[clang-tools-extra] db0e752 - [clang-tidy] Fix crash in bugprone-misplaced-pointer-arithmetic-in-alloc (#224509)
via cfe-commits
cfe-commits at lists.llvm.org
Fri Sep 18 04:00:18 PDT 2026
Author: Zeyi Xu
Date: 2026-09-18T19:00:12+08:00
New Revision: db0e752a8833b933b41ec15d8311b37d125f655d
URL: https://github.com/llvm/llvm-project/commit/db0e752a8833b933b41ec15d8311b37d125f655d
DIFF: https://github.com/llvm/llvm-project/commit/db0e752a8833b933b41ec15d8311b37d125f655d.diff
LOG: [clang-tidy] Fix crash in bugprone-misplaced-pointer-arithmetic-in-alloc (#224509)
This commit checks for an empty constructor argument list before
accessing its last element.
Reproducer at: https://godbolt.org/z/Tfvnbhx19
AI Usage: the issue was found by Grok 4.6. Although IMO this is a pretty
uncommon/rare case, less crash-on-valid is always better.
Added:
Modified:
clang-tools-extra/clang-tidy/bugprone/MisplacedPointerArithmeticInAllocCheck.cpp
clang-tools-extra/docs/ReleaseNotes.md
clang-tools-extra/test/clang-tidy/checkers/bugprone/misplaced-pointer-arithmetic-in-alloc.cpp
Removed:
################################################################################
diff --git a/clang-tools-extra/clang-tidy/bugprone/MisplacedPointerArithmeticInAllocCheck.cpp b/clang-tools-extra/clang-tidy/bugprone/MisplacedPointerArithmeticInAllocCheck.cpp
index 0c4dc6cddb64d..ccd121105124c 100644
--- a/clang-tools-extra/clang-tidy/bugprone/MisplacedPointerArithmeticInAllocCheck.cpp
+++ b/clang-tools-extra/clang-tidy/bugprone/MisplacedPointerArithmeticInAllocCheck.cpp
@@ -74,9 +74,10 @@ void MisplacedPointerArithmeticInAllocCheck::check(
CallName = "operator new[]";
} else {
const auto *CtrE = New->getConstructExpr();
- if (!CtrE || !CtrE->getArg(CtrE->getNumArgs() - 1)
- ->getType()
- ->isIntegralOrEnumerationType())
+ if (!CtrE || CtrE->getNumArgs() == 0 ||
+ !CtrE->getArg(CtrE->getNumArgs() - 1)
+ ->getType()
+ ->isIntegralOrEnumerationType())
return;
CallName = "operator new";
}
diff --git a/clang-tools-extra/docs/ReleaseNotes.md b/clang-tools-extra/docs/ReleaseNotes.md
index b77d0b5f5b7ec..8abc889a5aebf 100644
--- a/clang-tools-extra/docs/ReleaseNotes.md
+++ b/clang-tools-extra/docs/ReleaseNotes.md
@@ -176,6 +176,11 @@ infrastructure are described first, followed by tool-specific sections.
<clang-tidy/checks/bugprone/misplaced-operator-in-strlen-in-alloc>` when
checking an array new expression without a size expression.
+- Fixed a crash in {doc}`bugprone-misplaced-pointer-arithmetic-in-alloc
+ <clang-tidy/checks/bugprone/misplaced-pointer-arithmetic-in-alloc>` when
+ pointer arithmetic is applied to a non-array `new` expression whose
+ constructor has no arguments.
+
- Fixed a crash in {doc}`bugprone-pointer-arithmetic-on-polymorphic-object
<clang-tidy/checks/bugprone/pointer-arithmetic-on-polymorphic-object>` when
the pointer points to an incomplete (forward-declared) type.
diff --git a/clang-tools-extra/test/clang-tidy/checkers/bugprone/misplaced-pointer-arithmetic-in-alloc.cpp b/clang-tools-extra/test/clang-tidy/checkers/bugprone/misplaced-pointer-arithmetic-in-alloc.cpp
index 00d12891cde88..565b2638fed63 100644
--- a/clang-tools-extra/test/clang-tidy/checkers/bugprone/misplaced-pointer-arithmetic-in-alloc.cpp
+++ b/clang-tools-extra/test/clang-tidy/checkers/bugprone/misplaced-pointer-arithmetic-in-alloc.cpp
@@ -62,3 +62,8 @@ void placement_new_ptr(void *buf, C *old) {
C **p = new (buf) C*(old) + 1;
// CHECK-MESSAGES-NOT: :[[@LINE-1]]:11: warning: arithmetic operation is applied to the result of operator new() instead of its size-like argument
}
+
+void default_ctor() {
+ struct S {};
+ S *P = new S + 1;
+}
More information about the cfe-commits
mailing list