[clang] [NFC][analyzer] Refactor Environment to map Expr to SVal instead of Stmt to SVal (PR #193295)

Donát Nagy via cfe-commits cfe-commits at lists.llvm.org
Wed Apr 22 00:21:25 PDT 2026


================
@@ -949,7 +949,10 @@ class ReturnVisitor : public TrackingBugReporterVisitor {
     // Okay, we're at the right return statement, but do we have the return
     // value available?
     ProgramStateRef State = N->getState();
-    SVal V = State->getSVal(Ret, CalleeSFC);
+    const Expr *RV = Ret->getRetValue();
+    if (!RV)
+      return nullptr;
----------------
NagyDonat wrote:

> Can it return null or not? Who is right?

As Gábor wrote, I strongly suspect that `getRetValue()` returns null if and only if the return statement looks like `return;` – i.e. there is no subexpression.

This is invalid in non-void functions, so I presume that's why some logic may dereference it without checking. (But it's also possible that this is a bug in other locations.)

https://github.com/llvm/llvm-project/pull/193295


More information about the cfe-commits mailing list