[clang] [llvm] [analyzer] bypass io sandbox in debug checks (PR #224783)
Carson Radtke via cfe-commits
cfe-commits at lists.llvm.org
Fri Sep 18 18:05:13 PDT 2026
https://github.com/carsonRadtke updated https://github.com/llvm/llvm-project/pull/224783
>From 62500994ffbd16b6feecf847cc0e630a6c06986f Mon Sep 17 00:00:00 2001
From: Carson Radtke <nosrac925 at gmail.com>
Date: Fri, 18 Sep 2026 18:35:10 -0600
Subject: [PATCH 1/2] [analyzer] bypass io sandbox in debug check
The `debug.View*` debug checks look for a graph viewer on the user's
system. This ultimately calls `llvm::sys::fs::access` which raises a
sandbox violation.
This PR disables the IO sandbox during graph viewing.
---
clang/lib/StaticAnalyzer/Checkers/DebugCheckers.cpp | 4 ++++
llvm/lib/Support/Unix/Path.inc | 2 --
2 files changed, 4 insertions(+), 2 deletions(-)
diff --git a/clang/lib/StaticAnalyzer/Checkers/DebugCheckers.cpp b/clang/lib/StaticAnalyzer/Checkers/DebugCheckers.cpp
index 04bbe85473c0e..d077f68f425fe 100644
--- a/clang/lib/StaticAnalyzer/Checkers/DebugCheckers.cpp
+++ b/clang/lib/StaticAnalyzer/Checkers/DebugCheckers.cpp
@@ -20,6 +20,7 @@
#include "clang/StaticAnalyzer/Core/PathSensitive/CheckerContext.h"
#include "clang/StaticAnalyzer/Core/PathSensitive/ExplodedGraph.h"
#include "clang/StaticAnalyzer/Core/PathSensitive/ExprEngine.h"
+#include "llvm/Support/IOSandbox.h"
#include "llvm/Support/Process.h"
using namespace clang;
@@ -158,6 +159,7 @@ class CFGViewer : public Checker<check::ASTCodeBody> {
public:
void checkASTCodeBody(const Decl *D, AnalysisManager& mgr,
BugReporter &BR) const {
+ auto BypassSandbox = llvm::sys::sandbox::scopedDisable();
if (CFG *cfg = mgr.getCFG(D)) {
cfg->viewCFG(mgr.getLangOpts());
}
@@ -212,6 +214,7 @@ class CallGraphViewer : public Checker< check::ASTDecl<TranslationUnitDecl> > {
public:
void checkASTDecl(const TranslationUnitDecl *TU, AnalysisManager& mgr,
BugReporter &BR) const {
+ auto BypassSandbox = llvm::sys::sandbox::scopedDisable();
CallGraph CG;
CG.addToCallGraph(const_cast<TranslationUnitDecl*>(TU));
CG.viewGraph();
@@ -301,6 +304,7 @@ class ExplodedGraphViewer : public Checker< check::EndAnalysis > {
public:
ExplodedGraphViewer() {}
void checkEndAnalysis(ExplodedGraph &G, BugReporter &B,ExprEngine &Eng) const {
+ auto BypassSandbox = llvm::sys::sandbox::scopedDisable();
Eng.ViewGraph(false);
}
};
diff --git a/llvm/lib/Support/Unix/Path.inc b/llvm/lib/Support/Unix/Path.inc
index 44bc0d30b2fc2..dc363a2082d37 100644
--- a/llvm/lib/Support/Unix/Path.inc
+++ b/llvm/lib/Support/Unix/Path.inc
@@ -657,8 +657,6 @@ std::error_code access(const Twine &Path, AccessMode Mode) {
}
bool can_execute(const Twine &Path) {
- sandbox::violationIfEnabled();
-
return !access(Path, AccessMode::Execute);
}
>From bf3a37b32d58119c73f525b298cf56477f296e67 Mon Sep 17 00:00:00 2001
From: Carson Radtke <nosrac925 at gmail.com>
Date: Fri, 18 Sep 2026 19:05:02 -0600
Subject: [PATCH 2/2] apply patch from git-clang-format
---
clang/lib/StaticAnalyzer/Checkers/DebugCheckers.cpp | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/clang/lib/StaticAnalyzer/Checkers/DebugCheckers.cpp b/clang/lib/StaticAnalyzer/Checkers/DebugCheckers.cpp
index d077f68f425fe..b764eaac782c6 100644
--- a/clang/lib/StaticAnalyzer/Checkers/DebugCheckers.cpp
+++ b/clang/lib/StaticAnalyzer/Checkers/DebugCheckers.cpp
@@ -10,12 +10,12 @@
//
//===----------------------------------------------------------------------===//
-#include "clang/StaticAnalyzer/Checkers/BuiltinCheckerRegistration.h"
#include "clang/Analysis/Analyses/Dominators.h"
#include "clang/Analysis/Analyses/LiveVariables.h"
#include "clang/Analysis/CallGraph.h"
-#include "clang/StaticAnalyzer/Core/Checker.h"
+#include "clang/StaticAnalyzer/Checkers/BuiltinCheckerRegistration.h"
#include "clang/StaticAnalyzer/Core/BugReporter/BugType.h"
+#include "clang/StaticAnalyzer/Core/Checker.h"
#include "clang/StaticAnalyzer/Core/PathSensitive/AnalysisManager.h"
#include "clang/StaticAnalyzer/Core/PathSensitive/CheckerContext.h"
#include "clang/StaticAnalyzer/Core/PathSensitive/ExplodedGraph.h"
More information about the cfe-commits
mailing list