[clang] [clang][-Wunsafe-buffer-usage] Warn on annotated unsafe container construction (PR #227108)

Yitzhak Mandelbaum via cfe-commits cfe-commits at lists.llvm.org
Thu Oct 1 06:04:01 PDT 2026


================
@@ -8433,6 +8434,44 @@ alternatives, though the attribute can be used even when the fix can't be automa
   Here, every read/write to the fields ptr1, ptr2, buf and sz will trigger a warning
   that the field has been explcitly marked as unsafe due to unsafe-buffer operations.
 
+- Attribute attached to container constructors and factory functions: The
+  spellings `[[clang::unsafe_buffer_usage_in_container]]` and
+  `[[clang::unsafe_buffer_usage("container")]]` are equivalent and can be
+  placed on two-parameter constructors and factory functions of container or
+  view types (such as custom span types taking a `(pointer, size)` or
+  `(begin, end)` pair) to opt them in to `-Wunsafe-buffer-usage-in-container`.
+
+  Unlike the general `[[clang::unsafe_buffer_usage]]` attribute, which warns on
+  every call, this form suppresses the warning when the argument pair is
+  provably safe—for example, when constructing from `c.data(), c.size()` or
----------------
ymand wrote:

nit: i think this should be a double-dash

https://github.com/llvm/llvm-project/pull/227108


More information about the cfe-commits mailing list