5cae0d6bd5853df9a575b5283e97ef090697cbde
[gcc.git] / gcc / ada / restrict.ads
1 ------------------------------------------------------------------------------
2 -- --
3 -- GNAT COMPILER COMPONENTS --
4 -- --
5 -- R E S T R I C T --
6 -- --
7 -- S p e c --
8 -- --
9 -- Copyright (C) 1992-2014, Free Software Foundation, Inc. --
10 -- --
11 -- GNAT is free software; you can redistribute it and/or modify it under --
12 -- terms of the GNU General Public License as published by the Free Soft- --
13 -- ware Foundation; either version 3, or (at your option) any later ver- --
14 -- sion. GNAT is distributed in the hope that it will be useful, but WITH- --
15 -- OUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY --
16 -- or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License --
17 -- for more details. You should have received a copy of the GNU General --
18 -- Public License distributed with GNAT; see file COPYING3. If not, go to --
19 -- http://www.gnu.org/licenses for a complete copy of the license. --
20 -- --
21 -- GNAT was originally developed by the GNAT team at New York University. --
22 -- Extensive contributions were provided by Ada Core Technologies Inc. --
23 -- --
24 ------------------------------------------------------------------------------
25
26 -- This package deals with the implementation of the Restrictions pragma
27
28 with Namet; use Namet;
29 with Rident; use Rident;
30 with Table;
31 with Types; use Types;
32 with Uintp; use Uintp;
33
34 package Restrict is
35
36 Restrictions : Restrictions_Info := No_Restrictions;
37 -- This variable records restrictions found in any units in the main
38 -- extended unit, and in the case of restrictions checked for partition
39 -- consistency, restrictions found in any with'ed units, parent specs
40 -- etc., since we may as well check as much as we can at compile time.
41 -- These variables should not be referenced directly by clients. Instead
42 -- use Check_Restriction to record a violation of a restriction, and
43 -- Restriction_Active to test if a given restriction is active.
44
45 Restrictions_Loc : array (All_Restrictions) of Source_Ptr :=
46 (others => No_Location);
47 -- Locations of Restrictions pragmas for error message purposes.
48 -- Valid only if corresponding entry in Restrictions is set. A value
49 -- of No_Location is used for implicit restrictions set by another
50 -- pragma, and a value of System_Location is used for restrictions
51 -- set from package Standard by the processing in Targparm.
52
53 Restriction_Profile_Name : array (All_Restrictions) of Profile_Name;
54 -- Entries in this array are valid only if the corresponding restriction
55 -- in Restrictions set. The value is the corresponding profile name if the
56 -- restriction was set by a Profile or Profile_Warnings pragma. The value
57 -- is No_Profile in all other cases.
58
59 Main_Restrictions : Restrictions_Info := No_Restrictions;
60 -- This variable records only restrictions found in any units of the
61 -- main extended unit. These are the variables used for ali file output,
62 -- since we want the binder to be able to accurately diagnose inter-unit
63 -- restriction violations.
64
65 Restriction_Warnings : Rident.Restriction_Flags := (others => False);
66 -- If one of these flags is set, then it means that violation of the
67 -- corresponding restriction results only in a warning message, not
68 -- in an error message, and the restriction is not otherwise enforced.
69 -- Note that the flags in Restrictions are set to indicate that the
70 -- restriction is set in this case, but Main_Restrictions is never
71 -- set if Restriction_Warnings is set, so this does not look like a
72 -- restriction to the binder.
73
74 -- The following declarations establish a mapping between restriction
75 -- identifiers, and the names of corresponding restricted library units.
76
77 type Unit_Entry is record
78 Res_Id : Restriction_Id;
79 Filenm : String (1 .. 8);
80 end record;
81
82 Unit_Array : constant array (Positive range <>) of Unit_Entry := (
83 (No_Asynchronous_Control, "a-astaco"),
84 (No_Calendar, "a-calend"),
85 (No_Calendar, "calendar"),
86 (No_Delay, "a-calend"),
87 (No_Delay, "calendar"),
88 (No_Dynamic_Priorities, "a-dynpri"),
89 (No_Finalization, "a-finali"),
90 (No_IO, "a-direio"),
91 (No_IO, "directio"),
92 (No_IO, "a-sequio"),
93 (No_IO, "sequenio"),
94 (No_IO, "a-ststio"),
95 (No_IO, "a-textio"),
96 (No_IO, "text_io "),
97 (No_IO, "a-witeio"),
98 (No_Task_Attributes_Package, "a-tasatt"),
99 (No_Unchecked_Conversion, "a-unccon"),
100 (No_Unchecked_Conversion, "unchconv"),
101 (No_Unchecked_Deallocation, "a-uncdea"),
102 (No_Unchecked_Deallocation, "unchdeal"));
103
104 -- The following map has True for all GNAT-defined Restrictions. It is used
105 -- to implement pragma Restrictions (No_Implementation_Restrictions) (which
106 -- is why this restriction itself is excluded from the list).
107
108 Implementation_Restriction : array (All_Restrictions) of Boolean :=
109 (Simple_Barriers => True,
110 No_Calendar => True,
111 No_Default_Initialization => True,
112 No_Direct_Boolean_Operators => True,
113 No_Dispatching_Calls => True,
114 No_Dynamic_Attachment => True,
115 No_Elaboration_Code => True,
116 No_Enumeration_Maps => True,
117 No_Entry_Calls_In_Elaboration_Code => True,
118 No_Entry_Queue => True,
119 No_Exception_Handlers => True,
120 No_Exception_Propagation => True,
121 No_Exception_Registration => True,
122 No_Finalization => True,
123 No_Fixed_IO => True,
124 No_Implementation_Attributes => True,
125 No_Implementation_Pragmas => True,
126 No_Implicit_Conditionals => True,
127 No_Implicit_Aliasing => True,
128 No_Implicit_Dynamic_Code => True,
129 No_Implicit_Loops => True,
130 No_Initialize_Scalars => True,
131 No_Local_Protected_Objects => True,
132 No_Long_Long_Integers => True,
133 No_Multiple_Elaboration => True,
134 No_Protected_Type_Allocators => True,
135 No_Relative_Delay => True,
136 No_Requeue_Statements => True,
137 No_Secondary_Stack => True,
138 No_Select_Statements => True,
139 No_Standard_Storage_Pools => True,
140 No_Stream_Optimizations => True,
141 No_Streams => True,
142 No_Task_Attributes_Package => True,
143 No_Task_Termination => True,
144 No_Tasking => True,
145 No_Wide_Characters => True,
146 Static_Priorities => True,
147 Static_Storage_Size => True,
148 SPARK_05 => True,
149 others => False);
150
151 -- The following table records entries made by Restrictions pragmas
152 -- that specify a parameter for No_Dependence. Each such pragma makes
153 -- an entry in this table.
154
155 -- Note: we have chosen to implement this restriction in the "syntactic"
156 -- form, where we do not check that the named package is a language defined
157 -- package, but instead we allow arbitrary package names. The discussion of
158 -- this issue is not complete in the ARG, but the sense seems to be leaning
159 -- in this direction, which makes more sense to us, since it is much more
160 -- useful, and much easier to implement.
161
162 type ND_Entry is record
163 Unit : Node_Id;
164 -- The unit parameter from the No_Dependence pragma
165
166 Warn : Boolean;
167 -- True if from Restriction_Warnings, False if from Restrictions
168
169 Profile : Profile_Name;
170 -- Set to name of profile from which No_Dependence entry came, or to
171 -- No_Profile if a pragma Restriction set the No_Dependence entry.
172 end record;
173
174 package No_Dependences is new Table.Table (
175 Table_Component_Type => ND_Entry,
176 Table_Index_Type => Int,
177 Table_Low_Bound => 0,
178 Table_Initial => 200,
179 Table_Increment => 200,
180 Table_Name => "Name_No_Dependences");
181
182 -----------------
183 -- Subprograms --
184 -----------------
185
186 -- Note: several of these subprograms can generate error messages (e.g.
187 -- Check_Restriction). These routines should be called in the analyzer
188 -- rather than the expander, so that the associated error messages are
189 -- correctly generated in semantics only (-gnatc) mode.
190
191 function Abort_Allowed return Boolean;
192 pragma Inline (Abort_Allowed);
193 -- Tests to see if abort is allowed by the current restrictions settings.
194 -- For abort to be allowed, either No_Abort_Statements must be False,
195 -- or Max_Asynchronous_Select_Nesting must be non-zero.
196
197 procedure Check_Compiler_Unit (Feature : String; N : Node_Id);
198 -- If unit N is in a unit that has a pragma Compiler_Unit_Warning, then
199 -- a message is posted on node N noting use of the given feature is not
200 -- permitted in the compiler (bootstrap considerations).
201
202 procedure Check_Compiler_Unit (Feature : String; Loc : Source_Ptr);
203 -- If unit N is in a unit that has a pragma Compiler_Unit_Warning, then a
204 -- message is posted at location Loc noting use of the given feature is not
205 -- permitted in the compiler (bootstrap considerations).
206
207 procedure Check_Restricted_Unit (U : Unit_Name_Type; N : Node_Id);
208 -- Checks if loading of unit U is prohibited by the setting of some
209 -- restriction (e.g. No_IO restricts the loading of unit Ada.Text_IO).
210 -- If a restriction exists post error message at the given node.
211
212 procedure Check_Restriction
213 (Msg_Issued : out Boolean;
214 R : Restriction_Id;
215 N : Node_Id;
216 V : Uint := Uint_Minus_1);
217 -- Checks that the given restriction is not set, and if it is set, an
218 -- appropriate message is posted on the given node, in which case
219 -- Msg_Issued is set to True (and False otherwise). Also records the
220 -- violation in the appropriate internal arrays. Note that it is mandatory
221 -- to always use this routine to check if a restriction is violated. Such
222 -- checks must never be done directly by the caller, since otherwise
223 -- violations in the absence of restrictions are not properly recorded. The
224 -- value of V is relevant only for parameter restrictions, and in this case
225 -- indicates the exact count for the violation. If the exact count is not
226 -- known, V is left at its default of -1 which indicates an unknown count.
227
228 procedure Check_Restriction
229 (R : Restriction_Id;
230 N : Node_Id;
231 V : Uint := Uint_Minus_1);
232 -- Wrapper on Check_Restriction with Msg_Issued, with the out-parameter
233 -- being ignored here.
234
235 procedure Check_Restriction_No_Use_Of_Attribute (N : Node_Id);
236 -- N is the node of an attribute definition clause. An error message
237 -- (warning) will be issued if a restriction (warning) was previously set
238 -- for this attribute using Set_No_Use_Of_Attribute.
239
240 procedure Check_Restriction_No_Use_Of_Pragma (N : Node_Id);
241 -- N is the node of a pragma. An error message (warning) will be issued
242 -- if a restriction (warning) was previously set for this pragma using
243 -- Set_No_Use_Of_Pragma.
244
245 procedure Check_Restriction_No_Dependence (U : Node_Id; Err : Node_Id);
246 -- Called when a dependence on a unit is created (either implicitly, or by
247 -- an explicit WITH clause). U is a node for the unit involved, and Err is
248 -- the node to which an error will be attached if necessary.
249
250 procedure Check_Restriction_No_Specification_Of_Aspect (N : Node_Id);
251 -- N is the node id for an N_Aspect_Specification. An error message
252 -- (warning) will be issued if a restriction (warning) was previous set
253 -- for this aspect using Set_No_Specification_Of_Aspect.
254
255 procedure Check_Elaboration_Code_Allowed (N : Node_Id);
256 -- Tests to see if elaboration code is allowed by the current restrictions
257 -- settings. This function is called by Gigi when it needs to define an
258 -- elaboration routine. If elaboration code is not allowed, an error
259 -- message is posted on the node given as argument.
260
261 procedure Check_SPARK_Restriction
262 (Msg : String;
263 N : Node_Id;
264 Force : Boolean := False);
265 -- Node N represents a construct not allowed in SPARK_05 mode. If this is
266 -- a source node, or if the restriction is forced (Force = True), and
267 -- the SPARK_05 restriction is set, then an error is issued on N. Msg
268 -- is appended to the restriction failure message.
269
270 procedure Check_SPARK_Restriction (Msg1, Msg2 : String; N : Node_Id);
271 -- Same as Check_SPARK_Restriction except there is a continuation message
272 -- Msg2 following the initial message Msg1.
273
274 procedure Check_No_Implicit_Aliasing (Obj : Node_Id);
275 -- Obj is a node for which Is_Aliased_View is True, which is being used in
276 -- a context (e.g. 'Access) where no implicit aliasing is allowed if the
277 -- restriction No_Implicit_Aliasing is set. This procedure checks for the
278 -- case where the restriction is active and Obj does not meet the required
279 -- rules for avoiding implicit aliases, and issues a restriction message.
280
281 procedure Check_Implicit_Dynamic_Code_Allowed (N : Node_Id);
282 -- Tests to see if dynamic code generation (dynamically generated
283 -- trampolines, in particular) is allowed by the current restrictions
284 -- settings. This function is called by Gigi when it needs to generate code
285 -- that generates a trampoline. If not allowed, an error message is posted
286 -- on the node given as argument.
287
288 procedure Check_No_Implicit_Heap_Alloc (N : Node_Id);
289 -- Equivalent to Check_Restriction (No_Implicit_Heap_Allocations, N).
290 -- Provided for easy use by back end, which has to check this restriction.
291
292 procedure Check_Obsolescent_2005_Entity (E : Entity_Id; N : Node_Id);
293 -- This routine checks if the entity E is one of the obsolescent entries
294 -- in Ada.Characters.Handling in Ada 2005 and No_Obsolescent_Features
295 -- restriction is active. If so an appropriate message is given. N is
296 -- the node on which the message is to be placed. It's a bit kludgy to
297 -- have this highly specialized routine rather than some wonderful general
298 -- mechanism (e.g. a special pragma) to handle this case, but there are
299 -- only six cases, and it is not worth the effort to do something general.
300
301 procedure Check_Wide_Character_Restriction (E : Entity_Id; N : Node_Id);
302 -- This procedure checks if the No_Wide_Character restriction is active,
303 -- and if so, if N Comes_From_Source, and the root type of E is one of
304 -- [Wide_]Wide_Character or [Wide_]Wide_String, then the restriction
305 -- violation is recorded, and an appropriate message given.
306
307 function Get_Restriction_Id
308 (N : Name_Id) return Restriction_Id;
309 -- Given an identifier name, determines if it is a valid restriction
310 -- identifier, and if so returns the corresponding Restriction_Id value,
311 -- otherwise returns Not_A_Restriction_Id.
312
313 function OK_No_Dependence_Unit_Name (N : Node_Id) return Boolean;
314 -- Used in checking No_Dependence argument of pragma Restrictions or
315 -- pragma Restrictions_Warning, or attribute Restriction_Set. Returns
316 -- True if N has the proper form for a unit name, False otherwise.
317
318 function Is_In_Hidden_Part_In_SPARK (Loc : Source_Ptr) return Boolean;
319 -- Determine if given location is covered by a hidden region range in the
320 -- SPARK hides table.
321
322 function No_Exception_Handlers_Set return Boolean;
323 -- Test to see if current restrictions settings specify that no exception
324 -- handlers are present. This function is called by Gigi when it needs to
325 -- expand an AT END clean up identifier with no exception handler. True
326 -- will be returned if the configurable run-time is activated, and either
327 -- of the restrictions No_Exception_Handlers or No_Exception_Propagation is
328 -- set. In the latter case, the source may contain handlers but they either
329 -- get converted using the local goto transformation or deleted.
330
331 function No_Exception_Propagation_Active return Boolean;
332 -- Test to see if current restrictions settings specify that no
333 -- exception propagation is activated.
334
335 function Process_Restriction_Synonyms (N : Node_Id) return Name_Id;
336 -- Id is a node whose Chars field contains the name of a restriction.
337 -- If it is one of synonyms that we allow for historical purposes (for
338 -- list see System.Rident), then the proper official name is returned.
339 -- Otherwise the Chars field of the argument is returned unchanged.
340
341 function Restriction_Active (R : All_Restrictions) return Boolean;
342 pragma Inline (Restriction_Active);
343 -- Determines if a given restriction is active. This call should only be
344 -- used where the compiled code depends on whether the restriction is
345 -- active. Always use Check_Restriction to record a violation. Note that
346 -- this returns False if we only have a Restriction_Warnings set, since
347 -- restriction warnings should never affect generated code. If you want
348 -- to know if a call to Check_Restriction is needed then use the function
349 -- Restriction_Check_Required instead.
350
351 function Restriction_Check_Required (R : All_Restrictions) return Boolean;
352 pragma Inline (Restriction_Check_Required);
353 -- Determines if either a Restriction_Warnings or Restrictions pragma has
354 -- been given for the specified restriction. If true, then a subsequent
355 -- call to Check_Restriction is required if the restriction is violated.
356 -- This must not be used to guard code generation that depends on whether
357 -- a restriction is active (see Restriction_Active above). Typically it
358 -- is used to avoid complex code to determine if a restriction is violated,
359 -- executing this code only if needed.
360
361 function Restricted_Profile return Boolean;
362 -- Tests if set of restrictions corresponding to Profile (Restricted) is
363 -- currently in effect (set by pragma Profile, or by an appropriate set of
364 -- individual Restrictions pragmas). Returns True only if all the required
365 -- restrictions are set.
366
367 procedure Set_Hidden_Part_In_SPARK (Loc1, Loc2 : Source_Ptr);
368 -- Insert a new hidden region range in the SPARK hides table. The effect
369 -- is to hide any SPARK violation messages which are in the range Loc1 to
370 -- Loc2-1 (i.e. Loc2 is the first location for reenabling checks).
371
372 procedure Set_Profile_Restrictions
373 (P : Profile_Name;
374 N : Node_Id;
375 Warn : Boolean);
376 -- Sets the set of restrictions associated with the given profile name. N
377 -- is the node of the construct to which error messages are to be attached
378 -- as required. Warn is set True for the case of Profile_Warnings where the
379 -- restrictions are set as warnings rather than legality requirements, and
380 -- is also True for Profile if the Treat_Restrictions_As_Warnings flag is
381 -- set. It is false for Profile if this flag is not set.
382
383 procedure Set_Restriction
384 (R : All_Boolean_Restrictions;
385 N : Node_Id);
386 -- N is a node (typically a pragma node) that has the effect of setting
387 -- Boolean restriction R. The restriction is set in Restrictions, and
388 -- also in Main_Restrictions if this is the main unit.
389
390 procedure Set_Restriction
391 (R : All_Parameter_Restrictions;
392 N : Node_Id;
393 V : Integer);
394 -- Similar to the above, except that this is used for the case of a
395 -- parameter restriction, and the corresponding value V is given.
396
397 procedure Set_Restriction_No_Dependence
398 (Unit : Node_Id;
399 Warn : Boolean;
400 Profile : Profile_Name := No_Profile);
401 -- Sets given No_Dependence restriction in table if not there already. Warn
402 -- is True if from Restriction_Warnings, or for Restrictions if the flag
403 -- Treat_Restrictions_As_Warnings is set. False if from Restrictions and
404 -- this flag is not set. Profile is set to a non-default value if the
405 -- No_Dependence restriction comes from a Profile pragma.
406
407 procedure Set_Restriction_No_Specification_Of_Aspect
408 (N : Node_Id;
409 Warning : Boolean);
410 -- N is the node id for an identifier from a pragma Restrictions for the
411 -- No_Specification_Of_Aspect pragma. An error message will be issued if
412 -- the identifier is not a valid aspect name. Warning is set True for the
413 -- case of a Restriction_Warnings pragma specifying this restriction and
414 -- False for a Restrictions pragma specifying this restriction.
415
416 procedure Set_Restriction_No_Use_Of_Attribute
417 (N : Node_Id;
418 Warning : Boolean);
419 -- N is the node id for the identifier in a pragma Restrictions for
420 -- No_Use_Of_Attribute. Caller has verified that this is a valid attribute
421 -- designator.
422
423 procedure Set_Restriction_No_Use_Of_Pragma
424 (N : Node_Id;
425 Warning : Boolean);
426 -- N is the node id for the identifier in a pragma Restrictions for
427 -- No_Use_Of_Pragma. Caller has verified that this is a valid pragma id.
428
429 function Tasking_Allowed return Boolean;
430 pragma Inline (Tasking_Allowed);
431 -- Tests if tasking operations are allowed by the current restrictions
432 -- settings. For tasking to be allowed Max_Tasks must be non-zero.
433
434 ----------------------------------------------
435 -- Handling of Boolean Compilation Switches --
436 ----------------------------------------------
437
438 -- The following declarations are used for proper saving and restoring of
439 -- restrictions for separate compilation units. There are two cases:
440
441 -- For partition-wide restrictions, we just let the restrictions pragmas
442 -- pile up, and we never reset them. We might as well detect what we can
443 -- at compile time. If e.g. a with'ed unit has a restriction for one of
444 -- the partition-wide restrictions, then the binder will enforce it on
445 -- all units in the partition, including the unit with the WITH. Although
446 -- it would not be wrong to leave this till bind time, we might as well
447 -- flag it earlier at compile time.
448
449 -- For non-partition-wide restrictions, we have quite a different state
450 -- of affairs. Here it would be quite wrong to carry a restriction from
451 -- a with'ed unit to another with'ed unit, or from a package spec to the
452 -- package body. This means that we have to reset these non-partition
453 -- wide restrictions at the start of each separate compilation unit. For
454 -- units in the extended main program, we need to reset them all to the
455 -- values set by the configuration pragma file(s). For units not in the
456 -- extended main program, e.g. with'ed units, we might as well reset all
457 -- of these restrictions to off (False). The actual initial values will
458 -- be taken from the config files active when those units are compiled
459 -- as main units.
460
461 type Save_Cunit_Boolean_Restrictions is private;
462 -- Type used for saving and restoring compilation unit restrictions.
463
464 function Cunit_Boolean_Restrictions_Save
465 return Save_Cunit_Boolean_Restrictions;
466 -- This function saves the compilation unit restriction settings, leaving
467 -- then unchanged. This is used e.g. at the start of processing a context
468 -- clause, so that the main unit restrictions can be restored after all
469 -- the with'ed units have been processed.
470
471 procedure Cunit_Boolean_Restrictions_Restore
472 (R : Save_Cunit_Boolean_Restrictions);
473 -- This is the corresponding restore procedure to restore restrictions
474 -- previously saved by Cunit_Boolean_Restrictions_Save. However it does
475 -- not reset No_Elaboration_Code, this stays set if it was set before
476 -- the call, and also if it is set before the call, then the Config
477 -- setting is also updated to include this restriction. This is what
478 -- implements the special handling of No_Elaboration_Code.
479
480 procedure Save_Config_Cunit_Boolean_Restrictions;
481 -- This saves the current compilation unit restrictions in an internal
482 -- variable, and leaves them unchanged. This is called immediately after
483 -- processing the configuration file pragmas, to record the restrictions
484 -- set by these configuration file pragmas.
485
486 procedure Restore_Config_Cunit_Boolean_Restrictions;
487 -- This restores the value saved by the previous call to save config values
488 -- saved by Save_Config_Cunit_Boolean_Restrictions. It is called at the
489 -- start of processing a new unit that is part of the main sources (e.g.
490 -- a package spec when the main unit is a package body).
491
492 procedure Reset_Cunit_Boolean_Restrictions;
493 -- Turns off all non-partition-wide boolean restrictions
494
495 procedure Add_To_Config_Boolean_Restrictions (R : Restriction_Id);
496 -- Add specified restriction to stored configuration boolean restrictions.
497 -- This is used for handling the special case of No_Elaboration_Code.
498
499 private
500 type Save_Cunit_Boolean_Restrictions is
501 array (Cunit_Boolean_Restrictions) of Boolean;
502 -- Type used for saving and restoring compilation unit restrictions.
503 -- See Compilation_Unit_Restrictions_[Save|Restore] subprograms.
504
505 end Restrict;