[clang] [analyzer] Don't invalidate pointee of pointer-to-const on callback arguments (PR #225489)
Donát Nagy via cfe-commits
cfe-commits at lists.llvm.org
Thu Sep 24 07:11:27 PDT 2026
================
@@ -3940,7 +3940,8 @@ ProgramStateRef MallocChecker::checkPointerEscapeAux(
if (const RefState *RS = State->get<RegionState>(sym))
if (RS->isAllocated() || RS->isAllocatedOfSizeZero())
- if (!IsConstPointerEscape || checkIfNewOrNewArrayFamily(RS))
+ if (!IsConstPointerEscape || checkIfNewOrNewArrayFamily(RS) ||
+ (Call && Call->argumentsMayEscape()))
----------------
NagyDonat wrote:
Thanks for looking these up!
> I have traced through all the cases and they are similar to each other.
Yes, these are all very similar testcases that IIRC were added by the same commit. The "original version" is the test
```c++
// Callback is passed to a function defined in a system header.
void r11160612_4(void) {
char *x = malloc(12);
sqlite3_bind_text_my(0, x, 12, free); // no - warning
}
```
shows that this was intended to suppress a false positive of `unix.Malloc` where the memory was released by passing `free` as a callback function to [`sqlite3_bind_text()`](https://sqlite.org/c3ref/bind_blob.html) which – as expected – calls the callback received in the fourth argument when the buffer is no longer needed.
(Note that it is significant that the sqlite headers may be system headers – IIRC `MallocChecker` has a heuristic that it assumes that functions _coming from system headers_ do not release memory unless they are explicitly modeled like `free()`.)
I think returning true from `argumentsMayEscape()` when there is a callback argument is a very clumsy heuristic for suppressing this false positive with `sqlite3_bind_text()`.
**I will create a commit that moves this suppression heuristic from `argumentsMayEscape()` to `MallocChecker.cpp`.**
https://github.com/llvm/llvm-project/pull/225489
More information about the cfe-commits
mailing list