[clang] [analyzer] Implement potential underflow warnings (PR #216077)

Donát Nagy via cfe-commits cfe-commits at lists.llvm.org
Mon Aug 24 01:56:26 PDT 2026


================
@@ -334,13 +334,15 @@ static BugDescription describeInvalidAccess(bounds::CheckResult Res,
           std::string(Buf)};
 }
 
-static BugDescription describeTaintBug(StringRef RegName, StringRef OffsetName,
-                                       bool AlsoMentionUnderflow) {
+static BugDescription describeTaintBug(bounds::CheckResult Res,
+                                       StringRef RegName,
+                                       StringRef OffsetName) {
   return {formatv("Potential out of bound access to {0} with tainted {1}",
                   RegName, OffsetName),
-          formatv("Access of {0} with a tainted {1} that may be {2}too large",
-                  RegName, OffsetName,
-                  AlsoMentionUnderflow ? "negative or " : "")};
+          formatv("Access of {0} with a tainted {1} that may be{2}{3}{4}.",
----------------
NagyDonat wrote:

Oops, my bad.

This also changes the messages in the existing taint-based reports and should have been caught by the tests – but unfortunately `excepted-note` etc. match substrings :roll_eyes: so mistakes like this fly under the radar.

Perhaps we should think about introducing a way to match the full message (which is less ugly than using `-re` variant with `{{$}}` at the end) and automatically spreading it in the test suite.

https://github.com/llvm/llvm-project/pull/216077


More information about the cfe-commits mailing list