[clang] [Clang][Docs] Add documentation for -Wfortify-source (PR #224111)
Venkatesh Srinivasan via cfe-commits
cfe-commits at lists.llvm.org
Thu Sep 24 10:47:19 PDT 2026
https://github.com/venk-ks updated https://github.com/llvm/llvm-project/pull/224111
>From 179d7420898a807383cde51f4bc300d105d4b253 Mon Sep 17 00:00:00 2001
From: Venkatesh Srinivasan <venk at google.com>
Date: Wed, 16 Sep 2026 18:35:57 +0000
Subject: [PATCH] [Clang][Docs] Add documentation for -Wfortify-source
Document the -Wfortify-source diagnostic group in DiagnosticGroups.td covering all currently checked library functions.
Part of #142230
Assisted-by: Gemini
---
clang/include/clang/Basic/DiagnosticGroups.td | 29 ++++++++++++++++++-
1 file changed, 28 insertions(+), 1 deletion(-)
diff --git a/clang/include/clang/Basic/DiagnosticGroups.td b/clang/include/clang/Basic/DiagnosticGroups.td
index 1da7698944b24..8e8bf5748d089 100644
--- a/clang/include/clang/Basic/DiagnosticGroups.td
+++ b/clang/include/clang/Basic/DiagnosticGroups.td
@@ -1897,7 +1897,34 @@ def CrossTURemarks : DiagGroup<"ctu-remarks">;
def CTADMaybeUnsupported : DiagGroup<"ctad-maybe-unsupported">;
-def FortifySource : DiagGroup<"fortify-source", [FormatOverflow, FormatTruncation]>;
+def FortifySource : DiagGroup<"fortify-source", [FormatOverflow, FormatTruncation]> {
+ code Documentation = [{
+Warns at compile time when calls to standard C library or POSIX functions have
+provably out-of-bounds destination buffers or invalid constant arguments,
+modeled after `_FORTIFY_SOURCE` compile-time checks.
+
+This diagnostic group checks:
+
+1. **Destination buffer overflows and format truncation**: Diagnoses when a
+ write operation will always overflow the destination buffer, when an
+ explicit size argument exceeds the known size of the destination buffer, or
+ when formatted output will always be truncated:
+ - `<string.h>` / `<strings.h>`: `memcpy`, `memmove`, `memset`, `mempcpy`,
+ `bcopy`, `bzero`, `strcpy`, `stpcpy`, `strcat`, `strncpy`, `stpncpy`,
+ `strncat`, `strlcpy`, `strlcat` (and their `__builtin_` variants).
+ - `<stdio.h>`: `sprintf`, `snprintf`, `vsnprintf`, `scanf`, `fscanf`,
+ `sscanf` (also controlled by {ref}`-Wformat-overflow` and
+ {ref}`-Wformat-truncation`).
+
+2. **Invalid constant arguments**:
+ - `<sys/stat.h>`: `umask` when called with constant mode bits outside `0777`
+ that are silently ignored.
+
+Note: Related bounds checks for `__builtin___*_chk` functions and source buffer
+overreads in memory functions (such as `memcpy` and `memcmp`) are controlled
+separately by {ref}`-Wbuiltin-memcpy-chk-size` and {ref}`-Wstringop-overread`.
+ }];
+}
def OverflowBehaviorAttributeIgnored
: DiagGroup<"overflow-behavior-attribute-ignored">;
More information about the cfe-commits
mailing list