondExpr,
10128                                  Expr *LHSExpr, Expr *RHSExpr,
10129                                  SourceLocation RPLoc) {
10130   assert((CondExpr && LHSExpr && RHSExpr) && "Missing type argument(s)");
10131 
10132   ExprValueKind VK = VK_RValue;
10133   ExprObjectKind OK = OK_Ordinary;
10134   QualType resType;
10135   bool ValueDependent = false;
10136   bool CondIsTrue = false;
10137   if (CondExpr->isTypeDependent() || CondExpr->isValueDependent()) {
10138     resType = Context.DependentTy;
10139     ValueDependent = true;
10140   } else {
10141     // The conditional expression is required to be a constant expression.
10142     llvm::APSInt condEval(32);
10143     ExprResult CondICE
10144       = VerifyIntegerConstantExpression(CondExpr, &condEval,
10145           diag::err_typecheck_choose_expr_requires_constant, false);
10146     if (CondICE.isInvalid())
10147       return ExprError();
10148     CondExpr = CondICE.take();
10149     CondIsTrue = condEval.getZExtValue();
10150 
10151     // If the condition is > zero, then the AST type is the same as the LSHExpr.
10152     Expr *ActiveExpr = CondIsTrue ? LHSExpr : RHSExpr;
10153 
10154     resType = ActiveExpr->getType();
10155     ValueDependent = ActiveExpr->isValueDependent();
10156     VK = ActiveExpr->getValueKind();
10157     OK = ActiveExpr->getObjectKind();
10158   }
10159 
10160   return Owned(new (Context) ChooseExpr(BuiltinLoc, CondExpr, LHSExpr, RHSExpr,
10161                                         resType, VK, OK, RPLoc, CondIsTrue,
10162                                         resType->isDependentType(),
10163                                         ValueDependent));
10164 }
10165 
10166 //===----------------------------------------------------------------------===//
10167 // Clang Extensions.
10168 //===----------------------------------------------------------------------===//
10169 
10170 /// ActOnBlockStart - This callback is invoked when a block literal is started.
10171 void Sema::ActOnBlockStart(SourceLocation CaretLoc, Scope *CurScope) {
10172   BlockDecl *Block = BlockDecl::Create(Context, CurContext, CaretLoc);
10173 
10174   if (LangOpts.CPlusPlus) {
10175     Decl *ManglingContextDecl;
10176     if (MangleNumberingContext *MCtx =
10177             getCurrentMangleNumberContext(Block->getDeclContext(),
10178                                           ManglingContextDecl)) {
10179       unsigned ManglingNumber = MCtx->getManglingNumber(Block);
10180       Block->setBlockMangling(ManglingNumber, ManglingContextDecl);
10181     }
10182   }
10183 
10184   PushBlockScope(CurScope, Block);
10185   CurContext->addDecl(Block);
10186   if (CurScope)
10187     PushDeclContext(CurScope, Block);
10188   else
10189     CurContext = Block;
10190 
10191   getCurBlock()->HasImplicitReturnType = true;
10192 
10193   // Enter a new evaluation context to insulate the block from any
10194   // cleanups from the enclosing full-expression.
10195   PushExpressionEvaluationContext(PotentiallyEvaluated);
10196 }
10197 
10198 void Sema::ActOnBlockArguments(SourceLocation CaretLoc, Declarator &ParamInfo,
10199                                Scope *CurScope) {
10200   assert(ParamInfo.getIdentifier()==0 && "block-id should have no identifier!");
10201   assert(ParamInfo.getContext() == Declarator::BlockLiteralContext);
10202   BlockScopeInfo *CurBlock = getCurBlock();
10203 
10204   TypeSourceInfo *Sig = GetTypeForDeclarator(ParamInfo, CurScope);
10205   QualType T = Sig->getType();
10206 
10207   // FIXME: We should allow unexpanded parameter packs here, but that would,
10208   // in turn, make the block expression contain unexpanded parameter packs.
10209   if (DiagnoseUnexpandedParameterPack(CaretLoc, Sig, UPPC_Block)) {
10210     // Drop the parameters.
10211     FunctionProtoType::ExtProtoInfo EPI;
10212     EPI.HasTrailingReturn = false;
10213     EPI.TypeQuals |= DeclSpec::TQ_const;
10214     T = Context.getFunctionType(Context.DependentTy, None, EPI);
10215     Sig = Context.getTrivialTypeSourceInfo(T);
10216   }
10217 
10218   // GetTypeForDeclarator always produces a function type for a block
10219   // literal signature.  Furthermore, it is always a FunctionProtoType
10220   // unless the function was written with a typedef.
10221   assert(T->isFunctionType() &&
10222          "GetTypeForDeclarator made a non-function block signature");
10223 
10224   // Look for an explicit signature in that function type.
10225   FunctionProtoTypeLoc ExplicitSignature;
10226 
10227   TypeLoc tmp = Sig->getTypeLoc().IgnoreParens();
10228   if ((ExplicitSignature = tmp.getAs<FunctionProtoTypeLoc>())) {
10229 
10230     // Check whether that explicit signature was synthesized by
10231     // GetTypeForDeclarator.  If so, don't save that as part of the
10232     // written signature.
10233     if (ExplicitSignature.getLocalRangeBegin() ==
10234         ExplicitSignature.getLocalRangeEnd()) {
10235       // This would be much cheaper if we stored TypeLocs instead of
10236       // TypeSourceInfos.
10237       TypeLoc Result = ExplicitSignature.getResultLoc();
10238       unsigned Size = Result.getFullDataSize();
10239       Sig = Context.CreateTypeSourceInfo(Result.getType(), Size);
10240       Sig->getTypeLoc().initializeFullCopy(Result, Size);
10241 
10242       ExplicitSignature = FunctionProtoTypeLoc();
10243     }
10244   }
10245 
10246   CurBlock->TheDecl->setSignatureAsWritten(Sig);
10247   CurBlock->FunctionType = T;
10248 
10249   const FunctionType *Fn = T->getAs<FunctionType>();
10250   QualType RetTy = Fn->getResultType();
10251   bool isVariadic =
10252     (isa<FunctionProtoType>(Fn) && cast<FunctionProtoType>(Fn)->isVariadic());
10253 
10254   CurBlock->TheDecl->setIsVariadic(isVariadic);
10255 
10256   // Context.DependentTy is used as a placeholder for a missing block
10257   // return type.  TODO:  what should we do with declarators like:
10258   //   ^ * { ... }
10259   // If the answer is "apply template argument deduction"....
10260   if (RetTy != Context.DependentTy) {
10261     CurBlock->ReturnType = RetTy;
10262     CurBlock->TheDecl->setBlockMissingReturnType(false);
10263     CurBlock->HasImplicitReturnType = false;
10264   }
10265 
10266   // Push block parameters from the declarator if we had them.
10267   SmallVector<ParmVarDecl*, 8> Params;
10268   if (ExplicitSignature) {
10269     for (unsigned I = 0, E = ExplicitSignature.getNumArgs(); I != E; ++I) {
10270       ParmVarDecl *Param = ExplicitSignature.getArg(I);
10271       if (Param->getIdentifier() == 0 &&
10272           !Param->isImplicit() &&
10273           !Param->isInvalidDecl() &&
10274           !getLangOpts().CPlusPlus)
10275         Diag(Param->getLocation(), diag::err_parameter_name_omitted);
10276       Params.push_back(Param);
10277     }
10278 
10279   // Fake up parameter variables if we have a typedef, like
10280   //   ^ fntype { ... }
10281   } else if (const FunctionProtoType *Fn = T->getAs<FunctionProtoType>()) {
10282     for (FunctionProtoType::arg_type_iterator
10283            I = Fn->arg_type_begin(), E = Fn->arg_type_end(); I != E; ++I) {
10284       ParmVarDecl *Param =
10285         BuildParmVarDeclForTypedef(CurBlock->TheDecl,
10286                                    ParamInfo.getLocStart(),
10287                                    *I);
10288       Params.push_back(Param);
10289     }
10290   }
10291 
10292   // Set the parameters on the block decl.
10293   if (!Params.empty()) {
10294     CurBlock->TheDecl->setParams(Params);
10295     CheckParmsForFunctionDef(CurBlock->TheDecl->param_begin(),
10296                              CurBlock->TheDecl->param_end(),
10297                              /*CheckParameterNames=*/false);
10298   }
10299 
10300   // Finally we can process decl attributes.
10301   ProcessDeclAttributes(CurScope, CurBlock->TheDecl, ParamInfo);
10302 
10303   // Put the parameter variables in scope.
10304   for (BlockDecl::param_iterator AI = CurBlock->TheDecl->param_begin(),
10305          E = CurBlock->TheDecl->param_end(); AI != E; ++AI) {
10306     (*AI)->setOwningFunction(CurBlock->TheDecl);
10307 
10308     // If this has an identifier, add it to the scope stack.
10309     if ((*AI)->getIdentifier()) {
10310       CheckShadow(CurBlock->TheScope, *AI);
10311 
10312       PushOnScopeChains(*AI, CurBlock->TheScope);
10313     }
10314   }
10315 }
10316 
10317 /// ActOnBlockError - If there is an error parsing a block, this callback
10318 /// is invoked to pop the information about the block from the action impl.
10319 void Sema::ActOnBlockError(SourceLocation CaretLoc, Scope *CurScope) {
10320   // Leave the expression-evaluation context.
10321   DiscardCleanupsInEvaluationContext();
10322   PopExpressionEvaluationContext();
10323 
10324   // Pop off CurBlock, handle nested blocks.
10325   PopDeclContext();
10326   PopFunctionScopeInfo();
10327 }
10328 
10329 /// ActOnBlockStmtExpr - This is called when the body of a block statement
10330 /// literal was successfully completed.  ^(int x){...}
10331 ExprResult Sema::ActOnBlockStmtExpr(SourceLocation CaretLoc,
10332                                     Stmt *Body, Scope *CurScope) {
10333   // If blocks are disabled, emit an error.
10334   if (!LangOpts.Blocks)
10335     Diag(CaretLoc, diag::err_blocks_disable);
10336 
10337   // Leave the expression-evaluation context.
10338   if (hasAnyUnrecoverableErrorsInThisFunction())
10339     DiscardCleanupsInEvaluationContext();
10340   assert(!ExprNeedsCleanups && "cleanups within block not correctly bound!");
10341   PopExpressionEvaluationContext();
10342 
10343   BlockScopeInfo *BSI = cast<BlockScopeInfo>(FunctionScopes.back());
10344 
10345   if (BSI->HasImplicitReturnType)
10346     deduceClosureReturnType(*BSI);
10347 
10348   PopDeclContext();
10349 
10350   QualType RetTy = Context.VoidTy;
10351   if (!BSI->ReturnType.isNull())
10352     RetTy = BSI->ReturnType;
10353 
10354   bool NoReturn = BSI->TheDecl->getAttr<NoReturnAttr>();
10355   QualType BlockTy;
10356 
10357   // Set the captured variables on the block.
10358   // FIXME: Share capture structure between BlockDecl and CapturingScopeInfo!
10359   SmallVector<BlockDecl::Capture, 4> Captures;
10360   for (unsigned i = 0, e = BSI->Captures.size(); i != e; i++) {
10361     CapturingScopeInfo::Capture &Cap = BSI->Captures[i];
10362     if (Cap.isThisCapture())
10363       continue;
10364     BlockDecl::Capture NewCap(Cap.getVariable(), Cap.isBlockCapture(),
10365                               Cap.isNested(), Cap.getInitExpr());
10366     Captures.push_back(NewCap);
10367   }
10368   BSI->TheDecl->setCaptures(Context, Captures.begin(), Captures.end(),
10369                             BSI->CXXThisCaptureIndex != 0);
10370 
10371   // If the user wrote a function type in some form, try to use that.
10372   if (!BSI->FunctionType.isNull()) {
10373     const FunctionType *FTy = BSI->FunctionType->getAs<FunctionType>();
10374 
10375     FunctionType::ExtInfo Ext = FTy->getExtInfo();
10376     if (NoReturn && !Ext.getNoReturn()) Ext = Ext.withNoReturn(true);
10377 
10378     // Turn protoless block types into nullary block types.
10379     if (isa<FunctionNoProtoType>(FTy)) {
10380       FunctionProtoType::ExtProtoInfo EPI;
10381       EPI.ExtInfo = Ext;
10382       BlockTy = Context.getFunctionType(RetTy, None, EPI);
10383 
10384     // Otherwise, if we don't need to change anything about the function type,
10385     // preserve its sugar structure.
10386     } else if (FTy->getResultType() == RetTy &&
10387                (!NoReturn || FTy->getNoReturnAttr())) {
10388       BlockTy = BSI->FunctionType;
10389 
10390     // Otherwise, make the minimal modifications to the function type.
10391     } else {
10392       const FunctionProtoType *FPT = cast<FunctionProtoType>(FTy);
10393       FunctionProtoType::ExtProtoInfo EPI = FPT->getExtProtoInfo();
10394       EPI.TypeQuals = 0; // FIXME: silently?
10395       EPI.ExtInfo = Ext;
10396       BlockTy = Context.getFunctionType(RetTy, FPT->getArgTypes(), EPI);
10397     }
10398 
10399   // If we don't have a function type, just build one from nothing.
10400   } else {
10401     FunctionProtoType::ExtProtoInfo EPI;
10402     EPI.ExtInfo = FunctionType::ExtInfo().withNoReturn(NoReturn);
10403     BlockTy = Context.getFunctionType(RetTy, None, EPI);
10404   }
10405 
10406   DiagnoseUnusedParameters(BSI->TheDecl->param_begin(),
10407                            BSI->TheDecl->param_end());
10408   BlockTy = Context.getBlockPointerType(BlockTy);
10409 
10410   // If needed, diagnose invalid gotos and switches in the block.
10411   if (getCurFunction()->NeedsScopeChecking() &&
10412       !hasAnyUnrecoverableErrorsInThisFunction() &&
10413       !PP.isCodeCompletionEnabled())
10414     DiagnoseInvalidJumps(cast<CompoundStmt>(Body));
10415 
10416   BSI->TheDecl->setBody(cast<CompoundStmt>(Body));
10417 
10418   // Try to apply the named return value optimization. We have to check again
10419   // if we can do this, though, because blocks keep return statements around
10420   // to deduce an implicit return type.
10421   if (getLangOpts().CPlusPlus && RetTy->isRecordType() &&
10422       !BSI->TheDecl->isDependentContext())
10423     computeNRVO(Body, getCurBlock());
10424 
10425   BlockExpr *Result = new (Context) BlockExpr(BSI->TheDecl, BlockTy);
10426   AnalysisBasedWarnings::Policy WP = AnalysisWarnings.getDefaultPolicy();
10427   PopFunctionScopeInfo(&WP, Result->getBlockDecl(), Result);
10428 
10429   // If the block isn't obviously global, i.e. it captures anything at
10430   // all, then we need to do a few things in the surrounding context:
10431   if (Result->getBlockDecl()->hasCaptures()) {
10432     // First, this expression has a new cleanup object.
10433     ExprCleanupObjects.push_back(Result->getBlockDecl());
10434     ExprNeedsCleanups = true;
10435 
10436     // It also gets a branch-protected scope if any of the captured
10437     // variables needs destruction.
10438     for (BlockDecl::capture_const_iterator
10439            ci = Result->getBlockDecl()->capture_begin(),
10440            ce = Result->getBlockDecl()->capture_end(); ci != ce; ++ci) {
10441       const VarDecl *var = ci->getVariable();
10442       if (var->getType().isDestructedType() != QualType::DK_none) {
10443         getCurFunction()->setHasBranchProtectedScope();
10444         break;
10445       }
10446     }
10447   }
10448 
10449   return Owned(Result);
10450 }
10451 
10452 ExprResult Sema::ActOnVAArg(SourceLocation BuiltinLoc,
10453                                         Expr *E, ParsedType Ty,
10454                                         SourceLocation RPLoc) {
10455   TypeSourceInfo *TInfo;
10456   GetTypeFromParser(Ty, &TInfo);
10457   return BuildVAArgExpr(BuiltinLoc, E, TInfo, RPLoc);
10458 }
10459 
10460 ExprResult Sema::BuildVAArgExpr(SourceLocation BuiltinLoc,
10461                                 Expr *E, TypeSourceInfo *TInfo,
10462                                 SourceLocation RPLoc) {
10463   Expr *OrigExpr = E;
10464 
10465   // Get the va_list type
10466   QualType VaListType = Context.getBuiltinVaListType();
10467   if (VaListType->isArrayType()) {
10468     // Deal with implicit array decay; for example, on x86-64,
10469     // va_list is an array, but it's supposed to decay to
10470     // a pointer for va_arg.
10471     VaListType = Context.getArrayDecayedType(VaListType);
10472     // Make sure the input expression also decays appropriately.
10473     ExprResult Result = UsualUnaryConversions(E);
10474     if (Result.isInvalid())
10475       return ExprError();
10476     E = Result.take();
10477   } else if (VaListType->isRecordType() && getLangOpts().CPlusPlus) {
10478     // If va_list is a record type and we are compiling in C++ mode,
10479     // check the argument using reference binding.
10480     InitializedEntity Entity
10481       = InitializedEntity::InitializeParameter(Context,
10482           Context.getLValueReferenceType(VaListType), false);
10483     ExprResult Init = PerformCopyInitialization(Entity, SourceLocation(), E);
10484     if (Init.isInvalid())
10485       return ExprError();
10486     E = Init.takeAs<Expr>();
10487   } else {
10488     // Otherwise, the va_list argument must be an l-value because
10489     // it is modified by va_arg.
10490     if (!E->isTypeDependent() &&
10491         CheckForModifiableLvalue(E, BuiltinLoc, *this))
10492       return ExprError();
10493   }
10494 
10495   if (!E->isTypeDependent() &&
10496       !Context.hasSameType(VaListType, E->getType())) {
10497     return ExprError(Diag(E->getLocStart(),
10498                          diag::err_first_argument_to_va_arg_not_of_type_va_list)
10499       << OrigExpr->getType() << E->getSourceRange());
10500   }
10501 
10502   if (!TInfo->getType()->isDependentType()) {
10503     if (RequireCompleteType(TInfo->getTypeLoc().getBeginLoc(), TInfo->getType(),
10504                             diag::err_second_parameter_to_va_arg_incomplete,
10505                             TInfo->getTypeLoc()))
10506       return ExprError();
10507 
10508     if (RequireNonAbstractType(TInfo->getTypeLoc().getBeginLoc(),
10509                                TInfo->getType(),
10510                                diag::err_second_parameter_to_va_arg_abstract,
10511                                TInfo->getTypeLoc()))
10512       return ExprError();
10513 
10514     if (!TInfo->getType().isPODType(Context)) {
10515       Diag(TInfo->getTypeLoc().getBeginLoc(),
10516            TInfo->getType()->isObjCLifetimeType()
10517              ? diag::warn_second_parameter_to_va_arg_ownership_qualified
10518              : diag::warn_second_parameter_to_va_arg_not_pod)
10519         << TInfo->getType()
10520         << TInfo->getTypeLoc().getSourceRange();
10521     }
10522 
10523     // Check for va_arg where arguments of the given type will be promoted
10524     // (i.e. this va_arg is guaranteed to have undefined behavior).
10525     QualType PromoteType;
10526     if (TInfo->getType()->isPromotableIntegerType()) {
10527       PromoteType = Context.getPromotedIntegerType(TInfo->getType());
10528       if (Context.typesAreCompatible(PromoteType, TInfo->getType()))
10529         PromoteType = QualType();
10530     }
10531     if (TInfo->getType()->isSpecificBuiltinType(BuiltinType::Float))
10532       PromoteType = Context.DoubleTy;
10533     if (!PromoteType.isNull())
10534       DiagRuntimeBehavior(TInfo->getTypeLoc().getBeginLoc(), E,
10535                   PDiag(diag::warn_second_parameter_to_va_arg_never_compatible)
10536                           << TInfo->getType()
10537                           << PromoteType
10538                           << TInfo->getTypeLoc().getSourceRange());
10539   }
10540 
10541   QualType T = TInfo->getType().getNonLValueExprType(Context);
10542   return Owned(new (Context) VAArgExpr(BuiltinLoc, E, TInfo, RPLoc, T));
10543 }
10544 
10545 ExprResult Sema::ActOnGNUNullExpr(SourceLocation TokenLoc) {
10546   // The type of __null will be int or long, depending on the size of
10547   // pointers on the target.
10548   QualType Ty;
10549   unsigned pw = Context.getTargetInfo().getPointerWidth(0);
10550   if (pw == Context.getTargetInfo().getIntWidth())
10551     Ty = Context.IntTy;
10552   else if (pw == Context.getTargetInfo().getLongWidth())
10553     Ty = Context.LongTy;
10554   else if (pw == Context.getTargetInfo().getLongLongWidth())
10555     Ty = Context.LongLongTy;
10556   else {
10557     llvm_unreachable("I don't know size of pointer!");
10558   }
10559 
10560   return Owned(new (Context) GNUNullExpr(Ty, TokenLoc));
10561 }
10562 
10563 static void MakeObjCStringLiteralFixItHint(Sema& SemaRef, QualType DstType,
10564                                            Expr *SrcExpr, FixItHint &Hint,
10565                                            bool &IsNSString) {
10566   if (!SemaRef.getLangOpts().ObjC1)
10567     return;
10568 
10569   const ObjCObjectPointerType *PT = DstType->getAs<ObjCObjectPointerType>();
10570   if (!PT)
10571     return;
10572 
10573   // Check if the destination is of type 'id'.
10574   if (!PT->isObjCIdType()) {
10575     // Check if the destination is the 'NSString' interface.
10576     const ObjCInterfaceDecl *ID = PT->getInterfaceDecl();
10577     if (!ID || !ID->getIdentifier()->isStr("NSString"))
10578       return;
10579     IsNSString = true;
10580   }
10581 
10582   // Ignore any parens, implicit casts (should only be
10583   // array-to-pointer decays), and not-so-opaque values.  The last is
10584   // important for making this trigger for property assignments.
10585   SrcExpr = SrcExpr->IgnoreParenImpCasts();
10586   if (OpaqueValueExpr *OV = dyn_cast<OpaqueValueExpr>(SrcExpr))
10587     if (OV->getSourceExpr())
10588       SrcExpr = OV->getSourceExpr()->IgnoreParenImpCasts();
10589 
10590   StringLiteral *SL = dyn_cast<StringLiteral>(SrcExpr);
10591   if (!SL || !SL->isAscii())
10592     return;
10593 
10594   Hint = FixItHint::CreateInsertion(SL->getLocStart(), "@");
10595 }
10596 
10597 bool Sema::DiagnoseAssignmentResult(AssignConvertType ConvTy,
10598                                     SourceLocation Loc,
10599                                     QualType DstType, QualType SrcType,
10600                                     Expr *SrcExpr, AssignmentAction Action,
10601                                     bool *Complained) {
10602   if (Complained)
10603     *Complained = false;
10604 
10605   // Decode the result (notice that AST's are still created for extensions).
10606   bool CheckInferredResultType = false;
10607   bool isInvalid = false;
10608   unsigned DiagKind = 0;
10609   FixItHint Hint;
10610   ConversionFixItGenerator ConvHints;
10611   bool MayHaveConvFixit = false;
10612   bool MayHaveFunctionDiff = false;
10613   bool IsNSString = false;
10614 
10615   switch (ConvTy) {
10616   case Compatible:
10617       DiagnoseAssignmentEnum(DstType, SrcType, SrcExpr);
10618       return false;
10619 
10620   case PointerToInt:
10621     DiagKind = diag::ext_typecheck_convert_pointer_int;
10622     ConvHints.tryToFixConversion(SrcExpr, SrcType, DstType, *this);
10623     MayHaveConvFixit = true;
10624     break;
10625   case IntToPointer:
10626     DiagKind = diag::ext_typecheck_convert_int_pointer;
10627     ConvHints.tryToFixConversion(SrcExpr, SrcType, DstType, *this);
10628     MayHaveConvFixit = true;
10629     break;
10630   case IncompatiblePointer:
10631     MakeObjCStringLiteralFixItHint(*this, DstType, SrcExpr, Hint, IsNSString);
10632       DiagKind =
10633         (Action == AA_Passing_CFAudited ?
10634           diag::err_arc_typecheck_convert_incompatible_pointer :
10635           diag::ext_typecheck_convert_incompatible_pointer);
10636     CheckInferredResultType = DstType->isObjCObjectPointerType() &&
10637       SrcType->isObjCObjectPointerType();
10638     if (Hint.isNull() && !CheckInferredResultType) {
10639       ConvHints.tryToFixConversion(SrcExpr, SrcType, DstType, *this);
10640     }
10641     else if (CheckInferredResultType) {
10642       SrcType = SrcType.getUnqualifiedType();
10643       DstType = DstType.getUnqualifiedType();
10644     }
10645     else if (IsNSString && !Hint.isNull())
10646       DiagKind = diag::warn_missing_atsign_prefix;
10647     MayHaveConvFixit = true;
10648     break;
10649   case IncompatiblePointerSign:
10650     DiagKind = diag::ext_typecheck_convert_incompatible_pointer_sign;
10651     break;
10652   case FunctionVoidPointer:
10653     DiagKind = diag::ext_typecheck_convert_pointer_void_func;
10654     break;
10655   case IncompatiblePointerDiscardsQualifiers: {
10656     // Perform array-to-pointer decay if necessary.
10657     if (SrcType->isArrayType()) SrcType = Context.getArrayDecayedType(SrcType);
10658 
10659     Qualifiers lhq = SrcType->getPointeeType().getQualifiers();
10660     Qualifiers rhq = DstType->getPointeeType().getQualifiers();
10661     if (lhq.getAddressSpace() != rhq.getAddressSpace()) {
10662       DiagKind = diag::err_typecheck_incompatible_address_space;
10663       break;
10664 
10665 
10666     } else if (lhq.getObjCLifetime() != rhq.getObjCLifetime()) {
10667       DiagKind = diag::err_typecheck_incompatible_ownership;
10668       break;
10669     }
10670 
10671     llvm_unreachable("unknown error case for discarding qualifiers!");
10672     // fallthrough
10673   }
10674   case CompatiblePointerDiscardsQualifiers:
10675     // If the qualifiers lost were because we were applying the
10676     // (deprecated) C++ conversion from a string literal to a char*
10677     // (or wchar_t*), then there was no error (C++ 4.2p2).  FIXME:
10678     // Ideally, this check would be performed in
10679     // checkPointerTypesForAssignment. However, that would require a
10680     // bit of refactoring (so that the second argument is an
10681     // expression, rather than a type), which should be done as part
10682     // of a larger effort to fix checkPointerTypesForAssignment for
10683     // C++ semantics.
10684     if (getLangOpts().CPlusPlus &&
10685         IsStringLiteralToNonConstPointerConversion(SrcExpr, DstType))
10686       return false;
10687     DiagKind = diag::ext_typecheck_convert_discards_qualifiers;
10688     break;
10689   case IncompatibleNestedPointerQualifiers:
10690     DiagKind = diag::ext_nested_pointer_qualifier_mismatch;
10691     break;
10692   case IntToBlockPointer:
10693     DiagKind = diag::err_int_to_block_pointer;
10694     break;
10695   case IncompatibleBlockPointer:
10696     DiagKind = diag::err_typecheck_convert_incompatible_block_pointer;
10697     break;
10698   case IncompatibleObjCQualifiedId:
10699     // FIXME: Diagnose the problem in ObjCQualifiedIdTypesAreCompatible, since
10700     // it can give a more specific diagnostic.
10701     DiagKind = diag::warn_incompatible_qualified_id;
10702     break;
10703   case IncompatibleVectors:
10704     DiagKind = diag::warn_incompatible_vectors;
10705     break;
10706   case IncompatibleObjCWeakRef:
10707     DiagKind = diag::err_arc_weak_unavailable_assign;
10708     break;
10709   case Incompatible:
10710     DiagKind = diag::err_typecheck_convert_incompatible;
10711     ConvHints.tryToFixConversion(SrcExpr, SrcType, DstType, *this);
10712     MayHaveConvFixit = true;
10713     isInvalid = true;
10714     MayHaveFunctionDiff = true;
10715     break;
10716   }
10717 
10718   QualType FirstType, SecondType;
10719   switch (Action) {
10720   case AA_Assigning:
10721   case AA_Initializing:
10722     // The destination type comes first.
10723     FirstType = DstType;
10724     SecondType = SrcType;
10725     break;
10726 
10727   case AA_Returning:
10728   case AA_Passing:
10729   case AA_Passing_CFAudited:
10730   case AA_Converting:
10731   case AA_Sending:
10732   case AA_Casting:
10733     // The source type comes first.
10734     FirstType = SrcType;
10735     SecondType = DstType;
10736     break;
10737   }
10738 
10739   PartialDiagnostic FDiag = PDiag(DiagKind);
10740   if (Action == AA_Passing_CFAudited)
10741     FDiag << FirstType << SecondType << SrcExpr->getSourceRange();
10742   else
10743     FDiag << FirstType << SecondType << Action << SrcExpr->getSourceRange();
10744 
10745   // If we can fix the conversion, suggest the FixIts.
10746   assert(ConvHints.isNull() || Hint.isNull());
10747   if (!ConvHints.isNull()) {
10748     for (std::vector<FixItHint>::iterator HI = ConvHints.Hints.begin(),
10749          HE = ConvHints.Hints.end(); HI != HE; ++HI)
10750       FDiag << *HI;
10751   } else {
10752     FDiag << Hint;
10753   }
10754   if (MayHaveConvFixit) { FDiag << (unsigned) (ConvHints.Kind); }
10755 
10756   if (MayHaveFunctionDiff)
10757     HandleFunctionTypeMismatch(FDiag, SecondType, FirstType);
10758 
10759   Diag(Loc, FDiag);
10760 
10761   if (SecondType == Context.OverloadTy)
10762     NoteAllOverloadCandidates(OverloadExpr::find(SrcExpr).Expression,
10763                               FirstType);
10764 
10765   if (CheckInferredResultType)
10766     EmitRelatedResultTypeNote(SrcExpr);
10767 
10768   if (Action == AA_Returning && ConvTy == IncompatiblePointer)
10769     EmitRelatedResultTypeNoteForReturn(DstType);
10770 
10771   if (Complained)
10772     *Complained = true;
10773   return isInvalid;
10774 }
10775 
10776 ExprResult Sema::VerifyIntegerConstantExpression(Expr *E,
10777                                                  llvm::APSInt *Result) {
10778   class SimpleICEDiagnoser : public VerifyICEDiagnoser {
10779   public:
10780     virtual void diagnoseNotICE(Sema &S, SourceLocation Loc, SourceRange SR) {
10781       S.Diag(Loc, diag::err_expr_not_ice) << S.LangOpts.CPlusPlus << SR;
10782     }
10783   } Diagnoser;
10784 
10785   return VerifyIntegerConstantExpression(E, Result, Diagnoser);
10786 }
10787 
10788 ExprResult Sema::VerifyIntegerConstantExpression(Expr *E,
10789                                                  llvm::APSInt *Result,
10790                                                  unsigned DiagID,
10791                                                  bool AllowFold) {
10792   class IDDiagnoser : public VerifyICEDiagnoser {
10793     unsigned DiagID;
10794 
10795   public:
10796     IDDiagnoser(unsigned DiagID)
10797       : VerifyICEDiagnoser(DiagID == 0), DiagID(DiagID) { }
10798 
10799     virtual void diagnoseNotICE(Sema &S, SourceLocation Loc, SourceRange SR) {
10800       S.Diag(Loc, DiagID) << SR;
10801     }
10802   } Diagnoser(DiagID);
10803 
10804   return VerifyIntegerConstantExpression(E, Result, Diagnoser, AllowFold);
10805 }
10806 
10807 void Sema::VerifyICEDiagnoser::diagnoseFold(Sema &S, SourceLocation Loc,
10808                                             SourceRange SR) {
10809   S.Diag(Loc, diag::ext_expr_not_ice) << SR << S.LangOpts.CPlusPlus;
10810 }
10811 
10812 ExprResult
10813 Sema::VerifyIntegerConstantExpression(Expr *E, llvm::APSInt *Result,
10814                                       VerifyICEDiagnoser &Diagnoser,
10815                                       bool AllowFold) {
10816   SourceLocation DiagLoc = E->getLocStart();
10817 
10818   if (getLangOpts().CPlusPlus11) {
10819     // C++11 [expr.const]p5:
10820     //   If an expression of literal class type is used in a context where an
10821     //   integral constant expression is required, then that class type shall
10822     //   have a single non-explicit conversion function to an integral or
10823     //   unscoped enumeration type
10824     ExprResult Converted;
10825     class CXX11ConvertDiagnoser : public ICEConvertDiagnoser {
10826     public:
10827       CXX11ConvertDiagnoser(bool Silent)
10828           : ICEConvertDiagnoser(/*AllowScopedEnumerations*/false,
10829                                 Silent, true) {}
10830 
10831       virtual SemaDiagnosticBuilder diagnoseNotInt(Sema &S, SourceLocation Loc,
10832                                                    QualType T) {
10833         return S.Diag(Loc, diag::err_ice_not_integral) << T;
10834       }
10835 
10836       virtual SemaDiagnosticBuilder diagnoseIncomplete(
10837           Sema &S, SourceLocation Loc, QualType T) {
10838         return S.Diag(Loc, diag::err_ice_incomplete_type) << T;
10839       }
10840 
10841       virtual SemaDiagnosticBuilder diagnoseExplicitConv(
10842           Sema &S, SourceLocation Loc, QualType T, QualType ConvTy) {
10843         return S.Diag(Loc, diag::err_ice_explicit_conversion) << T << ConvTy;
10844       }
10845 
10846       virtual SemaDiagnosticBuilder noteExplicitConv(
10847           Sema &S, CXXConversionDecl *Conv, QualType ConvTy) {
10848         return S.Diag(Conv->getLocation(), diag::note_ice_conversion_here)
10849                  << ConvTy->isEnumeralType() << ConvTy;
10850       }
10851 
10852       virtual SemaDiagnosticBuilder diagnoseAmbiguous(
10853           Sema &S, SourceLocation Loc, QualType T) {
10854         return S.Diag(Loc, diag::err_ice_ambiguous_conversion) << T;
10855       }
10856 
10857       virtual SemaDiagnosticBuilder noteAmbiguous(
10858           Sema &S, CXXConversionDecl *Conv, QualType ConvTy) {
10859         return S.Diag(Conv->getLocation(), diag::note_ice_conversion_here)
10860                  << ConvTy->isEnumeralType() << ConvTy;
10861       }
10862 
10863       virtual SemaDiagnosticBuilder diagnoseConversion(
10864           Sema &S, SourceLocation Loc, QualType T, QualType ConvTy) {
10865         llvm_unreachable("conversion functions are permitted");
10866       }
10867     } ConvertDiagnoser(Diagnoser.Suppress);
10868 
10869     Converted = PerformContextualImplicitConversion(DiagLoc, E,
10870                                                     ConvertDiagnoser);
10871     if (Converted.isInvalid())
10872       return Converted;
10873     E = Converted.take();
10874     if (!E->getType()->isIntegralOrUnscopedEnumerationType())
10875       return ExprError();
10876   } else if (!E->getType()->isIntegralOrUnscopedEnumerationType()) {
10877     // An ICE must be of integral or unscoped enumeration type.
10878     if (!Diagnoser.Suppress)
10879       Diagnoser.diagnoseNotICE(*this, DiagLoc, E->getSourceRange());
10880     return ExprError();
10881   }
10882 
10883   // Circumvent ICE checking in C++11 to avoid evaluating the expression twice
10884   // in the non-ICE case.
10885   if (!getLangOpts().CPlusPlus11 && E->isIntegerConstantExpr(Context)) {
10886     if (Result)
10887       *Result = E->EvaluateKnownConstInt(Context);
10888     return Owned(E);
10889   }
10890 
10891   Expr::EvalResult EvalResult;
10892   SmallVector<PartialDiagnosticAt, 8> Notes;
10893   EvalResult.Diag = &Notes;
10894 
10895   // Try to evaluate the expression, and produce diagnostics explaining why it's
10896   // not a constant expression as a side-effect.
10897   bool Folded = E->EvaluateAsRValue(EvalResult, Context) &&
10898                 EvalResult.Val.isInt() && !EvalResult.HasSideEffects;
10899 
10900   // In C++11, we can rely on diagnostics being produced for any expression
10901   // which is not a constant expression. If no diagnostics were produced, then
10902   // this is a constant expression.
10903   if (Folded && getLangOpts().CPlusPlus11 && Notes.empty()) {
10904     if (Result)
10905       *Result = EvalResult.Val.getInt();
10906     return Owned(E);
10907   }
10908 
10909   // If our only note is the usual "invalid subexpression" note, just point
10910   // the caret at its location rather than producing an essentially
10911   // redundant note.
10912   if (Notes.size() == 1 && Notes[0].second.getDiagID() ==
10913         diag::note_invalid_subexpr_in_const_expr) {
10914     DiagLoc = Notes[0].first;
10915     Notes.clear();
10916   }
10917 
10918   if (!Folded || !AllowFold) {
10919     if (!Diagnoser.Suppress) {
10920       Diagnoser.diagnoseNotICE(*this, DiagLoc, E->getSourceRange());
10921       for (unsigned I = 0, N = Notes.size(); I != N; ++I)
10922         Diag(Notes[I].first, Notes[I].second);
10923     }
10924 
10925     return ExprError();
10926   }
10927 
10928   Diagnoser.diagnoseFold(*this, DiagLoc, E->getSourceRange());
10929   for (unsigned I = 0, N = Notes.size(); I != N; ++I)
10930     Diag(Notes[I].first, Notes[I].second);
10931 
10932   if (Result)
10933     *Result = EvalResult.Val.getInt();
10934   return Owned(E);
10935 }
10936 
10937 namespace {
10938   // Handle the case where we conclude a expression which we speculatively
10939   // considered to be unevaluated is actually evaluated.
10940   class TransformToPE : public TreeTransform<TransformToPE> {
10941     typedef TreeTransform<TransformToPE> BaseTransform;
10942 
10943   public:
10944     TransformToPE(Sema &SemaRef) : BaseTransform(SemaRef) { }
10945 
10946     // Make sure we redo semantic analysis
10947     bool AlwaysRebuild() { return true; }
10948 
10949     // Make sure we handle LabelStmts correctly.
10950     // FIXME: This does the right thing, but maybe we need a more general
10951     // fix to TreeTransform?
10952     StmtResult TransformLabelStmt(LabelStmt *S) {
10953       S->getDecl()->setStmt(0);
10954       return BaseTransform::TransformLabelStmt(S);
10955     }
10956 
10957     // We need to special-case DeclRefExprs referring to FieldDecls which
10958     // are not part of a member pointer formation; normal TreeTransforming
10959     // doesn't catch this case because of the way we represent them in the AST.
10960     // FIXME: This is a bit ugly; is it really the best way to handle this
10961     // case?
10962     //
10963     // Error on DeclRefExprs referring to FieldDecls.
10964     ExprResult TransformDeclRefExpr(DeclRefExpr *E) {
10965       if (isa<FieldDecl>(E->getDecl()) &&
10966           !SemaRef.isUnevaluatedContext())
10967         return SemaRef.Diag(E->getLocation(),
10968                             diag::err_invalid_non_static_member_use)
10969             << E->getDecl() << E->getSourceRange();
10970 
10971       return BaseTransform::TransformDeclRefExpr(E);
10972     }
10973 
10974     // Exception: filter out member pointer formation
10975     ExprResult TransformUnaryOperator(UnaryOperator *E) {
10976       if (E->getOpcode() == UO_AddrOf && E->getType()->isMemberPointerType())
10977         return E;
10978 
10979       return BaseTransform::TransformUnaryOperator(E);
10980     }
10981 
10982     ExprResult TransformLambdaExpr(LambdaExpr *E) {
10983       // Lambdas never need to be transformed.
10984       return E;
10985     }
10986   };
10987 }
10988 
10989 ExprResult Sema::TransformToPotentiallyEvaluated(Expr *E) {
10990   assert(isUnevaluatedContext() &&
10991          "Should only transform unevaluated expressions");
10992   ExprEvalContexts.back().Context =
10993       ExprEvalContexts[ExprEvalContexts.size()-2].Context;
10994   if (isUnevaluatedContext())
10995     return E;
10996   return TransformToPE(*this).TransformExpr(E);
10997 }
10998 
10999 void
11000 Sema::PushExpressionEvaluationContext(ExpressionEvaluationContext NewContext,
11001                                       Decl *LambdaContextDecl,
11002                                       bool IsDecltype) {
11003   ExprEvalContexts.push_back(
11004              ExpressionEvaluationContextRecord(NewContext,
11005                                                ExprCleanupObjects.size(),
11006                                                ExprNeedsCleanups,
11007                                                LambdaContextDecl,
11008                                                IsDecltype));
11009   ExprNeedsCleanups = false;
11010   if (!MaybeODRUseExprs.empty())
11011     std::swap(MaybeODRUseExprs, ExprEvalContexts.back().SavedMaybeODRUseExprs);
11012 }
11013 
11014 void
11015 Sema::PushExpressionEvaluationContext(ExpressionEvaluationContext NewContext,
11016                                       ReuseLambdaContextDecl_t,
11017                                       bool IsDecltype) {
11018   Decl *ClosureContextDecl = ExprEvalContexts.back().ManglingContextDecl;
11019   PushExpressionEvaluationContext(NewContext, ClosureContextDecl, IsDecltype);
11020 }
11021 
11022 void Sema::PopExpressionEvaluationContext() {
11023   ExpressionEvaluationContextRecord& Rec = ExprEvalContexts.back();
11024 
11025   if (!Rec.Lambdas.empty()) {
11026     if (Rec.isUnevaluated() || Rec.Context == ConstantEvaluated) {
11027       unsigned D;
11028       if (Rec.isUnevaluated()) {
11029         // C++11 [expr.prim.lambda]p2:
11030         //   A lambda-expression shall not appear in an unevaluated operand
11031         //   (Clause 5).
11032         D = diag::err_lambda_unevaluated_operand;
11033       } else {
11034         // C++1y [expr.const]p2:
11035         //   A conditional-expression e is a core constant expression unless the
11036         //   evaluation of e, following the rules of the abstract machine, would
11037         //   evaluate [...] a lambda-expression.
11038         D = diag::err_lambda_in_constant_expression;
11039       }
11040       for (unsigned I = 0, N = Rec.Lambdas.size(); I != N; ++I)
11041         Diag(Rec.Lambdas[I]->getLocStart(), D);
11042     } else {
11043       // Mark the capture expressions odr-used. This was deferred
11044       // during lambda expression creation.
11045       for (unsigned I = 0, N = Rec.Lambdas.size(); I != N; ++I) {
11046         LambdaExpr *Lambda = Rec.Lambdas[I];
11047         for (LambdaExpr::capture_init_iterator
11048                   C = Lambda->capture_init_begin(),
11049                CEnd = Lambda->capture_init_end();
11050              C != CEnd; ++C) {
11051           MarkDeclarationsReferencedInExpr(*C);
11052         }
11053       }
11054     }
11055   }
11056 
11057   // When are coming out of an unevaluated context, clear out any
11058   // temporaries that we may have created as part of the evaluation of
11059   // the expression in that context: they aren't relevant because they
11060   // will never be constructed.
11061   if (Rec.isUnevaluated() || Rec.Context == ConstantEvaluated) {
11062     ExprCleanupObjects.erase(ExprCleanupObjects.begin() + Rec.NumCleanupObjects,
11063                              ExprCleanupObjects.end());
11064     ExprNeedsCleanups = Rec.ParentNeedsCleanups;
11065     CleanupVarDeclMarking();
11066     std::swap(MaybeODRUseExprs, Rec.SavedMaybeODRUseExprs);
11067   // Otherwise, merge the contexts together.
11068   } else {
11069     ExprNeedsCleanups |= Rec.ParentNeedsCleanups;
11070     MaybeODRUseExprs.insert(Rec.SavedMaybeODRUseExprs.begin(),
11071                             Rec.SavedMaybeODRUseExprs.end());
11072   }
11073 
11074   // Pop the current expression evaluation context off the stack.
11075   ExprEvalContexts.pop_back();
11076 }
11077 
11078 void Sema::DiscardCleanupsInEvaluationContext() {
11079   ExprCleanupObjects.erase(
11080          ExprCleanupObjects.begin() + ExprEvalContexts.back().NumCleanupObjects,
11081          ExprCleanupObjects.end());
11082   ExprNeedsCleanups = false;
11083   MaybeODRUseExprs.clear();
11084 }
11085 
11086 ExprResult Sema::HandleExprEvaluationContextForTypeof(Expr *E) {
11087   if (!E->getType()->isVariablyModifiedType())
11088     return E;
11089   return TransformToPotentiallyEvaluated(E);
11090 }
11091 
11092 static bool IsPotentiallyEvaluatedContext(Sema &SemaRef) {
11093   // Do not mark anything as "used" within a dependent context; wait for
11094   // an instantiation.
11095   if (SemaRef.CurContext->isDependentContext())
11096     return false;
11097 
11098   switch (SemaRef.ExprEvalContexts.back().Context) {
11099     case Sema::Unevaluated:
11100     case Sema::UnevaluatedAbstract:
11101       // We are in an expression that is not potentially evaluated; do nothing.
11102       // (Depending on how you read the standard, we actually do need to do
11103       // something here for null pointer constants, but the standard's
11104       // definition of a null pointer constant is completely crazy.)
11105       return false;
11106 
11107     case Sema::ConstantEvaluated:
11108     case Sema::PotentiallyEvaluated:
11109       // We are in a potentially evaluated expression (or a constant-expression
11110       // in C++03); we need to do implicit template instantiation, implicitly
11111       // define class members, and mark most declarations as used.
11112       return true;
11113 
11114     case Sema::PotentiallyEvaluatedIfUsed:
11115       // Referenced declarations will only be used if the construct in the
11116       // containing expression is used.
11117       return false;
11118   }
11119   llvm_unreachable("Invalid context");
11120 }
11121 
11122 /// \brief Mark a function referenced, and check whether it is odr-used
11123 /// (C++ [basic.def.odr]p2, C99 6.9p3)
11124 void Sema::MarkFunctionReferenced(SourceLocation Loc, FunctionDecl *Func) {
11125   assert(Func && "No function?");
11126 
11127   Func->setReferenced();
11128 
11129   // C++11 [basic.def.odr]p3:
11130   //   A function whose name appears as a potentially-evaluated expression is
11131   //   odr-used if it is the unique lookup result or the selected member of a
11132   //   set of overloaded functions [...].
11133   //
11134   // We (incorrectly) mark overload resolution as an unevaluated context, so we
11135   // can just check that here. Skip the rest of this function if we've already
11136   // marked the function as used.
11137   if (Func->isUsed(false) || !IsPotentiallyEvaluatedContext(*this)) {
11138     // C++11 [temp.inst]p3:
11139     //   Unless a function template specialization has been explicitly
11140     //   instantiated or explicitly specialized, the function template
11141     //   specialization is implicitly instantiated when the specialization is
11142     //   referenced in a context that requires a function definition to exist.
11143     //
11144     // We consider constexpr function templates to be referenced in a context
11145     // that requires a definition to exist whenever they are referenced.
11146     //
11147     // FIXME: This instantiates constexpr functions too frequently. If this is
11148     // really an unevaluated context (and we're not just in the definition of a
11149     // function template or overload resolution or other cases which we
11150     // incorrectly consider to be unevaluated contexts), and we're not in a
11151     // subexpression which we actually need to evaluate (for instance, a
11152     // template argument, array bound or an expression in a braced-init-list),
11153     // we are not permitted to instantiate this constexpr function definition.
11154     //
11155     // FIXME: This also implicitly defines special members too frequently. They
11156     // are only supposed to be implicitly defined if they are odr-used, but they
11157     // are not odr-used from constant expressions in unevaluated contexts.
11158     // However, they cannot be referenced if they are deleted, and they are
11159     // deleted whenever the implicit definition of the special member would
11160     // fail.
11161     if (!Func->isConstexpr() || Func->getBody())
11162       return;
11163     CXXMethodDecl *MD = dyn_cast<CXXMethodDecl>(Func);
11164     if (!Func->isImplicitlyInstantiable() && (!MD || MD->isUserProvided()))
11165       return;
11166   }
11167 
11168   // Note that this declaration has been used.
11169   if (CXXConstructorDecl *Constructor = dyn_cast<CXXConstructorDecl>(Func)) {
11170     if (Constructor->isDefaulted() && !Constructor->isDeleted()) {
11171       if (Constructor->isDefaultConstructor()) {
11172         if (Constructor->isTrivial())
11173           return;
11174         if (!Constructor->isUsed(false))
11175           DefineImplicitDefaultConstructor(Loc, Constructor);
11176       } else if (Constructor->isCopyConstructor()) {
11177         if (!Constructor->isUsed(false))
11178           DefineImplicitCopyConstructor(Loc, Constructor);
11179       } else if (Constructor->isMoveConstructor()) {
11180         if (!Constructor->isUsed(false))
11181           DefineImplicitMoveConstructor(Loc, Constructor);
11182       }
11183     } else if (Constructor->getInheritedConstructor()) {
11184       if (!Constructor->isUsed(false))
11185         DefineInheritingConstructor(Loc, Constructor);
11186     }
11187 
11188     MarkVTableUsed(Loc, Constructor->getParent());
11189   } else if (CXXDestructorDecl *Destructor =
11190                  dyn_cast<CXXDestructorDecl>(Func)) {
11191     if (Destructor->isDefaulted() && !Destructor->isDeleted() &&
11192         !Destructor->isUsed(false))
11193       DefineImplicitDestructor(Loc, Destructor);
11194     if (Destructor->isVirtual())
11195       MarkVTableUsed(Loc, Destructor->getParent());
11196   } else if (CXXMethodDecl *MethodDecl = dyn_cast<CXXMethodDecl>(Func)) {
11197     if (MethodDecl->isDefaulted() && !MethodDecl->isDeleted() &&
11198         MethodDecl->isOverloadedOperator() &&
11199         MethodDecl->getOverloadedOperator() == OO_Equal) {
11200       if (!MethodDecl->isUsed(false)) {
11201         if (MethodDecl->isCopyAssignmentOperator())
11202           DefineImplicitCopyAssignment(Loc, MethodDecl);
11203         else
11204           DefineImplicitMoveAssignment(Loc, MethodDecl);
11205       }
11206     } else if (isa<CXXConversionDecl>(MethodDecl) &&
11207                MethodDecl->getParent()->isLambda()) {
11208       CXXConversionDecl *Conversion = cast<CXXConversionDecl>(MethodDecl);
11209       if (Conversion->isLambdaToBlockPointerConversion())
11210         DefineImplicitLambdaToBlockPointerConversion(Loc, Conversion);
11211       else
11212         DefineImplicitLambdaToFunctionPointerConversion(Loc, Conversion);
11213     } else if (MethodDecl->isVirtual())
11214       MarkVTableUsed(Loc, MethodDecl->getParent());
11215   }
11216 
11217   // Recursive functions should be marked when used from another function.
11218   // FIXME: Is this really right?
11219   if (CurContext == Func) return;
11220 
11221   // Resolve the exception specification for any function which is
11222   // used: CodeGen will need it.
11223   const FunctionProtoType *FPT = Func->getType()->getAs<FunctionProtoType>();
11224   if (FPT && isUnresolvedExceptionSpec(FPT->getExceptionSpecType()))
11225     ResolveExceptionSpec(Loc, FPT);
11226 
11227   // Implicit instantiation of function templates and member functions of
11228   // class templates.
11229   if (Func->isImplicitlyInstantiable()) {
11230     bool AlreadyInstantiated = false;
11231     SourceLocation PointOfInstantiation = Loc;
11232     if (FunctionTemplateSpecializationInfo *SpecInfo
11233                               = Func->getTemplateSpecializationInfo()) {
11234       if (SpecInfo->getPointOfInstantiation().isInvalid())
11235         SpecInfo->setPointOfInstantiation(Loc);
11236       else if (SpecInfo->getTemplateSpecializationKind()
11237                  == TSK_ImplicitInstantiation) {
11238         AlreadyInstantiated = true;
11239         PointOfInstantiation = SpecInfo->getPointOfInstantiation();
11240       }
11241     } else if (MemberSpecializationInfo *MSInfo
11242                                 = Func->getMemberSpecializationInfo()) {
11243       if (MSInfo->getPointOfInstantiation().isInvalid())
11244         MSInfo->setPointOfInstantiation(Loc);
11245       else if (MSInfo->getTemplateSpecializationKind()
11246                  == TSK_ImplicitInstantiation) {
11247         AlreadyInstantiated = true;
11248         PointOfInstantiation = MSInfo->getPointOfInstantiation();
11249       }
11250     }
11251 
11252     if (!AlreadyInstantiated || Func->isConstexpr()) {
11253       if (isa<CXXRecordDecl>(Func->getDeclContext()) &&
11254           cast<CXXRecordDecl>(Func->getDeclContext())->isLocalClass() &&
11255           ActiveTemplateInstantiations.size())
11256         PendingLocalImplicitInstantiations.push_back(
11257             std::make_pair(Func, PointOfInstantiation));
11258       else if (Func->isConstexpr())
11259         // Do not defer instantiations of constexpr functions, to avoid the
11260         // expression evaluator needing to call back into Sema if it sees a
11261         // call to such a function.
11262         InstantiateFunctionDefinition(PointOfInstantiation, Func);
11263       else {
11264         PendingInstantiations.push_back(std::make_pair(Func,
11265                                                        PointOfInstantiation));
11266         // Notify the consumer that a function was implicitly instantiated.
11267         Consumer.HandleCXXImplicitFunctionInstantiation(Func);
11268       }
11269     }
11270   } else {
11271     // Walk redefinitions, as some of them may be instantiable.
11272     for (FunctionDecl::redecl_iterator i(Func->redecls_begin()),
11273          e(Func->redecls_end()); i != e; ++i) {
11274       if (!i->isUsed(false) && i->isImplicitlyInstantiable())
11275         MarkFunctionReferenced(Loc, *i);
11276     }
11277   }
11278 
11279   // Keep track of used but undefined functions.
11280   if (!Func->isDefined()) {
11281     if (mightHaveNonExternalLinkage(Func))
11282       UndefinedButUsed.insert(std::make_pair(Func->getCanonicalDecl(), Loc));
11283     else if (Func->getMostRecentDecl()->isInlined() &&
11284              (LangOpts.CPlusPlus || !LangOpts.GNUInline) &&
11285              !Func->getMostRecentDecl()->hasAttr<GNUInlineAttr>())
11286       UndefinedButUsed.insert(std::make_pair(Func->getCanonicalDecl(), Loc));
11287   }
11288 
11289   // Normally the most current decl is marked used while processing the use and
11290   // any subsequent decls are marked used by decl merging. This fails with
11291   // template instantiation since marking can happen at the end of the file
11292   // and, because of the two phase lookup, this function is called with at
11293   // decl in the middle of a decl chain. We loop to maintain the invariant
11294   // that once a decl is used, all decls after it are also used.
11295   for (FunctionDecl *F = Func->getMostRecentDecl();; F = F->getPreviousDecl()) {
11296     F->markUsed(Context);
11297     if (F == Func)
11298       break;
11299   }
11300 }
11301 
11302 static void
11303 diagnoseUncapturableValueReference(Sema &S, SourceLocation loc,
11304                                    VarDecl *var, DeclContext *DC) {
11305   DeclContext *VarDC = var->getDeclContext();
11306 
11307   //  If the parameter still belongs to the translation unit, then
11308   //  we're actually just using one parameter in the declaration of
11309   //  the next.
11310   if (isa<ParmVarDecl>(var) &&
11311       isa<TranslationUnitDecl>(VarDC))
11312     return;
11313 
11314   // For C code, don't diagnose about capture if we're not actually in code
11315   // right now; it's impossible to write a non-constant expression outside of
11316   // function context, so we'll get other (more useful) diagnostics later.
11317   //
11318   // For C++, things get a bit more nasty... it would be nice to suppress this
11319   // diagnostic for certain cases like using a local variable in an array bound
11320   // for a member of a local class, but the correct predicate is not obvious.
11321   if (!S.getLangOpts().CPlusPlus && !S.CurContext->isFunctionOrMethod())
11322     return;
11323 
11324   if (isa<CXXMethodDecl>(VarDC) &&
11325       cast<CXXRecordDecl>(VarDC->getParent())->isLambda()) {
11326     S.Diag(loc, diag::err_reference_to_local_var_in_enclosing_lambda)
11327       << var->getIdentifier();
11328   } else if (FunctionDecl *fn = dyn_cast<FunctionDecl>(VarDC)) {
11329     S.Diag(loc, diag::err_reference_to_local_var_in_enclosing_function)
11330       << var->getIdentifier() << fn->getDeclName();
11331   } else if (isa<BlockDecl>(VarDC)) {
11332     S.Diag(loc, diag::err_reference_to_local_var_in_enclosing_block)
11333       << var->getIdentifier();
11334   } else {
11335     // FIXME: Is there any other context where a local variable can be
11336     // declared?
11337     S.Diag(loc, diag::err_reference_to_local_var_in_enclosing_context)
11338       << var->getIdentifier();
11339   }
11340 
11341   S.Diag(var->getLocation(), diag::note_local_variable_declared_here)
11342     << var->getIdentifier();
11343 
11344   // FIXME: Add additional diagnostic info about class etc. which prevents
11345   // capture.
11346 }
11347 
11348 
11349 static bool isVariableAlreadyCapturedInScopeInfo(CapturingScopeInfo *CSI, VarDecl *Var,
11350                                       bool &SubCapturesAreNested,
11351                                       QualType &CaptureType,
11352                                       QualType &DeclRefType) {
11353    // Check whether we've already captured it.
11354   if (CSI->CaptureMap.count(Var)) {
11355     // If we found a capture, any subcaptures are nested.
11356     SubCapturesAreNested = true;
11357 
11358     // Retrieve the capture type for this variable.
11359     CaptureType = CSI->getCapture(Var).getCaptureType();
11360 
11361     // Compute the type of an expression that refers to this variable.
11362     DeclRefType = CaptureType.getNonReferenceType();
11363 
11364     const CapturingScopeInfo::Capture &Cap = CSI->getCapture(Var);
11365     if (Cap.isCopyCapture() &&
11366         !(isa<LambdaScopeInfo>(CSI) && cast<LambdaScopeInfo>(CSI)->Mutable))
11367       DeclRefType.addConst();
11368     return true;
11369   }
11370   return false;
11371 }
11372 
11373 // Only block literals, captured statements, and lambda expressions can
11374 // capture; other scopes don't work.
11375 static DeclContext *getParentOfCapturingContextOrNull(DeclContext *DC, VarDecl *Var,
11376                                  SourceLocation Loc,
11377                                  const bool Diagnose, Sema &S) {
11378   if (isa<BlockDecl>(DC) || isa<CapturedDecl>(DC))
11379     return DC->getParent();
11380   else if (isa<CXXMethodDecl>(DC) &&
11381                 cast<CXXMethodDecl>(DC)->getOverloadedOperator() == OO_Call &&
11382                 cast<CXXRecordDecl>(DC->getParent())->isLambda())
11383     return DC->getParent()->getParent();
11384   else {
11385     if (Diagnose)
11386        diagnoseUncapturableValueReference(S, Loc, Var, DC);
11387   }
11388   return 0;
11389 }
11390 
11391 // Certain capturing entities (lambdas, blocks etc.) are not allowed to capture
11392 // certain types of variables (unnamed, variably modified types etc.)
11393 // so check for eligibility.
11394 static bool isVariableCapturable(CapturingScopeInfo *CSI, VarDecl *Var,
11395                                  SourceLocation Loc,
11396                                  const bool Diagnose, Sema &S) {
11397 
11398   bool IsBlock = isa<BlockScopeInfo>(CSI);
11399   bool IsLambda = isa<LambdaScopeInfo>(CSI);
11400 
11401   // Lambdas are not allowed to capture unnamed variables
11402   // (e.g. anonymous unions).
11403   // FIXME: The C++11 rule don't actually state this explicitly, but I'm
11404   // assuming that's the intent.
11405   if (IsLambda && !Var->getDeclName()) {
11406     if (Diagnose) {
11407       S.Diag(Loc, diag::err_lambda_capture_anonymous_var);
11408       S.Diag(Var->getLocation(), diag::note_declared_at);
11409     }
11410     return false;
11411   }
11412 
11413   // Prohibit variably-modified types; they're difficult to deal with.
11414   if (Var->getType()->isVariablyModifiedType()) {
11415     if (Diagnose) {
11416       if (IsBlock)
11417         S.Diag(Loc, diag::err_ref_vm_type);
11418       else
11419         S.Diag(Loc, diag::err_lambda_capture_vm_type) << Var->getDeclName();
11420       S.Diag(Var->getLocation(), diag::note_previous_decl)
11421         << Var->getDeclName();
11422     }
11423     return false;
11424   }
11425   // Prohibit structs with flexible array members too.
11426   // We cannot capture what is in the tail end of the struct.
11427   if (const RecordType *VTTy = Var->getType()->getAs<RecordType>()) {
11428     if (VTTy->getDecl()->hasFlexibleArrayMember()) {
11429       if (Diagnose) {
11430         if (IsBlock)
11431           S.Diag(Loc, diag::err_ref_flexarray_type);
11432         else
11433           S.Diag(Loc, diag::err_lambda_capture_flexarray_type)
11434             << Var->getDeclName();
11435         S.Diag(Var->getLocation(), diag::note_previous_decl)
11436           << Var->getDeclName();
11437       }
11438       return false;
11439     }
11440   }
11441   const bool HasBlocksAttr = Var->hasAttr<BlocksAttr>();
11442   // Lambdas and captured statements are not allowed to capture __block
11443   // variables; they don't support the expected semantics.
11444   if (HasBlocksAttr && (IsLambda || isa<CapturedRegionScopeInfo>(CSI))) {
11445     if (Diagnose) {
11446       S.Diag(Loc, diag::err_capture_block_variable)
11447         << Var->getDeclName() << !IsLambda;
11448       S.Diag(Var->getLocation(), diag::note_previous_decl)
11449         << Var->getDeclName();
11450     }
11451     return false;
11452   }
11453 
11454   return true;
11455 }
11456 
11457 // Returns true if the capture by block was successful.
11458 static bool captureInBlock(BlockScopeInfo *BSI, VarDecl *Var,
11459                                  SourceLocation Loc,
11460                                  const bool BuildAndDiagnose,
11461                                  QualType &CaptureType,
11462                                  QualType &DeclRefType,
11463                                  const bool Nested,
11464                                  Sema &S) {
11465   Expr *CopyExpr = 0;
11466   bool ByRef = false;
11467 
11468   // Blocks are not allowed to capture arrays.
11469   if (CaptureType->isArrayType()) {
11470     if (BuildAndDiagnose) {
11471       S.Diag(Loc, diag::err_ref_array_type);
11472       S.Diag(Var->getLocation(), diag::note_previous_decl)
11473       << Var->getDeclName();
11474     }
11475     return false;
11476   }
11477 
11478   // Forbid the block-capture of autoreleasing variables.
11479   if (CaptureType.getObjCLifetime() == Qualifiers::OCL_Autoreleasing) {
11480     if (BuildAndDiagnose) {
11481       S.Diag(Loc, diag::err_arc_autoreleasing_capture)
11482         << /*block*/ 0;
11483       S.Diag(Var->getLocation(), diag::note_previous_decl)
11484         << Var->getDeclName();
11485     }
11486     return false;
11487   }
11488   const bool HasBlocksAttr = Var->hasAttr<BlocksAttr>();
11489   if (HasBlocksAttr || CaptureType->isReferenceType()) {
11490     // Block capture by reference does not change the capture or
11491     // declaration reference types.
11492     ByRef = true;
11493   } else {
11494     // Block capture by copy introduces 'const'.
11495     CaptureType = CaptureType.getNonReferenceType().withConst();
11496     DeclRefType = CaptureType;
11497 
11498     if (S.getLangOpts().CPlusPlus && BuildAndDiagnose) {
11499       if (const RecordType *Record = DeclRefType->getAs<RecordType>()) {
11500         // The capture logic needs the destructor, so make sure we mark it.
11501         // Usually this is unnecessary because most local variables have
11502         // their destructors marked at declaration time, but parameters are
11503         // an exception because it's technically only the call site that
11504         // actually requires the destructor.
11505         if (isa<ParmVarDecl>(Var))
11506           S.FinalizeVarWithDestructor(Var, Record);
11507 
11508         // Enter a new evaluation context to insulate the copy
11509         // full-expression.
11510         EnterExpressionEvaluationContext scope(S, S.PotentiallyEvaluated);
11511 
11512         // According to the blocks spec, the capture of a variable from
11513         // the stack requires a const copy constructor.  This is not true
11514         // of the copy/move done to move a __block variable to the heap.
11515         Expr *DeclRef = new (S.Context) DeclRefExpr(Var, Nested,
11516                                                   DeclRefType.withConst(),
11517                                                   VK_LValue, Loc);
11518 
11519         ExprResult Result
11520           = S.PerformCopyInitialization(
11521               InitializedEntity::InitializeBlock(Var->getLocation(),
11522                                                   CaptureType, false),
11523               Loc, S.Owned(DeclRef));
11524 
11525         // Build a full-expression copy expression if initialization
11526         // succeeded and used a non-trivial constructor.  Recover from
11527         // errors by pretending that the copy isn't necessary.
11528         if (!Result.isInvalid() &&
11529             !cast<CXXConstructExpr>(Result.get())->getConstructor()
11530                 ->isTrivial()) {
11531           Result = S.MaybeCreateExprWithCleanups(Result);
11532           CopyExpr = Result.take();
11533         }
11534       }
11535     }
11536   }
11537 
11538   // Actually capture the variable.
11539   if (BuildAndDiagnose)
11540     BSI->addCapture(Var, HasBlocksAttr, ByRef, Nested, Loc,
11541                     SourceLocation(), CaptureType, CopyExpr);
11542 
11543   return true;
11544 
11545 }
11546 
11547 
11548 /// \brief Capture the given variable in the captured region.
11549 static bool captureInCapturedRegion(CapturedRegionScopeInfo *RSI,
11550                                     VarDecl *Var,
11551                                     SourceLocation Loc,
11552                                     const bool BuildAndDiagnose,
11553                                     QualType &CaptureType,
11554                                     QualType &DeclRefType,
11555                                     const bool RefersToEnclosingLocal,
11556                                     Sema &S) {
11557 
11558   // By default, capture variables by reference.
11559   bool ByRef = true;
11560   // Using an LValue reference type is consistent with Lambdas (see below).
11561   CaptureType = S.Context.getLValueReferenceType(DeclRefType);
11562   Expr *CopyExpr = 0;
11563   if (BuildAndDiagnose) {
11564     // The current implementation assumes that all variables are captured
11565     // by references. Since there is no capture by copy, no expression evaluation
11566     // will be needed.
11567     //
11568     RecordDecl *RD = RSI->TheRecordDecl;
11569 
11570     FieldDecl *Field
11571       = FieldDecl::Create(S.Context, RD, Loc, Loc, 0, CaptureType,
11572                           S.Context.getTrivialTypeSourceInfo(CaptureType, Loc),
11573                           0, false, ICIS_NoInit);
11574     Field->setImplicit(true);
11575     Field->setAccess(AS_private);
11576     RD->addDecl(Field);
11577 
11578     CopyExpr = new (S.Context) DeclRefExpr(Var, RefersToEnclosingLocal,
11579                                             DeclRefType, VK_LValue, Loc);
11580     Var->setReferenced(true);
11581     Var->markUsed(S.Context);
11582   }
11583 
11584   // Actually capture the variable.
11585   if (BuildAndDiagnose)
11586     RSI->addCapture(Var, /*isBlock*/false, ByRef, RefersToEnclosingLocal, Loc,
11587                     SourceLocation(), CaptureType, CopyExpr);
11588 
11589 
11590   return true;
11591 }
11592 
11593 /// \brief Create a field within the lambda class for the variable
11594 ///  being captured.  Handle Array captures.
11595 static ExprResult addAsFieldToClosureType(Sema &S,
11596                                  LambdaScopeInfo *LSI,
11597                                   VarDecl *Var, QualType FieldType,
11598                                   QualType DeclRefType,
11599                                   SourceLocation Loc,
11600                                   bool RefersToEnclosingLocal) {
11601   CXXRecordDecl *Lambda = LSI->Lambda;
11602 
11603   // Build the non-static data member.
11604   FieldDecl *Field
11605     = FieldDecl::Create(S.Context, Lambda, Loc, Loc, 0, FieldType,
11606                         S.Context.getTrivialTypeSourceInfo(FieldType, Loc),
11607                         0, false, ICIS_NoInit);
11608   Field->setImplicit(true);
11609   Field->setAccess(AS_private);
11610   Lambda->addDecl(Field);
11611 
11612   // C++11 [expr.prim.lambda]p21:
11613   //   When the lambda-expression is evaluated, the entities that
11614   //   are captured by copy are used to direct-initialize each
11615   //   corresponding non-static data member of the resulting closure
11616   //   object. (For array members, the array elements are
11617   //   direct-initialized in increasing subscript order.) These
11618   //   initializations are performed in the (unspecified) order in
11619   //   which the non-static data members are declared.
11620 
11621   // Introduce a new evaluation context for the initialization, so
11622   // that temporaries introduced as part of the capture are retained
11623   // to be re-"exported" from the lambda expression itself.
11624   EnterExpressionEvaluationContext scope(S, Sema::PotentiallyEvaluated);
11625 
11626   // C++ [expr.prim.labda]p12:
11627   //   An entity captured by a lambda-expression is odr-used (3.2) in
11628   //   the scope containing the lambda-expression.
11629   Expr *Ref = new (S.Context) DeclRefExpr(Var, RefersToEnclosingLocal,
11630                                           DeclRefType, VK_LValue, Loc);
11631   Var->setReferenced(true);
11632   Var->markUsed(S.Context);
11633 
11634   // When the field has array type, create index variables for each
11635   // dimension of the array. We use these index variables to subscript
11636   // the source array, and other clients (e.g., CodeGen) will perform
11637   // the necessary iteration with these index variables.
11638   SmallVector<VarDecl *, 4> IndexVariables;
11639   QualType BaseType = FieldType;
11640   QualType SizeType = S.Context.getSizeType();
11641   LSI->ArrayIndexStarts.push_back(LSI->ArrayIndexVars.size());
11642   while (const ConstantArrayType *Array
11643                         = S.Context.getAsConstantArrayType(BaseType)) {
11644     // Create the iteration variable for this array index.
11645     IdentifierInfo *IterationVarName = 0;
11646     {
11647       SmallString<8> Str;
11648       llvm::raw_svector_ostream OS(Str);
11649       OS << "__i" << IndexVariables.size();
11650       IterationVarName = &S.Context.Idents.get(OS.str());
11651     }
11652     VarDecl *IterationVar
11653       = VarDecl::Create(S.Context, S.CurContext, Loc, Loc,
11654                         IterationVarName, SizeType,
11655                         S.Context.getTrivialTypeSourceInfo(SizeType, Loc),
11656                         SC_None);
11657     IndexVariables.push_back(IterationVar);
11658     LSI->ArrayIndexVars.push_back(IterationVar);
11659 
11660     // Create a reference to the iteration variable.
11661     ExprResult IterationVarRef
11662       = S.BuildDeclRefExpr(IterationVar, SizeType, VK_LValue, Loc);
11663     assert(!IterationVarRef.isInvalid() &&
11664            "Reference to invented variable cannot fail!");
11665     IterationVarRef = S.DefaultLvalueConversion(IterationVarRef.take());
11666     assert(!IterationVarRef.isInvalid() &&
11667            "Conversion of invented variable cannot fail!");
11668 
11669     // Subscript the array with this iteration variable.
11670     ExprResult Subscript = S.CreateBuiltinArraySubscriptExpr(
11671                              Ref, Loc, IterationVarRef.take(), Loc);
11672     if (Subscript.isInvalid()) {
11673       S.CleanupVarDeclMarking();
11674       S.DiscardCleanupsInEvaluationContext();
11675       return ExprError();
11676     }
11677 
11678     Ref = Subscript.take();
11679     BaseType = Array->getElementType();
11680   }
11681 
11682   // Construct the entity that we will be initializing. For an array, this
11683   // will be first element in the array, which may require several levels
11684   // of array-subscript entities.
11685   SmallVector<InitializedEntity, 4> Entities;
11686   Entities.reserve(1 + IndexVariables.size());
11687   Entities.push_back(
11688     InitializedEntity::InitializeLambdaCapture(Var, Field, Loc));
11689   for (unsigned I = 0, N = IndexVariables.size(); I != N; ++I)
11690     Entities.push_back(InitializedEntity::InitializeElement(S.Context,
11691                                                             0,
11692                                                             Entities.back()));
11693 
11694   InitializationKind InitKind
11695     = InitializationKind::CreateDirect(Loc, Loc, Loc);
11696   InitializationSequence Init(S, Entities.back(), InitKind, Ref);
11697   ExprResult Result(true);
11698   if (!Init.Diagnose(S, Entities.back(), InitKind, Ref))
11699     Result = Init.Perform(S, Entities.back(), InitKind, Ref);
11700 
11701   // If this initialization requires any cleanups (e.g., due to a
11702   // default argument to a copy constructor), note that for the
11703   // lambda.
11704   if (S.ExprNeedsCleanups)
11705     LSI->ExprNeedsCleanups = true;
11706 
11707   // Exit the expression evaluation context used for the capture.
11708   S.CleanupVarDeclMarking();
11709   S.DiscardCleanupsInEvaluationContext();
11710   return Result;
11711 }
11712 
11713 
11714 
11715 /// \brief Capture the given variable in the lambda.
11716 static bool captureInLambda(LambdaScopeInfo *LSI,
11717                             VarDecl *Var,
11718                             SourceLocation Loc,
11719                             const bool BuildAndDiagnose,
11720                             QualType &CaptureType,
11721                             QualType &DeclRefType,
11722                             const bool RefersToEnclosingLocal,
11723                             const Sema::TryCaptureKind Kind,
11724                             SourceLocation EllipsisLoc,
11725                             const bool IsTopScope,
11726                             Sema &S) {
11727 
11728   // Determine whether we are capturing by reference or by value.
11729   bool ByRef = false;
11730   if (IsTopScope && Kind != Sema::TryCapture_Implicit) {
11731     ByRef = (Kind == Sema::TryCapture_ExplicitByRef);
11732   } else {
11733     ByRef = (LSI->ImpCaptureStyle == LambdaScopeInfo::ImpCap_LambdaByref);
11734   }
11735 
11736   // Compute the type of the field that will capture this variable.
11737   if (ByRef) {
11738     // C++11 [expr.prim.lambda]p15:
11739     //   An entity is captured by reference if it is implicitly or
11740     //   explicitly captured but not captured by copy. It is
11741     //   unspecified whether additional unnamed non-static data
11742     //   members are declared in the closure type for entities
11743     //   captured by reference.
11744     //
11745     // FIXME: It is not clear whether we want to build an lvalue reference
11746     // to the DeclRefType or to CaptureType.getNonReferenceType(). GCC appears
11747     // to do the former, while EDG does the latter. Core issue 1249 will
11748     // clarify, but for now we follow GCC because it's a more permissive and
11749     // easily defensible position.
11750     CaptureType = S.Context.getLValueReferenceType(DeclRefType);
11751   } else {
11752     // C++11 [expr.prim.lambda]p14:
11753     //   For each entity captured by copy, an unnamed non-static
11754     //   data member is declared in the closure type. The
11755     //   declaration order of these members is unspecified. The type
11756     //   of such a data member is the type of the corresponding
11757     //   captured entity if the entity is not a reference to an
11758     //   object, or the referenced type otherwise. [Note: If the
11759     //   captured entity is a reference to a function, the
11760     //   corresponding data member is also a reference to a
11761     //   function. - end note ]
11762     if (const ReferenceType *RefType = CaptureType->getAs<ReferenceType>()){
11763       if (!RefType->getPointeeType()->isFunctionType())
11764         CaptureType = RefType->getPointeeType();
11765     }
11766 
11767     // Forbid the lambda copy-capture of autoreleasing variables.
11768     if (CaptureType.getObjCLifetime() == Qualifiers::OCL_Autoreleasing) {
11769       if (BuildAndDiagnose) {
11770         S.Diag(Loc, diag::err_arc_autoreleasing_capture) << /*lambda*/ 1;
11771         S.Diag(Var->getLocation(), diag::note_previous_decl)
11772           << Var->getDeclName();
11773       }
11774       return false;
11775     }
11776 
11777     if (S.RequireNonAbstractType(Loc, CaptureType,
11778                                  diag::err_capture_of_abstract_type))
11779       return false;
11780   }
11781 
11782   // Capture this variable in the lambda.
11783   Expr *CopyExpr = 0;
11784   if (BuildAndDiagnose) {
11785     ExprResult Result = addAsFieldToClosureType(S, LSI, Var,
11786                                         CaptureType, DeclRefType, Loc,
11787                                         RefersToEnclosingLocal);
11788     if (!Result.isInvalid())
11789       CopyExpr = Result.take();
11790   }
11791 
11792   // Compute the type of a reference to this captured variable.
11793   if (ByRef)
11794     DeclRefType = CaptureType.getNonReferenceType();
11795   else {
11796     // C++ [expr.prim.lambda]p5:
11797     //   The closure type for a lambda-expression has a public inline
11798     //   function call operator [...]. This function call operator is
11799     //   declared const (9.3.1) if and only if the lambda-expression’s
11800     //   parameter-declaration-clause is not followed by mutable.
11801     DeclRefType = CaptureType.getNonReferenceType();
11802     if (!LSI->Mutable && !CaptureType->isReferenceType())
11803       DeclRefType.addConst();
11804   }
11805 
11806   // Add the capture.
11807   if (BuildAndDiagnose)
11808     LSI->addCapture(Var, /*IsBlock=*/false, ByRef, RefersToEnclosingLocal,
11809                     Loc, EllipsisLoc, CaptureType, CopyExpr);
11810 
11811   return true;
11812 }
11813 
11814 
11815 bool Sema::tryCaptureVariable(VarDecl *Var, SourceLocation ExprLoc,
11816                               TryCaptureKind Kind, SourceLocation EllipsisLoc,
11817                               bool BuildAndDiagnose,
11818                               QualType &CaptureType,
11819                               QualType &DeclRefType) {
11820   bool Nested = false;
11821 
11822   DeclContext *DC = CurContext;
11823   const unsigned MaxFunctionScopesIndex = FunctionScopes.size() - 1;
11824 
11825   // If the variable is declared in the current context (and is not an
11826   // init-capture), there is no need to capture it.
11827   if (!Var->isInitCapture() && Var->getDeclContext() == DC) return true;
11828   if (!Var->hasLocalStorage()) return true;
11829 
11830   // Walk up the stack to determine whether we can capture the variable,
11831   // performing the "simple" checks that don't depend on type. We stop when
11832   // we've either hit the declared scope of the variable or find an existing
11833   // capture of that variable.  We start from the innermost capturing-entity
11834   // (the DC) and ensure that all intervening capturing-entities
11835   // (blocks/lambdas etc.) between the innermost capturer and the variable`s
11836   // declcontext can either capture the variable or have already captured
11837   // the variable.
11838   CaptureType = Var->getType();
11839   DeclRefType = CaptureType.getNonReferenceType();
11840   bool Explicit = (Kind != TryCapture_Implicit);
11841   unsigned FunctionScopesIndex = MaxFunctionScopesIndex;
11842   do {
11843     // Only block literals, captured statements, and lambda expressions can
11844     // capture; other scopes don't work.
11845     DeclContext *ParentDC = getParentOfCapturingContextOrNull(DC, Var,
11846                                                               ExprLoc,
11847                                                               BuildAndDiagnose,
11848                                                               *this);
11849     if (!ParentDC) return true;
11850 
11851     FunctionScopeInfo  *FSI = FunctionScopes[FunctionScopesIndex];
11852     CapturingScopeInfo *CSI = cast<CapturingScopeInfo>(FSI);
11853 
11854 
11855     // Check whether we've already captured it.
11856     if (isVariableAlreadyCapturedInScopeInfo(CSI, Var, Nested, CaptureType,
11857                                              DeclRefType))
11858       break;
11859 
11860     // Certain capturing entities (lambdas, blocks etc.) are not allowed to capture
11861     // certain types of variables (unnamed, variably modified types etc.)
11862     // so check for eligibility.
11863     if (!isVariableCapturable(CSI, Var, ExprLoc, BuildAndDiagnose, *this))
11864        return true;
11865 
11866     if (CSI->ImpCaptureStyle == CapturingScopeInfo::ImpCap_None && !Explicit) {
11867       // No capture-default, and this is not an explicit capture
11868       // so cannot capture this variable.
11869       if (BuildAndDiagnose) {
11870         Diag(ExprLoc, diag::err_lambda_impcap) << Var->getDeclName();
11871         Diag(Var->getLocation(), diag::note_previous_decl)
11872           << Var->getDeclName();
11873         Diag(cast<LambdaScopeInfo>(CSI)->Lambda->getLocStart(),
11874              diag::note_lambda_decl);
11875       }
11876       return true;
11877     }
11878 
11879     FunctionScopesIndex--;
11880     DC = ParentDC;
11881     Explicit = false;
11882   } while (!Var->getDeclContext()->Equals(DC));
11883 
11884   // Walk back down the scope stack, (e.g. from outer lambda to inner lambda)
11885   // computing the type of the capture at each step, checking type-specific
11886   // requirements, and adding captures if requested.
11887   // If the variable had already been captured previously, we start capturing
11888   // at the lambda nested within that one.
11889   for (unsigned I = ++FunctionScopesIndex, N = MaxFunctionScopesIndex + 1; I != N;
11890        ++I) {
11891     CapturingScopeInfo *CSI = cast<CapturingScopeInfo>(FunctionScopes[I]);
11892 
11893     if (BlockScopeInfo *BSI = dyn_cast<BlockScopeInfo>(CSI)) {
11894       if (!captureInBlock(BSI, Var, ExprLoc,
11895                           BuildAndDiagnose, CaptureType,
11896                           DeclRefType, Nested, *this))
11897         return true;
11898       Nested = true;
11899     } else if (CapturedRegionScopeInfo *RSI = dyn_cast<CapturedRegionScopeInfo>(CSI)) {
11900       if (!captureInCapturedRegion(RSI, Var, ExprLoc,
11901                                    BuildAndDiagnose, CaptureType,
11902                                    DeclRefType, Nested, *this))
11903         return true;
11904       Nested = true;
11905     } else {
11906       LambdaScopeInfo *LSI = cast<LambdaScopeInfo>(CSI);
11907       if (!captureInLambda(LSI, Var, ExprLoc,
11908                            BuildAndDiagnose, CaptureType,
11909                            DeclRefType, Nested, Kind, EllipsisLoc,
11910                             /*IsTopScope*/I == N - 1, *this))
11911         return true;
11912       Nested = true;
11913     }
11914   }
11915   return false;
11916 }
11917 
11918 bool Sema::tryCaptureVariable(VarDecl *Var, SourceLocation Loc,
11919                               TryCaptureKind Kind, SourceLocation EllipsisLoc) {
11920   QualType CaptureType;
11921   QualType DeclRefType;
11922   return tryCaptureVariable(Var, Loc, Kind, EllipsisLoc,
11923                             /*BuildAndDiagnose=*/true, CaptureType,
11924                             DeclRefType);
11925 }
11926 
11927 QualType Sema::getCapturedDeclRefType(VarDecl *Var, SourceLocation Loc) {
11928   QualType CaptureType;
11929   QualType DeclRefType;
11930 
11931   // Determine whether we can capture this variable.
11932   if (tryCaptureVariable(Var, Loc, TryCapture_Implicit, SourceLocation(),
11933                          /*BuildAndDiagnose=*/false, CaptureType, DeclRefType))
11934     return QualType();
11935 
11936   return DeclRefType;
11937 }
11938 
11939 static void MarkVarDeclODRUsed(Sema &SemaRef, VarDecl *Var,
11940                                SourceLocation Loc) {
11941   // Keep track of used but undefined variables.
11942   // FIXME: We shouldn't suppress this warning for static data members.
11943   if (Var->hasDefinition(SemaRef.Context) == VarDecl::DeclarationOnly &&
11944       !Var->isExternallyVisible() &&
11945       !(Var->isStaticDataMember() && Var->hasInit())) {
11946     SourceLocation &old = SemaRef.UndefinedButUsed[Var->getCanonicalDecl()];
11947     if (old.isInvalid()) old = Loc;
11948   }
11949 
11950   SemaRef.tryCaptureVariable(Var, Loc);
11951 
11952   Var->markUsed(SemaRef.Context);
11953 }
11954 
11955 void Sema::UpdateMarkingForLValueToRValue(Expr *E) {
11956   // Per C++11 [basic.def.odr], a variable is odr-used "unless it is
11957   // an object that satisfies the requirements for appearing in a
11958   // constant expression (5.19) and the lvalue-to-rvalue conversion (4.1)
11959   // is immediately applied."  This function handles the lvalue-to-rvalue
11960   // conversion part.
11961   MaybeODRUseExprs.erase(E->IgnoreParens());
11962 }
11963 
11964 ExprResult Sema::ActOnConstantExpression(ExprResult Res) {
11965   if (!Res.isUsable())
11966     return Res;
11967 
11968   // If a constant-expression is a reference to a variable where we delay
11969   // deciding whether it is an odr-use, just assume we will apply the
11970   // lvalue-to-rvalue conversion.  In the one case where this doesn't happen
11971   // (a non-type template argument), we have special handling anyway.
11972   UpdateMarkingForLValueToRValue(Res.get());
11973   return Res;
11974 }
11975 
11976 void Sema::CleanupVarDeclMarking() {
11977   for (llvm::SmallPtrSetIterator<Expr*> i = MaybeODRUseExprs.begin(),
11978                                         e = MaybeODRUseExprs.end();
11979        i != e; ++i) {
11980     VarDecl *Var;
11981     SourceLocation Loc;
11982     if (DeclRefExpr *DRE = dyn_cast<DeclRefExpr>(*i)) {
11983       Var = cast<VarDecl>(DRE->getDecl());
11984       Loc = DRE->getLocation();
11985     } else if (MemberExpr *ME = dyn_cast<MemberExpr>(*i)) {
11986       Var = cast<VarDecl>(ME->getMemberDecl());
11987       Loc = ME->getMemberLoc();
11988     } else {
11989       llvm_unreachable("Unexpcted expression");
11990     }
11991 
11992     MarkVarDeclODRUsed(*this, Var, Loc);
11993   }
11994 
11995   MaybeODRUseExprs.clear();
11996 }
11997 
11998 // Mark a VarDecl referenced, and perform the necessary handling to compute
11999 // odr-uses.
12000 static void DoMarkVarDeclReferenced(Sema &SemaRef, SourceLocation Loc,
12001                                     VarDecl *Var, Expr *E) {
12002   Var->setReferenced();
12003 
12004   if (!IsPotentiallyEvaluatedContext(SemaRef))
12005     return;
12006 
12007   VarTemplateSpecializationDecl *VarSpec =
12008       dyn_cast<VarTemplateSpecializationDecl>(Var);
12009   assert(!isa<VarTemplatePartialSpecializationDecl>(Var) &&
12010          "Can't instantiate a partial template specialization.");
12011 
12012   // Implicit instantiation of static data members, static data member
12013   // templates of class templates, and variable template specializations.
12014   // Delay instantiations of variable templates, except for those
12015   // that could be used in a constant expression.
12016   TemplateSpecializationKind TSK = Var->getTemplateSpecializationKind();
12017   if (isTemplateInstantiation(TSK)) {
12018     bool TryInstantiating = TSK == TSK_ImplicitInstantiation;
12019 
12020     if (TryInstantiating && !isa<VarTemplateSpecializationDecl>(Var)) {
12021       if (Var->getPointOfInstantiation().isInvalid()) {
12022         // This is a modification of an existing AST node. Notify listeners.
12023         if (ASTMutationListener *L = SemaRef.getASTMutationListener())
12024           L->StaticDataMemberInstantiated(Var);
12025       } else if (!Var->isUsableInConstantExpressions(SemaRef.Context))
12026         // Don't bother trying to instantiate it again, unless we might need
12027         // its initializer before we get to the end of the TU.
12028         TryInstantiating = false;
12029     }
12030 
12031     if (Var->getPointOfInstantiation().isInvalid())
12032       Var->setTemplateSpecializationKind(TSK, Loc);
12033 
12034     if (TryInstantiating) {
12035       SourceLocation PointOfInstantiation = Var->getPointOfInstantiation();
12036       bool InstantiationDependent = false;
12037       bool IsNonDependent =
12038           VarSpec ? !TemplateSpecializationType::anyDependentTemplateArguments(
12039                         VarSpec->getTemplateArgsInfo(), InstantiationDependent)
12040                   : true;
12041 
12042       // Do not instantiate specializations that are still type-dependent.
12043       if (IsNonDependent) {
12044         if (Var->isUsableInConstantExpressions(SemaRef.Context)) {
12045           // Do not defer instantiations of variables which could be used in a
12046           // constant expression.
12047           SemaRef.InstantiateVariableDefinition(PointOfInstantiation, Var);
12048         } else {
12049           SemaRef.PendingInstantiations
12050               .push_back(std::make_pair(Var, PointOfInstantiation));
12051         }
12052       }
12053     }
12054   }
12055 
12056   // Per C++11 [basic.def.odr], a variable is odr-used "unless it satisfies
12057   // the requirements for appearing in a constant expression (5.19) and, if
12058   // it is an object, the lvalue-to-rvalue conversion (4.1)
12059   // is immediately applied."  We check the first part here, and
12060   // Sema::UpdateMarkingForLValueToRValue deals with the second part.
12061   // Note that we use the C++11 definition everywhere because nothing in
12062   // C++03 depends on whether we get the C++03 version correct. The second
12063   // part does not apply to references, since they are not objects.
12064   const VarDecl *DefVD;
12065   if (E && !isa<ParmVarDecl>(Var) &&
12066       Var->isUsableInConstantExpressions(SemaRef.Context) &&
12067       Var->getAnyInitializer(DefVD) && DefVD->checkInitIsICE()) {
12068     if (!Var->getType()->isReferenceType())
12069       SemaRef.MaybeODRUseExprs.insert(E);
12070   } else
12071     MarkVarDeclODRUsed(SemaRef, Var, Loc);
12072 }
12073 
12074 /// \brief Mark a variable referenced, and check whether it is odr-used
12075 /// (C++ [basic.def.odr]p2, C99 6.9p3).  Note that this should not be
12076 /// used directly for normal expressions referring to VarDecl.
12077 void Sema::MarkVariableReferenced(SourceLocation Loc, VarDecl *Var) {
12078   DoMarkVarDeclReferenced(*this, Loc, Var, 0);
12079 }
12080 
12081 static void MarkExprReferenced(Sema &SemaRef, SourceLocation Loc,
12082                                Decl *D, Expr *E, bool OdrUse) {
12083   if (VarDecl *Var = dyn_cast<VarDecl>(D)) {
12084     DoMarkVarDeclReferenced(SemaRef, Loc, Var, E);
12085     return;
12086   }
12087 
12088   SemaRef.MarkAnyDeclReferenced(Loc, D, OdrUse);
12089 
12090   // If this is a call to a method via a cast, also mark the method in the
12091   // derived class used in case codegen can devirtualize the call.
12092   const MemberExpr *ME = dyn_cast<MemberExpr>(E);
12093   if (!ME)
12094     return;
12095   CXXMethodDecl *MD = dyn_cast<CXXMethodDecl>(ME->getMemberDecl());
12096   if (!MD)
12097     return;
12098   const Expr *Base = ME->getBase();
12099   const CXXRecordDecl *MostDerivedClassDecl = Base->getBestDynamicClassType();
12100   if (!MostDerivedClassDecl)
12101     return;
12102   CXXMethodDecl *DM = MD->getCorrespondingMethodInClass(MostDerivedClassDecl);
12103   if (!DM || DM->isPure())
12104     return;
12105   SemaRef.MarkAnyDeclReferenced(Loc, DM, OdrUse);
12106 }
12107 
12108 /// \brief Perform reference-marking and odr-use handling for a DeclRefExpr.
12109 void Sema::MarkDeclRefReferenced(DeclRefExpr *E) {
12110   // TODO: update this with DR# once a defect report is filed.
12111   // C++11 defect. The address of a pure member should not be an ODR use, even
12112   // if it's a qualified reference.
12113   bool OdrUse = true;
12114   if (CXXMethodDecl *Method = dyn_cast<CXXMethodDecl>(E->getDecl()))
12115     if (Method->isVirtual())
12116       OdrUse = false;
12117   MarkExprReferenced(*this, E->getLocation(), E->getDecl(), E, OdrUse);
12118 }
12119 
12120 /// \brief Perform reference-marking and odr-use handling for a MemberExpr.
12121 void Sema::MarkMemberReferenced(MemberExpr *E) {
12122   // C++11 [basic.def.odr]p2:
12123   //   A non-overloaded function whose name appears as a potentially-evaluated
12124   //   expression or a member of a set of candidate functions, if selected by
12125   //   overload resolution when referred to from a potentially-evaluated
12126   //   expression, is odr-used, unless it is a pure virtual function and its
12127   //   name is not explicitly qualified.
12128   bool OdrUse = true;
12129   if (!E->hasQualifier()) {
12130     if (CXXMethodDecl *Method = dyn_cast<CXXMethodDecl>(E->getMemberDecl()))
12131       if (Method->isPure())
12132         OdrUse = false;
12133   }
12134   SourceLocation Loc = E->getMemberLoc().isValid() ?
12135                             E->getMemberLoc() : E->getLocStart();
12136   MarkExprReferenced(*this, Loc, E->getMemberDecl(), E, OdrUse);
12137 }
12138 
12139 /// \brief Perform marking for a reference to an arbitrary declaration.  It
12140 /// marks the declaration referenced, and performs odr-use checking for functions
12141 /// and variables. This method should not be used when building an normal
12142 /// expression which refers to a variable.
12143 void Sema::MarkAnyDeclReferenced(SourceLocation Loc, Decl *D, bool OdrUse) {
12144   if (OdrUse) {
12145     if (VarDecl *VD = dyn_cast<VarDecl>(D)) {
12146       MarkVariableReferenced(Loc, VD);
12147       return;
12148     }
12149     if (FunctionDecl *FD = dyn_cast<FunctionDecl>(D)) {
12150       MarkFunctionReferenced(Loc, FD);
12151       return;
12152     }
12153   }
12154   D->setReferenced();
12155 }
12156 
12157 namespace {
12158   // Mark all of the declarations referenced
12159   // FIXME: Not fully implemented yet! We need to have a better understanding
12160   // of when we're entering
12161   class MarkReferencedDecls : public RecursiveASTVisitor<MarkReferencedDecls> {
12162     Sema &S;
12163     SourceLocation Loc;
12164 
12165   public:
12166     typedef RecursiveASTVisitor<MarkReferencedDecls> Inherited;
12167 
12168     MarkReferencedDecls(Sema &S, SourceLocation Loc) : S(S), Loc(Loc) { }
12169 
12170     bool TraverseTemplateArgument(const TemplateArgument &Arg);
12171     bool TraverseRecordType(RecordType *T);
12172   };
12173 }
12174 
12175 bool MarkReferencedDecls::TraverseTemplateArgument(
12176   const TemplateArgument &Arg) {
12177   if (Arg.getKind() == TemplateArgument::Declaration) {
12178     if (Decl *D = Arg.getAsDecl())
12179       S.MarkAnyDeclReferenced(Loc, D, true);
12180   }
12181 
12182   return Inherited::TraverseTemplateArgument(Arg);
12183 }
12184 
12185 bool MarkReferencedDecls::TraverseRecordType(RecordType *T) {
12186   if (ClassTemplateSpecializationDecl *Spec
12187                   = dyn_cast<ClassTemplateSpecializationDecl>(T->getDecl())) {
12188     const TemplateArgumentList &Args = Spec->getTemplateArgs();
12189     return TraverseTemplateArguments(Args.data(), Args.size());
12190   }
12191 
12192   return true;
12193 }
12194 
12195 void Sema::MarkDeclarationsReferencedInType(SourceLocation Loc, QualType T) {
12196   MarkReferencedDecls Marker(*this, Loc);
12197   Marker.TraverseType(Context.getCanonicalType(T));
12198 }
12199 
12200 namespace {
12201   /// \brief Helper class that marks all of the declarations referenced by
12202   /// potentially-evaluated subexpressions as "referenced".
12203   class EvaluatedExprMarker : public EvaluatedExprVisitor<EvaluatedExprMarker> {
12204     Sema &S;
12205     bool SkipLocalVariables;
12206 
12207   public:
12208     typedef EvaluatedExprVisitor<EvaluatedExprMarker> Inherited;
12209 
12210     EvaluatedExprMarker(Sema &S, bool SkipLocalVariables)
12211       : Inherited(S.Context), S(S), SkipLocalVariables(SkipLocalVariables) { }
12212 
12213     void VisitDeclRefExpr(DeclRefExpr *E) {
12214       // If we were asked not to visit local variables, don't.
12215       if (SkipLocalVariables) {
12216         if (VarDecl *VD = dyn_cast<VarDecl>(E->getDecl()))
12217           if (VD->hasLocalStorage())
12218             return;
12219       }
12220 
12221       S.MarkDeclRefReferenced(E);
12222     }
12223 
12224     void VisitMemberExpr(MemberExpr *E) {
12225       S.MarkMemberReferenced(E);
12226       Inherited::VisitMemberExpr(E);
12227     }
12228 
12229     void VisitCXXBindTemporaryExpr(CXXBindTemporaryExpr *E) {
12230       S.MarkFunctionReferenced(E->getLocStart(),
12231             const_cast<CXXDestructorDecl*>(E->getTemporary()->getDestructor()));
12232       Visit(E->getSubExpr());
12233     }
12234 
12235     void VisitCXXNewExpr(CXXNewExpr *E) {
12236       if (E->getOperatorNew())
12237         S.MarkFunctionReferenced(E->getLocStart(), E->getOperatorNew());
12238       if (E->getOperatorDelete())
12239         S.MarkFunctionReferenced(E->getLocStart(), E->getOperatorDelete());
12240       Inherited::VisitCXXNewExpr(E);
12241     }
12242 
12243     void VisitCXXDeleteExpr(CXXDeleteExpr *E) {
12244       if (E->getOperatorDelete())
12245         S.MarkFunctionReferenced(E->getLocStart(), E->getOperatorDelete());
12246       QualType Destroyed = S.Context.getBaseElementType(E->getDestroyedType());
12247       if (const RecordType *DestroyedRec = Destroyed->getAs<RecordType>()) {
12248         CXXRecordDecl *Record = cast<CXXRecordDecl>(DestroyedRec->getDecl());
12249         S.MarkFunctionReferenced(E->getLocStart(),
12250                                     S.LookupDestructor(Record));
12251       }
12252 
12253       Inherited::VisitCXXDeleteExpr(E);
12254     }
12255 
12256     void VisitCXXConstructExpr(CXXConstructExpr *E) {
12257       S.MarkFunctionReferenced(E->getLocStart(), E->getConstructor());
12258       Inherited::VisitCXXConstructExpr(E);
12259     }
12260 
12261     void VisitCXXDefaultArgExpr(CXXDefaultArgExpr *E) {
12262       Visit(E->getExpr());
12263     }
12264 
12265     void VisitImplicitCastExpr(ImplicitCastExpr *E) {
12266       Inherited::VisitImplicitCastExpr(E);
12267 
12268       if (E->getCastKind() == CK_LValueToRValue)
12269         S.UpdateMarkingForLValueToRValue(E->getSubExpr());
12270     }
12271   };
12272 }
12273 
12274 /// \brief Mark any declarations that appear within this expression or any
12275 /// potentially-evaluated subexpressions as "referenced".
12276 ///
12277 /// \param SkipLocalVariables If true, don't mark local variables as
12278 /// 'referenced'.
12279 void Sema::MarkDeclarationsReferencedInExpr(Expr *E,
12280                                             bool SkipLocalVariables) {
12281   EvaluatedExprMarker(*this, SkipLocalVariables).Visit(E);
12282 }
12283 
12284 /// \brief Emit a diagnostic that describes an effect on the run-time behavior
12285 /// of the program being compiled.
12286 ///
12287 /// This routine emits the given diagnostic when the code currently being
12288 /// type-checked is "potentially evaluated", meaning that there is a
12289 /// possibility that the code will actually be executable. Code in sizeof()
12290 /// expressions, code used only during overload resolution, etc., are not
12291 /// potentially evaluated. This routine will suppress such diagnostics or,
12292 /// in the absolutely nutty case of potentially potentially evaluated
12293 /// expressions (C++ typeid), queue the diagnostic to potentially emit it
12294 /// later.
12295 ///
12296 /// This routine should be used for all diagnostics that describe the run-time
12297 /// behavior of a program, such as passing a non-POD value through an ellipsis.
12298 /// Failure to do so will likely result in spurious diagnostics or failures
12299 /// during overload resolution or within sizeof/alignof/typeof/typeid.
12300 bool Sema::DiagRuntimeBehavior(SourceLocation Loc, const Stmt *Statement,
12301                                const PartialDiagnostic &PD) {
12302   switch (ExprEvalContexts.back().Context) {
12303   case Unevaluated:
12304   case UnevaluatedAbstract:
12305     // The argument will never be evaluated, so don't complain.
12306     break;
12307 
12308   case ConstantEvaluated:
12309     // Relevant diagnostics should be produced by constant evaluation.
12310     break;
12311 
12312   case PotentiallyEvaluated:
12313   case PotentiallyEvaluatedIfUsed:
12314     if (Statement && getCurFunctionOrMethodDecl()) {
12315       FunctionScopes.back()->PossiblyUnreachableDiags.
12316         push_back(sema::PossiblyUnreachableDiag(PD, Loc, Statement));
12317     }
12318     else
12319       Diag(Loc, PD);
12320 
12321     return true;
12322   }
12323 
12324   return false;
12325 }
12326 
12327 bool Sema::CheckCallReturnType(QualType ReturnType, SourceLocation Loc,
12328                                CallExpr *CE, FunctionDecl *FD) {
12329   if (ReturnType->isVoidType() || !ReturnType->isIncompleteType())
12330     return false;
12331 
12332   // If we're inside a decltype's expression, don't check for a valid return
12333   // type or construct temporaries until we know whether this is the last call.
12334   if (ExprEvalContexts.back().IsDecltype) {
12335     ExprEvalContexts.back().DelayedDecltypeCalls.push_back(CE);
12336     return false;
12337   }
12338 
12339   class CallReturnIncompleteDiagnoser : public TypeDiagnoser {
12340     FunctionDecl *FD;
12341     CallExpr *CE;
12342 
12343   public:
12344     CallReturnIncompleteDiagnoser(FunctionDecl *FD, CallExpr *CE)
12345       : FD(FD), CE(CE) { }
12346 
12347     virtual void diagnose(Sema &S, SourceLocation Loc, QualType T) {
12348       if (!FD) {
12349         S.Diag(Loc, diag::err_call_incomplete_return)
12350           << T << CE->getSourceRange();
12351         return;
12352       }
12353 
12354       S.Diag(Loc, diag::err_call_function_incomplete_return)
12355         << CE->getSourceRange() << FD->getDeclName() << T;
12356       S.Diag(FD->getLocation(),
12357              diag::note_function_with_incomplete_return_type_declared_here)
12358         << FD->getDeclName();
12359     }
12360   } Diagnoser(FD, CE);
12361 
12362   if (RequireCompleteType(Loc, ReturnType, Diagnoser))
12363     return true;
12364 
12365   return false;
12366 }
12367 
12368 // Diagnose the s/=/==/ and s/\|=/!=/ typos. Note that adding parentheses
12369 // will prevent this condition from triggering, which is what we want.
12370 void Sema::DiagnoseAssignmentAsCondition(Expr *E) {
12371   SourceLocation Loc;
12372 
12373   unsigned diagnostic = diag::warn_condition_is_assignment;
12374   bool IsOrAssign = false;
12375 
12376   if (BinaryOperator *Op = dyn_cast<BinaryOperator>(E)) {
12377     if (Op->getOpcode() != BO_Assign && Op->getOpcode() != BO_OrAssign)
12378       return;
12379 
12380     IsOrAssign = Op->getOpcode() == BO_OrAssign;
12381 
12382     // Greylist some idioms by putting them into a warning subcategory.
12383     if (ObjCMessageExpr *ME
12384           = dyn_cast<ObjCMessageExpr>(Op->getRHS()->IgnoreParenCasts())) {
12385       Selector Sel = ME->getSelector();
12386 
12387       // self = [<foo> init...]
12388       if (isSelfExpr(Op->getLHS()) && ME->getMethodFamily() == OMF_init)
12389         diagnostic = diag::warn_condition_is_idiomatic_assignment;
12390 
12391       // <foo> = [<bar> nextObject]
12392       else if (Sel.isUnarySelector() && Sel.getNameForSlot(0) == "nextObject")
12393         diagnostic = diag::warn_condition_is_idiomatic_assignment;
12394     }
12395 
12396     Loc = Op->getOperatorLoc();
12397   } else if (CXXOperatorCallExpr *Op = dyn_cast<CXXOperatorCallExpr>(E)) {
12398     if (Op->getOperator() != OO_Equal && Op->getOperator() != OO_PipeEqual)
12399       return;
12400 
12401     IsOrAssign = Op->getOperator() == OO_PipeEqual;
12402     Loc = Op->getOperatorLoc();
12403   } else if (PseudoObjectExpr *POE = dyn_cast<PseudoObjectExpr>(E))
12404     return DiagnoseAssignmentAsCondition(POE->getSyntacticForm());
12405   else {
12406     // Not an assignment.
12407     return;
12408   }
12409 
12410   Diag(Loc, diagnostic) << E->getSourceRange();
12411 
12412   SourceLocation Open = E->getLocStart();
12413   SourceLocation Close = PP.getLocForEndOfToken(E->getSourceRange().getEnd());
12414   Diag(Loc, diag::note_condition_assign_silence)
12415         << FixItHint::CreateInsertion(Open, "(")
12416         << FixItHint::CreateInsertion(Close, ")");
12417 
12418   if (IsOrAssign)
12419     Diag(Loc, diag::note_condition_or_assign_to_comparison)
12420       << FixItHint::CreateReplacement(Loc, "!=");
12421   else
12422     Diag(Loc, diag::note_condition_assign_to_comparison)
12423       << FixItHint::CreateReplacement(Loc, "==");
12424 }
12425 
12426 /// \brief Redundant parentheses over an equality comparison can indicate
12427 /// that the user intended an assignment used as condition.
12428 void Sema::DiagnoseEqualityWithExtraParens(ParenExpr *ParenE) {
12429   // Don't warn if the parens came from a macro.
12430   SourceLocation parenLoc = ParenE->getLocStart();
12431   if (parenLoc.isInvalid() || parenLoc.isMacroID())
12432     return;
12433   // Don't warn for dependent expressions.
12434   if (ParenE->isTypeDependent())
12435     return;
12436 
12437   Expr *E = ParenE->IgnoreParens();
12438 
12439   if (BinaryOperator *opE = dyn_cast<BinaryOperator>(E))
12440     if (opE->getOpcode() == BO_EQ &&
12441         opE->getLHS()->IgnoreParenImpCasts()->isModifiableLvalue(Context)
12442                                                            == Expr::MLV_Valid) {
12443       SourceLocation Loc = opE->getOperatorLoc();
12444 
12445       Diag(Loc, diag::warn_equality_with_extra_parens) << E->getSourceRange();
12446       SourceRange ParenERange = ParenE->getSourceRange();
12447       Diag(Loc, diag::note_equality_comparison_silence)
12448         << FixItHint::CreateRemoval(ParenERange.getBegin())
12449         << FixItHint::CreateRemoval(ParenERange.getEnd());
12450       Diag(Loc, diag::note_equality_comparison_to_assign)
12451         << FixItHint::CreateReplacement(Loc, "=");
12452     }
12453 }
12454 
12455 ExprResult Sema::CheckBooleanCondition(Expr *E, SourceLocation Loc) {
12456   DiagnoseAssignmentAsCondition(E);
12457   if (ParenExpr *parenE = dyn_cast<ParenExpr>(E))
12458     DiagnoseEqualityWithExtraParens(parenE);
12459 
12460   ExprResult result = CheckPlaceholderExpr(E);
12461   if (result.isInvalid()) return ExprError();
12462   E = result.take();
12463 
12464   if (!E->isTypeDependent()) {
12465     if (getLangOpts().CPlusPlus)
12466       return CheckCXXBooleanCondition(E); // C++ 6.4p4
12467 
12468     ExprResult ERes = DefaultFunctionArrayLvalueConversion(E);
12469     if (ERes.isInvalid())
12470       return ExprError();
12471     E = ERes.take();
12472 
12473     QualType T = E->getType();
12474     if (!T->isScalarType()) { // C99 6.8.4.1p1
12475       Diag(Loc, diag::err_typecheck_statement_requires_scalar)
12476         << T << E->getSourceRange();
12477       return ExprError();
12478     }
12479   }
12480 
12481   return Owned(E);
12482 }
12483 
12484 ExprResult Sema::ActOnBooleanCondition(Scope *S, SourceLocation Loc,
12485                                        Expr *SubExpr) {
12486   if (!SubExpr)
12487     return ExprError();
12488 
12489   return CheckBooleanCondition(SubExpr, Loc);
12490 }
12491 
12492 namespace {
12493   /// A visitor for rebuilding a call to an __unknown_any expression
12494   /// to have an appropriate type.
12495   struct RebuildUnknownAnyFunction
12496     : StmtVisitor<RebuildUnknownAnyFunction, ExprResult> {
12497 
12498     Sema &S;
12499 
12500     RebuildUnknownAnyFunction(Sema &S) : S(S) {}
12501 
12502     ExprResult VisitStmt(Stmt *S) {
12503       llvm_unreachable("unexpected statement!");
12504     }
12505 
12506     ExprResult VisitExpr(Expr *E) {
12507       S.Diag(E->getExprLoc(), diag::err_unsupported_unknown_any_call)
12508         << E->getSourceRange();
12509       return ExprError();
12510     }
12511 
12512     /// Rebuild an expression which simply semantically wraps another
12513     /// expression which it shares the type and value kind of.
12514     template <class T> ExprResult rebuildSugarExpr(T *E) {
12515       ExprResult SubResult = Visit(E->getSubExpr());
12516       if (SubResult.isInvalid()) return ExprError();
12517 
12518       Expr *SubExpr = SubResult.take();
12519       E->setSubExpr(SubExpr);
12520       E->setType(SubExpr->getType());
12521       E->setValueKind(SubExpr->getValueKind());
12522       assert(E->getObjectKind() == OK_Ordinary);
12523       return E;
12524     }
12525 
12526     ExprResult VisitParenExpr(ParenExpr *E) {
12527       return rebuildSugarExpr(E);
12528     }
12529 
12530     ExprResult VisitUnaryExtension(UnaryOperator *E) {
12531       return rebuildSugarExpr(E);
12532     }
12533 
12534     ExprResult VisitUnaryAddrOf(UnaryOperator *E) {
12535       ExprResult SubResult = Visit(E->getSubExpr());
12536       if (SubResult.isInvalid()) return ExprError();
12537 
12538       Expr *SubExpr = SubResult.take();
12539       E->setSubExpr(SubExpr);
12540       E->setType(S.Context.getPointerType(SubExpr->getType()));
12541       assert(E->getValueKind() == VK_RValue);
12542       assert(E->getObjectKind() == OK_Ordinary);
12543       return E;
12544     }
12545 
12546     ExprResult resolveDecl(Expr *E, ValueDecl *VD) {
12547       if (!isa<FunctionDecl>(VD)) return VisitExpr(E);
12548 
12549       E->setType(VD->getType());
12550 
12551       assert(E->getValueKind() == VK_RValue);
12552       if (S.getLangOpts().CPlusPlus &&
12553           !(isa<CXXMethodDecl>(VD) &&
12554             cast<CXXMethodDecl>(VD)->isInstance()))
12555         E->setValueKind(VK_LValue);
12556 
12557       return E;
12558     }
12559 
12560     ExprResult VisitMemberExpr(MemberExpr *E) {
12561       return resolveDecl(E, E->getMemberDecl());
12562     }
12563 
12564     ExprResult VisitDeclRefExpr(DeclRefExpr *E) {
12565       return resolveDecl(E, E->getDecl());
12566     }
12567   };
12568 }
12569 
12570 /// Given a function expression of unknown-any type, try to rebuild it
12571 /// to have a function type.
12572 static ExprResult rebuildUnknownAnyFunction(Sema &S, Expr *FunctionExpr) {
12573   ExprResult Result = RebuildUnknownAnyFunction(S).Visit(FunctionExpr);
12574   if (Result.isInvalid()) return ExprError();
12575   return S.DefaultFunctionArrayConversion(Result.take());
12576 }
12577 
12578 namespace {
12579   /// A visitor for rebuilding an expression of type __unknown_anytype
12580   /// into one which resolves the type directly on the referring
12581   /// expression.  Strict preservation of the original source
12582   /// structure is not a goal.
12583   struct RebuildUnknownAnyExpr
12584     : StmtVisitor<RebuildUnknownAnyExpr, ExprResult> {
12585 
12586     Sema &S;
12587 
12588     /// The current destination type.
12589     QualType DestType;
12590 
12591     RebuildUnknownAnyExpr(Sema &S, QualType CastType)
12592       : S(S), DestType(CastType) {}
12593 
12594     ExprResult VisitStmt(Stmt *S) {
12595       llvm_unreachable("unexpected statement!");
12596     }
12597 
12598     ExprResult VisitExpr(Expr *E) {
12599       S.Diag(E->getExprLoc(), diag::err_unsupported_unknown_any_expr)
12600         << E->getSourceRange();
12601       return ExprError();
12602     }
12603 
12604     ExprResult VisitCallExpr(CallExpr *E);
12605     ExprResult VisitObjCMessageExpr(ObjCMessageExpr *E);
12606 
12607     /// Rebuild an expression which simply semantically wraps another
12608     /// expression which it shares the type and value kind of.
12609     template <class T> ExprResult rebuildSugarExpr(T *E) {
12610       ExprResult SubResult = Visit(E->getSubExpr());
12611       if (SubResult.isInvalid()) return ExprError();
12612       Expr *SubExpr = SubResult.take();
12613       E->setSubExpr(SubExpr);
12614       E->setType(SubExpr->getType());
12615       E->setValueKind(SubExpr->getValueKind());
12616       assert(E->getObjectKind() == OK_Ordinary);
12617       return E;
12618     }
12619 
12620     ExprResult VisitParenExpr(ParenExpr *E) {
12621       return rebuildSugarExpr(E);
12622     }
12623 
12624     ExprResult VisitUnaryExtension(UnaryOperator *E) {
12625       return rebuildSugarExpr(E);
12626     }
12627 
12628     ExprResult VisitUnaryAddrOf(UnaryOperator *E) {
12629       const PointerType *Ptr = DestType->getAs<PointerType>();
12630       if (!Ptr) {
12631         S.Diag(E->getOperatorLoc(), diag::err_unknown_any_addrof)
12632           << E->getSourceRange();
12633         return ExprError();
12634       }
12635       assert(E->getValueKind() == VK_RValue);
12636       assert(E->getObjectKind() == OK_Ordinary);
12637       E->setType(DestType);
12638 
12639       // Build the sub-expression as if it were an object of the pointee type.
12640       DestType = Ptr->getPointeeType();
12641       ExprResult SubResult = Visit(E->getSubExpr());
12642       if (SubResult.isInvalid()) return ExprError();
12643       E->setSubExpr(SubResult.take());
12644       return E;
12645     }
12646 
12647     ExprResult VisitImplicitCastExpr(ImplicitCastExpr *E);
12648 
12649     ExprResult resolveDecl(Expr *E, ValueDecl *VD);
12650 
12651     ExprResult VisitMemberExpr(MemberExpr *E) {
12652       return resolveDecl(E, E->getMemberDecl());
12653     }
12654 
12655     ExprResult VisitDeclRefExpr(DeclRefExpr *E) {
12656       return resolveDecl(E, E->getDecl());
12657     }
12658   };
12659 }
12660 
12661 /// Rebuilds a call expression which yielded __unknown_anytype.
12662 ExprResult RebuildUnknownAnyExpr::VisitCallExpr(CallExpr *E) {
12663   Expr *CalleeExpr = E->getCallee();
12664 
12665   enum FnKind {
12666     FK_MemberFunction,
12667     FK_FunctionPointer,
12668     FK_BlockPointer
12669   };
12670 
12671   FnKind Kind;
12672   QualType CalleeType = CalleeExpr->getType();
12673   if (CalleeType == S.Context.BoundMemberTy) {
12674     assert(isa<CXXMemberCallExpr>(E) || isa<CXXOperatorCallExpr>(E));
12675     Kind = FK_MemberFunction;
12676     CalleeType = Expr::findBoundMemberType(CalleeExpr);
12677   } else if (const PointerType *Ptr = CalleeType->getAs<PointerType>()) {
12678     CalleeType = Ptr->getPointeeType();
12679     Kind = FK_FunctionPointer;
12680   } else {
12681     CalleeType = CalleeType->castAs<BlockPointerType>()->getPointeeType();
12682     Kind = FK_BlockPointer;
12683   }
12684   const FunctionType *FnType = CalleeType->castAs<FunctionType>();
12685 
12686   // Verify that this is a legal result type of a function.
12687   if (DestType->isArrayType() || DestType->isFunctionType()) {
12688     unsigned diagID = diag::err_func_returning_array_function;
12689     if (Kind == FK_BlockPointer)
12690       diagID = diag::err_block_returning_array_function;
12691 
12692     S.Diag(E->getExprLoc(), diagID)
12693       << DestType->isFunctionType() << DestType;
12694     return ExprError();
12695   }
12696 
12697   // Otherwise, go ahead and set DestType as the call's result.
12698   E->setType(DestType.getNonLValueExprType(S.Context));
12699   E->setValueKind(Expr::getValueKindForType(DestType));
12700   assert(E->getObjectKind() == OK_Ordinary);
12701 
12702   // Rebuild the function type, replacing the result type with DestType.
12703   const FunctionProtoType *Proto = dyn_cast<FunctionProtoType>(FnType);
12704   if (Proto) {
12705     // __unknown_anytype(...) is a special case used by the debugger when
12706     // it has no idea what a function's signature is.
12707     //
12708     // We want to build this call essentially under the K&R
12709     // unprototyped rules, but making a FunctionNoProtoType in C++
12710     // would foul up all sorts of assumptions.  However, we cannot
12711     // simply pass all arguments as variadic arguments, nor can we
12712     // portably just call the function under a non-variadic type; see
12713     // the comment on IR-gen's TargetInfo::isNoProtoCallVariadic.
12714     // However, it turns out that in practice it is generally safe to
12715     // call a function declared as "A foo(B,C,D);" under the prototype
12716     // "A foo(B,C,D,...);".  The only known exception is with the
12717     // Windows ABI, where any variadic function is implicitly cdecl
12718     // regardless of its normal CC.  Therefore we change the parameter
12719     // types to match the types of the arguments.
12720     //
12721     // This is a hack, but it is far superior to moving the
12722     // corresponding target-specific code from IR-gen to Sema/AST.
12723 
12724     ArrayRef<QualType> ParamTypes = Proto->getArgTypes();
12725     SmallVector<QualType, 8> ArgTypes;
12726     if (ParamTypes.empty() && Proto->isVariadic()) { // the special case
12727       ArgTypes.reserve(E->getNumArgs());
12728       for (unsigned i = 0, e = E->getNumArgs(); i != e; ++i) {
12729         Expr *Arg = E->getArg(i);
12730         QualType ArgType = Arg->getType();
12731         if (E->isLValue()) {
12732           ArgType = S.Context.getLValueReferenceType(ArgType);
12733         } else if (E->isXValue()) {
12734           ArgType = S.Context.getRValueReferenceType(ArgType);
12735         }
12736         ArgTypes.push_back(ArgType);
12737       }
12738       ParamTypes = ArgTypes;
12739     }
12740     DestType = S.Context.getFunctionType(DestType, ParamTypes,
12741                                          Proto->getExtProtoInfo());
12742   } else {
12743     DestType = S.Context.getFunctionNoProtoType(DestType,
12744                                                 FnType->getExtInfo());
12745   }
12746 
12747   // Rebuild the appropriate pointer-to-function type.
12748   switch (Kind) {
12749   case FK_MemberFunction:
12750     // Nothing to do.
12751     break;
12752 
12753   case FK_FunctionPointer:
12754     DestType = S.Context.getPointerType(DestType);
12755     break;
12756 
12757   case FK_BlockPointer:
12758     DestType = S.Context.getBlockPointerType(DestType);
12759     break;
12760   }
12761 
12762   // Finally, we can recurse.
12763   ExprResult CalleeResult = Visit(CalleeExpr);
12764   if (!CalleeResult.isUsable()) return ExprError();
12765   E->setCallee(CalleeResult.take());
12766 
12767   // Bind a temporary if necessary.
12768   return S.MaybeBindToTemporary(E);
12769 }
12770 
12771 ExprResult RebuildUnknownAnyExpr::VisitObjCMessageExpr(ObjCMessageExpr *E) {
12772   // Verify that this is a legal result type of a call.
12773   if (DestType->isArrayType() || DestType->isFunctionType()) {
12774     S.Diag(E->getExprLoc(), diag::err_func_returning_array_function)
12775       << DestType->isFunctionType() << DestType;
12776     return ExprError();
12777   }
12778 
12779   // Rewrite the method result type if available.
12780   if (ObjCMethodDecl *Method = E->getMethodDecl()) {
12781     assert(Method->getResultType() == S.Context.UnknownAnyTy);
12782     Method->setResultType(DestType);
12783   }
12784 
12785   // Change the type of the message.
12786   E->setType(DestType.getNonReferenceType());
12787   E->setValueKind(Expr::getValueKindForType(DestType));
12788 
12789   return S.MaybeBindToTemporary(E);
12790 }
12791 
12792 ExprResult RebuildUnknownAnyExpr::VisitImplicitCastExpr(ImplicitCastExpr *E) {
12793   // The only case we should ever see here is a function-to-pointer decay.
12794   if (E->getCastKind() == CK_FunctionToPointerDecay) {
12795     assert(E->getValueKind() == VK_RValue);
12796     assert(E->getObjectKind() == OK_Ordinary);
12797 
12798     E->setType(DestType);
12799 
12800     // Rebuild the sub-expression as the pointee (function) type.
12801     DestType = DestType->castAs<PointerType>()->getPointeeType();
12802 
12803     ExprResult Result = Visit(E->getSubExpr());
12804     if (!Result.isUsable()) return ExprError();
12805 
12806     E->setSubExpr(Result.take());
12807     return S.Owned(E);
12808   } else if (E->getCastKind() == CK_LValueToRValue) {
12809     assert(E->getValueKind() == VK_RValue);
12810     assert(E->getObjectKind() == OK_Ordinary);
12811 
12812     assert(isa<BlockPointerType>(E->getType()));
12813 
12814     E->setType(DestType);
12815 
12816     // The sub-expression has to be a lvalue reference, so rebuild it as such.
12817     DestType = S.Context.getLValueReferenceType(DestType);
12818 
12819     ExprResult Result = Visit(E->getSubExpr());
12820     if (!Result.isUsable()) return ExprError();
12821 
12822     E->setSubExpr(Result.take());
12823     return S.Owned(E);
12824   } else {
12825     llvm_unreachable("Unhandled cast type!");
12826   }
12827 }
12828 
12829 ExprResult RebuildUnknownAnyExpr::resolveDecl(Expr *E, ValueDecl *VD) {
12830   ExprValueKind ValueKind = VK_LValue;
12831   QualType Type = DestType;
12832 
12833   // We know how to make this work for certain kinds of decls:
12834 
12835   //  - functions
12836   if (FunctionDecl *FD = dyn_cast<FunctionDecl>(VD)) {
12837     if (const PointerType *Ptr = Type->getAs<PointerType>()) {
12838       DestType = Ptr->getPointeeType();
12839       ExprResult Result = resolveDecl(E, VD);
12840       if (Result.isInvalid()) return ExprError();
12841       return S.ImpCastExprToType(Result.take(), Type,
12842                                  CK_FunctionToPointerDecay, VK_RValue);
12843     }
12844 
12845     if (!Type->isFunctionType()) {
12846       S.Diag(E->getExprLoc(), diag::err_unknown_any_function)
12847         << VD << E->getSourceRange();
12848       return ExprError();
12849     }
12850 
12851     if (CXXMethodDecl *MD = dyn_cast<CXXMethodDecl>(FD))
12852       if (MD->isInstance()) {
12853         ValueKind = VK_RValue;
12854         Type = S.Context.BoundMemberTy;
12855       }
12856 
12857     // Function references aren't l-values in C.
12858     if (!S.getLangOpts().CPlusPlus)
12859       ValueKind = VK_RValue;
12860 
12861   //  - variables
12862   } else if (isa<VarDecl>(VD)) {
12863     if (const ReferenceType *RefTy = Type->getAs<ReferenceType>()) {
12864       Type = RefTy->getPointeeType();
12865     } else if (Type->isFunctionType()) {
12866       S.Diag(E->getExprLoc(), diag::err_unknown_any_var_function_type)
12867         << VD << E->getSourceRange();
12868       return ExprError();
12869     }
12870 
12871   //  - nothing else
12872   } else {
12873     S.Diag(E->getExprLoc(), diag::err_unsupported_unknown_any_decl)
12874       << VD << E->getSourceRange();
12875     return ExprError();
12876   }
12877 
12878   // Modifying the declaration like this is friendly to IR-gen but
12879   // also really dangerous.
12880   VD->setType(DestType);
12881   E->setType(Type);
12882   E->setValueKind(ValueKind);
12883   return S.Owned(E);
12884 }
12885 
12886 /// Check a cast of an unknown-any type.  We intentionally only
12887 /// trigger this for C-style casts.
12888 ExprResult Sema::checkUnknownAnyCast(SourceRange TypeRange, QualType CastType,
12889                                      Expr *CastExpr, CastKind &CastKind,
12890                                      ExprValueKind &VK, CXXCastPath &Path) {
12891   // Rewrite the casted expression from scratch.
12892   ExprResult result = RebuildUnknownAnyExpr(*this, CastType).Visit(CastExpr);
12893   if (!result.isUsable()) return ExprError();
12894 
12895   CastExpr = result.take();
12896   VK = CastExpr->getValueKind();
12897   CastKind = CK_NoOp;
12898 
12899   return CastExpr;
12900 }
12901 
12902 ExprResult Sema::forceUnknownAnyToType(Expr *E, QualType ToType) {
12903   return RebuildUnknownAnyExpr(*this, ToType).Visit(E);
12904 }
12905 
12906 ExprResult Sema::checkUnknownAnyArg(SourceLocation callLoc,
12907                                     Expr *arg, QualType &paramType) {
12908   // If the syntactic form of the argument is not an explicit cast of
12909   // any sort, just do default argument promotion.
12910   ExplicitCastExpr *castArg = dyn_cast<ExplicitCastExpr>(arg->IgnoreParens());
12911   if (!castArg) {
12912     ExprResult result = DefaultArgumentPromotion(arg);
12913     if (result.isInvalid()) return ExprError();
12914     paramType = result.get()->getType();
12915     return result;
12916   }
12917 
12918   // Otherwise, use the type that was written in the explicit cast.
12919   assert(!arg->hasPlaceholderType());
12920   paramType = castArg->getTypeAsWritten();
12921 
12922   // Copy-initialize a parameter of that type.
12923   InitializedEntity entity =
12924     InitializedEntity::InitializeParameter(Context, paramType,
12925                                            /*consumed*/ false);
12926   return PerformCopyInitialization(entity, callLoc, Owned(arg));
12927 }
12928 
12929 static ExprResult diagnoseUnknownAnyExpr(Sema &S, Expr *E) {
12930   Expr *orig = E;
12931   unsigned diagID = diag::err_uncasted_use_of_unknown_any;
12932   while (true) {
12933     E = E->IgnoreParenImpCasts();
12934     if (CallExpr *call = dyn_cast<CallExpr>(E)) {
12935       E = call->getCallee();
12936       diagID = diag::err_uncasted_call_of_unknown_any;
12937     } else {
12938       break;
12939     }
12940   }
12941 
12942   SourceLocation loc;
12943   NamedDecl *d;
12944   if (DeclRefExpr *ref = dyn_cast<DeclRefExpr>(E)) {
12945     loc = ref->getLocation();
12946     d = ref->getDecl();
12947   } else if (MemberExpr *mem = dyn_cast<MemberExpr>(E)) {
12948     loc = mem->getMemberLoc();
12949     d = mem->getMemberDecl();
12950   } else if (ObjCMessageExpr *msg = dyn_cast<ObjCMessageExpr>(E)) {
12951     diagID = diag::err_uncasted_call_of_unknown_any;
12952     loc = msg->getSelectorStartLoc();
12953     d = msg->getMethodDecl();
12954     if (!d) {
12955       S.Diag(loc, diag::err_uncasted_send_to_unknown_any_method)
12956         << static_cast<unsigned>(msg->isClassMessage()) << msg->getSelector()
12957         << orig->getSourceRange();
12958       return ExprError();
12959     }
12960   } else {
12961     S.Diag(E->getExprLoc(), diag::err_unsupported_unknown_any_expr)
12962       << E->getSourceRange();
12963     return ExprError();
12964   }
12965 
12966   S.Diag(loc, diagID) << d << orig->getSourceRange();
12967 
12968   // Never recoverable.
12969   return ExprError();
12970 }
12971 
12972 /// Check for operands with placeholder types and complain if found.
12973 /// Returns true if there was an error and no recovery was possible.
12974 ExprResult Sema::CheckPlaceholderExpr(Expr *E) {
12975   const BuiltinType *placeholderType = E->getType()->getAsPlaceholderType();
12976   if (!placeholderType) return Owned(E);
12977 
12978   switch (placeholderType->getKind()) {
12979 
12980   // Overloaded expressions.
12981   case BuiltinType::Overload: {
12982     // Try to resolve a single function template specialization.
12983     // This is obligatory.
12984     ExprResult result = Owned(E);
12985     if (ResolveAndFixSingleFunctionTemplateSpecialization(result, false)) {
12986       return result;
12987 
12988     // If that failed, try to recover with a call.
12989     } else {
12990       tryToRecoverWithCall(result, PDiag(diag::err_ovl_unresolvable),
12991                            /*complain*/ true);
12992       return result;
12993     }
12994   }
12995 
12996   // Bound member functions.
12997   case BuiltinType::BoundMember: {
12998     ExprResult result = Owned(E);
12999     tryToRecoverWithCall(result, PDiag(diag::err_bound_member_function),
13000                          /*complain*/ true);
13001     return result;
13002   }
13003 
13004   // ARC unbridged casts.
13005   case BuiltinType::ARCUnbridgedCast: {
13006     Expr *realCast = stripARCUnbridgedCast(E);
13007     diagnoseARCUnbridgedCast(realCast);
13008     return Owned(realCast);
13009   }
13010 
13011   // Expressions of unknown type.
13012   case BuiltinType::UnknownAny:
13013     return diagnoseUnknownAnyExpr(*this, E);
13014 
13015   // Pseudo-objects.
13016   case BuiltinType::PseudoObject:
13017     return checkPseudoObjectRValue(E);
13018 
13019   case BuiltinType::BuiltinFn:
13020     Diag(E->getLocStart(), diag::err_builtin_fn_use);
13021     return ExprError();
13022 
13023   // Everything else should be impossible.
13024 #define BUILTIN_TYPE(Id, SingletonId) \
13025   case BuiltinType::Id:
13026 #define PLACEHOLDER_TYPE(Id, SingletonId)
13027 #include "clang/AST/BuiltinTypes.def"
13028     break;
13029   }
13030 
13031   llvm_unreachable("invalid placeholder type!");
13032 }
13033 
13034 bool Sema::CheckCaseExpression(Expr *E) {
13035   if (E->isTypeDependent())
13036     return true;
13037   if (E->isValueDependent() || E->isIntegerConstantExpr(Context))
13038     return E->getType()->isIntegralOrEnumerationType();
13039   return false;
13040 }
13041 
13042 /// ActOnObjCBoolLiteral - Parse {__objc_yes,__objc_no} literals.
13043 ExprResult
13044 Sema::ActOnObjCBoolLiteral(SourceLocation OpLoc, tok::TokenKind Kind) {
13045   assert((Kind == tok::kw___objc_yes || Kind == tok::kw___objc_no) &&
13046          "Unknown Objective-C Boolean value!");
13047   QualType BoolT = Context.ObjCBuiltinBoolTy;
13048   if (!Context.getBOOLDecl()) {
13049     LookupResult Result(*this, &Context.Idents.get("BOOL"), OpLoc,
13050                         Sema::LookupOrdinaryName);
13051     if (LookupName(Result, getCurScope()) && Result.isSingleResult()) {
13052       NamedDecl *ND = Result.getFoundDecl();
13053       if (TypedefDecl *TD = dyn_cast<TypedefDecl>(ND))
13054         Context.setBOOLDecl(TD);
13055     }
13056   }
13057   if (Context.getBOOLDecl())
13058     BoolT = Context.getBOOLType();
13059   return Owned(new (Context) ObjCBoolLiteralExpr(Kind == tok::kw___objc_yes,
13060                                         BoolT, OpLoc));
13061 }
13062