[clang] [clang][-Wunsafe-buffer-usage] Warn on annotated unsafe container construction (PR #227108)
Yitzhak Mandelbaum via cfe-commits
cfe-commits at lists.llvm.org
Thu Oct 1 06:04:02 PDT 2026
================
@@ -1985,6 +1974,99 @@ class StringViewTwoParamConstructorGadget : public WarningGadget {
SmallVector<const Expr *, 1> getUnsafePtrs() const override { return {}; }
};
+/// A call of a constructor or factory function annotated with
+/// `[[clang::unsafe_buffer_usage("container")]]` (or
+/// `[[clang::unsafe_buffer_usage_in_container]]`). Evaluates whether the
+/// arguments are safe via `isSafeTwoParamContainerConstruct` and emits a
+/// diagnostic under `-Wunsafe-buffer-usage-in-container` when unsafe.
+class UnsafeBufferUsageContainerAttrGadget : public WarningGadget {
+ constexpr static const char *const OpTag = "container_attr_expr";
+ const Expr *Op;
+
+public:
+ UnsafeBufferUsageContainerAttrGadget(const MatchResult &Result)
+ : WarningGadget(Kind::UnsafeBufferUsageContainerAttr),
+ Op(Result.getNodeAs<Expr>(OpTag)) {}
+
+ static bool classof(const Gadget *G) {
+ return G->getKind() == Kind::UnsafeBufferUsageContainerAttr;
+ }
+
+ // Returns true iff `Callee` is annotated with
+ // `[[clang::unsafe_buffer_usage("container")]]` and the arguments of `Node`
+ // are not provably safe.
+ template <typename CallOrConstructExpr>
+ static bool isUnsafeContainerConstruction(const Decl *Callee,
+ const CallOrConstructExpr &Node,
+ ASTContext &Ctx) {
+ if (!Callee)
+ return false;
+ const auto *Attr = Callee->getAttr<UnsafeBufferUsageAttr>();
+ if (!Attr || Attr->getCategory() != "container")
+ return false;
+ return Node.getNumArgs() != 2 ||
----------------
ymand wrote:
Why is this considered unsafe?
https://github.com/llvm/llvm-project/pull/227108
More information about the cfe-commits
mailing list