================
@@ -3940,7 +3940,8 @@ ProgramStateRef MallocChecker::checkPointerEscapeAux(
if (const RefState *RS = State->get<RegionState>(sym))
if (RS->isAllocated() || RS->isAllocatedOfSizeZero())
- if (!IsConstPointerEscape || checkIfNewOrNewArrayFamily(RS))
+ if (!IsConstPointerEscape || checkIfNewOrNewArrayFamily(RS) ||
+ (Call && Call->argumentsMayEscape()))
----------------
benedekaibas wrote:
Yes, there are multiple ones failing.
```text
# | File
/Users/benedekaibas/Documents/llvm-project/clang/test/Analysis/malloc.cpp Line
72: Potential leak of memory pointed to by 'x' [unix.Malloc]
# | File
/Users/benedekaibas/Documents/llvm-project/clang/test/Analysis/malloc.cpp Line
88: Potential leak of memory pointed to by 'x' [unix.Malloc]
```
Here is the link for it:
https://github.com/llvm/llvm-project/blob/f96febaf2701fc5f1979a4e0b49bdd97cae3fdb6/clang/test/Analysis/malloc.cpp#L68
My fix also does not overcorrect into supressing genuine use-after-free's. I
rewrote the test case to actually hit uaf and make sure that an inlined
callback invocation still reports ua:
```cpp
void const_ptr_and_callback_def_param(int, const char* cs, int n, void
(*f)(void*) = free) {
char *s = const_cast<char *>(cs);
void *stat_v = static_cast<void *>(s);
f(stat_v);
}
void r11160612_3() {
char *x = (char*)malloc(12);
const_ptr_and_callback_def_param(0, x, 12);
*x = 7;
}
```
(my fix works with this case)
There are also multiple other failures in `malloc.mm`:
```cpp
static void releaseDataCallback (void *info, const void *data, size_t size) {
#pragma unused (info, size)
free((void*)data);
}
// Assume that functions which take a function pointer can free memory even if
// they are defined in system headers and take the const pointer to the
// allocated memory.
extern CGDataProviderRef UnknownFunWithCallback(void *info,
const void *data, size_t size,
CGDataProviderReleaseDataCallback releaseData)
__attribute__((visibility("default")));
void testUnknownFunWithCallBack() {
void* b = calloc(8, 8);
CGDataProviderRef p = UnknownFunWithCallback(0, b, 8*8, releaseDataCallback);
// warning here
}
```
I have traced through all the cases and they are similar to each other.
https://github.com/llvm/llvm-project/pull/225489
_______________________________________________
cfe-commits mailing list
[email protected]
https://lists.llvm.org/cgi-bin/mailman/listinfo/cfe-commits