2016-12-01 13:55:02 +00:00
|
|
|
/*
|
|
|
|
This file is part of solidity.
|
|
|
|
|
|
|
|
solidity is free software: you can redistribute it and/or modify
|
|
|
|
it under the terms of the GNU General Public License as published by
|
|
|
|
the Free Software Foundation, either version 3 of the License, or
|
|
|
|
(at your option) any later version.
|
|
|
|
|
|
|
|
solidity is distributed in the hope that it will be useful,
|
|
|
|
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
GNU General Public License for more details.
|
|
|
|
|
|
|
|
You should have received a copy of the GNU General Public License
|
|
|
|
along with solidity. If not, see <http://www.gnu.org/licenses/>.
|
|
|
|
*/
|
2020-07-17 14:54:12 +00:00
|
|
|
// SPDX-License-Identifier: GPL-3.0
|
2016-12-01 13:55:02 +00:00
|
|
|
/**
|
|
|
|
* @author Federico Bond <federicobond@gmail.com>
|
|
|
|
* @date 2016
|
|
|
|
* Static analyzer and checker.
|
|
|
|
*/
|
|
|
|
|
|
|
|
#include <libsolidity/analysis/StaticAnalyzer.h>
|
2018-12-17 11:30:08 +00:00
|
|
|
|
2018-04-09 13:22:45 +00:00
|
|
|
#include <libsolidity/analysis/ConstantEvaluator.h>
|
2016-12-01 13:55:02 +00:00
|
|
|
#include <libsolidity/ast/AST.h>
|
2018-11-14 13:59:30 +00:00
|
|
|
#include <liblangutil/ErrorReporter.h>
|
2017-05-11 14:57:34 +00:00
|
|
|
#include <memory>
|
2016-12-01 13:55:02 +00:00
|
|
|
|
2019-12-11 16:31:36 +00:00
|
|
|
using namespace solidity;
|
|
|
|
using namespace solidity::langutil;
|
|
|
|
using namespace solidity::frontend;
|
2016-12-01 13:55:02 +00:00
|
|
|
|
2019-01-15 21:49:15 +00:00
|
|
|
/**
|
|
|
|
* Helper class that determines whether a contract's constructor uses inline assembly.
|
|
|
|
*/
|
2019-12-11 16:31:36 +00:00
|
|
|
class solidity::frontend::ConstructorUsesAssembly
|
2019-01-15 21:49:15 +00:00
|
|
|
{
|
|
|
|
public:
|
|
|
|
/// @returns true if and only if the contract's or any of its bases' constructors
|
|
|
|
/// use inline assembly.
|
|
|
|
bool check(ContractDefinition const& _contract)
|
|
|
|
{
|
|
|
|
for (auto const* base: _contract.annotation().linearizedBaseContracts)
|
|
|
|
if (checkInternal(*base))
|
|
|
|
return true;
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
private:
|
|
|
|
class Checker: public ASTConstVisitor
|
|
|
|
{
|
|
|
|
public:
|
|
|
|
Checker(FunctionDefinition const& _f) { _f.accept(*this); }
|
|
|
|
bool visit(InlineAssembly const&) override { assemblySeen = true; return false; }
|
|
|
|
bool assemblySeen = false;
|
|
|
|
};
|
|
|
|
|
|
|
|
bool checkInternal(ContractDefinition const& _contract)
|
|
|
|
{
|
|
|
|
if (!m_usesAssembly.count(&_contract))
|
|
|
|
{
|
|
|
|
bool usesAssembly = false;
|
|
|
|
if (_contract.constructor())
|
|
|
|
usesAssembly = Checker{*_contract.constructor()}.assemblySeen;
|
|
|
|
m_usesAssembly[&_contract] = usesAssembly;
|
|
|
|
}
|
|
|
|
return m_usesAssembly[&_contract];
|
|
|
|
}
|
|
|
|
|
2023-08-14 08:37:11 +00:00
|
|
|
std::map<ContractDefinition const*, bool> m_usesAssembly;
|
2019-01-15 21:49:15 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
StaticAnalyzer::StaticAnalyzer(ErrorReporter& _errorReporter):
|
|
|
|
m_errorReporter(_errorReporter)
|
|
|
|
{
|
|
|
|
}
|
|
|
|
|
|
|
|
StaticAnalyzer::~StaticAnalyzer()
|
|
|
|
{
|
|
|
|
}
|
|
|
|
|
2016-12-01 13:55:02 +00:00
|
|
|
bool StaticAnalyzer::analyze(SourceUnit const& _sourceUnit)
|
|
|
|
{
|
|
|
|
_sourceUnit.accept(*this);
|
2021-06-30 12:48:45 +00:00
|
|
|
return !Error::containsErrors(m_errorReporter.errors());
|
2016-12-01 13:55:02 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
bool StaticAnalyzer::visit(ContractDefinition const& _contract)
|
|
|
|
{
|
|
|
|
m_library = _contract.isLibrary();
|
2017-02-02 11:03:37 +00:00
|
|
|
m_currentContract = &_contract;
|
2016-12-01 13:55:02 +00:00
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
|
|
|
void StaticAnalyzer::endVisit(ContractDefinition const&)
|
|
|
|
{
|
|
|
|
m_library = false;
|
2017-02-02 11:03:37 +00:00
|
|
|
m_currentContract = nullptr;
|
2016-12-01 13:55:02 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
bool StaticAnalyzer::visit(FunctionDefinition const& _function)
|
|
|
|
{
|
2017-04-14 14:48:59 +00:00
|
|
|
if (_function.isImplemented())
|
2017-05-02 12:25:37 +00:00
|
|
|
m_currentFunction = &_function;
|
2017-05-02 15:14:42 +00:00
|
|
|
else
|
|
|
|
solAssert(!m_currentFunction, "");
|
|
|
|
solAssert(m_localVarUseCount.empty(), "");
|
2017-02-02 11:03:37 +00:00
|
|
|
m_constructor = _function.isConstructor();
|
2016-12-01 13:55:02 +00:00
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
|
|
|
void StaticAnalyzer::endVisit(FunctionDefinition const&)
|
|
|
|
{
|
2018-12-12 11:02:47 +00:00
|
|
|
if (m_currentFunction && !m_currentFunction->body().statements().empty())
|
|
|
|
for (auto const& var: m_localVarUseCount)
|
|
|
|
if (var.second == 0)
|
|
|
|
{
|
2019-09-05 18:02:34 +00:00
|
|
|
if (var.first.second->isCallableOrCatchParameter())
|
2018-12-12 11:02:47 +00:00
|
|
|
m_errorReporter.warning(
|
2020-05-05 22:38:28 +00:00
|
|
|
5667_error,
|
2018-12-12 11:02:47 +00:00
|
|
|
var.first.second->location(),
|
2019-09-05 18:02:34 +00:00
|
|
|
"Unused " +
|
2023-08-14 08:37:11 +00:00
|
|
|
std::string(var.first.second->isTryCatchParameter() ? "try/catch" : "function") +
|
2019-09-05 18:02:34 +00:00
|
|
|
" parameter. Remove or comment out the variable name to silence this warning."
|
2018-12-12 11:02:47 +00:00
|
|
|
);
|
|
|
|
else
|
2020-05-05 22:38:28 +00:00
|
|
|
m_errorReporter.warning(2072_error, var.first.second->location(), "Unused local variable.");
|
2018-12-12 11:02:47 +00:00
|
|
|
}
|
2017-05-02 15:14:42 +00:00
|
|
|
m_localVarUseCount.clear();
|
2018-12-12 11:02:47 +00:00
|
|
|
m_constructor = false;
|
|
|
|
m_currentFunction = nullptr;
|
2017-04-14 14:48:59 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
bool StaticAnalyzer::visit(Identifier const& _identifier)
|
|
|
|
{
|
2017-05-02 12:25:37 +00:00
|
|
|
if (m_currentFunction)
|
2017-04-14 14:48:59 +00:00
|
|
|
if (auto var = dynamic_cast<VariableDeclaration const*>(_identifier.annotation().referencedDeclaration))
|
|
|
|
{
|
|
|
|
solAssert(!var->name().empty(), "");
|
|
|
|
if (var->isLocalVariable())
|
2023-08-14 08:37:11 +00:00
|
|
|
m_localVarUseCount[std::make_pair(var->id(), var)] += 1;
|
2017-04-14 14:48:59 +00:00
|
|
|
}
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
|
|
|
bool StaticAnalyzer::visit(VariableDeclaration const& _variable)
|
|
|
|
{
|
2017-05-02 12:25:37 +00:00
|
|
|
if (m_currentFunction)
|
2017-04-14 14:48:59 +00:00
|
|
|
{
|
|
|
|
solAssert(_variable.isLocalVariable(), "");
|
|
|
|
if (_variable.name() != "")
|
2017-05-02 15:14:42 +00:00
|
|
|
// This is not a no-op, the entry might pre-exist.
|
2023-08-14 08:37:11 +00:00
|
|
|
m_localVarUseCount[std::make_pair(_variable.id(), &_variable)] += 0;
|
2017-04-14 14:48:59 +00:00
|
|
|
}
|
2020-09-14 00:52:00 +00:00
|
|
|
|
|
|
|
if (_variable.isStateVariable() || _variable.referenceLocation() == VariableDeclaration::Location::Storage)
|
2020-09-15 23:06:54 +00:00
|
|
|
if (auto varType = dynamic_cast<CompositeType const*>(_variable.annotation().type))
|
|
|
|
for (Type const* type: varType->fullDecomposition())
|
|
|
|
if (type->storageSizeUpperBound() >= (bigint(1) << 64))
|
|
|
|
{
|
2023-08-14 08:37:11 +00:00
|
|
|
std::string message = "Type " + type->toString(true) +
|
2020-09-15 23:06:54 +00:00
|
|
|
" covers a large part of storage and thus makes collisions likely."
|
|
|
|
" Either use mappings or dynamic arrays and allow their size to be increased only"
|
|
|
|
" in small quantities per transaction.";
|
|
|
|
m_errorReporter.warning(7325_error, _variable.typeName().location(), message);
|
|
|
|
}
|
2020-09-14 00:52:00 +00:00
|
|
|
|
2017-04-14 14:48:59 +00:00
|
|
|
return true;
|
2016-12-01 13:55:02 +00:00
|
|
|
}
|
|
|
|
|
2017-04-28 20:28:03 +00:00
|
|
|
bool StaticAnalyzer::visit(Return const& _return)
|
|
|
|
{
|
|
|
|
// If the return has an expression, it counts as
|
|
|
|
// a "use" of the return parameters.
|
2017-05-02 12:25:37 +00:00
|
|
|
if (m_currentFunction && _return.expression())
|
|
|
|
for (auto const& var: m_currentFunction->returnParameters())
|
|
|
|
if (!var->name().empty())
|
2023-08-14 08:37:11 +00:00
|
|
|
m_localVarUseCount[std::make_pair(var->id(), var.get())] += 1;
|
2017-04-28 20:28:03 +00:00
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
2017-04-21 09:13:10 +00:00
|
|
|
bool StaticAnalyzer::visit(ExpressionStatement const& _statement)
|
|
|
|
{
|
2020-09-10 10:01:23 +00:00
|
|
|
if (*_statement.expression().annotation().isPure)
|
2017-05-11 13:26:35 +00:00
|
|
|
m_errorReporter.warning(
|
2020-05-05 22:38:28 +00:00
|
|
|
6133_error,
|
2017-05-11 13:26:35 +00:00
|
|
|
_statement.location(),
|
|
|
|
"Statement has no effect."
|
|
|
|
);
|
|
|
|
|
2017-04-21 09:13:10 +00:00
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
2016-12-01 13:55:02 +00:00
|
|
|
bool StaticAnalyzer::visit(MemberAccess const& _memberAccess)
|
|
|
|
{
|
2019-04-15 13:33:39 +00:00
|
|
|
if (MagicType const* type = dynamic_cast<MagicType const*>(_memberAccess.expression().annotation().type))
|
2018-03-07 09:48:10 +00:00
|
|
|
{
|
2018-03-05 22:13:51 +00:00
|
|
|
if (type->kind() == MagicType::Kind::Message && _memberAccess.memberName() == "gas")
|
2018-07-04 09:42:05 +00:00
|
|
|
m_errorReporter.typeError(
|
2020-05-05 22:38:28 +00:00
|
|
|
1400_error,
|
2018-07-04 09:42:05 +00:00
|
|
|
_memberAccess.location(),
|
|
|
|
"\"msg.gas\" has been deprecated in favor of \"gasleft()\""
|
|
|
|
);
|
|
|
|
else if (type->kind() == MagicType::Kind::Block && _memberAccess.memberName() == "blockhash")
|
|
|
|
m_errorReporter.typeError(
|
2020-05-05 22:38:28 +00:00
|
|
|
8113_error,
|
2018-07-04 09:42:05 +00:00
|
|
|
_memberAccess.location(),
|
|
|
|
"\"block.blockhash()\" has been deprecated in favor of \"blockhash()\""
|
|
|
|
);
|
2019-01-15 21:49:15 +00:00
|
|
|
else if (type->kind() == MagicType::Kind::MetaType && _memberAccess.memberName() == "runtimeCode")
|
|
|
|
{
|
|
|
|
if (!m_constructorUsesAssembly)
|
2023-08-14 08:37:11 +00:00
|
|
|
m_constructorUsesAssembly = std::make_unique<ConstructorUsesAssembly>();
|
2019-01-15 21:49:15 +00:00
|
|
|
ContractType const& contract = dynamic_cast<ContractType const&>(*type->typeArgument());
|
|
|
|
if (m_constructorUsesAssembly->check(contract.contractDefinition()))
|
|
|
|
m_errorReporter.warning(
|
2020-05-05 22:38:28 +00:00
|
|
|
6417_error,
|
2019-01-15 21:49:15 +00:00
|
|
|
_memberAccess.location(),
|
|
|
|
"The constructor of the contract (or its base) uses inline assembly. "
|
|
|
|
"Because of that, it might be that the deployed bytecode is different from type(...).runtimeCode."
|
|
|
|
);
|
|
|
|
}
|
2020-12-08 08:12:55 +00:00
|
|
|
else if (
|
|
|
|
m_currentFunction &&
|
|
|
|
m_currentFunction->isReceive() &&
|
|
|
|
type->kind() == MagicType::Kind::Message &&
|
|
|
|
_memberAccess.memberName() == "data"
|
|
|
|
)
|
|
|
|
m_errorReporter.typeError(
|
|
|
|
7139_error,
|
|
|
|
_memberAccess.location(),
|
|
|
|
R"("msg.data" cannot be used inside of "receive" function.)"
|
|
|
|
);
|
2018-03-07 09:48:10 +00:00
|
|
|
}
|
2018-03-05 22:13:51 +00:00
|
|
|
|
2017-06-30 14:37:08 +00:00
|
|
|
if (_memberAccess.memberName() == "callcode")
|
2019-04-15 13:33:39 +00:00
|
|
|
if (auto const* type = dynamic_cast<FunctionType const*>(_memberAccess.annotation().type))
|
2017-06-30 14:37:08 +00:00
|
|
|
if (type->kind() == FunctionType::Kind::BareCallCode)
|
2018-06-18 15:06:23 +00:00
|
|
|
m_errorReporter.typeError(
|
2020-05-05 22:38:28 +00:00
|
|
|
2256_error,
|
2018-06-18 15:06:23 +00:00
|
|
|
_memberAccess.location(),
|
|
|
|
"\"callcode\" has been deprecated in favour of \"delegatecall\"."
|
|
|
|
);
|
2017-06-30 14:37:08 +00:00
|
|
|
|
2018-04-12 16:14:48 +00:00
|
|
|
if (m_constructor)
|
|
|
|
{
|
|
|
|
auto const* expr = &_memberAccess.expression();
|
2019-11-11 16:09:59 +00:00
|
|
|
while (expr)
|
2018-04-12 16:14:48 +00:00
|
|
|
{
|
|
|
|
if (auto id = dynamic_cast<Identifier const*>(expr))
|
|
|
|
{
|
|
|
|
if (id->name() == "this")
|
|
|
|
m_errorReporter.warning(
|
2020-05-05 22:38:28 +00:00
|
|
|
5805_error,
|
2018-04-12 16:14:48 +00:00
|
|
|
id->location(),
|
|
|
|
"\"this\" used in constructor. "
|
|
|
|
"Note that external functions of a contract "
|
|
|
|
"cannot be called while it is being constructed.");
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
else if (auto tuple = dynamic_cast<TupleExpression const*>(expr))
|
|
|
|
{
|
|
|
|
if (tuple->components().size() == 1)
|
|
|
|
expr = tuple->components().front().get();
|
|
|
|
else
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
else
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
2017-02-02 11:03:37 +00:00
|
|
|
|
2016-12-01 13:55:02 +00:00
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
2017-05-11 14:57:34 +00:00
|
|
|
bool StaticAnalyzer::visit(InlineAssembly const& _inlineAssembly)
|
|
|
|
{
|
|
|
|
if (!m_currentFunction)
|
|
|
|
return true;
|
|
|
|
|
|
|
|
for (auto const& ref: _inlineAssembly.annotation().externalReferences)
|
|
|
|
{
|
|
|
|
if (auto var = dynamic_cast<VariableDeclaration const*>(ref.second.declaration))
|
|
|
|
{
|
|
|
|
solAssert(!var->name().empty(), "");
|
|
|
|
if (var->isLocalVariable())
|
2023-08-14 08:37:11 +00:00
|
|
|
m_localVarUseCount[std::make_pair(var->id(), var)] += 1;
|
2017-05-11 14:57:34 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
return true;
|
|
|
|
}
|
2017-08-07 13:44:35 +00:00
|
|
|
|
2018-04-09 13:22:45 +00:00
|
|
|
bool StaticAnalyzer::visit(BinaryOperation const& _operation)
|
|
|
|
{
|
|
|
|
if (
|
2020-09-10 10:01:23 +00:00
|
|
|
*_operation.rightExpression().annotation().isPure &&
|
2018-04-09 13:22:45 +00:00
|
|
|
(_operation.getOperator() == Token::Div || _operation.getOperator() == Token::Mod)
|
|
|
|
)
|
2020-11-16 11:19:52 +00:00
|
|
|
if (auto rhs = ConstantEvaluator::evaluate(m_errorReporter, _operation.rightExpression()))
|
|
|
|
if (rhs->value == 0)
|
2018-04-09 13:22:45 +00:00
|
|
|
m_errorReporter.typeError(
|
2020-05-05 22:38:28 +00:00
|
|
|
1211_error,
|
2018-04-09 13:22:45 +00:00
|
|
|
_operation.location(),
|
|
|
|
(_operation.getOperator() == Token::Div) ? "Division by zero." : "Modulo zero."
|
|
|
|
);
|
|
|
|
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
|
|
|
bool StaticAnalyzer::visit(FunctionCall const& _functionCall)
|
|
|
|
{
|
2020-04-08 17:38:30 +00:00
|
|
|
if (*_functionCall.annotation().kind == FunctionCallKind::FunctionCall)
|
2018-04-09 13:22:45 +00:00
|
|
|
{
|
2019-04-15 13:33:39 +00:00
|
|
|
auto functionType = dynamic_cast<FunctionType const*>(_functionCall.expression().annotation().type);
|
2018-04-09 13:22:45 +00:00
|
|
|
solAssert(functionType, "");
|
|
|
|
if (functionType->kind() == FunctionType::Kind::AddMod || functionType->kind() == FunctionType::Kind::MulMod)
|
|
|
|
{
|
|
|
|
solAssert(_functionCall.arguments().size() == 3, "");
|
2020-09-10 10:01:23 +00:00
|
|
|
if (*_functionCall.arguments()[2]->annotation().isPure)
|
2020-11-16 11:19:52 +00:00
|
|
|
if (auto lastArg = ConstantEvaluator::evaluate(m_errorReporter, *(_functionCall.arguments())[2]))
|
|
|
|
if (lastArg->value == 0)
|
2018-04-09 13:22:45 +00:00
|
|
|
m_errorReporter.typeError(
|
2020-05-05 22:38:28 +00:00
|
|
|
4195_error,
|
2018-04-09 13:22:45 +00:00
|
|
|
_functionCall.location(),
|
|
|
|
"Arithmetic modulo zero."
|
|
|
|
);
|
|
|
|
}
|
2019-04-26 14:31:45 +00:00
|
|
|
if (
|
2020-05-04 16:38:00 +00:00
|
|
|
m_currentContract &&
|
2019-04-26 14:31:45 +00:00
|
|
|
m_currentContract->isLibrary() &&
|
|
|
|
functionType->kind() == FunctionType::Kind::DelegateCall &&
|
|
|
|
functionType->declaration().scope() == m_currentContract
|
|
|
|
)
|
|
|
|
m_errorReporter.typeError(
|
2020-05-05 22:38:28 +00:00
|
|
|
6700_error,
|
2019-04-26 14:31:45 +00:00
|
|
|
_functionCall.location(),
|
|
|
|
SecondarySourceLocation().append(
|
|
|
|
"The function declaration is here:",
|
|
|
|
functionType->declaration().scope()->location()
|
|
|
|
),
|
|
|
|
"Libraries cannot call their own functions externally."
|
|
|
|
);
|
2018-04-09 13:22:45 +00:00
|
|
|
}
|
|
|
|
return true;
|
|
|
|
}
|