[compiler-rt] [llvm] [asan] Adopt sanitizer_common operator-new framework (PR #196388)

Justin T. Gibbs via llvm-commits llvm-commits at lists.llvm.org
Sun Sep 27 13:57:21 PDT 2026


================
@@ -83,8 +83,17 @@ COMMON_FLAG(
     "detect_leaks=false, or if __lsan_do_leak_check() is called before the "
     "handler has a chance to run.")
 COMMON_FLAG(bool, allocator_may_return_null, false,
-            "If false, the allocator will crash instead of returning 0 on "
-            "out-of-memory.")
+            "Controls allocator behavior on out-of-memory. C-allocator entry "
+            "points (malloc / calloc / realloc / aligned_alloc / "
+            "posix_memalign): default=false reports and aborts, true returns "
+            "nullptr. AddressSanitizer's operator new always runs the "
+            "std::get_new_handler() chain first per [new.delete.single]/3+/4 "
+            "regardless of this flag; on chain exhaustion default=false "
+            "reports and aborts for both forms, true throws std::bad_alloc "
+            "(throwing form) or returns nullptr (nothrow form). On Windows "
+            "the asan runtime is built without exceptions, so the throwing "
+            "form aborts even with true; the nothrow form still returns "
+            "nullptr.")
----------------
scsiguy wrote:

Following up: I took your release-notes suggestion. The behavior change is now described in
`llvm/docs/ReleaseNotes.md` (Changes to Sanitizers), and the flag text no longer has a
Windows note. It's also tool-neutral, so later adopters don't need to edit it:

> If false (default), the allocator aborts on out-of-memory. If true, allocation functions
that can report failure return null instead (for example, malloc and nothrow operator new).
Throwing operator new throws std::bad_alloc where the runtime supports it (for example,
AddressSanitizer built with exceptions) and aborts otherwise.

https://github.com/llvm/llvm-project/pull/196388


More information about the llvm-commits mailing list