[clang] [analyzer] Fix null-pointer dereference in PthreadLockChecker (PR #210912)

Balázs Benics via cfe-commits cfe-commits at lists.llvm.org
Tue Jul 21 07:08:37 PDT 2026


================
@@ -493,8 +493,11 @@ void PthreadLockChecker::AcquireLockAux(const CallEvent &Call,
       default:
         llvm_unreachable("Unknown tryLock locking semantics");
       }
-      assert(lockFail && lockSucc);
-      C.addTransition(lockFail);
+      // The state where the lock failed can be infeasible if the constraint
+      // solver only now discovers a contradiction in the accumulated
+      // constraints; only take that transition when it is feasible.
----------------
steakhal wrote:

I second on Donat's comment. The whole point of PosteriorlyOverconstrained flag is to avoid anything like this. Otherwise people would need to check the States of assume left-right and center.

https://github.com/llvm/llvm-project/pull/210912


More information about the cfe-commits mailing list