clang -cc1 -cc1 -triple amd64-unknown-openbsd7.4 -analyze -disable-free -clear-ast-before-backend -disable-llvm-verifier -discard-value-names -main-file-name rxp.c -analyzer-checker=core -analyzer-checker=apiModeling -analyzer-checker=unix -analyzer-checker=deadcode -analyzer-checker=security.insecureAPI.UncheckedReturn -analyzer-checker=security.insecureAPI.getpw -analyzer-checker=security.insecureAPI.gets -analyzer-checker=security.insecureAPI.mktemp -analyzer-checker=security.insecureAPI.mkstemp -analyzer-checker=security.insecureAPI.vfork -analyzer-checker=nullability.NullPassedToNonnull -analyzer-checker=nullability.NullReturnedFromNonnull -analyzer-output plist -w -setup-static-analyzer -mrelocation-model pic -pic-level 1 -pic-is-pie -mframe-pointer=all -relaxed-aliasing -ffp-contract=on -fno-rounding-math -mconstructor-aliases -funwind-tables=2 -target-cpu x86-64 -target-feature +retpoline-indirect-calls -target-feature +retpoline-indirect-branches -tune-cpu generic -debugger-tuning=gdb -fcoverage-compilation-dir=/usr/src/games/quiz/obj -resource-dir /usr/local/llvm16/lib/clang/16 -internal-isystem /usr/local/llvm16/lib/clang/16/include -internal-externc-isystem /usr/include -O2 -fdebug-compilation-dir=/usr/src/games/quiz/obj -ferror-limit 19 -fwrapv -D_RET_PROTECTOR -ret-protector -fcf-protection=branch -fno-jump-tables -fgnuc-version=4.2.1 -vectorize-loops -vectorize-slp -fno-builtin-malloc -fno-builtin-calloc -fno-builtin-realloc -fno-builtin-valloc -fno-builtin-free -fno-builtin-strdup -fno-builtin-strndup -analyzer-output=html -faddrsig -D__GCC_HAVE_DWARF2_CFI_ASM=1 -o /home/ben/Projects/scan/2024-01-11-140451-98009-1 -x c /usr/src/games/quiz/rxp.c
1 | |
2 | |
3 | |
4 | |
5 | |
6 | |
7 | |
8 | |
9 | |
10 | |
11 | |
12 | |
13 | |
14 | |
15 | |
16 | |
17 | |
18 | |
19 | |
20 | |
21 | |
22 | |
23 | |
24 | |
25 | |
26 | |
27 | |
28 | |
29 | |
30 | |
31 | |
32 | |
33 | |
34 | |
35 | |
36 | |
37 | |
38 | |
39 | |
40 | |
41 | |
42 | |
43 | |
44 | |
45 | |
46 | |
47 | |
48 | |
49 | |
50 | |
51 | |
52 | |
53 | |
54 | |
55 | |
56 | |
57 | |
58 | #include <stdio.h> |
59 | #include <ctype.h> |
60 | #include "quiz.h" |
61 | |
62 | #define LIT (-1) /* literal character, char */ |
63 | #define SOT (-2) /* start text anchor, - */ |
64 | #define EOT (-3) /* end text anchor, - */ |
65 | #define GRP_S (-4) /* start alternate grp, ptr_to_end */ |
66 | #define GRP_E (-5) /* end group, - */ |
67 | #define ALT_S (-6) /* alternate starts, ptr_to_next */ |
68 | #define ALT_E (-7) /* alternate ends, - */ |
69 | #define END (-8) /* end of regexp, - */ |
70 | |
71 | typedef short Rxp_t; |
72 | |
73 | static Rxp_t rxpbuf[RXP_LINE_SZ]; |
74 | char rxperr[128]; |
75 | |
76 | static int rxp__compile(const char *, int); |
77 | static char *rxp__expand(int); |
78 | static int rxp__match(const char *, int, Rxp_t *, Rxp_t *, const char *); |
79 | |
80 | int |
81 | rxp_compile(const char *s) |
82 | { |
83 | return (rxp__compile(s, TRUE)); |
84 | } |
85 | |
86 | static int |
87 | rxp__compile(const char *s, int first) |
88 | { |
89 | static Rxp_t *rp; |
90 | static const char *sp; |
91 | Rxp_t *grp_ptr; |
92 | Rxp_t *alt_ptr; |
93 | int esc, err; |
94 | |
95 | if (s == NULL) { |
96 | (void)snprintf(rxperr, sizeof(rxperr), |
97 | "null string sent to rxp_compile"); |
98 | return(FALSE); |
99 | } |
100 | esc = 0; |
101 | if (first) { |
102 | rp = rxpbuf; |
103 | sp = s; |
104 | *rp++ = SOT; |
105 | *rp++ = GRP_S; |
106 | *rp++ = 0; |
107 | } |
108 | *rp++ = ALT_S; |
109 | alt_ptr = rp; |
110 | *rp++ = 0; |
111 | for (; *sp; ++sp) { |
112 | if (rp - rxpbuf >= RXP_LINE_SZ - 4) { |
113 | (void)snprintf(rxperr, sizeof(rxperr), |
114 | "regular expression too long %s", s); |
115 | return (FALSE); |
116 | } |
117 | if (*sp == ':' && !esc) |
118 | break; |
119 | if (esc) { |
120 | *rp++ = LIT; |
121 | *rp++ = *sp; |
122 | esc = 0; |
123 | } |
124 | else switch (*sp) { |
125 | case '\\': |
126 | esc = 1; |
127 | break; |
128 | case '{': |
129 | case '[': |
130 | *rp++ = GRP_S; |
131 | grp_ptr = rp; |
132 | *rp++ = 0; |
133 | sp++; |
134 | if ((err = rxp__compile(s, FALSE)) != TRUE) |
135 | return (err); |
136 | *rp++ = GRP_E; |
137 | *grp_ptr = rp - rxpbuf; |
138 | break; |
139 | case '}': |
140 | case ']': |
141 | case '|': |
142 | *rp++ = ALT_E; |
143 | *alt_ptr = rp - rxpbuf; |
144 | if (*sp != ']') { |
145 | *rp++ = ALT_S; |
146 | alt_ptr = rp; |
147 | *rp++ = 0; |
148 | } |
149 | if (*sp != '|') { |
150 | if (*sp != ']') { |
151 | *rp++ = ALT_E; |
152 | *alt_ptr = rp - rxpbuf; |
153 | } |
154 | if (first) { |
155 | (void)snprintf(rxperr, sizeof(rxperr), |
156 | "unmatched alternator in regexp %s", |
157 | s); |
158 | return (FALSE); |
159 | } |
160 | return (TRUE); |
161 | } |
162 | break; |
163 | default: |
164 | *rp++ = LIT; |
165 | *rp++ = *sp; |
166 | esc = 0; |
167 | break; |
168 | } |
169 | } |
170 | if (!first) { |
171 | (void)snprintf(rxperr, sizeof(rxperr), |
172 | "unmatched alternator in regexp %s", s); |
173 | return (FALSE); |
174 | } |
175 | *rp++ = ALT_E; |
176 | *alt_ptr = rp - rxpbuf; |
177 | *rp++ = GRP_E; |
178 | *(rxpbuf + 2) = rp - rxpbuf; |
179 | *rp++ = EOT; |
180 | *rp = END; |
181 | return (TRUE); |
182 | } |
183 | |
184 | |
185 | |
186 | |
187 | int |
188 | rxp_match(const char *s) |
189 | { |
190 | return (rxp__match(s, TRUE, NULL, NULL, NULL)); |
| |
191 | } |
192 | |
193 | |
194 | |
195 | |
196 | |
197 | |
198 | static int |
199 | rxp__match(const char *s, int first, Rxp_t *j_succ, Rxp_t *j_fail, |
200 | const char *sp_fail) |
201 | { |
202 | static Rxp_t *rp; |
203 | static const char *sp; |
204 | int ch; |
205 | Rxp_t *grp_end = NULL; |
| 2 | | 'grp_end' initialized to a null pointer value | |
|
206 | int err; |
207 | |
208 | if (first) { |
| |
209 | rp = rxpbuf; |
210 | sp = s; |
211 | } |
212 | while (rp < rxpbuf + RXP_LINE_SZ && *rp != END) |
| 4 | | Assuming the condition is true | |
|
| 5 | | Loop condition is true. Entering loop body | |
|
| 9 | | Assuming the condition is true | |
|
| 10 | | Loop condition is true. Entering loop body | |
|
| 15 | | Execution continues on line 212 | |
|
| 16 | | Dereference of null pointer (loaded from variable 'rp') |
|
213 | switch(*rp) { |
| 6 | | Control jumps to 'case -6:' at line 238 | |
|
| 11 | | Control jumps to 'case -7:' at line 244 | |
|
214 | case LIT: |
215 | rp++; |
216 | ch = isascii(*rp) && isupper(*rp) ? tolower(*rp) : *rp; |
217 | if (ch != *sp++) { |
218 | rp = j_fail; |
219 | sp = sp_fail; |
220 | return (TRUE); |
221 | } |
222 | rp++; |
223 | break; |
224 | case SOT: |
225 | if (sp != s) |
226 | return (FALSE); |
227 | rp++; |
228 | break; |
229 | case EOT: |
230 | if (*sp != 0) |
231 | return (FALSE); |
232 | rp++; |
233 | break; |
234 | case GRP_S: |
235 | rp++; |
236 | grp_end = rxpbuf + *rp++; |
237 | break; |
238 | case ALT_S: |
239 | rp++; |
240 | if ((err = rxp__match(sp, |
| |
| 13 | | Returning from 'rxp__match' | |
|
| |
241 | FALSE, grp_end, rxpbuf + *rp++, sp)) != TRUE) |
| 7 | | Passing null pointer value via 3rd parameter 'j_succ' | |
|
242 | return (err); |
243 | break; |
244 | case ALT_E: |
245 | rp = j_succ; |
| 12 | | Null pointer value stored to 'rp' | |
|
246 | return (TRUE); |
247 | case GRP_E: |
248 | default: |
249 | return (FALSE); |
250 | } |
251 | return (*rp != END ? FALSE : TRUE); |
252 | } |
253 | |
254 | |
255 | |
256 | |
257 | char * |
258 | rxp_expand(void) |
259 | { |
260 | return (rxp__expand(TRUE)); |
261 | } |
262 | |
263 | static char * |
264 | rxp__expand(int first) |
265 | { |
266 | static char buf[RXP_LINE_SZ/2]; |
267 | static Rxp_t *rp; |
268 | static char *bp; |
269 | Rxp_t *grp_ptr; |
270 | char *err; |
271 | |
272 | if (first) { |
273 | rp = rxpbuf; |
274 | bp = buf; |
275 | } |
276 | while (rp < rxpbuf + RXP_LINE_SZ && *rp != END) |
277 | switch(*rp) { |
278 | case LIT: |
279 | rp++; |
280 | *bp++ = *rp++; |
281 | break; |
282 | case GRP_S: |
283 | rp++; |
284 | grp_ptr = rxpbuf + *rp; |
285 | rp++; |
286 | if ((err = rxp__expand(FALSE)) == NULL) |
287 | return (err); |
288 | rp = grp_ptr; |
289 | break; |
290 | case ALT_E: |
291 | return (buf); |
292 | case ALT_S: |
293 | rp++; |
294 | |
295 | case SOT: |
296 | case EOT: |
297 | case GRP_E: |
298 | rp++; |
299 | break; |
300 | default: |
301 | return (NULL); |
302 | } |
303 | if (first) { |
304 | if (*rp != END) |
305 | return (NULL); |
306 | *bp = '\0'; |
307 | } |
308 | return (buf); |
309 | } |