1 // RUN: %clang_analyze_cc1 -triple x86_64-unknown-linux %s 2 3 #define __GFP_ZERO 0x8000 4 #define NULL ((void *)0) 5 6 typedef __typeof(sizeof(int)) size_t; 7 8 void *kmalloc(size_t, int); 9 10 struct test { 11 }; 12 13 void foo(struct test *); 14 15 void test_zeroed() { 16 struct test **list, *t; 17 int i; 18 19 list = kmalloc(sizeof(*list) * 10, __GFP_ZERO); 20 if (list == NULL) 21 return; 22 23 for (i = 0; i < 10; i++) { 24 t = list[i]; 25 foo(t); 26 } 27 kfree(list); // no-warning 28 } 29 30 void test_nonzero() { 31 struct test **list, *t; 32 int i; 33 34 list = kmalloc(sizeof(*list) * 10, 0); 35 if (list == NULL) 36 return; 37 38 for (i = 0; i < 10; i++) { 39 t = list[i]; // expected-warning{{undefined}} 40 foo(t); 41 } 42 kfree(list); 43 } 44 45 void test_indeterminate(int flags) { 46 struct test **list, *t; 47 int i; 48 49 list = kmalloc(sizeof(*list) * 10, flags); 50 if (list == NULL) 51 return; 52 53 for (i = 0; i < 10; i++) { 54 t = list[i]; // expected-warning{{undefined}} 55 foo(t); 56 } 57 kfree(list); 58 } 59 60 typedef unsigned long long uint64_t; 61 62 struct malloc_type; 63 64 void *malloc(unsigned long size, struct malloc_type *mtp, int flags); 65 66 void test_3arg_malloc(struct malloc_type *mtp) { 67 struct test **list, *t; 68 int i; 69 70 list = malloc(sizeof(*list) * 10, mtp, __GFP_ZERO); 71 if (list == NULL) 72 return; 73 74 for (i = 0; i < 10; i++) { 75 t = list[i]; 76 foo(t); 77 } 78 kfree(list); // no-warning 79 } 80 81 void test_3arg_malloc_nonzero(struct malloc_type *mtp) { 82 struct test **list, *t; 83 int i; 84 85 list = malloc(sizeof(*list) * 10, mtp, 0); 86 if (list == NULL) 87 return; 88 89 for (i = 0; i < 10; i++) { 90 t = list[i]; // expected-warning{{undefined}} 91 foo(t); 92 } 93 kfree(list); 94 } 95 96 void test_3arg_malloc_indeterminate(struct malloc_type *mtp, int flags) { 97 struct test **list, *t; 98 int i; 99 100 list = alloc(sizeof(*list) * 10, mtp, flags); 101 if (list == NULL) 102 return; 103 104 for (i = 0; i < 10; i++) { 105 t = list[i]; // expected-warning{{undefined}} 106 foo(t); 107 } 108 kfree(list); 109 } 110