[clang] [clang][-Wunsafe-buffer-usage] Warn on annotated unsafe container construction (PR #227108)

Yitzhak Mandelbaum via cfe-commits cfe-commits at lists.llvm.org
Thu Oct 1 06:04:02 PDT 2026


================
@@ -1985,6 +1974,99 @@ class StringViewTwoParamConstructorGadget : public WarningGadget {
   SmallVector<const Expr *, 1> getUnsafePtrs() const override { return {}; }
 };
 
+/// A call of a constructor or factory function annotated with
+/// `[[clang::unsafe_buffer_usage("container")]]` (or
+/// `[[clang::unsafe_buffer_usage_in_container]]`). Evaluates whether the
+/// arguments are safe via `isSafeTwoParamContainerConstruct` and emits a
+/// diagnostic under `-Wunsafe-buffer-usage-in-container` when unsafe.
+class UnsafeBufferUsageContainerAttrGadget : public WarningGadget {
+  constexpr static const char *const OpTag = "container_attr_expr";
+  const Expr *Op;
+
+public:
+  UnsafeBufferUsageContainerAttrGadget(const MatchResult &Result)
+      : WarningGadget(Kind::UnsafeBufferUsageContainerAttr),
+        Op(Result.getNodeAs<Expr>(OpTag)) {}
+
+  static bool classof(const Gadget *G) {
+    return G->getKind() == Kind::UnsafeBufferUsageContainerAttr;
+  }
+
+  // Returns true iff `Callee` is annotated with
+  // `[[clang::unsafe_buffer_usage("container")]]` and the arguments of `Node`
+  // are not provably safe.
+  template <typename CallOrConstructExpr>
+  static bool isUnsafeContainerConstruction(const Decl *Callee,
+                                            const CallOrConstructExpr &Node,
+                                            ASTContext &Ctx) {
+    if (!Callee)
+      return false;
+    const auto *Attr = Callee->getAttr<UnsafeBufferUsageAttr>();
+    if (!Attr || Attr->getCategory() != "container")
+      return false;
+    return Node.getNumArgs() != 2 ||
----------------
ymand wrote:

Why is this considered unsafe?

https://github.com/llvm/llvm-project/pull/227108


More information about the cfe-commits mailing list