[clang] [llvm] [NFC][analyzer] Extract bounds checking library (PR #202372)
DonĂ¡t Nagy via llvm-commits
llvm-commits at lists.llvm.org
Fri Jul 3 18:06:16 PDT 2026
================
@@ -0,0 +1,210 @@
+//===- BoundsChecking.h - Bounds checking related APIs ----------*- C++ -*-===//
+//
+// Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
+// See https://llvm.org/LICENSE.txt for license information.
+// SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
+//
+//===----------------------------------------------------------------------===//
+//
+// This file defines APIs for performing a bounds check (i.e. comparing a
+// symbolic Offset value to zero and a symbolic Extent value) and composing
+// descriptions that explain its results.
+//
+// This fulfills a similar role as `ProgramState::assumeInBound`, but uses
+// more accurate logic and heuristic workarounds to account for the quirks of
+// signed/unsigned conversions and the lack of cast modeling in the analyzer.
+//
+// As of now, this logic only supports the needs of `security.ArrayBound`, but
----------------
NagyDonat wrote:
> Also, this info might not be relevant to checker authors who want to use these facilities.
I intended this as a warning for checker authors that "right now, this is probably not yet ready for use in your checker" (but it will be in the future).
> I am not sure if it is a good idea to encode users and future plans in comments. This is likely to get stale.
I agree in general, but I felt that this information is relevant and I hope that I can pay attention to it and update it when the situation changes.
However, I can remove this paragraph if you prefer.
https://github.com/llvm/llvm-project/pull/202372
More information about the llvm-commits
mailing list