[clang] [Clang][Sema] Add fortify warnings for fread, fwrite, and fgets (PR #204337)

Radovan Božić via cfe-commits cfe-commits at lists.llvm.org
Mon Sep 21 06:27:46 PDT 2026


================
@@ -1496,7 +1522,24 @@ void Sema::checkFortifiedBuiltinMemoryFunction(FunctionDecl *FD,
     Checker.checkSourceOverread(/*SrcArgIdx=*/0, /*SizeArgIdx=*/2);
     break;
   }
-
+  case Builtin::BIfread: {
+    DiagID = diag::warn_fortify_source_overflow;
+    SourceSize = Checker.ComputeExplicitObjectSizeArgumentProduct(1, 2);
+    DestinationSize = Checker.ComputeSizeArgument(0);
+    break;
+  }
+  case Builtin::BIfwrite: {
+    DiagID = diag::warn_fortify_source_overread;
+    SourceSize = Checker.ComputeExplicitObjectSizeArgumentProduct(1, 2);
+    DestinationSize = Checker.ComputeSizeArgument(0);
----------------
bozicrHT wrote:

I agree that the names are confusing for the stdio cases. They are also used by exsiting string and memory checks, so I did not want to rename them globally. Using separate `BufferSize`/`AccessSize` variables would either duplicate the common diagnostic logic or require extracting it into a helper. I can refactor that logic into lambda like `DiagnoseSizeMismatch` and use the clearer names for `fwrite`, `fread` cases. Does that sounds good to you?

https://github.com/llvm/llvm-project/pull/204337


More information about the cfe-commits mailing list