[clang] [Clang][Sema] Add fortify warnings for fread, fwrite, and fgets (PR #204337)
Nick Desaulniers via cfe-commits
cfe-commits at lists.llvm.org
Wed Sep 16 15:00:57 PDT 2026
Radovan =?utf-8?q?Božić?= <radovan.bozic at htecgroup.com>,
Radovan =?utf-8?q?Božić?= <radovan.bozic at htecgroup.com>
Message-ID:
In-Reply-To: <llvm.org/llvm/llvm-project/pull/204337 at github.com>
================
@@ -1496,7 +1522,24 @@ void Sema::checkFortifiedBuiltinMemoryFunction(FunctionDecl *FD,
Checker.checkSourceOverread(/*SrcArgIdx=*/0, /*SizeArgIdx=*/2);
break;
}
-
+ case Builtin::BIfread: {
+ DiagID = diag::warn_fortify_source_overflow;
+ SourceSize = Checker.ComputeExplicitObjectSizeArgumentProduct(1, 2);
+ DestinationSize = Checker.ComputeSizeArgument(0);
+ break;
+ }
+ case Builtin::BIfwrite: {
+ DiagID = diag::warn_fortify_source_overread;
+ SourceSize = Checker.ComputeExplicitObjectSizeArgumentProduct(1, 2);
+ DestinationSize = Checker.ComputeSizeArgument(0);
----------------
nickdesaulniers wrote:
For `fwrite`, arg zero is the _source_ buffer, not the destination, so assigning to `DestinationSize` works, but it confusing, IMO.
Rather than `SourceSize`/`DestinationSize`; I think `BufferSize` / `AccessSize` (or `RequestedSize`) might be clearer between reads AND writes.
https://github.com/llvm/llvm-project/pull/204337
More information about the cfe-commits
mailing list