[clang] [analyzer] Don't invalidate pointee of pointer-to-const on callback arguments (PR #225489)
Donát Nagy via cfe-commits
cfe-commits at lists.llvm.org
Thu Sep 24 07:31:34 PDT 2026
NagyDonat wrote:
To summarize my (perhaps somewhat confusing :sweat:) comment https://github.com/llvm/llvm-project/pull/225489#discussion_r4094574805, I think these old "invalidate the arguments if ..." heuristics (probably all of them) should be moved to `MallocChecker::mayFreeAnyEscapedMemoryOrIsModeledExplicitly` from the general "pointerEscape" callback.
That way the memory leak false positives (which originally motivated the introduction of these clumsy heuristics) will stay suppressed, but we won't see unjustified invalidations where the analyzer assumes that a function overwrites something through a pointer-to-const argument.
I still stand by my original claim that `CallEvent::invalidateRegions()` should _always_ ensure that when the type of a parameter is pointer-to-const, then the pointee of the related argument is not invalidated. It was an ugly and unjustified hack to put this behind a `if (!argumentsMayEscape())` check – suppressing those false positives should be handled in `MallocChecker`.
https://github.com/llvm/llvm-project/pull/225489
More information about the cfe-commits
mailing list