[clang] [LifetimeSafety] Fix off-by-one crash in `lifetime_capture_by` argument indexing (PR #227231)
Utkarsh Saxena via cfe-commits
cfe-commits at lists.llvm.org
Tue Sep 29 02:17:41 PDT 2026
https://github.com/usx95 updated https://github.com/llvm/llvm-project/pull/227231
>From e3d9d651b17e77bce3a8ea2c499c2f139507a657 Mon Sep 17 00:00:00 2001
From: Utkarsh Saxena <usx at google.com>
Date: Tue, 29 Sep 2026 09:09:19 +0000
Subject: [PATCH] capture-by-crash
---
.../LifetimeSafety/FactsGenerator.cpp | 11 +++++----
clang/test/Sema/LifetimeSafety/safety.cpp | 23 +++++++++++++++++++
2 files changed, 29 insertions(+), 5 deletions(-)
diff --git a/clang/lib/Analysis/LifetimeSafety/FactsGenerator.cpp b/clang/lib/Analysis/LifetimeSafety/FactsGenerator.cpp
index 292e3279233bb..2457b8270cb80 100644
--- a/clang/lib/Analysis/LifetimeSafety/FactsGenerator.cpp
+++ b/clang/lib/Analysis/LifetimeSafety/FactsGenerator.cpp
@@ -1044,11 +1044,12 @@ void FactsGenerator::handleLifetimeCaptureBy(const FunctionDecl *FD,
CapturingArgIdx == LifetimeCaptureByAttr::Unknown ||
CapturingArgIdx == LifetimeCaptureByAttr::Invalid)
continue;
- ArrayRef<const Expr *> CallArgs = IsInstance ? Args.drop_front() : Args;
- const Expr *CapturedByArg =
- (CapturingArgIdx == LifetimeCaptureByAttr::This)
- ? Args[0]
- : CallArgs[CapturingArgIdx];
+ // FIXME: Diagnose bad CapturingArgIdx.
+ if (CapturingArgIdx != LifetimeCaptureByAttr::This &&
+ (CapturingArgIdx < 0 ||
+ static_cast<size_t>(CapturingArgIdx) >= Args.size()))
+ continue;
+ const Expr *CapturedByArg = Args[CapturingArgIdx];
assert(CapturedByArg && "Capturer expression must be valid");
OriginList *Dest = readValue(CapturedByArg);
diff --git a/clang/test/Sema/LifetimeSafety/safety.cpp b/clang/test/Sema/LifetimeSafety/safety.cpp
index bf49e86577678..fb91fb30713db 100644
--- a/clang/test/Sema/LifetimeSafety/safety.cpp
+++ b/clang/test/Sema/LifetimeSafety/safety.cpp
@@ -4076,6 +4076,29 @@ void capturing_multiple_locals() {
use(v); // expected-note 2 {{later used here}}
}
+namespace off_by_one_crash {
+struct Item {
+ const int* ptr;
+};
+
+struct Container {
+ const Item* saved;
+};
+
+struct Helper {
+ void AddItem(const Item& item [[clang::lifetime_capture_by(c)]],
+ Container& c) const;
+ void Populate() const {
+ Container c{};
+ {
+ Item item;
+ AddItem(item, c); // expected-warning {{local variable 'item' does not live long enough}}
+ } // expected-note {{local variable 'item' is destroyed here}}
+ use(c); // expected-note {{later used here}}
+ }
+};
+} // namespace off_by_one_crash
+
struct [[gsl::Pointer()]] PtrWithInt { int x; };
PtrWithInt f() {
return PtrWithInt{10};
More information about the cfe-commits
mailing list