[clang] [analyzer] Invalidate the object in opaque ctor calls regardless if an arg refers to it (PR #170887)

Balázs Benics via cfe-commits cfe-commits at lists.llvm.org
Mon Dec 8 06:40:07 PST 2025


steakhal wrote:

> void opaque(const void* a, void* b);
> 
> int top() {
>     int *x;
>     opaque(&x, &x);
>     return *x; // I expected an issue here
> }

Great observation. I could craft an example breaking this.
https://godbolt.org/z/E5avb1xdn
```
void opaque(const int* a, int* b);
void clang_analyzer_value(int);

int top() {
    int x = 1;
    opaque(&x, &x);
    clang_analyzer_value(x); // we should not be sure it's 1.
    return 100 / (x - 1);
}
```

https://github.com/llvm/llvm-project/pull/170887


More information about the cfe-commits mailing list