[clang] [clang][AST] Implement -Wunsigned-integer-overflow for checking for unsigned integer constants overflow (PR #222173)

via cfe-commits cfe-commits at lists.llvm.org
Wed Sep 9 06:47:47 PDT 2026


ArnaudBienner wrote:

> Thank you for working on this! There's a few things worth thinking about here:

Thanks for your feedback :)
 
> "False positive" is hard to nail down here given that it's well-defined behavior. Limiting it to just multiplication and addition seems questionable to me. e.g., why shouldn't `0u - 1u` be diagnosed? If diagnosing that, why not `-1u`?

My rationale `-1u` could be used to define `UINT_MAX` and the underflow might be intentional here.
 
> My intuition is that this kind of diagnostic is better left to other tooling (overflow behavior types, sanitizers, linters or static analyzers) given that it's well-defined behavior both at runtime and constexpr evaluation time and how much code intentionally overflows even constant expressions. However, I think @ojhunt has been thinking about this design space a considerable amount and maybe he has a different take on this.

Sanitizers already covers this usecase (`-fsanitize=unsigned-integer-overflow`) but indeed, if you think it's not suitable for a warning, I'll look at implementing this as a clang-tidy check.

But let's wait a bit to see if @ojhunt or others have a different opinion.

https://github.com/llvm/llvm-project/pull/222173


More information about the cfe-commits mailing list