================
@@ -3940,7 +3940,8 @@ ProgramStateRef MallocChecker::checkPointerEscapeAux(
if (const RefState *RS = State->get<RegionState>(sym))
if (RS->isAllocated() || RS->isAllocatedOfSizeZero())
- if (!IsConstPointerEscape || checkIfNewOrNewArrayFamily(RS))
+ if (!IsConstPointerEscape || checkIfNewOrNewArrayFamily(RS) ||
+ (Call && Call->argumentsMayEscape()))
----------------
NagyDonat wrote:
Thanks for looking these up!
> I have traced through all the cases and they are similar to each other.
Yes, these are all very similar testcases that IIRC were added by the same
commit. The "original version" is the test
```c++
// Callback is passed to a function defined in a system header.
void r11160612_4(void) {
char *x = malloc(12);
sqlite3_bind_text_my(0, x, 12, free); // no - warning
}
```
shows that this was intended to suppress a false positive of `unix.Malloc`
where the memory was released by passing `free` as a callback function to
[`sqlite3_bind_text()`](https://sqlite.org/c3ref/bind_blob.html) which – as
expected – calls the callback received in the fourth argument when the buffer
is no longer needed.
(Note that it is significant that the sqlite headers may be system headers –
IIRC `MallocChecker` has a heuristic that it assumes that functions _coming
from system headers_ do not release memory unless they are explicitly modeled
like `free()`.)
I think returning true from `argumentsMayEscape()` when there is a callback
argument is a very clumsy heuristic for suppressing this false positive with
`sqlite3_bind_text()`.
**I will create a commit that moves this suppression heuristic from
`argumentsMayEscape()` to `MallocChecker.cpp`.**
https://github.com/llvm/llvm-project/pull/225489
_______________________________________________
cfe-commits mailing list
[email protected]
https://lists.llvm.org/cgi-bin/mailman/listinfo/cfe-commits