aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--lib/Analysis/GRExprEngine.cpp10
-rw-r--r--test/Analysis/null-deref-ps.c7
2 files changed, 15 insertions, 2 deletions
diff --git a/lib/Analysis/GRExprEngine.cpp b/lib/Analysis/GRExprEngine.cpp
index 415bc3f88a..24250166c2 100644
--- a/lib/Analysis/GRExprEngine.cpp
+++ b/lib/Analysis/GRExprEngine.cpp
@@ -1720,8 +1720,14 @@ void GRExprEngine::VisitCastPointerToInteger(SVal V, const GRState* state,
// FIXME: Determine if the number of bits of the target type is
// equal or exceeds the number of bits to store the pointer value.
// If not, flag an error.
- unsigned bits = getContext().getTypeSize(PtrTy);
- V = nonloc::LocAsInteger::Make(getBasicVals(), cast<Loc>(V), bits);
+
+ if (loc::ConcreteInt *CI = dyn_cast<loc::ConcreteInt>(&V)) {
+ V = nonloc::ConcreteInt(CI->getValue());
+ }
+ else {
+ unsigned bits = getContext().getTypeSize(PtrTy);
+ V = nonloc::LocAsInteger::Make(getBasicVals(), cast<Loc>(V), bits);
+ }
}
MakeNode(Dst, CastE, Pred, BindExpr(state, CastE, V));
diff --git a/test/Analysis/null-deref-ps.c b/test/Analysis/null-deref-ps.c
index b320e8dd19..fe94d6fe7c 100644
--- a/test/Analysis/null-deref-ps.c
+++ b/test/Analysis/null-deref-ps.c
@@ -213,3 +213,10 @@ void f12(HF12ITEM i, char *q) {
*p = 1; // no-warning
}
+// Test handling of translating between integer "pointers" and back.
+void f13() {
+ int *x = 0;
+ if (((((int) x) << 2) + 1) >> 1) *x = 1; // no-warning
+}
+
+