[clang-tools-extra] [clang-tidy] New bugprone-unsafe-format-string check (PR #168691)

Yanzuo Liu via cfe-commits cfe-commits at lists.llvm.org
Sun Sep 27 02:45:41 PDT 2026


https://github.com/zwuis commented:

> I can imagine a checker extension that checks if the destination buffer is larger than limiter size specified in the format string.
> e.g. 
> ```
> char buffer[10]
> scanf("%99s",buffer) //warn unsafe string 
> ```
> So for now I would leave the checker name as is (bugprone-unsafe-format-string) to allow extensibility for other cases.

Makes sense to me.

New question, but not blocking this PR: IIUC we will not support another style of format string (`std::format_to`). Is there a better check name? Something like bugprone-unsafe-c-format-string?

https://github.com/llvm/llvm-project/pull/168691


More information about the cfe-commits mailing list