[llvm-branch-commits] [clang] [analyzer] Only underline the exact parameter that is bound to the return value in UseAfterLifetimeEnd (PR #215651)
Benedek Kaibas via llvm-branch-commits
llvm-branch-commits at lists.llvm.org
Wed Aug 12 04:42:24 PDT 2026
================
@@ -43,20 +43,30 @@ class UseAfterLifetimeEndBRVisitor : public BugReporterVisitor {
} // namespace
-static const Expr *getLifetimeBoundArg(const Expr *RetExpr) {
+static const Expr *getLifetimeBoundArg(const Expr *RetExpr,
+ const MemRegion *Region,
+ const ExplodedNode *N) {
const CallExpr *Expr = dyn_cast_or_null<CallExpr>(RetExpr);
if (!Expr)
return nullptr;
+
const FunctionDecl *FD = Expr->getDirectCallee();
if (!FD)
return nullptr;
+ const MemRegion *BaseReg = Region->getBaseRegion();
+
for (const ParmVarDecl *PVD : FD->parameters()) {
- if (PVD->hasAttr<LifetimeBoundAttr>()) {
- unsigned Idx = PVD->getFunctionScopeIndex();
- if (Idx < Expr->getNumArgs())
- return Expr->getArg(Idx);
- }
+ if (!PVD->hasAttr<LifetimeBoundAttr>())
+ continue;
+ unsigned Idx = PVD->getFunctionScopeIndex();
+
+ if (Idx >= Expr->getNumArgs())
+ continue;
+
+ const MemRegion *R = N->getSVal(Expr->getArg(Idx)).getAsRegion();
+ if (R && R->getBaseRegion() == BaseReg)
+ return Expr->getArg(Idx);
----------------
benedekaibas wrote:
The checker does report multiple parameters that are lifetimebound annotated. The problem was that the highlighting was incorrectly placed only on the first argument. I did not know the highlighting can be actually tested, but I figured out that it could, so I will add the test cases.
https://github.com/llvm/llvm-project/pull/215651
More information about the llvm-branch-commits
mailing list